Investigative analysis

profileLifelove
report_2.pdf

Fordham University CISC 6680 Intrusion Detection & Network Forensics

Professor: Ravi Tanikella

Packet Analysis Assignment 3

Scenario You are working as an analyst reviewing suspicious network events at Fictitious Corporations’ Security Operations Center (SOC). Things have been quiet for a while. However, you notice several alerts occur within minutes of each other on separate hosts.

Your were able to retrieve a pcap of network traffic, and you have a list of Snort and Suricata events from the activity. You are also able to capture the following image

Your Report Submission

You'll need to write a report. Your report should include with detailed screen shots with marking identifying each of the items listed below.

• When did the event take place? E.G. Date and time range of the traffic in question. • IP address, MAC address, and host name for each of the computers. • Description of the activity for each of the computers (what happened, if the host became

infected, any details, etc.). • A screenshot for each infected host with filters applied so you only see traffic for that host • Infection vector and payload if present. Correlate with all files to confirm your findings. • A conclusion with recommendations for any follow-up actions.