Analyzing Network Traffic For Incidents
Overview
Cybersecurity skill for analyzing network traffic for incidents. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"analyzing network traffic for incidents"
"Analyzes network traffic captures and flow data to identify adversary activity d"
SIEM alerts on anomalous network traffic patterns requiring deeper investigation
C2 beaconing is suspected and needs confirmation through packet-level analysis
Data exfiltration volume or destination must be quantified from network evidence
Lateral movement between systems needs to be traced through network connections
An IDS/IPS alert requires packet-level validation to confirm or dismiss
Do not use for host-based forensic analysis (process execution, file system artifacts); use endpoint forensics tools instead.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Full packet capture (PCAP) infrastructure or on-demand capture capability (network tap, SPAN port)
- Wireshark installed on the analysis workstation with appropriate display filters knowledge
- Zeek (formerly Bro) deployed for network metadata generation (conn.log, dns.log, http.log, ssl.log)
- NetFlow/IPFIX collection from network devices for traffic flow analysis
- Network architecture diagram showing VLAN layout, firewall placement, and monitoring points
- Threat intelligence feeds for correlating observed network indicators
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Scope the Analysis — Define what network traffic artifacts or data sources to examine and the investigation timeline.
- Preserve Evidence — Create forensic copies of relevant data. Maintain chain of custody documentation.
- Extract Key Indicators — Use incidents to parse and extract relevant network traffic data points from collected artifacts.
- Correlate Findings — Cross-reference extracted data with other sources (threat intel, logs, timelines).
- Build Timeline — Construct a chronological sequence of events related to network traffic.
- Document Analysis — Write findings report with evidence, conclusions, and recommendations.
Tools
- incidents — Primary tool for this skill
- Forensic Toolkit — Evidence collection and analysis
- Timeline Tools — Chronological event reconstruction
- Log Analysis Platform — Centralized log parsing and search
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: analyzing-network-traffic-for-incidents3description: Use when analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection. '.4license: Apache-2.05---67# Analyzing Network Traffic For Incidents89## Overview1011Cybersecurity skill for analyzing network traffic for incidents. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "analyzing network traffic for incidents"16- "Analyzes network traffic captures and flow data to identify adversary activity d"171819- SIEM alerts on anomalous network traffic patterns requiring deeper investigation20- C2 beaconing is suspected and needs confirmation through packet-level analysis21- Data exfiltration volume or destination must be quantified from network evidence22- Lateral movement between systems needs to be traced through network connections23- An IDS/IPS alert requires packet-level validation to confirm or dismiss2425**Do not use** for host-based forensic analysis (process execution, file system artifacts); use endpoint forensics tools instead.262728## When NOT to Use2930- When you lack proper authorization for testing31- For production systems without change management32- When the task requires legal or compliance expertise beyond technical scope333435## Prerequisites3637- Full packet capture (PCAP) infrastructure or on-demand capture capability (network tap, SPAN port)38- Wireshark installed on the analysis workstation with appropriate display filters knowledge39- Zeek (formerly Bro) deployed for network metadata generation (conn.log, dns.log, http.log, ssl.log)40- NetFlow/IPFIX collection from network devices for traffic flow analysis41- Network architecture diagram showing VLAN layout, firewall placement, and monitoring points42- Threat intelligence feeds for correlating observed network indicators4344## Workflow4546```python47# Example: IOC detection48import re4950IOC_PATTERNS = {51 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",52 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",53 "hash_md5": r"\b[a-f0-9]{32}\b",54 "hash_sha256": r"\b[a-f0-9]{64}\b",55}5657def extract_iocs(text: str) -> dict:58 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}59```60611. **Scope the Analysis** — Define what network traffic artifacts or data sources to examine and the investigation timeline.622. **Preserve Evidence** — Create forensic copies of relevant data. Maintain chain of custody documentation.633. **Extract Key Indicators** — Use incidents to parse and extract relevant network traffic data points from collected artifacts.644. **Correlate Findings** — Cross-reference extracted data with other sources (threat intel, logs, timelines).655. **Build Timeline** — Construct a chronological sequence of events related to network traffic.666. **Document Analysis** — Write findings report with evidence, conclusions, and recommendations.6768## Tools6970- **incidents** — Primary tool for this skill71- **Forensic Toolkit** — Evidence collection and analysis72- **Timeline Tools** — Chronological event reconstruction73- **Log Analysis Platform** — Centralized log parsing and search747576## Process77781. **Reconnaissance** — Gather target information, identify attack surface, enumerate services791. **Analysis/Exploitation** — Execute the technique, analyze results, document findings801. **Reporting** — Document IOCs, write findings, provide remediation recommendations8182## Verification8384- [ ] All network traffic procedures executed completely and documented85- [ ] Findings validated against multiple data sources86- [ ] False positives identified and filtered87- [ ] Results documented with evidence and timestamps88- [ ] Recommendations provided with risk-based prioritization8990## Anti-Rationalization Table9192| Rationalization | Reality |93|---|---|94| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |95| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |96| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |