2026-02-28 - TRAFFIC ANALYSIS EXERCISE: EASY AS 123

NOTE:

ASSOCIATED FILE:

 

BACKGROUND

As dynamic go-getter at a Security Operations Center (SOC), you check the Security Information and Event Management (SIEM) system and find several signature hits for NetSupport Manager RAT from 45.131.214[.]85 over TCP port 443. The activity started on 2026-02-28 at 19:55 UTC.

Using this information, you quickly retrieve a packet capture (pcap) of the traffic from the internal IP address that triggered these alerts. It's all on you now! You're expected to write up an incident report, so someone can track down the infected computer and put a stop to this nonsense!

The characteristics of your environment are:

Armed with pcap, you intend to find that infected host.

 


Shown above: You, presumably talking to the infected Windows host.

 

YOUR TASK

For this exercise, answer the following questions for your incident report:

 

ANSWERS

 

Click here to return to the main page.