Case 10E94E · Network · L2 Practitioner
Printer Scans the Subnet
Practise as: Incident drill
Live alertIDS fires at 11:20: 10.20.5.33, the third-floor printer, is sending SYNs to ports 445 and 3389 across all of 10.20.0.0/16.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Internal SMB/RDP sweep from an IoT device suggests compromise and discovery ahead of lateral movement
- Contain: move the printer to a quarantine VLAN or shut its switch port; keep a packet capture
- Check which hosts responded and whether any follow-on connections or authentications succeeded
- Review printer firmware, default creds and management interfaces; reimage or replace device
- Lesson: printers belong in an isolated segment with no reason to initiate SMB/RDP to clients
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.