Open cardosec

Case 67BE67 · Network · L3 Applied

Hunting with Flow Data

Practise as: Deep dive
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. NetFlow/IPFIX/VPC flow logs record 5-tuple, bytes, packets and timing without payload, so they survive encryption
  2. Beaconing detection: regular intervals and consistent sizes to one destination, allowing for jitter
  3. Exfil signals: large outbound byte ratios, new destinations, uploads at unusual hours
  4. Zeek adds protocol logs (conn, dns, ssl, http) with JA3/JA4 fingerprints for richer context
  5. Baseline east-west traffic so new SMB/RDP/WinRM pairs stand out

If the interviewer pushes back

  • How would an attacker blend C2 beacons to defeat interval-based detection?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.