Case 67BE67 · Network · L3 Applied
Hunting with Flow Data
Practise as: Deep dive
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- NetFlow/IPFIX/VPC flow logs record 5-tuple, bytes, packets and timing without payload, so they survive encryption
- Beaconing detection: regular intervals and consistent sizes to one destination, allowing for jitter
- Exfil signals: large outbound byte ratios, new destinations, uploads at unusual hours
- Zeek adds protocol logs (conn, dns, ssl, http) with JA3/JA4 fingerprints for richer context
- Baseline east-west traffic so new SMB/RDP/WinRM pairs stand out
If the interviewer pushes back
- How would an attacker blend C2 beacons to defeat interval-based detection?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.