Use case · SOC

SOC Triage

by My Network Consultant

From alert to evidence — surface beaconing, tunneling, and suspicious TLS/QUIC patterns in minutes.

SOC · IR · Threat Hunting JA3/JA4 · SNI · DNS tunneling · Beaconing QUIC / TLS / DoH PCAP / PCAPNG

Overview

When an alert fires, you need to confirm impact and scope fast. Upload a PCAP/PCAPNG and let the analyzer surface beaconing cadence, DNS tunneling, JA3/JA4 outliers, SNI/certificate anomalies, QUIC/TLS handshake issues, and exfiltration patterns. You’ll get a concise summary plus extractable IOCs for rapid enrichment and containment.

  • What you’ll see: periodicity and jitter analysis, rare destination scoring, SNI/JA3/JA4 outliers, TLS/QUIC negotiations and fallbacks, DNS status/truncation patterns, outbound volume spikes
  • Best for: malware C2 triage, suspicious egress, account takeover investigations, lateral movement scoping
  • Works with: classic DNS/TLS/HTTP as well as DoH, DoT, QUIC/HTTP/3, VPN tunnels, and proxy/CDN edges

What to look for

  • Beaconing: small, periodic flows to rare domains/IPs; low entropy payload sizes; jittered intervals
  • DNS tunneling: long/high-entropy labels, many TXT/CNAME, fixed cadence, unusual egress resolvers
  • TLS anomalies: SNI mismatch to rDNS, self-signed/uncommon issuers, version/cipher mismatch, alerts
  • JA3/JA4 outliers: rare fingerprints against sensitive endpoints or mismatched to user agents
  • QUIC/DoH behavior: repeated handshake retries or downgrades to TCP; DoH spikes tied to suspicious hosts
  • Exfiltration: sustained outbound volume, many POST-like flows, or large responses to uncommon destinations
  • Lateral movement: internal SMB/Kerberos/LDAP bursts, RDP/SSH scans, unexpected admin shares

Capture tips

  • Capture at the egress (gateway/WAN edge) to see true destinations and TLS/QUIC handshakes.
  • Include DNS traffic (UDP/TCP 53) and, when applicable, DoT/DoH or UDP/443 for QUIC.
  • Disable NIC offloads (LRO/GRO/TSO/checksum) on capture interfaces to preserve timing and header integrity.
  • Align with alert windows; keep a focused timeframe (fits within the 10 MB demo limit).
  • Preserve the original PCAP read-only, compute a hash (e.g., SHA-256), and document capture context for IR.

Example walkthrough

  1. Load the alert window PCAP and pivot to the suspect host and egress flows.
  2. Check periodicity view for beaconing cadence; review rare destination scoring and WHO (IP/ASN/domain).
  3. Open TLS/QUIC details: versions/ciphers, SNI, certificate hints, JA3/JA4, ALPN/fallback patterns.
  4. Inspect DNS behavior: long labels, TXT/CNAME spikes, TC bit and TCP fallbacks, resolver latency.
  5. Assess exfil indicators: sustained outbound bytes and unusual POST-like timing (if visible).
  6. Export IOCs (IPs, hostnames/SNI, JA3/JA4, ports) and attach the summary to your ticket.

Common scenarios

  • Malware C2 over HTTPS: periodic small requests with rare SNI and unusual JA3 → block and hunt peers
  • DNS tunneling exfil: long labels to a single domain at fixed intervals → contain and rotate resolvers
  • QUIC blocked → fallback: repeated UDP/443 retries then TCP to same host → inspect middleboxes/policy
  • Internal lateral movement: SMB/Kerberos bursts and RDP scans → isolate host and review auth logs

SOC Triage FAQ

Look for periodic connections with fixed or jittered intervals to rare destinations, plus unusual SNI and JA3/JA4 fingerprints.

Yes—watch for long/high-entropy labels, TXT/CNAME spikes, fixed-interval queries, and steady outbound volume.

Yes—handshake metadata (SNI, ALPN, versions/ciphers), timing, and retry/fallback patterns are highly indicative even without decryption.

IPs, hostnames/SNI, JA3/JA4, ports, and URLs (if visible). Use them for SIEM/SOAR enrichment and blocking.

Keep the original PCAP read-only, compute and store a cryptographic hash, and document capture context and timeline. Export reports with timestamps and flow references.
We use cookies & process data
By using this site, you agree to our Terms and Privacy Policy. We process file uploads for network analysis only.