Overview
When an alert fires, you need to confirm impact and scope fast. Upload a PCAP/PCAPNG and let the analyzer surface beaconing cadence, DNS tunneling, JA3/JA4 outliers, SNI/certificate anomalies, QUIC/TLS handshake issues, and exfiltration patterns. You’ll get a concise summary plus extractable IOCs for rapid enrichment and containment.
- What you’ll see: periodicity and jitter analysis, rare destination scoring, SNI/JA3/JA4 outliers, TLS/QUIC negotiations and fallbacks, DNS status/truncation patterns, outbound volume spikes
- Best for: malware C2 triage, suspicious egress, account takeover investigations, lateral movement scoping
- Works with: classic DNS/TLS/HTTP as well as DoH, DoT, QUIC/HTTP/3, VPN tunnels, and proxy/CDN edges
What to look for
- Beaconing: small, periodic flows to rare domains/IPs; low entropy payload sizes; jittered intervals
- DNS tunneling: long/high-entropy labels, many TXT/CNAME, fixed cadence, unusual egress resolvers
- TLS anomalies: SNI mismatch to rDNS, self-signed/uncommon issuers, version/cipher mismatch, alerts
- JA3/JA4 outliers: rare fingerprints against sensitive endpoints or mismatched to user agents
- QUIC/DoH behavior: repeated handshake retries or downgrades to TCP; DoH spikes tied to suspicious hosts
- Exfiltration: sustained outbound volume, many POST-like flows, or large responses to uncommon destinations
- Lateral movement: internal SMB/Kerberos/LDAP bursts, RDP/SSH scans, unexpected admin shares
Capture tips
- Capture at the egress (gateway/WAN edge) to see true destinations and TLS/QUIC handshakes.
- Include DNS traffic (UDP/TCP 53) and, when applicable, DoT/DoH or UDP/443 for QUIC.
- Disable NIC offloads (LRO/GRO/TSO/checksum) on capture interfaces to preserve timing and header integrity.
- Align with alert windows; keep a focused timeframe (fits within the 10 MB demo limit).
- Preserve the original PCAP read-only, compute a hash (e.g., SHA-256), and document capture context for IR.
Example walkthrough
- Load the alert window PCAP and pivot to the suspect host and egress flows.
- Check periodicity view for beaconing cadence; review rare destination scoring and WHO (IP/ASN/domain).
- Open TLS/QUIC details: versions/ciphers, SNI, certificate hints, JA3/JA4, ALPN/fallback patterns.
- Inspect DNS behavior: long labels, TXT/CNAME spikes, TC bit and TCP fallbacks, resolver latency.
- Assess exfil indicators: sustained outbound bytes and unusual POST-like timing (if visible).
- Export IOCs (IPs, hostnames/SNI, JA3/JA4, ports) and attach the summary to your ticket.
Common scenarios
- Malware C2 over HTTPS: periodic small requests with rare SNI and unusual JA3 → block and hunt peers
- DNS tunneling exfil: long labels to a single domain at fixed intervals → contain and rotate resolvers
- QUIC blocked → fallback: repeated UDP/443 retries then TCP to same host → inspect middleboxes/policy
- Internal lateral movement: SMB/Kerberos bursts and RDP scans → isolate host and review auth logs
SOC Triage FAQ
Look for periodic connections with fixed or jittered intervals to rare destinations, plus unusual SNI and JA3/JA4 fingerprints.
Yes—watch for long/high-entropy labels, TXT/CNAME spikes, fixed-interval queries, and steady outbound volume.
Yes—handshake metadata (SNI, ALPN, versions/ciphers), timing, and retry/fallback patterns are highly indicative even without decryption.
IPs, hostnames/SNI, JA3/JA4, ports, and URLs (if visible). Use them for SIEM/SOAR enrichment and blocking.
Keep the original PCAP read-only, compute and store a cryptographic hash, and document capture context and timeline. Export reports with timestamps and flow references.