1/9
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced |
|---|
No study sessions yet.
SPAN
Switch Port Analyzer AKA Mirrored Port
Copies Ingress & Egress communication between ports to another port & Allows Monitoring
Functions as a network tap
tcpdump
CLI TOOL - Network Packet Analyzer
.pcap file
TCP/IP transmitted over network
FPC
Full Packet Capture
Captures entire packet; Header and Payload for ALL Traffic
Flow Collector
Record network traffic metadata and statistics - Capture Flow Information
Does NOT capture specific content flow
Allows alerts and highlights trends and patterns
NetFlow
Delivers NetFlow METADATA info to database
Utilizes IPFIX to define specific traffic flow based on packets with same characteristic (Destination, Origin, etc)
Zeek
Packet Sniffer Tool
Logs potentially interesting data
Unifies data into .json format
Performs data normalization
DGA
Domain Generation Algorithm
Dynamically changes domain names to circumvent blocklists for C2 networks.
Fast Flux Network
Method to hide presence of C2 networks by changing host IP Address in domain records using DGA
DGA Detection
Calls out to randomly generated Domains (Suspicious Looking)
NXDOMAIN errors
Secure Recursive DNS Resolver
Resolves DNS requests by querying DNS hierarchy then filters and blocks dangerous sites using Threat Intelligence.