<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Network Forensics on XSS3cut10n3r</title><link>https://xss3cut10n3r.com/tags/network-forensics/</link><description>Recent content in Network Forensics on XSS3cut10n3r</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sat, 03 Oct 2026 00:02:00 +0100</lastBuildDate><atom:link href="https://xss3cut10n3r.com/tags/network-forensics/index.xml" rel="self" type="application/rss+xml"/><item><title>NSA Codebreaker 2025 - Task 2: The Hunt Continues</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-2/</link><pubDate>Sat, 03 Oct 2026 00:02:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-2/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-2---the-hunt-continues---network-forensics"&gt;Task 2 - The Hunt Continues - (Network Forensics)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;With your help, the team concludes that there was clearly a sophisticated piece of malware installed on that endpoint that was generating some network traffic. Fortunately, DAFIN-SOC also has an IDS which retained the recent network traffic in this segment.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;DAFIN-SOC has provided a PCAP to analyze. Thoroughly evaluate the PCAP to identify potential malicious activity.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="downloads"&gt;Downloads&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;PCAP to analyze:&lt;/strong&gt; &lt;code&gt;traffic.pcap&lt;/code&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="task"&gt;Task&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;Submit all the IP addresses that are assigned to the malicious device, one per line.&lt;/strong&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="writeup"&gt;Writeup&lt;/h2&gt;&#10;&lt;p&gt;Upon opening the PCAP in Wireshark, I was greeted by approximately 2,400 packets consisting primarily of IPv4 and ARP traffic.&lt;/p&gt;</description></item></channel></rss>