DEV Community

Mark0
Mark0

Posted on

2026-10-01: Traffic analysis exercise - Natureforce

This traffic analysis exercise, titled "Natureforce," presents a scenario where a security operations center (SOC) analyst investigates alerts involving a Windows executable download from an unusual TCP port and CNCmachineRMS RAT C2 traffic. The exercise provides a packet capture (pcap) to analyze activity within a simulated Active Directory environment on the domain natureforce.com.

The objective is to perform network forensics to identify the infected client's IP, MAC address, hostname, and user account. Additionally, participants must extract and calculate the SHA-256 hash of the suspicious EXE file delivered over the network. This provides hands-on experience in incident response and pcap analysis.


Read Full Article

Top comments (0)