QuestionQ26

Security Operations

A company finds that its proprietary information is being sold on the dark web. A security analyst uses threat hunting to look for indicators of compromise. After using a network packet-capture tool, the analyst identifies millions of packets resembling the following:

Question Image

The analyst finds no other abnormalities. Which of the following is the most likely malicious activity in this scenario?

Explanation

A very large volume of outbound ICMP Echo Request packets with data payloads can indicate ICMP tunneling, in which encoded information is sent inside ICMP packets to evade controls focused on common application protocols. This is consistent with exfiltrating proprietary data over an alternative protocol. MITRE ATT&CK identifies ICMP as a non-application-layer protocol that adversaries can misuse for communications and notes anomalous ICMP traffic as a potential indicator of exfiltration or remote control.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!