Trying to figure what type of attack this is

asked 2019-11-09

I have the file here I am trying to figure what type of attack this is! I believe it is a DDOS attack but I am just not sure. Thanks.

The file name is Lab2 - NMAP-Scan.pcap. Is this a nmap scan file? Have you checked the nmap docs?

Chuckc ( 2019-11-09 )

answered 2019-11-09

Chuckc gravatar image

updated 2019-11-09 18:06:03 +0000

There is a nmap scan buried in the capture. Is that what you're looking for?
Work down through the Statistics menus.
Protocol Hierarchy - not very interesting for this capture
Conversations - will help to find a very large conversation that can be excluded from analysis
Also pay attention to the ports being accessed. Does this look like expected traffic?
Endpoints - who are the chatty nodes and what are they doing?
Good luck!

Asked: 2019-11-09

Seen: 161 times

Last updated: Nov 09 '19