Ghost MAC Address
We use Unifi UDM Pro for firewall and local network control for our customers. At one location, I have a device showing up in the firewall blocked traffic that is generating >100 blocked hits a min according to the Unifi monitoring system. Unifi shows the MAC address as 90:d0..... but no IP address.
Also using Advance IP scanner, this mac address does not show up
Unsing Wireshark with a filter of ether host 90:d0:...... Nothing shows up.
Doing a complete capture for 5 min and then doing a find in the capture using the MAC address, nothing shows up.
What am I missing? Is there a way to find this device on the network.
And for what its worth, I was doing a test on the local network for the new Kimwolf infection. The test for the public IP address of this network shows up on the Kimwolf ip list of addresses that the Kimwolf server has conversed with. I am trying to determine "IF" any local devices have been compromised.
Thanks, any help is appreciated.