network-protocols
Network protocol internals for detection engineering — DNS resolution chain and tunnelling indicators, TLS handshake and certificate anomalies, SMB authentication and lateral movement surface, HTTP/S C2 patterns (beaconing, jitter, domain fronting), LDAP bind and search patterns, RDP session mechanics, WinRM/PSRemoting transport, SMTP relay and header analysis, and the telemetry each protocol produces across detection platforms. Use when authoring detections that need to understand protocol-level behaviour to distinguish malicious from legitimate traffic.
Pinned to revision 591443442d56, so it is the text this page describes rather than whatever the author pushed since.
Files
Every link opens the file at its source, pinned to the revision this page describes.