The Academy is free // the war room is optional
DAEMONCORE // ACADEMY
ZERO-CLOUD // 100% LOCAL AIR-GAPPED IN-BROWSER DISSECTOR

PCAP & Frame Forensics Inspector

EVIDENCE PRESET:
THREAT ACTOR:APT29 (Cozy Bear) / UNC4192|TECHNIQUE:T1071.004 - DNS Application Layer Protocol
ACTIVE FILE:incident_evidence.pcap

A compromised engineering workstation (10.0.1.45) queries high-entropy base64 subdomains against an internal DNS resolver (10.0.1.2) to exfiltrate system reconnaissance and receive secondary stager stages without direct outbound TCP/HTTPS.

INVESTIGATION OBJECTIVES:
  • What is the average subdomain entropy and length?
  • Which rogue apex domain is authoritative for the queries?
  • Can you decode the stage fragment hidden within the TXT records?
KEY CORRELATED IOCS:
10.0.1.45 (Compromised Host)198.51.100.88 (External C2 DNS)c2-cdn-edge.cloud
FRAMES: 0 / 0|TOTAL BYTES: 0.0 KB|SPAN: 0.000s
No.
Time (s)
Source
Destination
Protocol
Length
Info
No packets match current filter or capture is empty.
Select a frame from the packet table to inspect protocol layers.
Select a frame to load raw byte stream.