Endace Packet Forensics Files: Episode #63

Original Entry by : Michael Morris

In Episode 63, Michael talks to Jack Chan, Vice President, Product Management at Fortinet

By Michael Morris, Director of Global Business Development, Endace


Michael Morris, Director of Global Business Development, Endace

Why NDR is Evolving—And What Enterprises Should Demand From It

In this episode of The Packet Forensic Files, I spoke with Jack Chan, VP of Product and Field CTO at Fortinet, about what sets a strong Network Detection and Response (NDR) solution apart. Jack explained that while many vendors claim to offer NDR, the best solutions help security teams see deep into their networks, spot threats early, and look back in time to understand what really happened before and after an incident.

Jack pointed out that most companies already have too many security tools creating alerts. That’s why it’s so important for NDR to work well with other tools like EDR—so SOC teams know which alerts really matter. He also shared how AI and machine learning are helping to detect threats even in encrypted traffic, and how newer tech like generative AI is making it easier for analysts to investigate issues without writing complex queries.

We talked about the benefits of using NDR alongside firewalls. Since NDR is passive, it can show you how clean or risky your network is without disrupting anything. But when NDR spots a threat, teams need to decide—should it trigger an automatic response or wait for human approval? Jack recommends using automation carefully, with some human oversight.

Finally, Jack reminded us that technology alone isn’t enough. Security starts with people—whether it’s developers writing secure code or staff avoiding risky clicks. No matter how advanced your tools are, the human factor still plays a huge role in keeping networks safe.

Don’t miss this episode as Jack shares practical tips, real-world examples, and a clear-eyed view of where the NDR space is heading.

 

Other episodes in the Secure Networks video/audio podcast series are available here. Or listen to the podcast here or on your favorite podcast platform.


Threat actors are recording PCAPs, maybe you should too?

Original Entry by : Barry "Baz" Shaw

By Barry “Baz” Shaw, Senior Engineering Manager, Technology Partner Programs, Endace


Barry

On Aug 29th, Government Cybersecurity agencies from around the world released a joint advisory detailing how nation-state threat actors are compromising networks across the world, particularly in the US, Australia, Canada, New Zealand and the UK: www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a www.darkreading.com/cybersecurity-operations/cisa-fbi-nsa-warn-chinese-global-espionage-system

These attacks are primarily focussed on telecommunications, government, lodging and military networks, and the tactics, techniques, and procedures (TTP) overlaps with APT (Advanced Persistent Threat) actors linked to multiple China-based entities. These threat actors are exploiting well-known vulnerabilities in VPN servers and web user interfaces on switches and routers.  Even devices not owned by targets of interest are being compromised in order to provide additional attack pathways to the intended targets.  Upon gaining a foothold in a network, persistence is achieved by modifying ACLs, opening services on non-standard ports to avoid detection, and tunnelling C2 and exfiltrated data to obfuscate malicious activity.

Of note in this particular instance is the use of PCAP collection on the target network by the threat actors.  Once they’ve gained a foothold on the network infrastructure, the native capability of some routers to record PCAPs is then used to capture TACACS+ (authentication) traffic.  When transmitted in clear text (or weakly encrypted) this authentication traffic exposes users credentials which can then be used to elevate the attacker’s access and enable them to move laterally across the network.

The use of network sniffing to extract credentials in authentication traffic is a common technique of threat actors (attack.mitre.org/versions/v17/techniques/T1040/).  As we continue to see the stubborn use of unencrypted and weakly-encrypted protocols on networks, these insecure communications remain prime targets for credential gathering.  Additionally, the uses of maliciously collected PCAP is evolving, with the ArcaneDoor campaign taking this a step further and exfiltrating captured PCAPs for remote analysis (attack.mitre.org/campaigns/C0046/).  Exfiltrated PCAPs may contain anything from authentication data to file objects.

PCAP data is the ground-truth for what is happening on the network, and it is the source that all other network and security telemetry is derived from.  Threat actors know this and value the raw unfiltered and unsampled intel that it provides about the target.  This begs the question: if your adversaries see value in collecting PCAPs off your network, shouldn’t you be capturing full PCAP too!? 

If you are not recording your network traffic, your security team has less visibility into network activity than your attackers – which makes the job of protecting your network impossibly difficult. With PCAP at their fingertips, SOC analysts can see exactly what’s happening on the network, making for faster, more accurate investigation and resolution of security incidents – as this excellent blog post from Cisco’s Steve Nowell describes.

That full PCAP data is so valuable to attackers also highlights a stark warning that wise defenders should heed. PCAP data must be protected and secured to the highest standards.  Can you trust packet capture solutions that aren’t FIPS and Common Criteria certified? Or packet capture sources that can’t be properly locked down and protected from access by attackers?

For more blogs in our Endace SOC series, see here:
https://blog.endace.com/tag/soc/ 


Network Visibility in Action: Endace and Cisco Drive SOC Defenses at RSAC 2025

Original Entry by : Cary Wright

By Cary Wright, VP Product Management, Endace


Cary Wright, VP Product Management, Endace

Uncovering insights from the 6th Annual Security Operations Center at RSA Conference

For the sixth consecutive year, a dedicated Security Operations Center (SOC) monitored the RSA Conference (RSAC) network, protecting a dynamic environment serving over 40,000 attendees.  A collaboration between Endace and Cisco (and other security partners), the SOC provided real-world insights into current threat landscapes and security challenges, and demonstrated the critical importance of comprehensive network monitoring and real-time threat detection in large-scale environments.

The 2025 SOC team consisted of:

  • 5 Endace analysts
  • 9 Cisco/Splunk analysts
  • 3 dedicated threat hunters
  • 3 managers

 

Network Monitoring at Unprecedented Scale

The SOC captured and analyzed an astounding volume of data flowing through the conference network:

  • 40+ billion packets captured (more than double the 19 billion from the previous year)
  • 33 TB of packet data (up from 17TB)
  • Peak bandwidth usage of 3.4 Gbps (up from 2.2 Gbps)
  • 615 million total sessions (increased from 383 million)
  • 793 million logs captured
  • 287,000 files extracted with 26,374 submitted for deeper analysis

Endace’s VP of Product Management Cary Wright explained the scope: “We tapped into the network and recorded everything—all the packets that traveled across that network—approximately 30 terabytes of data over the course of the whole conference.”

The Technical Architecture: Integration in Action

The SOC implemented a sophisticated, multi-layered security architecture centered around visibility and integration:

    1. Network Capture Layer: EndaceProbe appliances performed full packet capture, creating a complete record of all network activity.
    2. Log Generation and Analysis: The Endace systems generated metadata through tools like Zeek, which was then forwarded to Splunk and Cisco security tools for analysis.
    3. Threat Detection Systems: Cisco Secure Firewall provided intrusion detection (running in non-blocking mode to avoid disrupting vendor demonstrations while still identifying potential threats).
    4. Integration Layer: All components were interconnected, allowing analysts to pivot seamlessly from alerts directly to the relevant packet data, providing context for rapid investigation.
    5. File Analysis Pipeline: Files transmitted across the network were extracted and analyzed: 
      • 287,000+ files extracted from network traffic
      • 26,374 files sent to Splunk Attack Analyzer
      • 7,546 files forwarded to Cisco Malware Analytics for in-depth examination

Key Security Findings and Trends

The SOC’s monitoring revealed several concerning security trends:

1. Declining Encryption Levels

One surprising finding was a drop in the percentage of encrypted traffic, from approximately 80% in 2024 to 74% in 2025. This regression toward “the dark past” of unencrypted communications creates significant security vulnerabilities.

More troubling was the increase in weak encryption (TLS 1.0/1.1) to 40% of encrypted traffic, along with the continued presence of plaintext password transmission.

2. Plaintext Passwords Continue

Though trending downward over the years, plaintext passwords remain a persistent problem, showing that the power of a strong password is nothing without an encrypted communication protocol!

      • 2020: 96,361 cleartext passwords (2,178 unique accounts)
      • 2022: 55,525 cleartext passwords (2,210 unique accounts)
      • 2023: 36,910 cleartext passwords (424 unique accounts)
      • 2024: 20,916 cleartext passwords (99 unique accounts)
      • 2025: 1,807 cleartext passwords (87 unique accounts)
3. Legacy Protocol Persistence: POP3 Refuses to Die

The SOC discovered continued use of vulnerable legacy protocols:

      • POP3 (unencrypted email retrieval)
      • Non-secured SMTP (email transmission)
      • Unencrypted IMAP
4. Advanced Threat Techniques

The SOC identified several sophisticated attack techniques, including:

      • New domain generation algorithm (DGA) approaches using combinations of 2-3 random words
      • Command and control (C2) traffic
      • Cleartext transmission of sensitive data
      • Unsecured translation services transmitting text and audio in the clear
      • Exposed CCTV camera feeds

The Value of Complete Network Visibility

The collaborative SOC deployment at RSAC 2025 demonstrated the crucial role that full packet capture plays in modern security operations. By capturing and analyzing every packet traversing the network, security teams gained:

      • Complete visibility into all network communications
      • Contextual evidence for security investigations
      • Rapid response capabilities through integrated tools
      • Retrospective analysis of historical network data

The integration between Endace’s packet capture technology and Cisco’s security suite enabled a powerful workflow: alerts from security tools could be immediately investigated by pivoting directly to the relevant network traffic, dramatically reducing investigation time.

Key Takeaways for Security Teams

Based on the RSAC 2025 SOC experience, organizations should consider these best practices:

      • Deploy comprehensive network monitoring with full packet capture for complete visibility
      • Implement integrated security tools that work together seamlessly
      • Focus on encryption enforcement to protect sensitive data in transit
      • Eliminate legacy protocols that transmit data in cleartext
      • Use personal VPNs when connecting to public networks
      • Keep operating systems patched and maintain robust configuration management

The Endace and Cisco-powered SOC at RSAC 2025 demonstrated that comprehensive network visibility remains fundamental to effective security operations. As threats grow more sophisticated, the ability to see, analyze, and respond to every packet traversing the network becomes increasingly critical.

By integrating full packet capture with advanced security analytics, organizations can build security operations centers that provide both the breadth and depth of visibility needed to detect and respond to today’s most sophisticated threats.

This blog post is based on information shared during the “PROTECTED: The 6th Annual Report from the SOC at RSAC” session at RSA Conference 2025.

For more blogs in our Endace SOC series, see here:
https://blog.endace.com/tag/soc/