By Cary Wright, VP Product Management, Endace
The SOC implemented a sophisticated, multi-layered security architecture centered around visibility and integration:
-
- Network Capture Layer: EndaceProbe appliances performed full packet capture, creating a complete record of all network activity.
- Log Generation and Analysis: The Endace systems generated metadata through tools like Zeek, which was then forwarded to Splunk and Cisco security tools for analysis.
- Threat Detection Systems: Cisco Secure Firewall provided intrusion detection (running in non-blocking mode to avoid disrupting vendor demonstrations while still identifying potential threats).
- Integration Layer: All components were interconnected, allowing analysts to pivot seamlessly from alerts directly to the relevant packet data, providing context for rapid investigation.
- File Analysis Pipeline: Files transmitted across the network were extracted and analyzed:
-
-
- 287,000+ files extracted from network traffic
- 26,374 files sent to Splunk Attack Analyzer
- 7,546 files forwarded to Cisco Malware Analytics for in-depth examination
-
Key Security Findings and Trends
The SOC’s monitoring revealed several concerning security trends:
1. Declining Encryption Levels
One surprising finding was a drop in the percentage of encrypted traffic, from approximately 80% in 2024 to 74% in 2025. This regression toward “the dark past” of unencrypted communications creates significant security vulnerabilities.
More troubling was the increase in weak encryption (TLS 1.0/1.1) to 40% of encrypted traffic, along with the continued presence of plaintext password transmission.
2. Plaintext Passwords Continue
Though trending downward over the years, plaintext passwords remain a persistent problem, showing that the power of a strong password is nothing without an encrypted communication protocol!
-
-
- 2020: 96,361 cleartext passwords (2,178 unique accounts)
- 2022: 55,525 cleartext passwords (2,210 unique accounts)
- 2023: 36,910 cleartext passwords (424 unique accounts)
- 2024: 20,916 cleartext passwords (99 unique accounts)
- 2025: 1,807 cleartext passwords (87 unique accounts)
-
3. Legacy Protocol Persistence: POP3 Refuses to Die
The SOC discovered continued use of vulnerable legacy protocols:
-
-
- POP3 (unencrypted email retrieval)
- Non-secured SMTP (email transmission)
- Unencrypted IMAP
-
4. Advanced Threat Techniques
The SOC identified several sophisticated attack techniques, including:
-
-
- New domain generation algorithm (DGA) approaches using combinations of 2-3 random words
- Command and control (C2) traffic
- Cleartext transmission of sensitive data
- Unsecured translation services transmitting text and audio in the clear
- Exposed CCTV camera feeds
-
The Value of Complete Network Visibility
The collaborative SOC deployment at RSAC 2025 demonstrated the crucial role that full packet capture plays in modern security operations. By capturing and analyzing every packet traversing the network, security teams gained:
-
-
- Complete visibility into all network communications
- Contextual evidence for security investigations
- Rapid response capabilities through integrated tools
- Retrospective analysis of historical network data
-
The integration between Endace’s packet capture technology and Cisco’s security suite enabled a powerful workflow: alerts from security tools could be immediately investigated by pivoting directly to the relevant network traffic, dramatically reducing investigation time.
Key Takeaways for Security Teams
Based on the RSAC 2025 SOC experience, organizations should consider these best practices:
-
-
- Deploy comprehensive network monitoring with full packet capture for complete visibility
- Implement integrated security tools that work together seamlessly
- Focus on encryption enforcement to protect sensitive data in transit
- Eliminate legacy protocols that transmit data in cleartext
- Use personal VPNs when connecting to public networks
- Keep operating systems patched and maintain robust configuration management
-
The Endace and Cisco-powered SOC at RSAC 2025 demonstrated that comprehensive network visibility remains fundamental to effective security operations. As threats grow more sophisticated, the ability to see, analyze, and respond to every packet traversing the network becomes increasingly critical.
By integrating full packet capture with advanced security analytics, organizations can build security operations centers that provide both the breadth and depth of visibility needed to detect and respond to today’s most sophisticated threats.
This blog post is based on information shared during the “PROTECTED: The 6th Annual Report from the SOC at RSAC” session at RSA Conference 2025.
For more blogs in our Endace SOC series, see here:
https://blog.endace.com/tag/soc/
