Cisco Live APJ 2025: Endace Full Packet Capture Finds Active Directory Credentials in Clear Text

Original Entry by : Daniel Lawson

By Daniel Lawson, Senior Engineering Manager – Software, Endace
and Shaun Coulter, Technical Solutions Architect, Cisco


Daniel Lawson, Endace

Summary

The Mission of the SOC at events like Cisco Live is:

Protect, Educate, Innovate.

While at Cisco Live APJC 2025, we were able to meet these objectives in a very direct way.

When Threat Hunting using full packet capture data we quickly identified a series of unencrypted Active Directory connections from conference attendees to their organization’s AD servers. Within an hour of identifying and documenting the issue the SOC had contacted the organization’s IT team and invited team members who were attending the conference to the SOC to walk them through the evidence.

We were only able to discover this serious security issue because EndaceProbe had recorded full continuous packet data for the entire conference, and EndaceVision provided us with a UI to rapidly threat hunt by searching, visualizing, and analyzing the packet data.

Curious Threat Hunt Leads to Rapid Discovery

During one of the SOC tours, one of my fellow engineers was discussing having identified some Kerberos traffic on the network. This prompted me to wonder if there was any LDAP traffic, as that is another common authentication protocol, and while it should be deployed with an encrypted communication channel, it isn’t always.

Sure enough, an EndaceVision query with an “Application is ldap” filter showed some unencrypted LDAP traffic!

EndaceVision Query Shows Unencrypted LDAP traffic
EndaceVision Query Shows Unencrypted LDAP traffic

Sending this traffic to Endace’s hosted Wireshark allowed me to view the raw packet decodes and confirm that these were completed connections, involving what looked like a service account and a password.

Analyzing Unencrypted LDAP traffic in Wireshark
Analyzing Unencrypted LDAP traffic in Wireshark

The device went on to request some entries from the organizations AD Global Address List, returning email addresses, job titles, and phone numbers. The GAL may also include other job and address information, and photos. Had an attacker found this information, at a minimum this password leakage could have resulted in the exfiltration of the organization’s complete address book, which may have been used for spamming or identify theft.

Depending on the nature of the service account that was leaked however, this might have resulted in a wider compromise: it might also have been a valid login account and therefore a foothold in the organization’s network, and potentially further scope for lateral movement within the network.

We used a Conversations Chords Chart to see if this involved other attendees, this showed us four local devices communicating with three LDAP servers for that organization.

Viewing conversations in the EndaceVision chord chart
Viewing conversations in the EndaceVision chord chart

The SOC was able to contact the organization involved and get in touch with the attendees, and they were invited down to the SOC where they got a detailed one-on-one demonstration of how we found the insecurity using the capabilities of Cisco and Endace SOC and the benefits of full packet capture.

The organization was both surprised and concerned with the data that had been exposed and stated that they would address the finding immediately.

Members of the Cisco Live APJ 2025 SOC Team
Members of the Cisco Live APJ 2025 SOC Team
Acknowledgements

Once again, our thanks go to the Cisco team led by @Jessica Oppenheimer for the opportunity to include EndaceProbes in the Cisco Live APJC SOC architecture. The SOC team is a collection of Cisco experts across many domains who were a pleasure to work and innovate with and we came away with a great appreciation for power of the Cisco Security tools.

The Endace team was able to prove out integration innovations from previous SOC events and test these in earnest in a real-world environment in preparation for making them generally available to the market.

Read related Cisco Team Blogs from the Cisco Live APJC SOC: https://blogs.cisco.com/security/cisco-live-melbourne-2025-soc

For more Endace blogs in our SOC series, see here:
https://blog.endace.com/tag/soc/