By Peter Watt, Senior Sales and Partner Integration Engineer, Endace
Summary
At Cisco Live APJC 2025 the SOC has a robust procedure in place to identify cleartext passwords, and through use of automation with Splunk/XDR to notify users directly via-email of their potential exposure – offering them support through the SOC on-site, during the conference.
This is a powerful capability of the SOC. It does however, require a valid email address – which is found within SMTP, IMAP and POP3.
When cleartext Passwords, and other PII are identified outside email based protocols … it becomes more difficult.
What we Identified
Firstly, through automation, the SOC was able to identify the use of a cleartext password:

From within the incident in XDR, a https reference link is provided to provide direct access to the packets of interest, stored on the Endace Packet Capture Appliance.
Using the session construction capabilities of Wireshark – we were able to reconstruct the data stream, and identify an FTP session had taken place with the following actions:

This exposed:
- External IP Address
- Username,
- Password
- Directory
- Filename
- Internal IP address
- Filetype being transferred
Missing:
- Email Address
Reverse lookup of the IP address was able to shed further light upon the situation. But we still needed additional information. Which is where the full packet capture became valuable.
Using Endace’s recorded full packet capture data, we extracted packet data between the source and destination IP’s and found that the FTP was also taking place on a non-standard port:

Upon reconstructing the session, the file being transferred was able to be reassembled too. The file format can be clearly seen in the following:

Piecing together all the components above, we were able to identify the source of the FTP, notify and educate them to resolve a potential security threat.
Having an FTP server open and accessible on the internet with clear text passwords is very risky indeed. An attacker that obtains credentials could easily access and download any private or sensitive content, and more concerning they could place infected binaries or malware on the server with the intention to infect and own any machines accessing content on that server. The users were shocked to learn about this exposure and immediately stopped using the FTP service.
The same methodology was used during threat hunting where other cleartext PII was identified.
Acknowledgements
Once again, our thanks go to the Cisco team led by @Jessica Oppenheimer for the opportunity to include EndaceProbes in the Cisco Live APJC SOC architecture. The SOC team is a collection of Cisco experts across many domains who were a pleasure to work and innovate with and we came away with a great appreciation for power of the Cisco Security tools.
The Endace team was able to prove out integration innovations from previous SOC events and test these in earnest in a real-world environment in preparation for making them generally available to the market.
Read related Cisco Team Blogs from the Cisco Live APJC SOC: https://blogs.cisco.com/security/cisco-live-melbourne-2025-soc
For more Endace blogs in our SOC series, see here:
https://blog.endace.com/tag/soc/