Sundarram Paravastu, Principal Software Engineer, Endace
At each Security Operations Center (SOC) event, we capture and inspect every packet from start of show through to the very last hour, for the purpose of securing the attendees and conference, wiping the data at the end.
We had two of Endace’s newest EP94C8 EndaceProbes™ doing full packet capture providing unique insight into all activity on the network, delivering critical context and evidence for Incident Response and Threat Hunting teams. As part of the setup, we also had Application Dock VMs running on the EndaceProbes, extracting files where possible from unencrypted traffic, and sending rich metadata and Zeek® logs to Splunk® and Splunk Attack Analyzer®.
|
Stats |
Count |
|
Total files extracted |
1,743,259 |
|
Total files submitted for malware analysis |
55,939 |
|
Top extensions of files submitted |
.xz, .gz, .pptx, .zip, .vnd, .pdf |
|
Files extracted from email (POP3, IMAP etc.) |
887 |
As part of SOC, we extracted more than 1.7M files and many of them were filtered out based on a known benign file list or excluded if they were duplicates of files already submitted. Within the files that were submitted, there were many files that were extracted from HTTP, POP3, IMAP etc.
Incident example: Malicious trojan file sent over email to compromise user system
There were 70+ users using POP3 emails and all their communication was in the clear. It’s worth noting that the SOC already has Splunk automation in place (using logs submitted to Splunk by EndaceProbe-hosted VMs) that notify affected users via email that their communications are using protocols (like POP3, IMAP) that expose their credentials.
In this specific incident example, we went looking for .rar files that were extracted and submitted to Splunk Attack Analyzer. Malicious .rar files have some notoriety so it was natural to look for any potential anomalies. As it turned out, there was indeed an email attachment that had malicious files in it.
The example above had a trojan file inside the archive, that was flagged as malicious.
We now had to trace that file extracted back to the user and their IP addresses for further analysis. Looking into Splunk’s file submission log, we could narrow down the hosts responsible for sending the email:
Digging further using the packet data recorded by our EndaceProbes, we were able to access all that affected user’s POP3 traffic over the two days of the conference and review it.
We analyzed the actual PCAP data related to these POP3 sessions using Wireshark™ – hosted on EndaceProbes – to find the user related to the event.
We then extracted all the files related to those POP3 sessions so they could be submitted to Splunk Attack Analyzer for further analysis.
We did not find further malicious files sent to the user other than the one we had originally found. However, some of the links in the emails were flagged as suspicious.
In this incident, we not only analyzed the files extracted at the time of capture but were also able to retrospectively get all related packets and extract all files related to the host involved in this incident. This enabled us to do very comprehensive, and conclusive, incident analysis.
Acknowledgements
This would not have been possible without the great work done by the Cisco Live EMEA SOC team, led by Jessica Oppenheimer and Ivan Berlinson.
Data collected and analyzed was the result of a team, many thanks go to the following team members:
Network Operations Center Liaisons
- Remco Kamerman, Luke Hebditch, Mark Bremner and Scott Neuman
Cisco Security and Splunk SOC Team
- SOC in a Box: Adi Sankar
- Splunk Security Integrations: Paul Pelletier and Kenneth Bouchard, with Josh Wilson and Duane Waddle
- Splunk Threat Researchers: Nasreddine Bencherchali and Paul Pang
- Breach Protection Suite: Mark Pleunes, Ibrahim Yusuf, Piotr Jarzynka, Matt Vander Horst, Yannis Steiakogiannakis and Eric Rennie, with Bilal Qamar
- User Protection Suite: Aaron Woland
- Firewall and Security Cloud Control: Adam Kilgore and Christopher Grabowski
Endace SOC Team
- Co-SOC Leader: Cary Wright
- Endace Engineering: Owen Gallagher, Sundarram Paravastu and Sam Brockelsby
Read related Cisco Team Blogs from the Cisco Live Europe 2026 SOC:
https://blogs.cisco.com/security/emea-soc-2026
For more Endace blogs in our SOC series, see here:
https://blog.endace.com/tag/soc/
Event SOC Website
Visit Cisco’s Event SOC website for full details of the SOC setup, and download the whitepaper written by Jessica Oppenheimer:
https://www.cisco.com/site/us/en/products/security/event-soc-report.html







