Sundarram Paravastu, Principal Software Engineer, Endace
At the recent Govware 2025 event in Singapore, two of Endace’s newest EP94C8 EndaceProbes were installed in the GovWare SOC to provide full packet capture to support the conference SOC directives of Protect, Educate, and Innovate.
Full packet capture provides unique insight into all activity on the network, delivering critical context and evidence for Incident Response and Threat Hunting teams.
The EndaceProbes each hosted three VMs that were running Zeek and delivering critical log data into Splunk. Custom Zeek script additions provided additional valuable details around clear text passwords in email and HTTP, and the use of insecure protocols. Attendees at GovWare 2025 impressed the SOC team with a high level of security awareness resulting in a very low prevalence of clear text data and insecure protocols. Zeek was also used for file-carving and automated submission of object to Splunk Attack Analyzer and a beta of Endace’s new Vault API used in a Cisco XDR automated workflow was field tested.
SOC Findings and Lessons Learned
A firewall incident of blocking connection to a malicious IP by firewall was reported in Cisco XDR.
Looking further into the incident, any markers for compromise was further investigated. Inspecting the packets in EndaceProbe revealed a strange pattern of successive connection creation within a short span of time (2-5ms) to different hosts. The other strange aspect was that the connection was immediately closed after receiving a response from these hosts. Adding to the suspicion was this beaconing was done within a few seconds of connecting to the Wifi network. Most of the ips being connected to on further investigation revealed were flagged and were reported to have been involved in suspicious/malware activities.
Pivoting to the hosted wireshark instance available on all EndaceProbes quickly revealed that a burst of connections were created by the host within a span of 3 milliseconds and closed immediately after receiving response:
Following the individual connections in Wireshark revealed that no data was being shared, and only ability to connect was being tested.
None of these IP addresses are present in any DNS lookup prior to the connection initiation and this many connections within a very short span (3ms) reveals it is likely a program doing it with a pre-existing list of IP addresses.
This is likely a beaconing to C2 infrastructure, where it is only touching base with servers to see which ones are active and the program is probably in dormant state or in the initial stage of just verifying connectivity.
Having full packet capture gave us visibility beyond the single blocked IP reported by the firewall. It allowed us to examine all other connections that were not flagged. The packet data confirmed that the IP addresses were not obtained via DNS and that the activity was triggered immediately after the host connected to the Wi-Fi network. Additionally, the captures verified that no data was transmitted during the beaconing attempts to the malicious IP addresses. As part of the investigation, we also checked whether other hosts on the network were making connections to these IPs.
Acknowledgements
Once again, our thanks go to the Cisco team lead by @Jessica Oppenheimer for the opportunity to include EndaceProbes in the GovWare SOC architecture. The SOC team is a collection of Cisco experts across many domains who were a pleasure to work and innovate with and we came away with a great appreciation for power of the Cisco Security tools. The Endace team was able to prove out integration innovations from previous SOC events and test these in earnest in a real-world environment in preparation for making them generally available to the market.
About GovWare
GovWare Conference and Exhibition is the region’s premier cyber information and connectivity platform, offering multi-channel touchpoints to drive community intel sharing, training, and strategic collaborations.
A trusted nexus for over three decades, GovWare unites policymakers, tech innovators, and end-users across Asia and beyond, driving pertinent dialogues on the latest trends and critical information flow. It empowers growth and innovation through collective insights and partnerships.
Its success lies in the trust and support from the cybersecurity and broader cyber community that it has had the privilege to serve over the years, as well as organisational partners who share the same values and mission to enrich the cyber ecosystem.
Read More
For more blogs in our Endace SOC series, see here:
https://blog.endace.com/tag/soc/

