Wired Network Attacks
Wireless Network attacks
Indicators of Compromise
Types of Network-Based Evidence
100

What does the term Indicators of Compromise refer to?

Evidence items pointing to any security intrusion that has taken place on a host system or network.

200

 Is a technique used to intercept unsecured connections in order to steal personal information.

What is Eavesdropping

200

What can be termed rogue if it has been installed within a WLAN without the authorization of the network administrator. 

What is a Rouge access point?

200

These indicators are based on files or file attributes that suggest malicious activity

What is File-Based IoCs?

200

This is gathered by capturing and storing all the packets flowing through a network without any filtration. It offers a significant amount of granularity and flexibility during network-based data analysis.

What is Full content data?

300

 When an intruder obtains access to sensitive information, they might alter or delete the data as well. This is commonly referred to as?

What is Data Modification

300

This attack occurs due to the misconfiguration of a wireless access point. This is one of the easiest vulnerabilities that an attacker can exploit.

What is a Misconfigured Access Point Attack?

300

 These indicators relate to suspicious network traffic or communication patterns

What is Network-Based IoCs?

300

 This provides the summary of a conversation between two network devices. Although it is not as detailed as full content data, it includes an aggregation of metadata of network traffic such as the destination IP and destination port, source IP and source port, start time of the session, and information exchanged during the session.

What is Session Data?

400

  In this attack, the attacker floods the target with large amounts of invalid traffic, thereby exhausting the resources available on the target.

What is Dos attack?

400

The attacker can reconfigure the MAC address so that it appears to be an authorized access point to a host on a trusted network

What is Access Point MAC Spoofing?

400

 These indicators focus on deviations from normal system behavior, which may suggest compromise.

What is Behavior-based IoCs?
400

This is triggered by tools like Snort IDS and Suricata that inspect the network traffic flow and report potential security events as alerts.

What is Alert Data?

500

This is the process of gathering information about a network, which may subsequently be used to attack the network. 

What is Enumeration?

500

The attacker conducts the attack using a USB adapter or wireless card. In this method, the host connects with an unsecured station to attack a particular station or evade access point security.

What is Ad-Hoc Connection Attack?

500

 These indicators are found in the system's volatile memory and can signal active attacks or malware.

What is Memory-based IoCs?

500

This type of data provides an overall profile or summary of the network traffic, which can be of significant investigative value.

What is Statistical Data?