Video

Unlock the Hidden Power of DriftNet’s Summary Page

Unlock the Hidden Power of DriftNet’s Summary Page
A Driftnet tip for threat hunters: how the summary page reveals co-hosted domains and certs that hint at what an IP is really being used for.

Hi everyone, Gilad here with another quick tip for you thrack hunters out there using DriftNet Something nifty but commonly overlooked, the summary page I know, I know Threat hunters, threat researchers, when we look at summary pages, for us, it’s like a dashboard, it’s a nice view of things, but you can’t really use it for data. I will prefer to see it as a table. We want to go into the artifacts, the dataset itself. Summary is nice when you present it to your board, when you present information for other colleagues, but really for hunting it’s not as useful or so you might think and I felt the same but here’s a cool element of the summary page of DriftNet that I don’t want you to overlook because I did and now I am well aware of it and using it to the best of my knowledge. Here’s what the summary page gives you. You can go through, I will show you now the different tabs here, the different potential information that can be presented here. You can see the host, IPs, geolocations. Let me go up on the page here for the query itself. Just for this demonstration I pulled all the visible SMB protocols For those of you aware SMB protocols are highly sought after by threat actors It is commonly misconfigured, not necessarily supposed to be exposed to the internet. And so it is, threat actors will really want to try to use it to get into your infrastructure. This could be seen on OT environments, end of life devices, things that are really vulnerable and shouldn’t be exposed to the internet and so you don’t necessarily want to have that out there. But the case is, many times it is. And so I pulled the visible SMB protocols that DriftNet have seen in the last three days. The information you can see here is interesting. To those familiar with SMB, it does not usually carry a domain name, it doesn’t carry a TLS certificate but the information is visible here and so you will ask what are those? What are these domains and what are these subject certificates here? These are TLS certificate leaf data information What is it doing here? In fact, when we dive into visible services and we go specifically to see the ports and IPs that presented this SMB service you will see that there’s no host information here. There’s no domain name being presented. There’s no TLS certificate. So where is Drifton getting this from? You probably guessed already, but these are services that are basically sitting on the same IP sharing this IP with the SMB service. Now, this doesn’t always mean that they’re related. There are many IP addresses where you can have shared hosting environments that, you know, a single IP has hundreds, if not thousands of services running at the same time. And they might be used by different operators. They might be running different operations all the same. And the IP is basically just the gateway for them to externalize their services to the world, to the internet. But at the same time, when you see those hosts, you do know that if you found an IP that’s interesting to you, or for example, if your pivot is to go from your set of IPs, you want to examine your footprint and you want to filter for SMB services that are visible from your footprint, the information that you will get on the visible services page will show you the IP and port that it’s presented on. But the summary page will also give you indication to what are the domains that are being co hosted in those IPs? What are the certificates? This can give you some clue and effectively a really useful hint as to what are these specific IPs serving. What are they used for? For example, if you detect a certificate that’s being used in your OT environment not supposed to be exposed to the internet and you can see a domain name that’s supposed to be internal and then both of them are presented on an IP within your footprint that also serves as SMB protocol that’s a major hint to that your OT environment might have accidentally been exposed to the internet. Not necessarily something you want to happen. And so the summary page really empowers you in that sense because it gives you information not only on the specific services you pulled but their neighbors. This is really useful for hunting because you might detect them the summary page. I’ve turned it into my best practice to always go first for the summary page and try to see what kind of artifacts can I find here? Each one of those could be a lead that will help me dive better into the information, better into the data, find the artifacts that I can use as filters, either positive or negative filters, right? Because some of them might be noise that I wanna filter out. But really effectively using this page as a bird eye view and then picking different artifacts from here is lenses, different lenses I want to use to focus on the information later on when I dive into the visible services, into the table of datasets and really go into the data itself. So that’s it. That’s really what I wanted to show you today, the summary page and I hope you will use it wisely as I do or possibly better hopefully. Thank you for listening and good luck out there!

Driftnet Tip: Don’t Overlook the Summary Page

Hi everyone, Gilad here with another quick tip for threat hunters using Driftnet: something nifty but commonly overlooked, the summary page.

Why Threat Hunters Underrate the Summary Page

Threat hunters and researchers tend to look at summary pages as a dashboard a nice view of things, but not something you can really use for data. You’d rather see it as a table and go straight into the artifacts, the dataset itself.

A summary page is nice when you’re presenting to your board or to colleagues, but for hunting it can seem less useful. I felt the same way until I found a feature of Driftnet’s summary page I don’t want you to overlook. I missed it at first, and now I use it to the best of my knowledge.

What the Summary Page Gives You

The summary page has different tabs presenting different types of information, including:

  • Hosts
  • IPs
  • Geolocations

Example: Visible SMB Protocols

For this demonstration, I pulled all the visible SMB protocols Driftnet has seen in the last three days.

SMB protocols are highly sought after by threat actors. They’re commonly misconfigured and not necessarily meant to be exposed to the internet, so threat actors will try to use them to get into your infrastructure. This shows up on OT environments, end-of-life devices, and other systems that are vulnerable and shouldn’t be internet-facing but often are.

To those familiar with SMB: it doesn’t usually carry a domain name or a TLS certificate. But that information is visible on the summary page. So what are these domains and subject certificates showing up here? They’re TLS certificate leaf data.

Where This Data Actually Comes From

When you dive into Visible Services and look specifically at the ports and IPs presenting the SMB service, you’ll see there’s no host information, no domain name, and no TLS certificate there.

So where is Driftnet getting this from? These are services sitting on the same IP, sharing that IP with the SMB service.

This doesn’t always mean they’re related. Many IP addresses sit in shared hosting environments where a single IP has hundreds, if not thousands, of services running at once used by different operators running different operations, with the IP just acting as the gateway to externalize their services to the internet.

Why This Matters for Hunting

If you’re examining your footprint and filtering for SMB services visible from it, the Visible Services page will show you the IP and port the service is presented on. But the summary page also shows you the domains and certificates co-hosted on those IPs a useful hint as to what those specific IPs are serving and what they’re used for.

Example scenario: Say you detect a certificate used in your OT environment (which isn’t supposed to be exposed to the internet), and you also see a domain name that’s supposed to be internal. If both are presented on an IP within your footprint that also serves an SMB protocol, that’s a major hint that your OT environment might have accidentally been exposed to the internet.

The summary page empowers you here because it gives you information not just on the specific services you pulled, but on their neighbors too.

Best Practice: Start With the Summary Page

This is really useful for hunting, because you might spot these connections on the summary page first. I’ve made it my best practice to always start there and see what artifacts I can find. Each one can be a lead that helps me dive deeper into the data and find artifacts to use as filters positive or negative since some of them are noise I’ll want to filter out.

Think of the summary page as a bird’s-eye view, and the artifacts you pick from it as different lenses to focus on the information later, when you dive into Visible Services and the dataset itself.

Try It Yourself

That’s what I wanted to show you today: the summary page. I hope you’ll use it wisely or possibly even better than I do.

Thank you for listening, and good luck out there!