A SOC analyst reviews NetFlow for a workstation. For the past six hours, the host has opened a TCP session to the same external IP every 300 seconds, sending about 120 bytes and receiving about 100 bytes, with no corresponding user activity. Which behavior is most strongly indicated?
Select an answer to reveal the explanation.
Short Explanation
Think of NetFlow like a heartbeat: same beat, same interval, same tiny packet. When you see that, you're probably watching beaconing, not a one-time download. Confirm the process before you panic.
Full Explanation
NetFlow records flow metadata, so regular, small, bidirectional sessions to one external destination at a fixed interval are the classic signature of beaconing. Malware or an implant often checks in on a schedule, with jitter sometimes present, while payload transfer remains minimal. The key signals are periodicity, a stable destination, and a consistent byte pattern rather than volume alone. Data exfiltration would typically show asymmetric outbound transfer, larger sustained flows, or bursts tied to file access, not a steady low-byte handshake. Lateral movement is an internal east-west pattern, often involving SMB, RDP, SSH, or administrative shares, and would not center on a single external endpoint. DNS tunneling may create periodic traffic if it is beacon-like, but it is usually identified through DNS request patterns such as many unique subdomains, long labels, or abnormal query volume, not merely TCP flows to one IP. Exam caveat: benign services also produce periodic traffic, so a NetFlow pattern alone is a hypothesis, not proof of compromise. Operational check: pivot from the destination and interval to endpoint telemetry to identify the originating process, command line, and parent-child relationships before containment.