GreatCoder Academy Home Class 2: IP Lab ⚑ Class 3: Operations & Security Lab GREATCODER · PORTS, PROTOCOLS & DEEP PACKET SUITE
⚑ SIM ENGINE ACTIVE
RANGEFORCE CYBER-OS ARCHITECTURE Β· VISUAL & SIMULATOR DOMINANT

Ports, Protocols & Deep Packet Inspection Studio

Step through real network mechanicsβ€”from the application socket and 5-tuple down to Ethernet Layer 2 frames, TCP state machines, Wireshark conversation forensics, and role-aligned operations across SOC, VAPT, Firewall, and Compliance.

MODULE 01 Network Communication: Start With the Socket
Foundations
1.1 What Actually Happens When an Application Communicates? Application β†’ Socket β†’ Kernel Stack β†’ NIC

An application (e.g. Chrome, curl, Python) does not send raw electricity onto wires. It asks the operating system kernel to open a Socketβ€”a software doorway bound to an IP address, port number, and transport protocol.

Visual Communication Pipeline

1. Application Layer: User enters https://example.com
    β”‚
    β–Ό
2. Socket API (Kernel): Opens socket descriptor (fd=3)
    β”œβ”€β”€ IP Address: 192.168.1.10 (Host Identity)
    β”œβ”€β”€ Port Number: 51542 (Ephemeral App Endpoint)
    β””── Protocol: TCP (Reliable byte-stream)
    β”‚
    β–Ό
3. OS Network Stack: Builds TCP segment & IP packet
    β”‚
    β–Ό
4. NIC Controller: Converts frames into wire signals ⚑

Interactive Socket Simulator

Trigger an application to observe the OS kernel bind the socket in real-time:

Select an application above and click "Bind Socket" to inspect kernel state.

1.2 The 5-Tuple Sandbox (Foundation for SIEM, Firewalls & Wireshark)

Every IP session on earth is uniquely tracked by 5 parameters. Modify values below to observe how the network conversation updates:

1. SOURCE IP
2. SOURCE PORT
3. DESTINATION IP
4. DESTINATION PORT
5. PROTOCOL
SOCKET STATE & DIRECTION
ESTABLISHED (OUTBOUND)
5-Tuple: 10.10.20.15:51542 ──[TCP]──► 142.250.72.14:443
MODULE 02 Port β‰  Protocol & Transport State Machines
Transport Layer
2.1 Critical Truth: Port β‰  Protocol β‰  Application β‰  Security Why 443 is not always safe HTTPS

Port Categories

  • 0 – 1023: Well-Known Ports (System / Root privilege)
  • 1024 – 49151: Registered Ports (Vendor designated)
  • 49152 – 65535: Ephemeral / Dynamic Ports (Client OS assigned)

Multi-Use Port 443

Port 443 does not enforce HTTPS. It can carry:

β€’ HTTP/1.1 over TLS
β€’ HTTP/2 binary streams
β€’ HTTP/3 (QUIC over UDP 443)
β€’ VPN / Shadowsocks / C2 Evasion

Interactive Port Search

2.2 Live TCP 3-Way Handshake & Flow Control Simulator

πŸ’»

CLIENT
10.10.20.15
πŸ–₯️

SERVER
10.10.20.10
SYN [Seq=0]
TCP HANDSHAKE LOGCLOSED
Click "Step 1: Send SYN" to initiate the 3-Way Handshake.

TCP Control Flags Explained

SYNSynchronize Seq
ACKAcknowledge receipt
FINGraceful close
RSTHard reset / abort
PSHPush to application
URGUrgent pointer valid
MODULE 03 The Packet Journey: Encapsulation & Headers
Packet Forensics
3.1 Interactive Layer-by-Layer Encapsulation Box Model Russian-doll byte packaging

Type a sample application payload below and watch the operating system wrap it in TCP, IPv4, and Ethernet headers before transmitting raw bits:

PACKET ENCAPSULATION ENGINEBYTES ON WIRE
Click "Run Encapsulation Pipeline" to inspect byte prepending and header offsets.

Layer 2: Ethernet Frame Header (14 Bytes)

β€’ Destination MAC: 00:0c:29:84:11:ae (Gateway NIC)
β€’ Source MAC: 00:50:56:c0:00:08 (VMware Host)
β€’ EtherType: 0x0800 (IPv4) | 0x0806 (ARP) | 0x86DD (IPv6)
β€’ FCS / CRC32: 4-byte checksum for physical corruption

Layer 3: IPv4 Header (20 Bytes Base)

β€’ Version: 4 | IHL: 5 (20 Bytes)
β€’ Total Length: 64 Bytes | TTL: 64 hops
β€’ Protocol: 6 (TCP) | 17 (UDP) | 1 (ICMP)
β€’ Flags: 0x02 (Don't Fragment - DF) | Offset: 0
MODULE 04 Core Protocols Deep-Dive & Threat Scenarios
Threat Analysis
4.1 DNS Recursive Resolution & Tunneling UDP/TCP 53

DNS translates names to IPs via Root $ ightarrow$ TLD $ ightarrow$ Authoritative servers. Threat actors abuse TXT queries for covert data exfiltration.

Ready to query DNS resolver.
4.2 HTTP Cleartext vs. TLS 1.3 Encryption TCP 80 / 443

Inspect cleartext credentials over HTTP vs. cryptographic handshake metadata (SNI, cipher suites) over TLS 1.3:

Select a protocol above to dissect packet streams.

4.3 DHCP DORA Sequence

Discover $ ightarrow$ Offer $ ightarrow$ Request $ ightarrow$ ACK (UDP 67/68). Rogue DHCP servers hijack client default gateways.

4.4 ICMP Diagnostics & Tunneling

Type 8 (Echo Req), Type 0 (Echo Reply), Type 11 (TTL Exceeded). Attackers hide stolen data in ICMP payload bytes.

4.5 SMB Lateral Movement

TCP 445 Session Setup $ ightarrow$ Tree Connect $ ightarrow$ ADMIN$. Primary indicator of active ransomware spreading across LAN.

MODULE 05 Interactive Wireshark Forensic Studio
Core Analyst Tool
5.1 Live 3-Pane Dissector & Display Filter Engine Packet List Β· Packet Details Β· Packet Bytes
DISPLAY FILTER:
No. Time Source Destination Protocol Length Info
Click a packet in the table above to dissect Layer 2, Layer 3, Layer 4 and Application payload.
0000 00 0c 29 84 11 ae 00 50 56 c0 00 08 08 00 45 00 ..)p...PV...E.

5.2 Follow TCP Stream (Conversation Reassembly)

TCP STREAM RECONSTRUCTION #0ASCII STREAM
Click button above to reassemble client request (red) and server response (blue).
MODULE 06 Role-Aligned Operations & Certification Capstone
SLA & Practice Arena
6.1 Multi-Role Cybersecurity Consoles SOC Β· VAPT Β· Firewall Β· Threat Hunter Β· GRC

Live SIEM Alert Triage (P1 SLA: 15 Minutes)

ALERT IDALERT-9824: Inbound Connection on Port 4444

Host 10.10.20.15 accepted TCP connection on non-standard port 4444 from 185.44.21.8 followed by interactive cmd.exe execution.

Analyst Containment Log

Awaiting SOC Analyst action...

Nmap Port Scanner & Banner Grabbing

Execute scan to identify open ports, service versions, and CVE vulnerabilities.

CVE Vulnerability Association

No scan executed yet. Run nmap scan on target.

Stateful ACL Rule Generator

SOURCE ZONE
DESTINATION PORT
ACTION

Active Rulebase

Rule 1: ALLOW TCP 80,443 INGRESS TO DMZ
Rule 2: DENY ANY ANY (Default Egress)

MITRE ATT&CK Mapping & Sigma Rule Generator

β€’ T1071.001: Web Protocols C2 (HTTP/S)
β€’ T1071.004: DNS Exfiltration (High query volume)
β€’ T1571: Non-Standard Port Communication (TCP 4444)
β€’ T1046: Network Service Discovery (SYN Sweeps)

Sigma Detection Rule

Click generate to build Sigma detection logic for non-standard port beaconing.

Regulatory Compliance Auditor

β€’ PCI-DSS 4.0 Req 1.2: Prohibit insecure cleartext protocols (Telnet 23, FTP 21) in CDE.
β€’ NIST SP 800-53 CM-7: Least Functionality β€” Disable unapproved ports.
β€’ ISO/IEC 27001:2022 A.8.20: Network Security controls.

Compliance Gap Report

Click Audit to check environment against PCI-DSS and NIST standards.
6.2 Certification Capstone: Comprehensive PCAP Investigation
Live PCAP Source

Investigate the live captured packet stream enterprise_breach.pcap (Click to View Source Packets β†—) to uncover the attacker's full kill-chain, from initial exploit to lateral movement and exfiltration:

πŸ“¦ Live PCAP Source: enterprise_breach.pcap

Captured on: 10.10.20.0/24 Core Gateway Β· Total Packets: 12 Β· Duration: 42.8s
No. Time Source IP:Port Destination IP:Port Proto Len Decoded Packet Payload / Attack Signature
Click any packet frame above to inspect its decoded Layer 2, Layer 3, Layer 4, and Application payload evidence.

10-Point Forensic Triage Questions

Review the packet evidence in enterprise_breach.pcap above to answer all questions:

Forensic Verdict & Incident Scorecard

Inspect the packet frames above, select answers for each question, and submit your report to receive the root cause forensic assessment.