Ports, Protocols & Deep Packet Inspection Studio
Step through real network mechanicsβfrom the application socket and 5-tuple down to Ethernet Layer 2 frames, TCP state machines, Wireshark conversation forensics, and role-aligned operations across SOC, VAPT, Firewall, and Compliance.
An application (e.g. Chrome, curl, Python) does not send raw electricity onto wires. It asks the operating system kernel to open a Socketβa software doorway bound to an IP address, port number, and transport protocol.
Visual Communication Pipeline
β
βΌ
2. Socket API (Kernel): Opens socket descriptor (fd=3)
βββ IP Address: 192.168.1.10 (Host Identity)
βββ Port Number: 51542 (Ephemeral App Endpoint)
βββ Protocol: TCP (Reliable byte-stream)
β
βΌ
3. OS Network Stack: Builds TCP segment & IP packet
β
βΌ
4. NIC Controller: Converts frames into wire signals β‘
Interactive Socket Simulator
Trigger an application to observe the OS kernel bind the socket in real-time:
1.2 The 5-Tuple Sandbox (Foundation for SIEM, Firewalls & Wireshark)
Every IP session on earth is uniquely tracked by 5 parameters. Modify values below to observe how the network conversation updates:
Port Categories
- 0 β 1023: Well-Known Ports (System / Root privilege)
- 1024 β 49151: Registered Ports (Vendor designated)
- 49152 β 65535: Ephemeral / Dynamic Ports (Client OS assigned)
Multi-Use Port 443
Port 443 does not enforce HTTPS. It can carry:
β’ HTTP/2 binary streams
β’ HTTP/3 (QUIC over UDP 443)
β’ VPN / Shadowsocks / C2 Evasion
Interactive Port Search
2.2 Live TCP 3-Way Handshake & Flow Control Simulator
CLIENT
10.10.20.15
SERVER
10.10.20.10
TCP Control Flags Explained
Type a sample application payload below and watch the operating system wrap it in TCP, IPv4, and Ethernet headers before transmitting raw bits:
Layer 2: Ethernet Frame Header (14 Bytes)
β’ Source MAC: 00:50:56:c0:00:08 (VMware Host)
β’ EtherType: 0x0800 (IPv4) | 0x0806 (ARP) | 0x86DD (IPv6)
β’ FCS / CRC32: 4-byte checksum for physical corruption
Layer 3: IPv4 Header (20 Bytes Base)
β’ Total Length: 64 Bytes | TTL: 64 hops
β’ Protocol: 6 (TCP) | 17 (UDP) | 1 (ICMP)
β’ Flags: 0x02 (Don't Fragment - DF) | Offset: 0
DNS translates names to IPs via Root $ ightarrow$ TLD $ ightarrow$ Authoritative servers. Threat actors abuse TXT queries for covert data exfiltration.
Inspect cleartext credentials over HTTP vs. cryptographic handshake metadata (SNI, cipher suites) over TLS 1.3:
4.3 DHCP DORA Sequence
Discover $ ightarrow$ Offer $ ightarrow$ Request $ ightarrow$ ACK (UDP 67/68). Rogue DHCP servers hijack client default gateways.
4.4 ICMP Diagnostics & Tunneling
Type 8 (Echo Req), Type 0 (Echo Reply), Type 11 (TTL Exceeded). Attackers hide stolen data in ICMP payload bytes.
4.5 SMB Lateral Movement
TCP 445 Session Setup $ ightarrow$ Tree Connect $ ightarrow$ ADMIN$. Primary indicator of active ransomware spreading across LAN.
| No. | Time | Source | Destination | Protocol | Length | Info |
|---|
5.2 Follow TCP Stream (Conversation Reassembly)
Live SIEM Alert Triage (P1 SLA: 15 Minutes)
Host 10.10.20.15 accepted TCP connection on non-standard port 4444 from 185.44.21.8 followed by interactive cmd.exe execution.
Analyst Containment Log
Nmap Port Scanner & Banner Grabbing
CVE Vulnerability Association
Stateful ACL Rule Generator
Active Rulebase
Rule 2: DENY ANY ANY (Default Egress)
MITRE ATT&CK Mapping & Sigma Rule Generator
β’ T1071.004: DNS Exfiltration (High query volume)
β’ T1571: Non-Standard Port Communication (TCP 4444)
β’ T1046: Network Service Discovery (SYN Sweeps)
Sigma Detection Rule
Regulatory Compliance Auditor
β’ NIST SP 800-53 CM-7: Least Functionality β Disable unapproved ports.
β’ ISO/IEC 27001:2022 A.8.20: Network Security controls.
Compliance Gap Report
Investigate the live captured packet stream enterprise_breach.pcap (Click to View Source Packets β) to uncover the attacker's full kill-chain, from initial exploit to lateral movement and exfiltration:
π¦ Live PCAP Source: enterprise_breach.pcap
Captured on: 10.10.20.0/24 Core Gateway Β· Total Packets: 12 Β· Duration: 42.8s| No. | Time | Source IP:Port | Destination IP:Port | Proto | Len | Decoded Packet Payload / Attack Signature |
|---|
10-Point Forensic Triage Questions
Review the packet evidence in enterprise_breach.pcap above to answer all questions: