Investigating/forensics of suspicious endpoints
At this point, we take our threat hunt investigation to the suspected victim machine. Let's quickly see what we can find out about 172.25.100.220
from Security Onion. Clicking on the IP address 172.25.100.220
in the Connections dashboard has Kibana open a new tab with the indicator dashboard loaded and the IP address as a search term. This dashboard allows us to see a variety of interesting facts about our suspected victim:
At a glance, we can see the types of logs (Dataset) that are present in the database for the suspect system, as well as summary widgets for Source IP, Destination IP, and Destination Port.
In this case, the default indicator screen isn't showing too much useful information, but we can make things fit our needs (starting to see a pattern?). Simply add the Security Onion – DNS - Queries...