Summary
In this chapter, we learned what SPAN/mirroring and TAPs are, as well as the importance of understanding how they fit into the ICS ecosystem. Knowing what to look for on the network and how to interact with it is key to having a successful outcome. Discovering what traffic is communicating and exchanging data allows us to build out a network topology of the assets the client has in their network. Utilizing technologies such as Wireshark, TShark, and Tcpdump to listen to and review the traffic in real time is required during an engagement. More advanced technologies, such as the IDS vendors listed in this chapter, will even divulge auto-discovered vulnerabilities.
In the next chapter, which is all about listening to a SPAN or TAP on the network, we will build packet captures that will allow us to analyze and dissect protocols being passed on the network. This is the secret sauce that IDS companies use to build out their product. This is an arms race for protocol dissectors...