TechKnowSurge
VideoSecurityFree

Strange Communication

Anomalous network communication—including unexpected outbound traffic, unknown open ports, and unauthorized emails—can signal data exfiltration, command-and-control activity, or a compromised system.

Complete this video to capture a CTF flag worth 1 point.

About this video

Monitoring for anomalous communication patterns is essential to detecting threats before they cause significant damage. Unexpected outbound traffic leaving the network is one of the most telling indicators, often pointing to data exfiltration or an attacker maintaining command-and-control channels on compromised systems. Similarly, irregular peer-to-peer communication between internal devices can suggest malware propagating laterally across the network or unauthorized coordination between endpoints. Unknown or unusual TCP and UDP ports—whether observed on individual devices or across network traffic—warrant close examination, as attackers frequently use non-standard ports to evade detection. Devices initiating internet connections without any corresponding user activity are another serious concern, potentially indicating an automated process under external control. Emails appearing in a sent folder without the account holder's knowledge are a strong sign of credential compromise or malware with email-based exfiltration or propagation capabilities, and should trigger an immediate investigation into the scope and source of the breach.

What you'll learn

What's covered

Strange Network Communication

Key terms

Data Exfiltration
The unauthorized transfer of data from a system to an external destination.
Transmission Control Protocol
TCP
A connection-oriented transport protocol that ensures reliable, ordered, and error-checked delivery of data.
User Datagram Protocol
UDP
A connectionless transport protocol that sends data without establishing a connection or guaranteeing delivery.
Port
A logical endpoint for communication in a network, identified by a number that specifies a particular service or application.
Command and Control
C2
Command and Control refers to the infrastructure and communication channels used by attackers to issue instructions to and receive data from compromised systems, enabling persistent access and coordinated attack operations.
Egress Filtering
The practice of monitoring and restricting outbound network traffic based on security policies.

Topics

Network Traffic Analysis Command And Control Data Exfiltration Anomaly Detection Tcp Udp Ports Threat Detection Cybersecurity

Transcript

Another thing that we are looking for on our devices and on our network is any kind of strange communication - communication across our networks and across our devices that we are not used to seeing.

What to look for

Unexpected outbound communication. What is going out of our network? It could be a sign that there maybe is some sort of data exfiltration, or maybe some sort of command and control that is going on.

Irregular peer-to-peer communication. Any communication that is going between two devices on the network could also be concerning.

Unknown TCP or UDP ports, whether they are communicating across our network or opened up on one of our devices. That could be something that we look into.

Connections made to the internet without user actions. Maybe a device is suddenly reaching out to a site and there is not even a user on that machine at that time. That could be a concern.

And then also emails being sent without user knowledge. If there are emails in your sent folder that you did not send, then the question is, well, who is compromising the system, and why are those emails going out?

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →