πŸ”„ Topic

Testing connectivity between systems and verifying whether services are reachable over the network.


🎯 Goal

Understand how to verify whether a remote service is accessible and correctly listening on a port.


πŸ›  What I Did

Used tools like:

  • Test-NetConnection (Windows)
  • netcat (nc)
  • ss -tulpn (Linux)

to check:

  • whether port 22 was reachable
  • whether services were listening

πŸ”— Key Cybersecurity Connections

Port connectivity testing is essential for:

  • troubleshooting infrastructure
  • validating service availability
  • detecting exposed services

Attackers use the same techniques during:

  • reconnaissance
  • network scanning
  • lateral movement

πŸ” Investigation Questions

  • Is the target port open?
  • Is a service actually listening?
  • Is the issue network-level or host-level?

🚨 Detection Opportunities

  • port scanning activity (multiple connection attempts)
  • unusual probing across multiple hosts
  • repeated connection failures

🧭 MITRE ATT&CK Techniques

  • T1046 β€” Network Service Discovery

⚠ Challenges

Distinguishing between:

  • network reachability
  • service availability

A host can be reachable but still not accept connections.


πŸ“š What I Learned

  • open port β‰  reachable service
  • tools must be used together for validation
  • connectivity issues must be broken down step by step

➑ Next Steps

  • simulate port scanning scenarios
  • analyze logs generated by connection attempts

🧠 Reflection

This reinforced a key principle:

Always test assumptions at the network level.


🧩 Lessons Learned

What worked

Using multiple tools to verify connectivity.

What broke

Assuming reachability meant service availability.

Why it broke

Incomplete understanding of networking layers.

Fix / takeaway

Validate each layer independently.


πŸ“ˆ Skill Progression Context

This builds core networking and investigation skills used daily in SOC environments.


πŸ˜„ TL;DR

Just because you can ping it…
doesn’t mean you can talk to it.