πŸ”„ Topic

Understanding how to identify devices on a network using ARP (Address Resolution Protocol).


🎯 Goal

Learn how to map IP addresses to physical devices using MAC addresses.


πŸ›  What I Did

Used:

arp -an

to view mappings between:

  • IP addresses
  • MAC addresses

This allowed me to see which devices were present on the network.

The useful part was not the command itself. The useful part was learning to translate a table of addresses into an investigation question: which machine is this, should it be here, and does the identity match what I expect?


πŸ”— Key Cybersecurity Connections

ARP is fundamental for:

  • network visibility
  • device identification
  • investigation of suspicious hosts

Attackers also abuse ARP through:

  • ARP spoofing
  • man-in-the-middle attacks

πŸ” Investigation Questions

  • Which device owns this IP?
  • Is this MAC address expected?
  • Has a device changed identity?

🚨 Detection Opportunities

  • duplicate IPs with different MACs
  • unexpected MAC addresses on network
  • ARP table anomalies

🧭 MITRE ATT&CK Techniques

  • T1557 β€” Man-in-the-Middle

⚠ Challenges

Understanding that:

  • IP addresses can change
  • MAC addresses are more stable identifiers

πŸ“š What I Learned

  • ARP bridges network and physical layers
  • mapping is essential for investigation
  • attackers can manipulate this relationship
  • a single identifier is rarely enough during triage
  • good network investigation means correlating IP, MAC, hostname, timing, and expected asset ownership

➑ Next Steps

  • explore ARP spoofing detection
  • simulate MITM attacks in lab

🧠 Reflection

This is where networking becomes investigative:

IP is β€œwhere” β€” MAC is β€œwho”.


🧩 Lessons Learned

What worked

Using ARP to visualize the network.

What broke

Assuming IP alone identifies a device.

Why it broke

IP addresses are dynamic.

Fix / takeaway

Correlate multiple identifiers.

For a SOC workflow, the practical lesson is simple: do not stop at β€œI found the IP.” Keep going until the device identity and the surrounding evidence make sense.


πŸ“ˆ Skill Progression Context

This builds foundational network investigation skills used in SOC environments.


πŸ˜„ TL;DR

IP tells you where to look…
MAC tells you who’s actually there.