🔄 Topic

Studying common protocols and ports as practical SOC vocabulary.


🎯 Goal

Memorize key protocols by connecting each one to what defenders see in logs and traffic.


🛠 What I Did

Today I worked through network operations material from Course 3 and focused on common protocols.

Protocols are not just exam facts. They are field values in logs.

Important examples:

  • DNS uses port 53 and resolves names to IP addresses
  • HTTP commonly uses port 80
  • HTTPS commonly uses port 443
  • SSH commonly uses port 22
  • Telnet commonly uses port 23 and is insecure
  • SMTP is used for email sending
  • IMAP and POP3 are used for email retrieval
  • DHCP assigns network configuration
  • ARP resolves IP addresses to MAC addresses on local networks

🔗 Key Cybersecurity Connections

Every protocol creates different investigation questions.

DNS asks:

What domain did this host try to resolve?

HTTP/HTTPS asks:

What web resource did the host contact?

SSH asks:

Was remote access attempted or successful?

SMTP asks:

Was email sent, relayed, or abused?

ARP asks:

Is local network address mapping normal or suspicious?

This helps turn memorization into detection thinking.


🔍 Investigation Questions

  • Which protocol is involved?
  • What port is used?
  • Is the port expected for the protocol?
  • Is the source host expected to use this protocol?
  • Is the destination internal or external?
  • Is the protocol encrypted or cleartext?
  • Does the event show connection attempt, success, failure, or data transfer?
  • Which logs would confirm the activity?

🚨 Detection Opportunities

Detection ideas:

  • Telnet traffic in a modern environment
  • SSH brute force attempts
  • DNS queries to newly seen domains
  • HTTP traffic to suspicious paths
  • SMTP sending from unauthorized host
  • unusual outbound connection on non-standard port

Example:

protocol=SSH
dst_port=22
failed_logins=45
src_ip=203.0.113.90
target=linux-server-01
detection=possible_ssh_bruteforce

🧭 MITRE ATT&CK Techniques

Possible mappings:

  • T1110 — Brute Force
  • T1021.004 — SSH
  • T1071.001 — Web Protocols
  • T1048 — Exfiltration Over Alternative Protocol
  • T1046 — Network Service Discovery

🗺 Visual Investigation Diagram

Protocol
    ↓
Port
    ↓
Expected behavior
    ↓
Log source
    ↓
Suspicious deviation
    ↓
Investigation

⚠ Challenges

The challenge is memorizing ports without context. Port numbers stick better when connected to real attacker behavior and defender telemetry.

For example, SSH port 22 is not just a number. It means remote access, authentication logs, brute force risk, and possible server compromise.


📚 What I Learned

I learned that protocol knowledge is SOC vocabulary. If I cannot quickly recognize DNS, HTTP, SSH, SMTP, DHCP, and ARP traffic, I will struggle to triage basic network events.


➡ Next Steps

  • Create protocol flashcards with port, purpose, logs, and attack examples
  • Build fake logs for DNS, SSH, HTTP, and SMTP events
  • Practice identifying protocols from port numbers
  • Separate normal protocol use from suspicious patterns

🧠 Reflection

This was practical because protocols appear constantly in SOC alerts. Memorization alone is weak; evidence-based protocol recognition is the real skill.


🧩 Lessons Learned

What worked

Linking each protocol to logs and attacks.

What broke

Port memorization feels random when isolated.

Why it broke

Numbers are hard to retain without scenarios.

Fix / takeaway

Study protocols as purpose + port + evidence + attacker abuse.


📈 Skill Progression Context

This supports my SOC analyst and detection engineering progression because it turns course material into investigation habits: identifying assets, reading evidence, asking better questions, and explaining security risk clearly.

Instead of treating the certificate as passive study, I am using each topic to build practical analyst thinking that can later become lab notes, detections, diagrams, or portfolio writeups.


😄 TL;DR

Ports are not trivia. They are clues.