Catching Windows in the Act with Proxmox Packet Capture [YouTube Release]

Additional Resources:

My VM Packet Capture

Doug Burk So-Crates Github

My Security Onion Video

The previous video regarding the Threat Actor Arrest

Connect With Us

Lawrence Systems Shirts and Swag

:t_shirt: Lawrence Systems

AFFILIATES & REFERRAL LINKS

Amazon Affiliate Store
:shopping_cart: Lawrence Systems's Amazon Page

UniFi Affiliate Link
:shopping_cart: Ubiquiti Store

All Of Our Affiliates help us out and can get you discounts!
:shopping_cart: Partners We Love – Lawrence Systems

Gear we use on Kit
:shopping_cart: https://kit.co/lawrencesystems

Use OfferCode LTSERVICES to get 10% off your order at
:shopping_cart: Tech Supply Direct - Premium Refurbished Servers & Workstations at Unbeatable Prices

Digital Ocean Offer Code
:shopping_cart: AI-Native Cloud | DigitalOcean

HostiFi UniFi Cloud Hosting Service
:shopping_cart: HostiFi - Fast and Reliable UniFi in the Cloud

Protect your privacy with a VPN from Private Internet Access
:shopping_cart: https://www.privateinternetaccess.com/pages/buy-vpn/LRNSYS

Patreon
:money_bag: https://www.patreon.com/lawrencesystems

Chapters
0:00 The Hacker Windows Caught
0:26 The Experiment: Fresh Windows in Proxmox
0:40 Finding the VM Interface
1:27 Capturing with tcpdump
1:53 The Auto-Capture Script
3:11 Pulling the PCAP and Opening Wireshark
3:51 Filtering for SNI: Where Windows Phones Home
4:15 Easier Analysis with SO-CRATES
5:03 Reading the Results: DNS, HTTP, TLS
6:12 The EFF Shirt and Can You Block It?
7:51 Why I Trust Linux More
8:00 Wrap-Up

I just rerun elements of christitus’s powershell script after every windows update

A good brain dead quick “it’ll do” solution

As Tom said, everything you do at OS level can be reverted later by windows update. There are several things you can do at network level, but thats also not a reliable solution because windows update can change network destinations as well, and get around whatever you have setup on your network. Just dont use windows.

Thanks Tom, I didn’t need to use proxmox to see the network flow I just did a filter in the flows in the Unifi dashboard and filtered on my Windows PC. I am also publishing flows to visualize them in GrayLog and have a nice dashboard setup.

1 Like

Anyone who is surprised by this has not been paying attention for the last decade or so.

I suppose you could block some of these domains from resolving at all, but I guarantee if you do that that a bunch of websites won’t work.

The better solution is to use an OS that doesn’t treat you like a product.

Without actual testimonials or reports such as this one, all pieces of information remains speculation. I therefore very much support and appreciate such journalism which uncovers the actual consequences of such data collection and @LTS_Tom for extending the awareness even further.

1 Like