---
title: Analyzing security breach connection attempts with IOTA
description: IOTA Workflow, how to Analyzing security breach connection attempts
image: https://insights.profitap.com/hubfs/Blank%20diagram%20(1)-1.jpeg
---

[![Profitap](https://insights.profitap.com/hubfs/profitap-logo-white-rev1.png "Profitap")](https://www.profitap.com)

- [Solutions](https://www.profitap.com/solutions/)
- Products
- Resources
- Company
- <https://twitter.com/Profitap>
- <https://www.youtube.com/c/Profitap>
- <https://www.facebook.com/Profitap>
- <https://www.linkedin.com/company/profitap-international>

# Profitap Blog

### Recent Posts

### Categories

- [Network Monitoring (75)](https://insights.profitap.com/topic/network-monitoring)
- [Insights (38)](https://insights.profitap.com/topic/insights)
- [IOTA (32)](https://insights.profitap.com/topic/iota)
- [Copper TAPs (31)](https://insights.profitap.com/topic/copper-taps)
- [ProfiShark (24)](https://insights.profitap.com/topic/profishark)
- [Fiber TAPs (23)](https://insights.profitap.com/topic/fiber-taps)
- [Data Center (17)](https://insights.profitap.com/topic/data-center)
- [Network Packet Brokers (14)](https://insights.profitap.com/topic/network-packet-brokers)
- [Network Visibility and Cybersecurity (14)](https://insights.profitap.com/topic/network-visibility-and-cybersecurity)
- [Network Security (13)](https://insights.profitap.com/topic/network-security)
- [News (13)](https://insights.profitap.com/topic/news)
- [Product Update (11)](https://insights.profitap.com/topic/product-update)
- [Field Service (10)](https://insights.profitap.com/topic/field-service)
- [Case Study (3)](https://insights.profitap.com/topic/case-study)
- [OIDA (3)](https://insights.profitap.com/topic/oida)
- [Events (2)](https://insights.profitap.com/topic/events)
- [Heroes of Packet Analysis (2)](https://insights.profitap.com/topic/heroes-of-packet-analysis)
- [Solutions for Government and Defense (2)](https://insights.profitap.com/topic/solutions-for-government-and-defense)
- [Power and Utilities Solutions (1)](https://insights.profitap.com/topic/power-and-utilities-solutions)
- [Solutions for Logistics (1)](https://insights.profitap.com/topic/solutions-for-logistics)
- [cloud (1)](https://insights.profitap.com/topic/cloud)

see all

### Archives

- [July 2026 (1)](https://insights.profitap.com/archive/2026/07)
- [June 2026 (1)](https://insights.profitap.com/archive/2026/06)
- [May 2026 (3)](https://insights.profitap.com/archive/2026/05)
- [April 2026 (2)](https://insights.profitap.com/archive/2026/04)
- [March 2026 (3)](https://insights.profitap.com/archive/2026/03)
- [February 2026 (3)](https://insights.profitap.com/archive/2026/02)
- [January 2026 (3)](https://insights.profitap.com/archive/2026/01)
- [November 2025 (1)](https://insights.profitap.com/archive/2025/11)
- [October 2025 (4)](https://insights.profitap.com/archive/2025/10)
- [September 2025 (1)](https://insights.profitap.com/archive/2025/09)
- [August 2025 (2)](https://insights.profitap.com/archive/2025/08)
- [July 2025 (3)](https://insights.profitap.com/archive/2025/07)
- [May 2025 (1)](https://insights.profitap.com/archive/2025/05)
- [March 2025 (2)](https://insights.profitap.com/archive/2025/03)
- [February 2025 (3)](https://insights.profitap.com/archive/2025/02)
- [January 2025 (2)](https://insights.profitap.com/archive/2025/01)
- [December 2024 (1)](https://insights.profitap.com/archive/2024/12)
- [November 2024 (2)](https://insights.profitap.com/archive/2024/11)
- [October 2024 (1)](https://insights.profitap.com/archive/2024/10)
- [September 2024 (3)](https://insights.profitap.com/archive/2024/09)
- [August 2024 (8)](https://insights.profitap.com/archive/2024/08)
- [July 2024 (7)](https://insights.profitap.com/archive/2024/07)
- [June 2024 (1)](https://insights.profitap.com/archive/2024/06)
- [May 2024 (6)](https://insights.profitap.com/archive/2024/05)
- [April 2024 (1)](https://insights.profitap.com/archive/2024/04)
- [March 2024 (3)](https://insights.profitap.com/archive/2024/03)
- [February 2024 (2)](https://insights.profitap.com/archive/2024/02)
- [January 2024 (1)](https://insights.profitap.com/archive/2024/01)
- [December 2023 (2)](https://insights.profitap.com/archive/2023/12)
- [November 2023 (1)](https://insights.profitap.com/archive/2023/11)
- [July 2023 (1)](https://insights.profitap.com/archive/2023/07)
- [June 2023 (1)](https://insights.profitap.com/archive/2023/06)
- [April 2023 (1)](https://insights.profitap.com/archive/2023/04)
- [February 2023 (1)](https://insights.profitap.com/archive/2023/02)
- [January 2023 (1)](https://insights.profitap.com/archive/2023/01)
- [December 2022 (1)](https://insights.profitap.com/archive/2022/12)
- [October 2022 (1)](https://insights.profitap.com/archive/2022/10)
- [April 2022 (1)](https://insights.profitap.com/archive/2022/04)
- [March 2022 (1)](https://insights.profitap.com/archive/2022/03)
- [February 2022 (2)](https://insights.profitap.com/archive/2022/02)
- [January 2022 (1)](https://insights.profitap.com/archive/2022/01)
- [December 2021 (2)](https://insights.profitap.com/archive/2021/12)
- [October 2021 (2)](https://insights.profitap.com/archive/2021/10)
- [September 2021 (1)](https://insights.profitap.com/archive/2021/09)
- [August 2021 (1)](https://insights.profitap.com/archive/2021/08)
- [June 2021 (1)](https://insights.profitap.com/archive/2021/06)
- [May 2021 (1)](https://insights.profitap.com/archive/2021/05)
- [March 2021 (2)](https://insights.profitap.com/archive/2021/03)
- [February 2021 (1)](https://insights.profitap.com/archive/2021/02)
- [January 2021 (2)](https://insights.profitap.com/archive/2021/01)
- [November 2020 (1)](https://insights.profitap.com/archive/2020/11)
- [September 2020 (1)](https://insights.profitap.com/archive/2020/09)
- [August 2020 (1)](https://insights.profitap.com/archive/2020/08)
- [July 2020 (2)](https://insights.profitap.com/archive/2020/07)
- [June 2020 (2)](https://insights.profitap.com/archive/2020/06)
- [April 2020 (2)](https://insights.profitap.com/archive/2020/04)
- [March 2020 (2)](https://insights.profitap.com/archive/2020/03)
- [February 2020 (4)](https://insights.profitap.com/archive/2020/02)
- [September 2019 (1)](https://insights.profitap.com/archive/2019/09)
- [August 2019 (1)](https://insights.profitap.com/archive/2019/08)
- [May 2019 (2)](https://insights.profitap.com/archive/2019/05)
- [April 2019 (1)](https://insights.profitap.com/archive/2019/04)
- [March 2019 (1)](https://insights.profitap.com/archive/2019/03)
- [February 2019 (1)](https://insights.profitap.com/archive/2019/02)
- [December 2018 (2)](https://insights.profitap.com/archive/2018/12)
- [October 2018 (2)](https://insights.profitap.com/archive/2018/10)
- [August 2018 (1)](https://insights.profitap.com/archive/2018/08)
- [July 2018 (2)](https://insights.profitap.com/archive/2018/07)
- [June 2018 (1)](https://insights.profitap.com/archive/2018/06)
- [May 2018 (4)](https://insights.profitap.com/archive/2018/05)
- [April 2018 (1)](https://insights.profitap.com/archive/2018/04)
- [March 2018 (2)](https://insights.profitap.com/archive/2018/03)
- [February 2018 (1)](https://insights.profitap.com/archive/2018/02)
- [January 2018 (1)](https://insights.profitap.com/archive/2018/01)
- [December 2017 (1)](https://insights.profitap.com/archive/2017/12)
- [November 2017 (2)](https://insights.profitap.com/archive/2017/11)
- [October 2017 (1)](https://insights.profitap.com/archive/2017/10)
- [July 2017 (1)](https://insights.profitap.com/archive/2017/07)
- [May 2017 (2)](https://insights.profitap.com/archive/2017/05)
- [February 2016 (1)](https://insights.profitap.com/archive/2016/02)
- [December 2015 (2)](https://insights.profitap.com/archive/2015/12)
- [June 2015 (2)](https://insights.profitap.com/archive/2015/06)
- [May 2015 (3)](https://insights.profitap.com/archive/2015/05)

see all

### Stay up to date

[Follow @Profitap](https://twitter.com/Profitap?ref_src=twsrc%5Etfw)

[Return to Blog](https://insights.profitap.com/)

# Analyzing security breach connection attempts with IOTA

- [Tweet](https://twitter.com/share)

Learn more about the IOTA solution at **[profitap.com/iota](https://www.profitap.com/iota/)**

# Problem description<https://kb.profitap.com/iota/workflow/analyzing-security-breach-connection-attempts#problem_description>

Security analysts and forensic experts often have to analyze which client established connections to specific target systems at what time. Classic perimeter firewalls can log connection attempts from the WAN, but they do not allow lateral movements in the internal network to be detected. Therefore, there is a “blind spot” that needs to be closed.

The following example gives a step-by-step overview of how to analyze connection setups after a security incident with the profitap IOTA. The goal is to identify the host that was infected or that spread the malicious code to an internal file server in the network.

## Preparation<https://kb.profitap.com/iota/workflow/analyzing-security-breach-connection-attempts#preparation>

For this to be successful, the IOTA must capture traffic on the network before the event occurs so that a retrospective analysis can be performed afterward.

In the first step, we prepare the physical interface. To do this, we navigate to the *Capture* page using the left menu tree, and then to the *Interface Configuration* section. The interface is configured as SPAN (out-of-band) with 10/100/1000 Mbit/s Auto Negotiation as shown below, meaning both physical interfaces can receive the traffic to be analyzed from a SPAN port or a TAP.

![](https://kb.profitap.com/_media/iota/workflow/iota-workflow-analyzing-security-breach-connection-attempts-1.png?w=1200&tok=d6a86e)  
*Figure 1: Configuration of the physical interfaces. In this case, 10/100/1000 Mbit/s Auto-Negotiation in SPAN Mode.*

## Positioning or integration of the IOTA<https://kb.profitap.com/iota/workflow/analyzing-security-breach-connection-attempts#positioning_or_integration_of_the_iota>

An uplink of the switch can be used as a SPAN source to include several client VLANs. If the IOTA is to be integrated in-line into the data stream, for example between the access switch and router or access and distribution switch, the checkbox next to *Inline Mode* must be ticked, and the *Save* button clicked. This depends on the positioning of the VLAN gateway. In-line operation between the switch and server in the data center would also be conceivable if traffic to and from specific servers is to be recorded in order to be analyzed later.

![](https://kb.profitap.com/_media/iota/workflow/iota-workflow-analyzing-security-breach-connection-attempts-2.png?w=1200&tok=c859cd)  
*Figure 2: Placement of the IOTA for packet averaging and subsequent security incident analysis.*

## Start the capture<https://kb.profitap.com/iota/workflow/analyzing-security-breach-connection-attempts#start_the_capture>

After placing the IOTA and preparing the physical interface, we connect the appropriate cable, then start the capture process by navigating to the *Capture Control* section and clicking the *Start Capture* button at the bottom of the screen. Alternatively, we can start the capture process by pressing the physical *Start Capture* button on the IOTA device. This speeds up the process and can be done by untrained or non-privileged persons.

![](https://kb.profitap.com/_media/iota/workflow/iota-workflow-analyzing-security-breach-connection-attempts-3.png?w=1200&tok=d543d0)  
*Figure 3: Start the capture using the “Start Capture” button in the “Capture Control” submenu.*

## Troubleshooting dashboards<https://kb.profitap.com/iota/workflow/analyzing-security-breach-connection-attempts#troubleshooting_dashboards>

To identify the so-called patient zero, we need two approaches. The first is to determine which client has connected to a command and control server (C2) or malware distribution server if known. The second approach uses an affected server or client as a baseline to analyze which other systems have established connections to it.

If it is a known attack, which can be detected by a specific ransomware message, for example, it might be possible to search specifically for communication patterns, such as specific target ports. We use that as an example as well. We assume a ransomware attack on a file server that provided its services via Server Message Block (SMB) on the network. The IPv4 address of the server is 192.168.178.6.

Knowing that SMB operates on TCP port 445, we filter on this destination port on the *Overview* dashboard and on the previously mentioned IP address 192.168.178.6. In the aftermath, only client 192.168.178.22 had established an SMB connection with the file server during the encryption time window.

![](https://kb.profitap.com/_media/iota/workflow/iota-workflow-analyzing-security-breach-connection-attempts-4.png?w=1200&tok=1feb91)  
*Figure 4: Filters to IP address 192.168.178.6 and destination port 445.*

We also check on the *Overview* dashboard, via the filter “IP\_SRC = 192.168.178.22”, which communication relationships were established shortly before by client 192.168.178.22 to clarify whether command and control traffic or a download took place.

At the bottom of the dashboard, we review the filtered flow data in the “List of Flows”. In it, we see that only one communication attempt left the internal network before. Specifically, a TCP connection with TLS on destination port 443, i.e., HTTPS, and the destination IP address 91.215.100.47.

![](https://kb.profitap.com/_media/iota/workflow/iota-workflow-analyzing-security-breach-connection-attempts-5.png?w=1200&tok=7993bc)  
*Figure 5: Communication relationships based on the filtered source host at the bottom of the Overview dashboard.*

Based on this flow data, we switch to the *SSL/TLS Overview* dashboard via the *Navigate* menu at the top right-hand corner of the screen to check with which server name a connection was established. This can be seen in the client hello, or, more concretely, in the TLS extension Server Name Indication (SNI). This contains the hostname with which the client established a connection.

![](https://kb.profitap.com/_media/iota/workflow/iota-workflow-analyzing-security-breach-connection-attempts-6.png?w=300&tok=7552f1)  
*Figure 6: Switching to the SSL/TLS Overview dashboard via the Navigate menu.*

In the *SSL/TLS Overview* dashboard, in the SSL/TLS servers listing, we recognize the associated server name with “config.ioam.de”, with which the client had established a connection.

![](https://kb.profitap.com/_media/iota/workflow/iota-workflow-analyzing-security-breach-connection-attempts-7.png?w=1200&tok=adbc50)  
*Figure 7: SSL/TLS Overview dashboard in which we can see the server name from the TLS client hello.*

Further analysis would have to be done on the client in the log files since the TLS encryption meant that the download itself was not recognizable in plain text. It was then determined that the user had downloaded and installed an application. This executed the encryption process of files over the analyzed SMB network share. Thus, we now had the IP address, hostname, and file that led to the attack. However, in some cases, the servers from which the malware is downloaded are only the “front-end servers” of the attackers, which also change from time to time.

Since lateral movements in the network are often detectable in the case of attacks, other clients should also be checked since the affected client could also have already distributed the malware. If no external communication relationship was visible on the affected client, all internal communication patterns should have been checked for anomalies that could have brought malware to client 192.168.178.22.

If we need to check which hosts attempted to connect to a specific server that seems to provide malicious software, we can also do that with IOTA. If there are known FQDNs that are related to these servers, we could use the *DNS Overview* dashboard.

![](https://kb.profitap.com/_media/iota/workflow/iota-workflow-analyzing-security-breach-connection-attempts-8.png?w=300&tok=f9e59b)  
*Figure 8: Switch to DNS Overview dashboard via Navigate menu.*

We switch to the *DNS Overview* dashboard and use the *Search DNS* filter to search by name. We used the domain *akamaitechcloudservices.com*, which sounds like a connection attempt to a content delivery network, but is known to be a malicious server that is used in a security incident.

![](https://kb.profitap.com/_media/iota/workflow/iota-workflow-analyzing-security-breach-connection-attempts-9.png?w=1200&tok=a7000f)  
*Figure 9: Search by name akamaitechcloudservices.com.*

After the search, we can see that the malicious server was requested by DNS at about 9:20 PM. To further investigate which client attempts to connect to this server, we can go down to the *DNS Overview* dashboard and see the Client IP address which is requesting *akamaitechcloudservices.com*. In our example in Figure 10, it was 192.168.178.22. Now we know which client tried to connect to this server.

![](https://kb.profitap.com/_media/iota/workflow/iota-workflow-analyzing-security-breach-connection-attempts-10.png?w=1200&tok=99ce48)  
*Figure 10: DNS query/response and corresponding flow table.*

## IOTA benefits<https://kb.profitap.com/iota/workflow/analyzing-security-breach-connection-attempts#iota_benefits>

IOTA offers a wide range of options for filtering the relevant communication patterns and time windows for security analyses. In addition, it provides intuitive dashboards compared to other tools to enable simplified and accelerated analysis, even for people without in-depth protocol knowledge.

 

[![CTA All IOTA Dashboards_v5](https://no-cache.hubspot.com/cta/default/2954816/interactive-167361556522.png)](https://insights.profitap.com/hs/cta/wi/redirect?encryptedPayload=AVxigLLpWgPrFFo59qAJL9kHHv%2BL5d%2FJ45abXeDhCzwF98HRaaXomBK8jIfFzLSOGKG%2F4Mb9XyY7f8%2Fgxo6ELKTDZ1ueOfmwAJgrzJijSMSlTBEG77x3YeN7%2BZSTYxvbqUor803wyAXJV40%2B%2BegrcVp681V5c193OHaIr3q6xtKOXxQ7&webInteractiveContentId=167361556522&portalId=2954816)

- [Tweet](https://twitter.com/share)

by [Profitap](https://insights.profitap.com/author/profitap) |  May 27, 2024  | [IOTA](https://insights.profitap.com/topic/iota)

[**Packet Capture & Analysis**](https://www.profitap.com/iota/)

- [IOTA 1G](https://www.profitap.com/iota-1g/)
- [IOTA 1G+](https://www.profitap.com/iota-1g-plus/)
- [IOTA 10G](https://www.profitap.com/iota-10g/)
- [IOTA 10G+](https://www.profitap.com/iota-10g-plus/)
- [IOTA 10 CORE](https://www.profitap.com/iota-10-core/)
- [IOTA 10 CORE+](https://www.profitap.com/iota-10-core-plus/)
- [IOTA 100 CORE](https://www.profitap.com/iota-100-core/)

 

[**ProfiShark**](https://www.profitap.com/profishark-network-taps/)

- [ProfiShark 100M](https://www.profitap.com/profishark-100m/)
- [ProfiShark 1G](https://www.profitap.com/profishark-1g/)
- [ProfiShark 1G+](https://www.profitap.com/profishark-1g-plus/)
- [ProfiShark 10G](https://www.profitap.com/profishark-10g/)
- [ProfiShark 10G+](https://www.profitap.com/profishark-10g-plus/)

 

[**Accessories**](https://www.profitap.com/accessories/)

- [Transceivers](https://www.profitap.com/transceivers/)
- [Data Diodes](https://www.profitap.com/data-diodes/)
- [Connectivity](https://www.profitap.com/accessories/#connectivity/)

<https://twitter.com/Profitap>

<https://www.youtube.com/c/Profitap>

<https://www.facebook.com/Profitap>

<https://www.linkedin.com/company/profitap-international>

[**Network Traffic Aggregators**](https://www.profitap.com/network-traffic-aggregators/)

- [XX-720G](https://www.profitap.com/xx-720g-network-packet-broker/)
- [XX-1800G](https://www.profitap.com/xx-1800g-network-packet-broker/)
- [XX-3200G](https://www.profitap.com/xx-3200g-network-packet-broker/)

 

[**Network Packet Brokers**](https://www.profitap.com/network-packet-brokers/)

- [X3-Series](https://www.profitap.com/x3-series-advanced-network-packet-brokers/)
- [X2-2010G](https://www.profitap.com/x2-2010g-network-packet-broker/)
- [X2-3200G](https://www.profitap.com/x2-3200g-network-packet-broker/)
- [X2-6400G](https://www.profitap.com/x2-6400g-network-packet-broker/)
- [X2-12800G](https://www.profitap.com/x2-12800g-network-packet-broker/)

 

**NPB Features**

- [Data Masking](https://www.profitap.com/data-masking/)
- [Timestamping](https://www.profitap.com/timestamping/)
- [Packet Deduplication](https://www.profitap.com/packet-deduplication/)
- [Tunneling & De-tunneling](https://www.profitap.com/tunneling-de-tunneling/)
- [Packet Slicing](https://www.profitap.com/packet-slicing/)
- [GTP IP Filtering](https://www.profitap.com/gtp-ip-filtering/)

[**Network TAPs**](https://www.profitap.com/network-taps/)

- [Secure TAPs](https://www.profitap.com/secure-data-access/)
- [Fiber TAPs](https://www.profitap.com/fiber-taps/)
- [Copper TAPs](https://www.profitap.com/copper-taps/)
- [Aggregation TAPs](https://www.profitap.com/aggregation-taps/)
- [Bypass TAPs](https://www.profitap.com/bypass-taps/)
- [Regeneration TAPs](https://www.profitap.com/regeneration-taps/)
- [Replication TAPs](https://www.profitap.com/replication-taps/)

 

**Cloud Visibility**

- [VMware](https://www.profitap.com/vtap/)
- [Kubernetes](https://www.profitap.com/cloud-tap/)
- [AWS EKS](https://www.profitap.com/cloud-tap/)
- [Azure VM](https://www.profitap.com/cloud-tap/#azure)

 

**Centralized Management**

- [IOTA CM](https://www.profitap.com/iota-cm/)
- [Supervisor](https://www.profitap.com/supervisor/)

 

[**Solutions**](https://www.profitap.com/solutions/)

- [Performance analysis & diagnostics](https://www.profitap.com/performance-analysis-and-diagnostics-solutions/)
- [Network troubleshooting](https://www.profitap.com/network-troubleshooting-solutions/)
- [Packet forensics](https://www.profitap.com/packet-forensics-solutions/)
- [Network security](https://www.profitap.com/network-security-solutions/)
- [ICS/OT network monitoring](https://www.profitap.com/ics-ot-network-monitoring-solutions/)

[**About Us**](https://www.profitap.com/our-story/)

- [Our Story](https://www.profitap.com/our-story/)
- [Events](https://www.profitap.com/events/)
- [Careers](https://jobs.profitap.com/)
- [News](https://news.profitap.com/)

 

**Resources**

- [Knowledge Base](https://kb.profitap.com/)
- [Software & Drivers](https://resources.profitap.com/)
- [Product Portfolio](https://www.profitap.com/portfolio/)
- [Blog](https://insights.profitap.com/)
- [Library](https://www.profitap.com/library/)
- [Product Updates](https://www.profitap.com/product-updates/)
- [Academy](https://www.profitap.com/academy/)

 

**Partners**

- [Partner with Us](https://www.profitap.com/partner-with-us/)
- [Our Partners](https://www.profitap.com/our-partners/)
- [Locate a Reseller](https://www.profitap.com/locate-a-reseller/)

 

**Contact**

- [Contact Us](https://www.profitap.com/contact-us/)
- [Professional Services](https://www.profitap.com/professional-services/)
- [Get a Quote](https://www.profitap.com/get-a-quote/)

---

© 2026 Profitap HQ B.V. and its licensors. All Rights Reserved — Profitap HQ B.V., High Tech Campus 84, 5656 AG Eindhoven, The Netherlands | [Privacy Policy](https://www.profitap.com/privacy-policy/) | [Terms and Conditions](https://www.profitap.com/terms-and-conditions/)

```json
{
  "@context" : "http://schema.org",
  "@type" : "Blog",
  "author" : {
    "@type" : "Person",
    "name" : "Profitap"
  },
  "dateModified" : "May 27, 2024, 12:19:05 PM",
  "datePublished" : "2024-05-27 11:38:29",
  "description" : "IOTA Workflow, how to Analyzing security breach connection attempts",
  "headline" : "Analyzing security breach connection attempts with IOTA",
  "image" : {
    "@type" : "ImageObject",
    "url" : "https://2954816.fs1.hubspotusercontent-na1.net/hubfs/2954816/Blank%20diagram%20%281%29-1.jpeg"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://cdn2.hubspot.net/hubfs/2954816/Logos/Profitap-logo-black-orange-whitebg.png"
    },
    "name" : "Profitap HQ B.V."
  }
}
```