Key Takeaways
Endpoint alerts are not enough and should be correlated with network traffic to add context to the malware behavior.
As part of Malware Network Traffic Analysis, identifying command and control (C2) traffic, payload downloads, lateral movements, or attempts to exfiltrate data are helpful in identifying hidden threats.
The ability to map endpoint events to network activity helps analysts’ complete investigations more quickly by reconstructing attack timelines and identifying attacker infrastructure.
Behavioral malware analysis helps to link unusual processes, persistence methods, and recurring network traffic.
Fidelis Security is a platform that provides endpoint visibility and network intelligence, enabling security teams to speed up their threat hunting efforts, enhance incident response, and gain a holistic understanding of attacker activity.
Modern cyberattacks rarely remain confined to a single device. Once malware runs on a device, it typically communicates with the outside world, downloads more payloads, moves laterally in the environment, or tries to exfiltrate data. Knowing what to anticipate on these types of network traffic is crucial for SOC analysts and Endpoint Detection and Response (EDR) teams as it is to investigate endpoint alerts. This is where Malware Traffic Analysis (MTA) for EDR Teams can make all the difference.
A USENIX study found that 58% of malware samples exhibited network activity within the first five minutes of execution, and 78% displayed additional behaviors when allowed limited Internet connectivity, demonstrating how critical network communications are for understanding modern malware[1]. The context provided by correlating endpoint telemetry with network traffic enables security teams to detect attack progression, look for hidden threats, and rapidly respond to incidents.
Malware Analysis and Network Traffic
Malware analysis examines malicious software to understand how it executes, communicates, and impacts an infected system. Modern malware rarely operates alone; it often connects to command-and-control (C2) servers, downloads additional payloads, moves laterally across networks, or exfiltrates sensitive data. Malware types such as ransomware, trojans, remote access trojans (RATs), infostealers, and fileless malware use different techniques to compromise systems and evade detection.
While endpoint tools provide visibility into processes, files, and system changes, network traffic reveals what those processes communicate with after execution. For example, a PowerShell process may be legitimate, but communication with a known malicious domain can indicate compromise. Combining endpoint telemetry with malware traffic analysis helps security teams understand attacker behavior, detect threats faster, and improve incident response.
Advanced malware analysis combines multiple security techniques to understand attacker behavior. Sandbox analysis helps security teams safely execute and observe suspicious files to identify malicious actions, while endpoint sandboxing provides visibility into how malware behaves on compromised devices. Machine learning-driven analytics help identify unusual patterns and behaviors that may indicate emerging threats, and behavioral malware detection helps uncover techniques such as persistence, command-and-control communication, and lateral movement.
Sandbox Technology
Behavior Analysis
Sandbox Data Analysis
Cloud Sandbox
Connecting Endpoint Events to Network Behavior
The best endpoint malware analysis is achieved when security teams can match endpoint events with the network communication. Instead of looking into alerts one by one, analysts can trace the events leading to external communication and attacker activity.
1. Process Execution and Network Connections
A very early sign of compromise is the execution of an unusual process. This can be a suspicious executable, PowerShell script, a malicious macro in a document, or a legitimate system tool being misused by an attacker. The investigation process usually starts by determining what process has caused the alert. Analysts then check to see if that process created DNS requests, made an outbound connection, or downloaded other files.
If PowerShell starts up and makes an immediate connection to an unknown domain, downloads a payload, and spawns other processes, the endpoint and network evidence give a much better understanding of the attack chain. Using this correlation, analysts can follow the entire chain of events, see which infrastructure the malware was able to reach, if any were delivered further, and whether a command-and-control communication was made. Teams should think of a process alert as a piece in a process, rather than an isolated event.
2. Persistence Mechanisms and Associated Traffic
Once initial access is achieved, many malware families try to gain persistence to stay up and running after system reboots and to gain long-term access to the environment. Modifying registry keys can be done, as well as creating scheduled tasks, installing services, or exploiting start-up folders.
When looking at network activity, these endpoint events have a much greater meaning. For example, a new task in the scheduled tasks list might look suspicious, but not necessarily malicious. If, however, that task causes a process to communicate with the same external server periodically, say every few minutes, then a likely beaconing pattern can be observed by the analysts. When looking at persistence mechanisms and recurring network communications, security teams can identify if malware is still active in the environment. This can be useful in identifying threats that could go unnoticed if they were not part of a “red team” exercise.
3. Command-and-Control and Data Exfiltration
A primary objective of behavioral malware analysis is to identify C&C traffic and to get a sense of attacker communication. Upon communications with the attacker-controlled infrastructure, malware can be instructed, malware tools could be downloaded, or sensitive data could be gathered. Common communications patterns, links to unrecognized or suspicious domains, unusual and encrypted traffic patterns, and outbound transfers not typical of users are typical things that analysts will look for.
The investigation process will then be based around correlation of endpoint activity and network sessions to see if the malware is communicating to external infrastructure. When a suspicious process continues to establish communications to a particular destination and generates outbound communications periodically, it can be an active command-and-control channel. Additionally, if the number of outbound transfers is significant after accessing the file, this could be a sign of data exfiltration. By connecting endpoint events to network events, security teams can move from detection to knowing what the attacker is looking for, what he can do, and how far he can penetrate the environment.
How Fidelis Security Helps Connect Endpoint and Network Intelligence
To get a better understanding of how malware works in an environment, you need to be able to correlate endpoint events with network activities. By integrating endpoint detection and response (EDR) with deep network visibility, organizations can investigate threats more effectively, which is where Fidelis Security comes in.
Fidelis Endpoint® continuously monitors and records endpoint activity including process, file and script activity, registry and user actions. This visibility enables analysts to detect unusual activity, investigate alerts, and determine the timeline of an attack. The platform also enables threat hunting, forensic investigations, and automated response actions to mitigate the spread of threats.
In addition to endpoint visibility, Fidelis Network® can analyze network traffic throughout the environment to identify malicious communication, command and control (C2), lateral movement, and possible data exfiltration threats. Network traffic is correlated with endpoint events, allowing analysts to identify which processes started connections, what external infrastructure was reached, and how an attack has progressed since initial compromise.
Fidelis also enhances investigations through threat intelligence, behavioral analytics, malware analysis, and sandbox capabilities. By analyzing suspicious files, endpoint behavior, and network communications together, security teams can identify malicious activity, understand attack techniques, and accelerate incident response.
How Fidelis Prevent, Detect, and Respond
Threat Prevention and Intelligence
Investigating, Hunting, and Forensics
Conclusion
Modern malware investigations require more than endpoint visibility alone. While EDR tools provide valuable insights into process execution, persistence mechanisms, and system changes, they often tell only part of the story. By combining endpoint malware analysis with malware network traffic analysis, organizations gain a more complete understanding of attacker behavior. Security teams can trace attacks from initial execution through command-and-control communications, lateral movement, and potential data exfiltration, allowing them to respond more effectively.
Effective malware investigations require a combination of endpoint visibility, network intelligence, behavioral analysis, and threat detection capabilities. By correlating endpoint activity with network communications, security teams can better understand attacker behavior, identify hidden threats, and respond faster. Fidelis Security further strengthens this capability by correlating endpoint and network intelligence, enabling more effective threat detection, investigation, and response.
The post Malware Traffic Analysis for EDR Teams: How to Connect Endpoint Events to Network Behavior appeared first on Fidelis Security.
No Responses