Northwind Outfitters runs a small public-facing services subnet. The SOC wants to know whether
anyone is poking at it. Stand up a low-interaction decoy on dmz-sentry01 in the screened
subnet, trigger a probe from soc-wks14, then read the capture log to find who knocked.
dmz-sentry01 · console
listener: off
admin@dmz-sentry01:~$
soc-wks14 · probe tool
203.0.113.45
target: dmz-sentry01:<none>
SnareLite · capture log
Time
Source IP
Dst port
Proto
Request
Log not opened yet.
Tasks
0 / 4
✓Start the SnareLite decoy listener on dmz-sentry01 (pick any valid port).
✓From soc-wks14, send a probe to the decoy and get it logged.
✓Open the capture log and confirm at least one recorded hit.
✓Enter the source IP shown in the log to identify the prober.