Wireless CNO Flashcards
wlan.fc.type eq 0 is what?
Filter for All Management frames in wireshark
wlan.fc.type_subtype eq 0 is what?
Association Request filter is a type of management frame
above is the filter for Wireshark
wlan.fc.type_subtype eq 1 is what?
Association response a type of management frame. above is the filter for Wireshark
wlan.fc.type_subtype eq 12
Deauthentication frame is a type of management frame.
above is the filter for Wireshark
wlan.fc.type_subtype eq 4
Probe Request frame is a type of management frame.
above is the filter for Wireshark
wlan.fc.type_subtype eq 5
Probe Response frame is a type of management frame
above is the filter for Wireshark
wlan.fc.type_subtype eq 27
Request to Send frame is a type of management frame.
above is the filter for Wireshark
wlan.fc.type_subtype eq 28
Clear to Send frame is a type of management frame.
above is the filter for Wireshark
Continue Collection
Collect as able to maintain tgt awareness, but no action at this time
Conduct CNE
Active & Passive operations to gain access to tgt information systems
Conduct CNA
We must be careful with these activities since DISRUPTING, DENYING, DEGRADING target systems and their ability to communicate result in a denial of service that will disrupt future collection efforts, and may alert the target that they are being targeted
Kill/Capture
Final part of the Find/Fix/Finish picture. POL efforts must be used to ensure time/location when units conduct kill/capture
ROGUE AP - EVIL TWIN ATTACK
- Fake Wi-Fi network that looks like a legitimate access point to steal victims sensitive details
- Attackers can initiate a DEAUTHENTICATION to get victims to associate with the new rogue APs