Clicky

How InterConnect Defense Made Packet Analysis Accessible to Hundreds of Analysts | qa | cafe
Case Studies

How InterConnect Defense Made Packet Analysis Accessible to Hundreds of Analysts

"We've got something like 400 active users looking at packet captures now, which is a massive jump from the one or two 'grey beards' we had before. That is a huge success." - Seth Philips, InterConnect Defense 

InterConnect Defense, LLC (ICD) provides contracted cybersecurity services for a variety of U.S. federal organizations. Seth Phillips leads a tactical engineering team embedded directly with one of those customers, developing rapid-response capabilities, reverse engineering solutions, and analytics tools that help analysts solve difficult operational problems faster.

We recently spoke with Seth to learn how CloudShark Enterprise has changed the way his organization works with packet captures, and why packet analysis has gone from an expert-only activity to something hundreds of analysts now use every day.

Key Takeaways:

InterConnect Defense was able to:

  • Expand packet analysis from a handful of specialists to nearly 400 active users.
  • Use Deep Search to find relevant captures across an entire packet repository instead of searching files individually.
  • Reduce duplicated work with annotations and collaborative analysis that preserve and share analyst knowledge.

QA Cafe (QAC): Tell us a little about InterConnect Defense and what your team does.

Seth Phillips (SP): ICD provides contracted services for a variety of federal organizations. Our company has folks that specialize in both the cybersecurity (defense) and computer network operations (offense) domains.

For my role, I'm specifically embedded in a government customer's spaces and lead a tactical team that performs quick-reaction capabilities, reverse engineering, and analytics and visualization development for analysts and operators.

We're kind of like a Swiss Army knife team. We sit directly with our users, identify their operational problems, and then find or build a solution within hours or days so they can spend less time on tedious work and more time solving hard problems.

QAC: Where do packet captures fit into that mission?

SP: We deeply care about understanding our networks and being able to speak to them with SME-level confidence. Everyone on our team has deep technical knowledge of network architectures and communications standards. But historically we've lacked the ability to easily look at, share, and use packet captures.

Gerald Combs said something in a SharkFest keynote that really resonated with us:

"Packet captures are often the last resort, when really, they should be a first or second."

Our guys weren't bothering with packets, not because they don't value them, but because they're too difficult and cumbersome to work with on their own. Our customer's own corporate all-in-one visualizer even says something to the effect of "this file type is unsupported because it's too hard to parse".

QA Cafe: What made packet analysis so difficult?

SP: Before CloudShark, there'd be the occasional "greybeard" that could recite a tshark/awk/grep incantation, and the average analyst would go to these guys for a high-level ask. Our network SMEs frequented Wireshark, but that came with compute environment struggles and a surprising amount of overhead that most users just didn't want to deal with.

To top it off, sharing the analytic results has been difficult ("Hey Pete, can you check out a virtual machine, install Wireshark, download this file and these dissectors, trace this TCP stream, and look at hex offset x in packet y?").

It's no wonder people avoided them.

QAC: How did CloudShark Enterprise change that?

SP: Most packet analysis software forces a tradeoff we didn't want to make. Tools like Wireshark are powerful but far too heavy for day-to-day collaborative use; they're built for one person digging in alone, not for a team trying to stay aligned. On the other end, most lightweight alternatives barely render packets correctly, let alone support any real workflow.

In our experience, CloudShark Enterprise is the tool that fits that gap perfectly. Deep search lets us scan across our whole pool of captures at once to find the ones that actually matter. And once we're in a capture, packet annotation lets us leave notes right on the packets that matter, so the rest of the team can pick up the analysis without having to redo it. Together, that saves us from having to redo work someone else has already finished.

QAC: Which capabilities have had the biggest impact?

SP: We hear so much praise from our team for the ease of access and the intuitive nature. Because it looks and feels like Wireshark but runs in a browser, there is no need to build a virtual machine or download files just to view a capture.

And Deep Search has been transformative. Instead of opening captures one at a time, we can search across our entire repository and immediately find the captures that matter. We then leave notes directly on the packets that matter, so someone else can continue the investigation without having to repeat the work.

QAC: Was deployment difficult?

SP: Not at all. From a sysadmin perspective, getting the team set up was refreshingly painless. The QA Cafe team has also been consistently responsive, patient, and willing to actually listen and help. That combination of a genuinely useful product backed by a great support team is rare, and it's a big reason CloudShark Enterprise has become something my team relies on every day.

QAC: What has adoption looked like?

SP: I actually checked our metrics recently. We've got something like 400 active users, which is a massive jump from the one or two "greybeards" we had before. That is a huge success.