From Local Capture to Structured Protective Intelligence

In early 2023 a set of 294 local screenshots captured terminal activity on a residential New York Charter/Spectrum network. What began as reactive documentation of traffic, DNS, and tool output became a multi-year exercise in disciplined residual ranking, passive OSINT, and defensive tradecraft.

This article walks through that progression—not as a claim of compromise, but as a transparent record of how Quantitative Security refined its approach to inventory, prioritization, and public-source correlation. The work illustrates the company’s shift from ad-hoc defensive capture to structured protective-intelligence practice.

The 2023 starting point

The source material was ordinary operator activity: tcpdump, nmap, browser sessions, ARP tables, and DNS overlays. From those screenshots we extracted:

  • ~1,450 unique IPv4 addresses (≈1,266 public)

  • Hundreds of domains, MACs, ASNs, and a small set of emails/URLs

Early goals were simple: organize the noise, separate self-generated traffic from external destinations, and avoid treating every foreign address as an indicator. Counts were screenshot files and OCR hits, not packet volumes. OCR fragments were flagged rather than trusted.

That first inventory already contained the seeds of later discipline: vision-checked rows preferred over pure OCR, LAN traffic quarantined from any IOC list, and a refusal to invent attribution.

Methodological growth

Ranking

By 2026 the same data set carried an explicit T1–T5 scale:

  • T1 — unexplained residual with real 2023 session evidence

  • T2 — 2026 exposed surface worth hygiene documentation

  • T3 — explained session traffic (self-tools, adtech, CDN, consumer)

  • T4 — local / “us”

  • T5 — do-not-scan / OCR ghosts / sensitive organizational ranges

This replaced undifferentiated “interesting IP” lists with prioritization that could be handed to another analyst without reinterpretation.

Live recon with guardrails

A full 2026 pass added header grabs, limited HTML title clones, nmap on open ports, certificate checks, and BGP context. Rules remained strict: no credential use, no brute force, no exploitation, and explicit “document only” treatment for Boeing-range and DNIC-style OCR addresses.

Service identification before speculation

Residuals were not left open as “interesting foreign IPs.” Each was pushed through passive identification—WHOIS, BGP history, certificate data, public scan repositories, and historical associations—until a concrete service or reclassification could be stated.

The clearest illustration is 103.235.46.191 (Baidu HK, AS55967). On 9 July 2023 the local capture showed two concurrent roles: an explicit ip-api lookup of the address and a TLS conversation to port 443 that later stalled. In 2026 the same address timed out from external vantage while its prefix remained announced. Passive correlation tied the block to Baidu’s Hong Kong allocation and to the hm.baidu.com analytics/Tongji edge. Service identity closed; the residual that remains is purely operational (why the 2023 session occurred and why the address is dark now).

Other high-visibility destinations received the same treatment and were closed:

  • 23.82.31.230 resolved to TradingView infrastructure on Leaseweb in the San Jose/Equinix footprint (server: tv, certificate for *.tradingview.com). What had looked like an unexplained colo residual was ordinary trading-platform traffic.

  • Foreign CPE-style addresses that carried noisy geo overlays were re-checked against live PTR and RIR data and reclassified as residential or small-business customer ranges rather than servers of interest.

  • Self-tool and commodity destinations (ip-api, Ubuntu snap store, major CDN and ad-tech anycast) were documented.

The discipline is deliberate: identify the actual service—or the actual customer edge—before any residual is allowed to remain open. Only after that step does an item stay on a T1 list, and only with the precise unanswered question attached. Speculation is deferred until the service layer is exhausted.

Event and geography without forced attribution

Public event windows were aligned against the inventory for context only.

February 2023 — local path and telecom disruption

The capture sat on a Charter/Spectrum New York residential path. That same month Charter experienced a multi-state VoIP outage that affected New York among other regions. The inventory’s repeated traceroute and netops.charter.com destinations simply reflected the operator’s own upstream; the outage supplied temporal context for why telecom path visibility mattered, not evidence of targeting. Separately, Spain saw a multi-operator fiber-trunk disruption the same month. Early geo overlays that pointed some residuals toward Spanish networks were later corrected by live PTR and RIR data (reclassified as Virgin Media UK customer edge). The correction itself became part of the methodology: treat geo overlays as noisy until confirmed.

May–June 2023 — U.S. research and time infrastructure

In the same capture window the inventory recorded repeated contact with California research-and-education destinations, including Stanford NTP (srcf-ntp.stanford.edu) and CENIC path elements. These resolved cleanly to academic and regional research networking—ordinary time-synchronization and research-path traffic—and were closed as explained session traffic.

Their presence matters for framing. Public Chinese statements in this broader period included reciprocal claims that U.S. actors had targeted or misused time infrastructure, including references centered on China’s National Time Service Center and allegations directed at NSA-linked activity. On the other side of the same ledger, the defensive capture set itself was documenting Chinese-space destinations (analytics edge and provincial telecom allocations) in the weeks that followed. The inventory therefore sat inside a mutual-accusation climate: Chinese public statements pointing at U.S. NTP/time infrastructure, and the operator’s own traffic record simultaneously containing Chinese-network destinations under review. The contrast was logged as geopolitical context, not as proof.

May–July 2023 — residual timing and public attribution windows

A Boeing-range address appeared in the May captures and was immediately placed on an explicit do-not-scan / document-only list. Months later, in October 2023, Boeing’s parts-and-distribution business was publicly linked to a LockBit intrusion (Citrix Bleed, later confirmed ransom demand and data leak). The inventory address and the later incident share an organizational name and nothing else; no session data, no timeline overlap, and no claim of connection were made. The item remained documentary.

Chinese-space destinations concentrated around 9–10 July 2023—three days before the Microsoft and White House statements attributing Storm-0558 activity to China-based actors. Reciprocal Chinese statements followed. The capture set’s own Chinese-network residuals and the parallel U.S. research/NTP path traffic were both already on record. Proximity and the mutual-accusation backdrop were noted. No residual address from the inventory was named in any of those statements, and none was elevated on that basis. Later public reporting on Salt Typhoon and related PRC telecom-targeting activity (2024–2025) kept U.S. and Chinese telecom infrastructure in the broader analytic frame.

August 2023 — provider incident near a closed residual

Leaseweb publicly reported unusual activity in its cloud environments on 22 August 2023, took systems offline, and engaged external forensics. An earlier residual in Leaseweb address space had already been service-identified as TradingView colo traffic and closed. The provider’s own incident stood as independent public record; it was not retroactively attached to the inventory destination.

Ongoing discipline

Telecom-path visibility (Charter VoIP outage, later national focus on telecom as a Salt Typhoon sector), organizational name collision (Boeing residual vs. later LockBit reporting), U.S. research/NTP path traffic alongside Chinese-space destinations in the same months, and provider self-disclosure (Leaseweb) were all logged as correlation opportunities. Each was tested against session evidence, timing, and public naming. Geography and event windows therefore function as context layers, not attribution engines. The same rule applied to every other public statement examined—Cl0p campaigns, MSS/MPS-linked reporting, and reciprocal claims involving time or network infrastructure: useful for timeline, silent on the specific addresses in the capture set.

Updated tactics

Quantitative Security’s current and growing practice, refined through this and parallel work, emphasizes:

  • Inventory first, narrative second — full extraction and classification before any external correlation

  • Explicit ranking — T-levels that travel with the data

  • Passive-first OSINT — WHOIS, BGP, certificate transparency, public scan repositories, and historical DNS before any active follow-up

  • Service closure — identify the actual service (analytics edge, trading colo, CPE, research NTP) before leaving an item open

  • Do-not-scan discipline — organizational and OCR-ambiguous ranges stay documentary

  • Temporal honesty — public event windows are aligned for context, never forced into attribution

These habits scale from a single residential capture set to protective-intelligence and future federal-contract support work.

Company trajectory

What began as personal defensive documentation in 2023 now sits inside Quantitative Security’s broader offering: protective intelligence, threat hunting, custom tooling, OSINT. The same discipline that turned 294 screenshots into ranked residuals and closed service identities is the discipline applied to client environments—separating noise from signal without inflating findings.

The 2023–2026 arc demonstrates measurable growth:

  • From raw OCR lists → structured, ranked, transferable packages

  • From reactive “what is this IP” → systematic residual closure and hygiene tracking

  • From isolated local capture → methodology that incorporates live recon, public-source correlation, and explicit non-actions

  • From individual operator notes → branded, repeatable process suitable for external hand-off and contract delivery

Closing

Defensive traffic analysis is most useful when it refuses to over-claim. The 2023 inventory never became a malware case; it became a training ground for ranking, service identification, custom tooling growth, arsenal building and disciplined private/public-source work. Those habits are now core to how Quantitative Security approaches protective intelligence.

Past data stays past data. Updated tactics turn it into process. The distance between a folder of screenshots and a ranked, transferable intelligence package is the measure of growth.

Quantitative Security Protective intelligence · Threat hunting ·

quantitativesecurity.org · @unccno

Next
Next

The Front Said T-Mobile. The Block Was Always Verizon.