runZero Hour, Ep. 4: Network Lookalikes and Fingerprinting Challenges

Episode 4 of the runZero Hour webcast discussed lookalikes on the network, which can include: human-machine interfaces found in OT environments, simulators/probes, honeypots, rogue devices, and compatible devices that happen to look alike just because they speak the same protocol. Most of these serve legitimate purposes for testing and monitoring, so their presence isn’t necessarily malicious, but they present challenges for fingerprinting. How do you differentiate a lookalike from the real thing?

The hurdle is incredibly steep if you're just doing passive discovery. It can't always differentiate between request and response with some protocols, such as Factory Interface Network Service (FINS). You really need to initiate the conversation for accurate fingerprinting.

Beyond that, you must leverage other techniques to identify the device doppelgängers. For example, with GasPot for the Automatic Tank Gauge (ATG) protocol, you can leverage line endings–carriage return line feed (\r\n) versus line feed (\n)--as a “tell”. Another fun example would be IoT/OT devices and their Windows lookalikes. You can actually use the discrepancy between ICMP and TCP syn response times as a giveaway.

Lookalikes was just one segment in this episode of runZero Hour. Watch the recording for more insights.

Meet Our Speakers

HD Moore

Founder & CEO, runZero

Huxley Barbee

Contributor

Rob King

Director of Applied Research, runZero

Tom Sellers

Principal Research Engineer

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Webcasts
runZero Hour, Ep. 27: KEVology 101 – observing exploit trajectories in the KEV Collider
In this episode or runZero Hour, Tod Beardsley, Rob King, and special guest Wade Sparks (CISA and VulnCheck KEV veteran) explore the science of...
Webcasts
Segmentation Theater: Finding the routes attackers use with HD Moore
From the SANS Winter Cyber Solutions Fest 2026: Utilities and Critical Infrastructure event, HD Moore presents Segmentation Theater.
Webcasts
How TeamSystem accelerates M&A integration with runZero
Learn how TeamSystem used runZero to accelerate M&A integration, reduce risk, and maintain confidence while scaling.
Webcasts
runZero Hour, Ep. 26: Exploring offseason resorts and OT networks with Brianna Cluck
In the first 2026 episode of runZero Hour, Rob King and Tod Beardsley chat it up with fan-favorite OT expert Brianna Cluck from GreyNoise...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.