Back to all posts
Day 70Saturday, April 11, 20262 min read

Mapping IP Addresses to Devices Using ARP

cybersecuritynetworkinglearningprocess
View original post

πŸ”„ Topic

Understanding how to identify devices on a network using ARP (Address Resolution Protocol).


🎯 Goal

Learn how to map IP addresses to physical devices using MAC addresses.


πŸ›  What I Did

Used:

arp -an

to view mappings between:

  • IP addresses
  • MAC addresses

This allowed me to see which devices were present on the network.

The useful part was not the command itself. The useful part was learning to translate a table of addresses into an investigation question: which machine is this, should it be here, and does the identity match what I expect?


πŸ”— Key Cybersecurity Connections

ARP is fundamental for:

  • network visibility
  • device identification
  • investigation of suspicious hosts

Attackers also abuse ARP through:

  • ARP spoofing
  • man-in-the-middle attacks

πŸ” Investigation Questions

  • Which device owns this IP?
  • Is this MAC address expected?
  • Has a device changed identity?

🚨 Detection Opportunities

  • duplicate IPs with different MACs
  • unexpected MAC addresses on network
  • ARP table anomalies

🧭 MITRE ATT&CK Techniques

  • T1557 β€” Man-in-the-Middle

⚠ Challenges

Understanding that:

  • IP addresses can change
  • MAC addresses are more stable identifiers

πŸ“š What I Learned

  • ARP bridges network and physical layers
  • mapping is essential for investigation
  • attackers can manipulate this relationship
  • a single identifier is rarely enough during triage
  • good network investigation means correlating IP, MAC, hostname, timing, and expected asset ownership

➑ Next Steps

  • explore ARP spoofing detection
  • simulate MITM attacks in lab

🧠 Reflection

This is where networking becomes investigative:

IP is β€œwhere” β€” MAC is β€œwho”.


🧩 Lessons Learned

What worked

Using ARP to visualize the network.

What broke

Assuming IP alone identifies a device.

Why it broke

IP addresses are dynamic.

Fix / takeaway

Correlate multiple identifiers.

For a SOC workflow, the practical lesson is simple: do not stop at "I found the IP." Keep going until the device identity and the surrounding evidence make sense.


πŸ“ˆ Skill Progression Context

This builds foundational network investigation skills used in SOC environments.


πŸ˜„ TL;DR

IP tells you where to look…
MAC tells you who’s actually there.