I have a device on my network I’m trying to identify. It goes offline for the whole day, comes on in the 1am hour for 15 minutes, and it’s gone again…
I want to build some kind of automated task that will trigger when online and run some basic commands to investigate it.
Tips?
It’s under device_tracker.74c246dbe673 - I need to trigger when “home” - run diag commands: nmap it’s ip, run tcpdump on it’s host until it goes offline, and anything else? I’m using nmap device tracker, example attributes:
But still cannot understand why it shows at 1am. Hmm. I’ve already accounted for our Echo Dot and Fire tablet. We don’t have any other Amazon device I can think of … but I’ll start looking there, too.
Wait … My Kindle ! Ha. That might be it. Damn, can’t believe I forgot that one.
These things phone home constantly. My son has one that I see constantly talking to Amazon.
Not sure if its still the case, but in the past if you tried to block this traffic, the device would keep trying over and over until it killed its battery in a short period.