Home Network Defense — Day Companion

Clinic 1 of Home Cyber Defense · Wed 7 Oct · 6–8pm Pacific ·

You leave knowing what is actually on your network — which is something very few people can say about their own house.

Your bench status

Nothing saved yet. Open the Home Network Bench and start at Station 01. Your progress shows up here, read from this browser only.

Why this matters more this year

Assume you're facing a "resourced" attacker now. Everyone is.

Threat models usually sort attackers into three tiers: casual (someone trying default passwords), targeted (someone who wants you specifically), and resourced (a skilled, funded team that can chain many steps together). Home security advice used to assume tier 1.

2026 changed that. Between May and July, AI agents broke into Hugging Face on their own: one of the first multi-step break-ins run end to end by AI rather than by a person. On September 10, Anthropic's threat report showed criminals using Claude to run whole attacks, not just to write the odd email. Work that used to take a funded team can now be done by one person with an AI.

What that means tonight: the boring basics matter more, not less. An AI-assisted attacker tries every default password, every open door and every forgotten gadget, tirelessly and cheaply. Tonight's list closes exactly those doors.

Can't log into your router? Read this first

About half the room hits this: the landlord owns the box, the building manages the network, the ISP locked it down, or the admin password was set years ago by someone who has since moved out.

That is a supported answer, not a failure. Say so in the bench and the router-only items come off your scorecard instead of sitting there unfinished.

Do it in the bench → Station 01 · Router Access Mark "I can't get into my router" there and those items come off your scorecard.

Three things still work without admin access: see what's on the network (scan from a laptop), filtering DNS per device (set it on each phone and computer), and the real fix — put your own router in front of theirs. A router you own, plugged into their box, gives you back every item on this list. If you rent long-term it's worth about $50.

1 · The router itself

Change the admin password off the default

DoOpen 192.168.1.1 or 192.168.0.1 in a browser (the default login is often on a sticker underneath). Change the admin password to something generated and store it in your password manager.

WhyOn older routers the default is the same for every unit and printed in the manual online, so anyone on your wifi could reconfigure the whole network.

Sticker shows a random, unique password? Good, that's much lower risk. Still change it if anyone else has had access to the box (roommates, landlord, the previous tenant, the installer), because the sticker is readable by anyone who's been near it. Some ISP routers also generate the "random" password from the serial number, and that has been reverse-engineered before.

Common mistakeChanging the wifi password and thinking that was the admin password. They're two different things.

Turn on automatic firmware updates

DoLook for "firmware", "router update" or "administration" and enable automatic updates. No such option? Set a reminder to check twice a year — or take it as a sign the router is old enough to replace.

WhyRouters are small computers sitting directly on the internet, and nobody remembers to update them. That's exactly why they're a popular target.

Turn off remote administration

DoFind "remote management", "WAN access" or "administration from internet" and switch it off.

WhyIt lets anyone on the internet reach your router's login page. A home router almost never needs it, and when it's on it gets scanned constantly.

Turn off UPnP

DoFind UPnP and disable it. If a game or console breaks, turn it back on knowingly.

WhyUPnP lets any program on your network silently open a hole from the internet to itself — convenient for a console, equally convenient for anything unpleasant.

Gamers in the house?Consoles are the usual reason UPnP stays on. If your router can run a third network (or VLANs), make a consoles network and put the Xbox, PlayStation and Switch there. On most home routers UPnP is still one switch for the whole router, but at least a console that gets compromised can't reach your laptops.

Set filtering DNS

DoPoint the router at a filtering resolver — NextDNS, Quad9 or Control D. It's two address fields. (No router access? Set it on each phone and laptop instead.)

WhyDNS is the phone book your devices use. A filtering resolver refuses to look up known-malicious addresses, so a tapped scam link often just fails to load — for everyone in the house, including people who won't come to this clinic.

Check the wifi encryption and password

DoWPA3 if offered, otherwise WPA2 (AES). Make the wifi password long, and not the one printed on the sticker.

Do it in the bench → Station 02 · Router Hardening

2 · The rest of the house

Move the smart gadgets to the guest network

DoTurn on the guest network and move the TV, doorbell, speakers, cameras, robot vacuum and printer onto it. Keep laptops and phones on the main one.

WhyCheap connected devices are rarely updated. On your main network a compromised camera can reach your laptop; on the guest network it can only reach the internet. The guest network isn't for guests — it's for things you don't trust.

Common mistakeMoving everything, laptops included. Then the separation does nothing.

Watch for bridgesA device bridges two networks when it's connected to both at once, and then the separation leaks. Common culprits: a smart hub or TV plugged into the router by cable and joined to the guest wifi; a laptop or phone sharing its connection (hotspot / "internet sharing"); a printer's own Wi-Fi Direct network; and router settings like "allow guests to access the local network" or an "mDNS reflector", usually switched on so casting and printing work across networks. Check each gadget is on one network only, and leave those router settings off unless you've decided you need them.

Can do more than two?Go further: main for laptops and phones, guest for smart gadgets and actual guests, consoles for gaming. Each gets only what it needs.

Find out what is actually connected — tonight's deliverable

DoOpen the router's device list ("attached devices", "DHCP clients", "my network") — or scan from a laptop. Name everything you recognise. For a mystery device, look up the manufacturer from the first half of its MAC address; still a mystery, change the wifi password and see what stops working.

WhyMost people have two to three times as many things on their network as they'd guess. The strays are usually forgotten, not sinister — but you can't notice something new appearing if you never knew the baseline.

Do it in the bench → Station 03 · Device Inventory

3 · Your device list

Write your list in the bench. It saves there and becomes part of your Network Audit Card, the thing you'll compare against next month.

Do it in the bench → Station 03 · Device Inventory

Follow-up bench · Watch your own packets

Go do it, then report what you found. Install Wireshark (free) on a laptop on your home network and capture for five minutes. Only capture networks you own or have permission to watch.

What to expect: on wifi you'll mostly see your own laptop's traffic — plus the gadgets that announce themselves to everyone on the network. That second part is the interesting bit.

Capture five minutes

DoOpen Wireshark, double-click your wifi interface (the one with the moving squiggle), browse normally for a few minutes, then press the red square to stop.

See who your laptop talks to

DoType dns in the filter bar. Every line is your machine asking "where is this name?" Then try tls.handshake.extensions_server_name to see which sites it opened encrypted connections to.

WhyThis is exactly what your filtering DNS sees — and what it can block. Expect names you never typed: analytics, ad networks, update checks.

Catch the gadgets announcing themselves

DoFilter mdns || ssdp || llmnr. Printers, TVs, speakers and smart plugs broadcast their names and what they do to everyone on the network.

WhyAnything announcing itself here is on the same network as your laptop. If it's a smart gadget, that's the one to move to the guest network. Anything you didn't know about goes on your device list in the bench.

Your report

Fill in what you found — any of it is useful, none of it is required. Then copy it and post it in the class chat, or bring it to Consumer Device Rescue.

Surprising name your laptop looked up
Gadgets announcing themselves
New to your device list?
What you'll change

Follow-up bench · Watch for anomalies

Go do it, then report what you found. Tonight's device list is your baseline. A monitor tells you when the network stops matching it — a new device, a gadget suddenly talking to somewhere strange, a burst of traffic at 3am. Pick one level, run it for a week, report back.

Easy · no new hardware

DoTurn on the logs in the filtering DNS you set up tonight (NextDNS and Control D both have a per-device query log), and/or install Fing on your phone and switch on new-device alerts. Many routers also have a "notify me when a new device joins" setting.

WhyDNS logs show what every device is reaching for. A smart plug that suddenly looks up dozens of unfamiliar names, or a device you've never heard of joining, is exactly the anomaly worth noticing.

Weekend project · your own DNS sinkhole

DoRun Pi-hole or AdGuard Home on a Raspberry Pi or an old laptop and point your router's DNS at it. You get a dashboard of every query from every device, and you own the logs.

WhySame visibility as the hosted option, but the data never leaves your house — and you can see which device is the noisiest.

Deep end · watch the traffic itself

DoFor the curious: ntopng shows who's talking to whom and how much; Zeek or a Security Onion box logs connections and flags suspicious patterns. These need a router or switch that can mirror traffic (or a box sitting between router and modem).

WhyDNS only tells you what devices look up. Flow monitoring tells you what they actually send, and where — the closest thing to an alarm system for your network.

Your report — after a week

Any of it is useful, none of it is required. "I saw nothing weird" is a real result — that's your baseline confirmed.

What you ran
Your baseline
Anything anomalous?
What you did about it

Glossary · every network term on this page

Before you leave

Your Home Network Bench scorecard should have moved. If you couldn't get into the router, it should still have moved — the items that don't apply to you don't count against you.