Get in Touch

Course Outline

  • Command-Line Tools and Usage
  • TShark and Dumpcap Command-Line Tools
  • Capinfos Command-Line Tool
  • Editcap Command-Line Tool
  • Mergecap Command-Line Tool
  • Text2pcap Command-Line Tool
  • Splitting and Merging Trace Files
  • Advanced Usage of Capture and Display Filters
  • Writing Advanced Capture Filter Scripts
  • Writing Advanced Display Filters
  • Utilizing Triggered Filters
  • Advanced Usage of the Expert System
  • Managing Congestion - Shattered Windows and Flooding
  • Establishing Network Communication Baselines
  • Identifying Unusual Network Communications
  • Vulnerabilities in the TCP/IP Resolution Process
  • Lab Exercises and Case Studies
  • Identifying Communicating Parties (Who is talking?)
  • Port Scans
  • Mutant Scans
  • IP Scans
  • Application Mapping
  • Operating System Fingerprinting
  • Lab Exercises and Case Studies
  • VoIP Analysis
  • SIP Analysis and Troubleshooting
  • RTP, RTCP, and Media Analysis
  • Creating VoIP Filters and Analysis Profiles
  • Lab Exercises and Case Studies
  • Application Analysis and Troubleshooting
  • HTTP Analysis and Troubleshooting
  • FTP Analysis and Troubleshooting
  • DNS Operation and Troubleshooting
  • Video Transmission Analysis
  • Network-Related Database Problems
  • Network Security and Forensics Basics
  • Information Gathering – What to Look For
  • Detecting Unusual Traffic Patterns
  • Complementary Tools
  • Detecting Suspicious Security Patterns
  • MAC and IP Address Spoofing
  • Attack Signatures and Signature Locations
  • ARP Poisoning
  • Header and Sequencing Signatures
  • Attacks and Exploits
  • TCP Splicing and Unusual Traffic
  • DoS and DDoS Attacks
  • Protocol Scans
  • Maliciously Malformed Packets
  • Lab Exercises and Case Studies

Requirements

Participants must have in-depth knowledge of the TCP/IP protocol stack and should have completed the "Basic Network Troubleshooting using Wireshark" course or possess equivalent knowledge. Attendees are required to bring their own laptops with Wireshark software installed (available for free download at www.wireshark.org).

 21 Hours

Number of participants


Price per participant

Testimonials (5)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories