NET-FORENSIC.AW1
Mastering Network Forensics
Develop the skills to investigate cybercrimes, from identifying threats to recovering evidence.
- Practice in 15 Laboratorios prácticos — nothing to install
- 15 Lecciones interactivas y 90 topics mapped to the official exam objectives
- 155 Preguntas del examen de práctica
Expert A tu propio ritmo · 1 año de acceso
15 LiveLabs prácticos
Practice real IT tasks in guided environments.
- Entornos reales
- Calificación automática
- Sin instalación
01 / Habilidades que obtendrás
What you will be able to do
- Analyze network traffic and packet structures for suspicious activities.
- Investigate cyberattacks, including ransomware, DDoS, and web server attacks.
- Decrypt SSL/TLS communication to detect hidden threats.
- Identify covert communication channels and misuse of DNS protocols.
- Examine logs from SSh, proxy servers, and email authentication for anomalies.
- Detect wireless attacks and monitor radio frequencies.
- Simulate network environments to study exploit kits and malicious payloads.
- Track malware activities through reverse engineering and memory forensics.
- Automate forensic tasks like IP reputation analysis and protocol dissection with tools like Lua.
- Utilize forensic tools such as Wireshark, Splunk, and MitmProxy for in-depth investigations.
- Identify and remove ransomware and capture decryption keys.
- Explore command-and-control systems to uncover attackers' methods.
- Develop proactive network defense strategies using forensic insights.
Course Highlights
-
15 Lecciones estructuradas Cobertura completa de los objetivos principales del curso
-
15 LiveLabs prácticos Escenarios interactivos guiados con evaluación instantánea
-
155 Preguntas de práctica Pruebas de evaluación con justificaciones de respuesta detalladas
-
1 año de acceso completo Aprendizaje a tu propio ritmo, accesible en cualquier momento y en todos los dispositivos
02 / Lecciones y laboratorios
See exactly what you will learn and practice
Plan de estudios
15 Lecciones interactivas · 90 topics01 Introduction +
02 Foundations of Network Forensics 6 topics · 2 Laboratorio en vivo +
- Introduction
- Types of network forensics
- Setting up the environment for analysis
- Case study: Suspicious Web Server
- Conclusion
- Long questions
2 Laboratorio en vivo in this lesson — see the labs panel →
03 Protocols and Deep Packet Analysis 9 topics · 1 Laboratorio en vivo +
- Introduction
- The OSI model
- The TCP/IP model
- The Packet structure
- Case study: Curious case of protocol misuse
- Deep Packet Inspection
- Case study: Investigating Distributed Denial of service attacks
- Conclusion
- Long questions
1 Laboratorio en vivo in this lesson — see the labs panel →
04 Flow Analysis versus Packet Analysis 8 topics · 2 Laboratorio en vivo +
- Introduction
- Statistical Flow analysis
- Flow Record and FRP Systems
- Uniflow and BitFlow
- Types of Sensor deployment
- Flow analysis
- Conclusion
- Long questions
2 Laboratorio en vivo in this lesson — see the labs panel →
05 Conducting Log Analysis 6 topics · 1 Laboratorio en vivo +
- Introduction
- Investigating Remote Login attempts on SSH
- Investigating Web Server Attacks with Splunk
- Investigating Proxy Logs
- Conclusion
- Long questions
1 Laboratorio en vivo in this lesson — see the labs panel →
06 Wireless Forensics 7 topics +
- Introduction
- Basics of Radio Frequency Monitoring
- The 802.11 standard
- Evidence types in wireless local area networking
- Other wireless attacks and their analysis
- Conclusion
- Long questions
07 TLS Decryption and Visibility 5 topics · 1 Laboratorio en vivo +
- Introduction
- Techniques to decrypt SSL/TLS communication
- Examining SSL/TLS traffic using proxy
- Conclusion
- Long questions
1 Laboratorio en vivo in this lesson — see the labs panel →
08 Demystifying Covert Channels 8 topics · 2 Laboratorio en vivo +
- Introduction
- Identifying covert communication using proxies
- Using MitmProxy to decrypt Dropbox traffic
- Using Dropbox API to gather attack details
- Uncovering the attack pattern
- Uncovering DNS misuse
- Conclusion
- Long questions
2 Laboratorio en vivo in this lesson — see the labs panel →
09 Analyzing Exploit Kits 8 topics +
- Introduction
- How exploit kits work
- Analysis of an exploit kit infection
- Network forensics with Security Onion
- Extracting malicious payload
- Using Fakenet-Ng to simulate a network
- Conclusion
- Long questions
10 Automating Network Forensics 6 topics · 1 Laboratorio en vivo +
- Introduction
- Parsing the Syslog format
- IP reputation analysis
- Writing dissectors for protocols in Lua
- Conclusion
- Long questions
1 Laboratorio en vivo in this lesson — see the labs panel →
11 Backtracking Malware 5 topics · 2 Laboratorio en vivo +
- Introduction
- Investigating Cobalt Strike Encrypted traffic
- Investigating TeamViewer and AnyDesk
- Conclusion
- Long questions
2 Laboratorio en vivo in this lesson — see the labs panel →
12 Investigating Ransomware Attacks 7 topics · 1 Laboratorio en vivo +
- Introduction
- Analysis of WannaCry ransomware
- Capturing ransomware keys for decryption
- Analyzing GandCrab ransomware
- Case Study: REVIL ransomware at a Bank
- Conclusion
- Long questions
1 Laboratorio en vivo in this lesson — see the labs panel →
13 Investigating Command and Control Systems 6 topics · 1 Laboratorio en vivo +
- Introduction
- Investigating Metasploit Reverse Shell
- Investigating Meterpreter Reverse Shell
- Investigating Meterpreter Stageless Reverse Shell
- Conclusion
- Long questions
1 Laboratorio en vivo in this lesson — see the labs panel →
14 Investigating Attacks on Email Servers 5 topics · 1 Laboratorio en vivo +
- Introduction
- Analysis of ProxyLogon attack
- Investigating Email authentication logs
- Conclusion
- Long questions
1 Laboratorio en vivo in this lesson — see the labs panel →
15 Investigating Web Server Attacks 4 topics +
- Introduction
- Web Server attack analysis
- Conclusion
- Long questions
Laboratorios prácticos Our edge
15 Laboratorio en vivos- Capturing Network Packets Using TCPDump
- Performing Network Analysis Using Wireshark
- Using tshark to Filter Data from a PCAP File
- Generating IPFIX from PCAP
- Analyzing SiLK Flow Records
- Investigating SSH Logs
- Capturing Browser Requests Using mitmproxy
- Resolving IP Addresses for Network Analysis
- Investigating DNS Misuse
- Performing IP Reputation Analysis
- Monitoring a TeamViewer Session
- Investigating AnyDesk Sessions
- Analyzing the WannaCry Ransomware Attack
- Investigating the Metasploit Reverse Shell
- Investigating the ProxyLogon Attack
03 / Preguntas frecuentes
Preguntas antes de empezar
What is network forensics?+
Who should take this course?+
This online network forensics course is ideal for
- IT professionals
- Network Forensics Analyst
- Cybersecurity Analyst
- Digital Forensics Investigator
- Incident Response Specialist
- Security Operations Center (SOC) Analyst
And for anyone interested in the cybersecurity field
What are the prerequisites for this course?+
What tools will I learn to use in this course?+
How can network forensics skills benefit my career?+
Master Network Investigations
Learn to analyze traffic, decrypt data, and detect covert channels like a pro!
- 1 año de acceso completo
- 15 LiveLab incluido
- Certificado de finalización
No se requiere tarjeta de crédito