Get in Touch

Course Outline

  • Command-Line Tools and Their Application
  • TShark and Dumpcap Command-Line Utilities
  • The Capinfos Command-Line Tool
  • The Editcap Command-Line Tool
  • The Mergecap Command-Line Tool
  • The Text2pcap Command-Line Tool
  • Splitting and Merging Trace Files
  • Advanced Use of Capture and Display Filters
  • Developing Advanced Capture Filter Scripts
  • Creating Advanced Display Filters
  • Implementing Triggered Filters
  • Advanced Usage of the Expert System
  • Managing Congestion: Shattered Windows and Flooding
  • Establishing Baselines for Network Communications
  • Identifying Unusual Network Communications
  • Vulnerabilities in the TCP/IP Resolution Process
  • Laboratory Exercises and Case Studies
  • Identifying Active Participants: Who is Talking?
  • Analyzing Port Scans
  • Investigating Mutant Scans
  • Examining IP Scans
  • Application Mapping Techniques
  • OS Fingerprinting Methods
  • Laboratory Exercises and Case Studies
  • VoIP Analysis
  • SIP Analysis and Troubleshooting
  • RTP, RTCP, and Media Analysis
  • Creating VoIP Filters and Analysis Profiles
  • Laboratory Exercises and Case Studies
  • Application Analysis and Troubleshooting
  • HTTP Analysis and Troubleshooting
  • FTP Analysis and Troubleshooting
  • DNS Operations and Troubleshooting
  • Video Transmission Analysis
  • Network-Related Issues in Databases
  • Fundamentals of Network Security and Forensics
  • Information Gathering: Key Indicators to Monitor
  • Recognizing Unusual Traffic Patterns
  • Utilizing Complementary Tools
  • Detecting Suspicious Security Patterns
  • MAC and IP Address Spoofing
  • Attack Signatures and Their Locations
  • ARP Poisoning
  • Header and Sequencing Signatures
  • Analyzing Attacks and Exploits
  • TCP Splicing and Anomalous Traffic
  • DoS and DDoS Attacks
  • Protocol Scans
  • Maliciously Malformed Packets
  • Laboratory Exercises and Case Studies

Requirements

Participants are expected to possess an in-depth understanding of the TCP/IP protocol stack, along with completion of the "Basic Network Troubleshooting using Wireshark" course or equivalent expertise. Attendees should bring their laptops equipped with Wireshark software, available for free download at www.wireshark.org.

 21 Hours

Number of participants


Price per participant

Testimonials (5)

Upcoming Courses

Related Categories