Get in Touch

Course Outline

  • Overview of Command-Line Tools and Their Applications
  • Utilizing TShark and Dumpcap Command-Line Utilities
  • Working with the Capinfos Command-Line Tool
  • Using the Editcap Command-Line Tool
  • Using the Mergecap Command-Line Tool
  • Using the Text2pcap Command-Line Tool
  • Splitting and Merging Trace Files
  • Advanced Application of Capture and Display Filters
  • Developing Advanced Capture Filter Scripts
  • Creating Advanced Display Filters
  • Implementing Triggered Filters
  • Advanced Usage of the Expert System
  • Managing Congestion: Shattered Windows and Flooding
  • Establishing Baseline Network Communications
  • Identifying Unusual Network Communications
  • Vulnerabilities in the TCP/IP Resolution Process
  • Laboratory Exercises and Case Studies
  • Identifying Active Participants in Traffic
  • Analyzing Port Scans
  • Detecting Mutant Scans
  • Investigating IP Scans
  • Application Mapping Techniques
  • Operating System Fingerprinting
  • Laboratory Exercises and Case Studies
  • VoIP Traffic Analysis
  • SIP Protocol Analysis and Troubleshooting
  • Analyzing RTP, RTCP, and Media Streams
  • Developing VoIP Filters and Analysis Profiles
  • Laboratory Exercises and Case Studies
  • General Application Analysis and Troubleshooting
  • HTTP Protocol Analysis and Troubleshooting
  • FTP Protocol Analysis and Troubleshooting
  • DNS Operations and Troubleshooting
  • Video Transmission Analysis
  • Diagnosing Network-Related Database Issues
  • Fundamentals of Network Security and Forensics
  • Information Gathering: Key Indicators to Monitor
  • Recognizing Unusual Traffic Patterns
  • Utilizing Complementary Security Tools
  • Identifying Suspicious Security Patterns
  • Detecting MAC and IP Address Spoofing
  • Understanding Attack Signatures and Their Locations
  • Investigating ARP Poisoning Attacks
  • Analyzing Header and Sequencing Signatures
  • Examining Attacks and Exploits
  • Detecting TCP Splicing and Anomalous Traffic
  • Mitigating DoS and DDoS Attacks
  • Analyzing Protocol Scans
  • Identifying Maliciously Malformed Packets
  • Laboratory Exercises and Case Studies

Requirements

Participants require a thorough understanding of the TCP/IP protocol stack and should have completed the “Basic Network Troubleshooting using Wireshark” course or possess equivalent knowledge. Please ensure your laptop has Wireshark installed (available for free download at www.wireshark.org) before attending.

 21 Hours

Number of participants


Price per participant

Testimonials (5)

Upcoming Courses

Related Categories