Course Outline
- Overview of Command-Line Tools and Their Applications
- Utilizing TShark and Dumpcap Command-Line Utilities
- Working with the Capinfos Command-Line Tool
- Using the Editcap Command-Line Tool
- Using the Mergecap Command-Line Tool
- Using the Text2pcap Command-Line Tool
- Splitting and Merging Trace Files
- Advanced Application of Capture and Display Filters
- Developing Advanced Capture Filter Scripts
- Creating Advanced Display Filters
- Implementing Triggered Filters
- Advanced Usage of the Expert System
- Managing Congestion: Shattered Windows and Flooding
- Establishing Baseline Network Communications
- Identifying Unusual Network Communications
- Vulnerabilities in the TCP/IP Resolution Process
- Laboratory Exercises and Case Studies
- Identifying Active Participants in Traffic
- Analyzing Port Scans
- Detecting Mutant Scans
- Investigating IP Scans
- Application Mapping Techniques
- Operating System Fingerprinting
- Laboratory Exercises and Case Studies
- VoIP Traffic Analysis
- SIP Protocol Analysis and Troubleshooting
- Analyzing RTP, RTCP, and Media Streams
- Developing VoIP Filters and Analysis Profiles
- Laboratory Exercises and Case Studies
- General Application Analysis and Troubleshooting
- HTTP Protocol Analysis and Troubleshooting
- FTP Protocol Analysis and Troubleshooting
- DNS Operations and Troubleshooting
- Video Transmission Analysis
- Diagnosing Network-Related Database Issues
- Fundamentals of Network Security and Forensics
- Information Gathering: Key Indicators to Monitor
- Recognizing Unusual Traffic Patterns
- Utilizing Complementary Security Tools
- Identifying Suspicious Security Patterns
- Detecting MAC and IP Address Spoofing
- Understanding Attack Signatures and Their Locations
- Investigating ARP Poisoning Attacks
- Analyzing Header and Sequencing Signatures
- Examining Attacks and Exploits
- Detecting TCP Splicing and Anomalous Traffic
- Mitigating DoS and DDoS Attacks
- Analyzing Protocol Scans
- Identifying Maliciously Malformed Packets
- Laboratory Exercises and Case Studies
Requirements
Participants require a thorough understanding of the TCP/IP protocol stack and should have completed the “Basic Network Troubleshooting using Wireshark” course or possess equivalent knowledge. Please ensure your laptop has Wireshark installed (available for free download at www.wireshark.org) before attending.
Testimonials (5)
Many exercises, good knowladge
Piotr Kucharski
Course - Advanced Network Troubleshooting Using Wireshark
interesting practical cases
Robert
Course - Advanced Network Troubleshooting Using Wireshark
First of all it was very interesting practically for all topics covered by this training. Well balanced with theory, practise labs and breaks. Some of tips and tricks I have introduced to my work yet.
Dawid Wozny - ATOS PGS sp. z o.o.
Course - Advanced Network Troubleshooting Using Wireshark
That the Wojciech Wójcik knowledge is really huge.
Kornel - ATOS PGS sp. z o.o.
Course - Advanced Network Troubleshooting Using Wireshark
trainer listen to participants