Home
>
Courses
>
Network Forensics
Course

Network Forensics

The Network Forensics course delves into the principles and practices of dissecting network-based incidents. Participants will learn to use network analysis and attack detection tools. The course emphasizes the governance of network forensics, equipping students with the skills to manage and conduct comprehensive network investigations effectively.

Hour Course Icon
Hours
40 Academic Hours
Format Course Icon
Format
Online
Duration Course Icon
Duration
4 Weeks

LIVE, instructor-led training

Participants will gain a holistic understanding of how to:

• Lead cybersecurity strategy at agency and national level

• Govern large-scale incident response and multi-agency crises

• Secure modern cloud and digital service platforms

• Embed security into digital product deliveries

• Prepare organisations for AI-driven and next-generation threats

The bootcamp combines executive briefings, case studies, interactive workshops, and hands-on cyber exercises delivered on CyberproAI’s Cympire Cyber Range, enabling leaders to experience real-world cyber crises in a controlled, immersive environment.

Learning Outcomes

This course is designed for cybersecurity professionals, IT practitioners, and ethical hackers looking to deepen their expertise in web application security.

It’s ideal for those who already have a foundational knowledge of networking and security and want to advance their skills in identifying, exploiting, andmitigating web-based vulnerabilities. Whether you’re a penetration tester, security analyst, or IT manager, this course will provide practical tools and insights to help you defend against modern cyber threats targeting web applications.

Target Audience

This program is designed for IT professionals, cybersecurity analysts, network administrators, incident responders, and digital forensics specialists with a foundational understanding of IT systems, networking principles, cybersecurity fundamentals, and forensic investigation techniques.

The ideal participants seek to expand their expertise in analysing and investigating network traffic to detect, understand, and respond to security incidents. This course is precious for individuals in roles that involve monitoring, securing, or auditing network environments, as well as those responsible for conducting forensic investigations in the aftermath of a cyber incident. It is well-suited for mid-to-large-sized organization professionals who aim to enhance their ability to trace network-based attacks and gather critical evidence to support incident response efforts.

Required Prior Knowledge

• Core cybersecurity

• Networking

Training for CompTIA’s certifications

Learning Method

Computing Requirements

• CPU: Intel i5/i7 or AMD 5x/7x

• RAM: 16GB

• HDD: 300GB available space

The OSI Model and How it Can Be Broken

  • The OSI Model as it is supposed to be used
  • The nature of protocols
  • Encapsulation and demultiplexing
  • Layer 8 & 9, the Missing Layers, and EVIL

Protocols Up and Down the Stack

  • Layer 2 details and structures
  • Addressing and correlation between L2 and L3
  • Layer 3 addressing
  • Layer 3 details and structures (IPv4 and IPv6)
  • Layer 4 details and structures (TCP, UDP and ICMP)
  • Numerical systems and conversions

Packet Tools

  • Wireshark / tshark and their Display Filters
  • Using Wireshark to explore a typical sequence of packets
  • tcpdump and the Berkeley Packet Filter (BPF) language
  • Bitmasking with BPF

Addressing and Resolution Protocols and How They Go Wrong

  • Binary and Hex
  • The dynamic Host configuration Protocol (DHCP) in the IPv4
  • The Address Resolution Protocol (ARP) in IPv4
  • The Neigbor Discovery Protocol (ARP) in IPv6
  • The Domain Name System (DNS) in depth
  • The link-Local Multicast Name Resolution (LLMR) Protocol
  • The Web Proxy Auto-configuration Discovery (WPAD) Protocol

Network Forensics Methodology

  • The basics of Network Forensics Methodology
  • The basics of Network Forensics Analysis

Network Flow Record Analysis

  • Understanding traffic analysis
  • Network flow data and record analysis
  • Understanding sensors and sensor replacement
  • Network flow data formats
  • Introduction to Argus, SiLK, and other tools
  • Simple and complex flow analysis techniques
  • Analysis of a flow diagram of successful brute force

Network-based Intrusion Detection Systems (NIDS) and Other Tools

  • NIDS and NIPS and their functionality
  • Introduction to Snort In-Depth
  • Introduction to Zeek In-Depth
  • Other advanced network forensics and packet analysis tools
  • Argus and detecting the pivot with network flow analysis
  • Using Snort and Zeek to analyze malware-based lateral movement
  • Analysis of browser exploitation via LLMR and WPAD

Learn More
Register
Arrow Icon

$ 4200*

$ 5400

* Special Launch Pricing - Act Fast
* The price is excluding booking of
venue and refreshments
Learn More
Register