Course Outline
- Command-Line Utilities and Operational Procedures
- Deployment of TShark and Dumpcap Command-Line Interfaces
- Utilization of the Capinfos Command-Line Interface
- Application of the Editcap Command-Line Interface
- Implementation of the Mergecap Command-Line Interface
- Functionality of the Text2pcap Command-Line Interface
- Procedures for Dividing and Combining Trace Data Files
- Advanced Configuration of Capture and Display Filters
- Development of Advanced Capture Filter Scripts
- Construction of Complex Display Filters
- Implementation of Triggered Filtering Mechanisms
- Advanced Application of the Expert Analysis System
- Mitigation of Network Congestion: Shattered Windows and Flooding Events
- Establishment of Network Communication Baselines
- Identification of Anomalous Network Activity
- Vulnerabilities Within the TCP/IP Resolution Process
- Practical Exercises and Operational Case Studies
- Entity Identification Techniques
- Detection of Port Scanning Activities
- Identification of Mutant Scan Patterns
- Execution of IP Address Scans
- Application Service Mapping
- Operating System Fingerprinting Methodologies
- Practical Exercises and Operational Case Studies
- Voice over IP (VoIP) Traffic Analysis
- Session Initiation Protocol (SIP) Analysis and Troubleshooting
- Evaluation of RTP, RTCP, and Media Streams
- Development of VoIP Filters and Analysis Profiles
- Practical Exercises and Operational Case Studies
- Application Layer Analysis and Troubleshooting
- HyperText Transfer Protocol (HTTP) Analysis and Resolution
- File Transfer Protocol (FTP) Analysis and Resolution
- Domain Name System (DNS) Operations and Troubleshooting
- Video Transmission Performance Analysis
- Resolution of Network-Related Database Issues
- Fundamentals of Network Security and Digital Forensics
- Information Gathering: Key Indicators and Data Sources
- Analysis of Irregular Traffic Patterns
- Integration of Complementary Analytical Tools
- Identification of Security-Suspicious Activity Patterns
- Detection of MAC and IP Address Spoofing
- Signature Characteristics and Location Analysis
- ARP Poisoning Attacks
- Header and Sequence-Based Signatures
- Classification of Attacks and Exploits
- TCP Splicing Techniques and Anomalous Traffic Indicators
- Denial of Service (DoS) and Distributed Denial of Service (DDoS) Attacks
- Protocol Scan Detection
- Analysis of Maliciously Crafted Packets
- Practical Exercises and Operational Case Studies
Requirements
Candidates must possess a thorough understanding of the TCP/IP protocol stack and have completed, or demonstrate equivalent competency in, “Basic Network Troubleshooting using Wireshark.” Participants are required to provide their own laptops equipped with Wireshark software, which may be obtained at no cost from www.wireshark.org. This training is designed for government personnel seeking to enhance their technical capabilities for government infrastructure support.
Testimonials (5)
Many exercises, good knowladge
Piotr Kucharski
Course - Advanced Network Troubleshooting Using Wireshark
interesting practical cases
Robert
Course - Advanced Network Troubleshooting Using Wireshark
First of all it was very interesting practically for all topics covered by this training. Well balanced with theory, practise labs and breaks. Some of tips and tricks I have introduced to my work yet.
Dawid Wozny - ATOS PGS sp. z o.o.
Course - Advanced Network Troubleshooting Using Wireshark
That the Wojciech Wójcik knowledge is really huge.
Kornel - ATOS PGS sp. z o.o.
Course - Advanced Network Troubleshooting Using Wireshark
trainer listen to participants