Bloqueo de seguridad en pantalla digital

Análisis de Ciberseguridad y Forense de Redes

Categoría: Red / Formación, Security / Forensics
Formato Aula abierta / Virtual / Presencial
Advanced Network Forensics Training with Wireshark Network forensics is the process of collecting, analyzing, and interpreting network traffic to determine what happened on a network, how an incident occurred, and which systems and communications were involved. The Cyber Security &.. leer más abajo
Ámsterdam / Interno / Virtual
duración: 5 días
5-12 class size
English

No hay datos disponibles todavía.

¿Estás interesado en este curso? Solicita más información. 

Advanced Network Forensics Training with Wireshark

Network forensics is the process of collecting, analyzing, and interpreting network traffic to determine what happened on a network, how an incident occurred, and which systems and communications were involved.

The Análisis de Ciberseguridad y Forense de Redes course provides practical, hands-on training in network traffic analysis, PCAP investigation, and digital network forensics using Wireshark and other vendor-neutral tools.

Participants learn how to investigate network activity from a forensic perspective. Starting with raw packet captures, they learn how to identify relevant hosts and communications, reconstruct network activity, detect suspicious behavior, and extract information that can support cybersecurity and forensic investigations.

The course combines network forensics theory with realistic packet captures, practical investigation scenarios, and extensive hands-on exercises.

From Network Traffic to Forensic Evidence

A PCAP file can contain a detailed record of network communications, but identifying the relevant evidence requires a structured investigation methodology.

During the course, participants learn how to:

  • Collect and analyze network traffic.
  • Identify hosts, protocols, services, and conversations.
  • Use Wireshark capture and display filters to isolate relevant traffic.
  • Follow TCP streams and reconstruct network communications.
  • Analyze network behavior and communication patterns.
  • Identify suspicious and potentially malicious traffic.
  • Investigate indicators of compromise.
  • Reconstruct events and establish a timeline from packet-level evidence.
  • Extract relevant information from PCAP files.
  • Interpret technical findings in a forensic context.

The emphasis is on understanding what the network traffic means, rather than simply identifying individual packets.

Practical, Investigation-Focused Training

Network forensics is best learned by investigating realistic network traffic.

Throughout the course, participants work with PCAP files and practical investigation scenarios. They analyze network communications, identify relevant evidence, reconstruct events, and formulate conclusions based on packet-level information.

The course can be delivered as Open Classroom, Virtual, or In-house training.

In-house training can also be adapted to an organization’s specific security environment, investigation requirements, and operational scenarios.

The Análisis de Ciberseguridad y Forense de Redes course is designed for professionals who need to investigate, analyze, or understand network traffic as part of cybersecurity, digital forensics, incident response, or security operations.

The course is particularly relevant for professionals who need to move beyond basic packet capture and develop practical skills in network investigation, PCAP analysis, and forensic network traffic analysis.

Target Audience

This course is suitable for:

  • Network security professionals
  • Cybersecurity professionals
  • Security analysts
  • SOC analysts
  • Incident responders
  • Digital forensic investigators
  • Network engineers
  • Network administrators
  • IT security specialists
  • Threat hunters
  • Law enforcement investigators
  • Intelligence analysts
  • Government security professionals
  • Defense and military personnel
  • Technical investigators

Law Enforcement, Intelligence and Defense

Network traffic can provide valuable evidence during criminal, intelligence, and security investigations.

The course is particularly suitable for law enforcement, intelligence services, government organizations, and defense organizations that need to investigate network-based activity and analyze digital evidence.

For these organizations, the training can be delivered as a tailored in-house course using relevant investigation scenarios and network traffic.

Prerequisites

Participants should have a basic understanding of:

  • TCP/IP networking
  • The OSI model
  • IP addressing
  • Common network protocols
  • Basic network communication concepts



The course provides practical guidance throughout the exercises, allowing participants to develop their Wireshark and network forensic analysis skills during the training.

After completing the Análisis de Ciberseguridad y Forense de Redes course, participants will be able to apply a structured methodology to network forensic investigations and use Wireshark to analyze network traffic and PCAP files.

Network Forensics Fundamentals

  • Understand the principles of network forensics.
  • Understand network forensic terminology and methodology.
  • Identify the role of packet captures as network evidence.
  • Understand the difference between real-time and post-capture analysis.
  • Apply a structured approach to network forensic investigations.

Network Traffic Collection

  • Configure Wireshark for network investigations.
  • Select appropriate capture interfaces.
  • Understand capture filters.
  • Collect relevant network traffic.
  • Work with multiple packet captures.
  • Identify and preserve traffic relevant to an investigation.

Packet and Protocol Analysis

  • Analyze IPv4 and IPv6 communications.
  • Investigate ARP, DHCP, DNS, TCP, UDP and ICMP traffic.
  • Analyze HTTP and other application-layer protocols.
  • Understand normal protocol behavior.
  • Identify protocol anomalies.
  • Interpret packet-level information in a forensic context.

Wireshark Filtering and Investigation

  • Use Wireshark display filters effectively.
  • Use capture filters.
  • Filter traffic by IP address, host, protocol and port.
  • Identify conversations between systems.
  • Follow TCP streams.
  • Locate relevant packets in large PCAP files.
  • Apply advanced filtering techniques during investigations.

Network Conversation Reconstruction

  • Identify communicating systems.
  • Reconstruct network conversations.
  • Follow application-level communications.
  • Analyze TCP connection establishment and termination.
  • Understand communication sequences.
  • Reconstruct events from packet captures.
  • Build a timeline of relevant network activity.

Detecting Suspicious Network Activity

  • Distinguish normal from unusual network behavior.
  • Identify suspicious communication patterns.
  • Investigate network scanning and reconnaissance.
  • Identify suspicious connections.
  • Analyze malware-related network traffic.
  • Investigate command-and-control communications.
  • Analyze data transfers and potential data exfiltration.
  • Identify indicators of compromise.
  • Recognize abnormal protocol behavior.

Cybersecurity Incident Investigation

  • Investigate potentially compromised systems.
  • Analyze suspicious network behavior.
  • Identify evidence of attack activity.
  • Examine network communications before, during, and after an incident.
  • Correlate network activity with investigation findings.
  • Extract relevant evidence from PCAP files.
  • Apply a structured methodology to incident investigations.

Advanced Network Forensic Analysis

  • Perform traffic reconstruction.
  • Analyze network conversations and communication patterns.
  • Recognize relevant traffic within large captures.
  • Reconstruct timelines from network traffic.
  • Analyze network behavior.
  • Interpret packet-level evidence.
  • Document and communicate forensic findings.

Practical Outcome

At the end of the course, participants will be able to start with a network capture, systematically identify relevant traffic, isolate suspicious communications, reconstruct network activity, and use packet-level evidence to support a cybersecurity or forensic investigation.

They will have developed practical skills for using Wireshark for network forensics, PCAP analysis, incident response, cybersecurity investigations, and network traffic analysis.

Citas de estudiantes

"Me pareció que Phill es el mejor profesor y aprendo mucho de él. Gracias, Phill"

- Paul Broyd

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Es sin duda el curso más interesante que he seguido"

- Karin van der Plas

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Fue un curso muy, muy, muy interesante, y hecho por el mejor"

- Matthew Steenwijk

Curso:

"Fue un verdadero placer recibir la formación de Wireshark de parte de un instructor muy dedicado"

- Wim de Vries

Curso: Análisis de Redes de Voz y Video sobre IP

"Pensaba que ya conocía Wireshark. Estaba equivocada, muy equivocada"

- Jeroen Valkonet

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Este curso es imprescindible para todos en TI"

- Johan den Besten

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Excelente para análisis de redes o investigaciones forenses"

- Sven Schneider

Curso: Clase magistral – Redes avanzadas e introducción al análisis de seguridad

"Por mucho, el mejor curso que he tomado jamás"

- Joachim van Doeselaar

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Si hay un paquete, ¡se puede WireSharked!!"

- Elena Petrova

Curso: Análisis de redes inalámbricas y Wi-Fi con Wireshark

"Extremadamente satisfecho con la capacitación. Instructor muy servicial y excelentes métodos de enseñanza"

- Lars Mikkelsen

Curso: Clase magistral – Redes avanzadas e introducción al análisis de seguridad

Más cursos de la categoría «Red / Formación»

duración: 5 días
Por anunciar.
El análisis de redes y forense abarca las habilidades de captura de datos y la capacidad de discernir patrones inusuales ocultos dentro de un tráfico de red aparentemente normal. Este curso proporciona al estudiante un...
duración: 5 días
Por anunciar.
This course is for Networking, Engineering, and Security personnel who need to develop a set of packet investigation techniques through study of the Industrial Control Systems and SCADA networking Protocols..
duración: 5 días
Por anunciar.
This course is for Networking and Security personnel who need to develop a set of packet investigation techniques to support recognition, analysis, and threat recognition for many of the next..
duración: 5 días
Por anunciar.
Este curso está dirigido a personal de Redes y Seguridad que necesita desarrollar técnicas de investigación de paquetes mediante el estudio de protocolos de IoT y automatización del hogar utilizando Wireshark y otras herramientas de análisis de código abierto...
duración: 5 días
Por anunciar.
Este curso proporcionará al estudiante un conjunto de técnicas de análisis centradas en el uso de herramientas de código abierto e independientes de proveedores para ofrecer información sobre las siguientes áreas:

Regístrate y suscríbete para Análisis de Ciberseguridad y Forense de Redes

Elige una fecha para el curso *
Nombre *
Apellido *
Empresa *
País *
Dirección de correo electrónico *
Número de teléfono
Asistentes *
Comentario
¿Cómo se enteró de este curso? *
Un curso solo se realiza si hay suficiente participación.
*
= obligatorio

Solicitar información para Análisis de Ciberseguridad y Forense de Redes

*
= obligatorio

¿Desea solicitar información para más de un curso? Haga clic aquí