Tráfico de red cifrado de Wireshark y análisis de PCAP

Taller PCAP: Análisis de tráfico cifrado con Wireshark

Categoría: Capacitación en Wireshark
Formato Virtual
PCAP it or it didn’t happen. What is PCAP? Analyzing Encrypted Traffic with Wireshark Modern network traffic is increasingly encrypted, making traditional packet analysis more challenging. However, encrypted traffic still contains valuable information that can help network professionals understand communication.. leer más abajo
Virtual
duración: 1 día
tamaño de la clase
English

Courses available

5 Oct
- 5 Oct 2026
- Virtual
- 9.00 - 16.00
- € 895,00

PCAP it or it didn’t happen.

What is PCAP?

Analyzing Encrypted Traffic with Wireshark

Modern network traffic is increasingly encrypted, making traditional packet analysis more challenging. However, encrypted traffic still contains valuable information that can help network professionals understand communication patterns, troubleshoot connectivity and performance problems, and identify potentially suspicious activity.

This hands-on workshop teaches practical techniques for analyzing encrypted network traffic and PCAP files with Wireshark. Participants learn how to identify and interpret the information that remains visible in encrypted communications and how to use Wireshark to investigate network behavior when packet payloads cannot be directly read.

The workshop covers:

  • Wireshark configuration and analysis profiles designed to make encrypted traffic analysis faster and more efficient.
  • The fundamentals of network encryption, including SSL/TLS, HTTPS, WEP, WPA, WPA2, and WPA3.
  • Techniques for analyzing encrypted traffic and identifying useful packet-level information even when the payload is encrypted.
  • Wireshark filtering and analysis techniques for isolating relevant encrypted communications.
  • Analysis of communication patterns, endpoints, protocols, timing, packet sizes, and other observable characteristics of encrypted traffic.
  • Traffic reconstruction and conversation analysis to understand network communications and application behavior.
  • Identification of unusual or suspicious data flows that may warrant further investigation.
  • Practical methodologies for applying encrypted traffic analysis to network troubleshooting, cybersecurity, threat hunting, and network forensics.

Throughout the workshop, participants work with real-world encrypted traffic and practical PCAP examples. Extensive hands-on exercises allow attendees to apply Wireshark techniques and develop a structured methodology for investigating encrypted network communications.

The workshop provides a practical foundation for professionals who need to understand what can be learned from encrypted network traffic, how to investigate it efficiently, and how to recognize patterns that may indicate network problems or security threats.

This workshop is designed for networking, cybersecurity, government, law enforcement, intelligence, incident response, and security professionals who need practical techniques for investigating encrypted network traffic and PCAP files.

It is particularly suited to professionals who use or need to use Wireshark for network analysis, troubleshooting, security investigations, threat hunting, or network forensics, including:

  • Network engineers and network administrators
  • Cybersecurity and security analysts
  • Incident responders and threat hunters
  • Digital and network forensics professionals
  • Law enforcement and government investigators
  • Intelligence and security personnel
  • Professionals responsible for investigating suspicious network communications

 

The workshop is especially valuable for professionals who already understand basic networking concepts and want to develop the ability to analyze encrypted traffic when packet payloads are not directly visible.

Participants will learn how to examine observable characteristics of encrypted communications, identify relevant traffic, recognize unusual communication patterns, and use Wireshark to investigate encrypted network activity.

The workshop provides a practical foundation for further work in encrypted traffic analysis, network troubleshooting, cybersecurity, incident response, threat hunting, and network forensics.

By completing this workshop, participants will develop practical skills to analyze encrypted network traffic and PCAP files using Wireshark, even when the contents of network communications cannot be directly viewed.

You will learn how to:

Configure Wireshark for Encrypted Traffic Analysis

  • Configure Wireshark for efficient encrypted traffic investigations.
  • Use specialized Wireshark profiles to organize and accelerate analysis.
  • Configure relevant views, fields, statistics, and analysis tools.
  • Apply an efficient workflow when investigating large or complex PCAP files.

Understand Network Encryption

  • Understand the fundamentals of SSL/TLS and HTTPS.
  • Understand the principles of wireless encryption, including WEP, WPA, WPA2, and WPA3.
  • Identify where encryption is applied within network communications.
  • Determine which information remains observable when traffic is encrypted.

Analyze Encrypted Network Traffic

  • Identify encrypted communications within a PCAP file.
  • Analyze endpoints, protocols, ports, packet sizes, timing, and communication patterns.
  • Examine TLS connections and relevant protocol fields.
  • Identify communication relationships between systems and services.
  • Use packet-level information to understand encrypted network behavior without relying solely on payload contents.

Investigate Encrypted Traffic with Wireshark

  • Create effective Wireshark display filters for encrypted traffic.
  • Isolate relevant hosts, conversations, protocols, and network events.
  • Follow network conversations and analyze communication flows.
  • Use Wireshark statistics to identify significant traffic patterns.
  • Reconstruct and visualize network communications where possible.

Identify Suspicious Network Behavior

  • Establish a baseline for normal encrypted communication.
  • Identify unusual data flows and unexpected communication patterns.
  • Recognize indicators that may require further security investigation.
  • Analyze encrypted traffic as part of threat hunting and network security investigations.
  • Use PCAP evidence to support network and forensic investigations.

Apply Real-World Analysis Techniques

  • Work with realistic encrypted PCAP files and practical investigation scenarios.
  • Apply a structured methodology to encrypted traffic analysis.
  • Combine protocol analysis, Wireshark statistics, filtering, and traffic visualization.
  • Translate packet-level observations into meaningful technical conclusions.

Practical Outcome

After completing the workshop, participants will be able to approach an encrypted PCAP systematically, identify relevant communications, analyze observable characteristics of encrypted traffic, recognize unusual behavior, and use Wireshark to determine what can be learned from encrypted network activity.

These skills provide a practical foundation for professional work in encrypted traffic analysis, network troubleshooting, cybersecurity, threat hunting, incident response, and network forensics.

Citas de estudiantes

"Me pareció que Phill es el mejor profesor y aprendo mucho de él. Gracias, Phill"

- Paul Broyd

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Es sin duda el curso más interesante que he seguido"

- Karin van der Plas

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Fue un curso muy, muy, muy interesante, y hecho por el mejor"

- Matthew Steenwijk

Curso:

"Fue un verdadero placer recibir la formación de Wireshark de parte de un instructor muy dedicado"

- Wim de Vries

Curso: Análisis de Redes de Voz y Video sobre IP

"Pensaba que ya conocía Wireshark. Estaba equivocada, muy equivocada"

- Jeroen Valkonet

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Este curso es imprescindible para todos en TI"

- Johan den Besten

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Excelente para análisis de redes o investigaciones forenses"

- Sven Schneider

Curso: Clase magistral – Redes avanzadas e introducción al análisis de seguridad

"Por mucho, el mejor curso que he tomado jamás"

- Joachim van Doeselaar

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Si hay un paquete, ¡se puede WireSharked!!"

- Elena Petrova

Curso: Análisis de redes inalámbricas y Wi-Fi con Wireshark

"Extremadamente satisfecho con la capacitación. Instructor muy servicial y excelentes métodos de enseñanza"

- Lars Mikkelsen

Curso: Clase magistral – Redes avanzadas e introducción al análisis de seguridad

More courses within category Wireshark training

duración: 5 días
Por anunciar.
El análisis de redes y forense abarca las habilidades de captura de datos y la capacidad de discernir patrones inusuales ocultos dentro de un tráfico de red aparentemente normal. Este curso proporciona al estudiante un...
duración: 5 días
Por anunciar.
Este curso está dirigido a personal de Redes y Seguridad que deba desarrollar técnicas de investigación de paquetes mediante el estudio de protocolos de WiFi y redes inalámbricas (IEEE 802.11a, b, g, n, ac, ad, az).
duración: 5 días
Por anunciar.
Analista certificado de Wireshark: WCA, incl. cupón para el examen WCA-101 350 € La finalización con éxito de la certificación de Wireshark certifica que una persona posee un conocimiento profundo de TCP/IP y análisis de redes/protocolos, resolución de problemas de comunicaciones,..
duración: 5 días
Por anunciar.
This course is for Networking and Security personnel who need to develop a set of packet investigation techniques to support recognition, analysis, and threat recognition for many of the next..
duración: 5 días
Por anunciar.
Análisis y Optimización Eficaces de Redes TCP/IP El análisis y la optimización eficaces de redes TCP/IP requieren más que la captura de tráfico de red. Los profesionales de redes necesitan saber cómo interpretar paquetes, identificar patrones de comunicación,...
duración: 5 días
Por anunciar.
Las realidades del análisis moderno del tráfico exigen interpretar correctamente el tráfico de red cifrado. Un conocimiento detallado de cómo funcionan protocolos clave como HTTP puede aportar información valiosa sobre lo que está ocurriendo...

Regístrate y suscríbete para Taller PCAP: Análisis de tráfico cifrado con Wireshark

Elige una fecha para el curso *
Nombre *
Apellido *
Empresa *
País *
Dirección de correo electrónico *
Número de teléfono
Asistentes *
Comentario
¿Cómo se enteró de este curso? *
Un curso solo se realiza si hay suficiente participación.
*
= obligatorio

Solicitar información para Taller PCAP: Análisis de tráfico cifrado con Wireshark

*
= obligatorio

¿Desea solicitar información para más de un curso? Haga clic aquí