Traffico di rete criptato Wireshark e analisi PCAP

Workshop PCAP: Analisi del traffico cifrato con Wireshark

Category: Wireshark training
Format: Virtuale
PCAP it or it didn’t happen. What is PCAP? Analyzing Encrypted Traffic with Wireshark Modern network traffic is increasingly encrypted, making traditional packet analysis more challenging. However, encrypted traffic still contains valuable information that can help network professionals understand communication.. read more below
Virtuale
durata: 1 giorno
class size
English

Courses available

5 Ott
- 5 Ott 2026
- Virtual
- 9.00 - 16.00
- € 895,00

PCAP it or it didn’t happen.

What is PCAP?

Analyzing Encrypted Traffic with Wireshark

Modern network traffic is increasingly encrypted, making traditional packet analysis more challenging. However, encrypted traffic still contains valuable information that can help network professionals understand communication patterns, troubleshoot connectivity and performance problems, and identify potentially suspicious activity.

This hands-on workshop teaches practical techniques for analyzing encrypted network traffic and PCAP files with Wireshark. Participants learn how to identify and interpret the information that remains visible in encrypted communications and how to use Wireshark to investigate network behavior when packet payloads cannot be directly read.

The workshop covers:

  • Wireshark configuration and analysis profiles designed to make encrypted traffic analysis faster and more efficient.
  • The fundamentals of network encryption, including SSL/TLS, HTTPS, WEP, WPA, WPA2, and WPA3.
  • Techniques for analyzing encrypted traffic and identifying useful packet-level information even when the payload is encrypted.
  • Wireshark filtering and analysis techniques for isolating relevant encrypted communications.
  • Analysis of communication patterns, endpoints, protocols, timing, packet sizes, and other observable characteristics of encrypted traffic.
  • Traffic reconstruction and conversation analysis to understand network communications and application behavior.
  • Identification of unusual or suspicious data flows that may warrant further investigation.
  • Practical methodologies for applying encrypted traffic analysis to network troubleshooting, cybersecurity, threat hunting, and network forensics.

Throughout the workshop, participants work with real-world encrypted traffic and practical PCAP examples. Extensive hands-on exercises allow attendees to apply Wireshark techniques and develop a structured methodology for investigating encrypted network communications.

The workshop provides a practical foundation for professionals who need to understand what can be learned from encrypted network traffic, how to investigate it efficiently, and how to recognize patterns that may indicate network problems or security threats.

This workshop is designed for networking, cybersecurity, government, law enforcement, intelligence, incident response, and security professionals who need practical techniques for investigating encrypted network traffic and PCAP files.

It is particularly suited to professionals who use or need to use Wireshark for network analysis, troubleshooting, security investigations, threat hunting, or network forensics, including:

  • Network engineers and network administrators
  • Cybersecurity and security analysts
  • Incident responders and threat hunters
  • Digital and network forensics professionals
  • Law enforcement and government investigators
  • Intelligence and security personnel
  • Professionals responsible for investigating suspicious network communications

 

The workshop is especially valuable for professionals who already understand basic networking concepts and want to develop the ability to analyze encrypted traffic when packet payloads are not directly visible.

Participants will learn how to examine observable characteristics of encrypted communications, identify relevant traffic, recognize unusual communication patterns, and use Wireshark to investigate encrypted network activity.

The workshop provides a practical foundation for further work in encrypted traffic analysis, network troubleshooting, cybersecurity, incident response, threat hunting, and network forensics.

By completing this workshop, participants will develop practical skills to analyze encrypted network traffic and PCAP files using Wireshark, even when the contents of network communications cannot be directly viewed.

You will learn how to:

Configure Wireshark for Encrypted Traffic Analysis

  • Configure Wireshark for efficient encrypted traffic investigations.
  • Use specialized Wireshark profiles to organize and accelerate analysis.
  • Configure relevant views, fields, statistics, and analysis tools.
  • Apply an efficient workflow when investigating large or complex PCAP files.

Understand Network Encryption

  • Understand the fundamentals of SSL/TLS and HTTPS.
  • Understand the principles of wireless encryption, including WEP, WPA, WPA2, and WPA3.
  • Identify where encryption is applied within network communications.
  • Determine which information remains observable when traffic is encrypted.

Analyze Encrypted Network Traffic

  • Identify encrypted communications within a PCAP file.
  • Analyze endpoints, protocols, ports, packet sizes, timing, and communication patterns.
  • Examine TLS connections and relevant protocol fields.
  • Identify communication relationships between systems and services.
  • Use packet-level information to understand encrypted network behavior without relying solely on payload contents.

Investigate Encrypted Traffic with Wireshark

  • Create effective Wireshark display filters for encrypted traffic.
  • Isolate relevant hosts, conversations, protocols, and network events.
  • Follow network conversations and analyze communication flows.
  • Use Wireshark statistics to identify significant traffic patterns.
  • Reconstruct and visualize network communications where possible.

Identify Suspicious Network Behavior

  • Establish a baseline for normal encrypted communication.
  • Identify unusual data flows and unexpected communication patterns.
  • Recognize indicators that may require further security investigation.
  • Analyze encrypted traffic as part of threat hunting and network security investigations.
  • Use PCAP evidence to support network and forensic investigations.

Apply Real-World Analysis Techniques

  • Work with realistic encrypted PCAP files and practical investigation scenarios.
  • Apply a structured methodology to encrypted traffic analysis.
  • Combine protocol analysis, Wireshark statistics, filtering, and traffic visualization.
  • Translate packet-level observations into meaningful technical conclusions.

Practical Outcome

After completing the workshop, participants will be able to approach an encrypted PCAP systematically, identify relevant communications, analyze observable characteristics of encrypted traffic, recognize unusual behavior, and use Wireshark to determine what can be learned from encrypted network activity.

These skills provide a practical foundation for professional work in encrypted traffic analysis, network troubleshooting, cybersecurity, threat hunting, incident response, and network forensics.

Student qoutes

"Ho trovato che Phill sia il miglior insegnante e imparo molto da lui. Grazie Phill"

- Paul Broyd

Corso: TCP/IP Analysis and Troubleshooting with Wireshark

"È sicuramente il corso più interessante che abbia seguito"

- Karin van der Plas

Corso: TCP/IP Analysis and Troubleshooting with Wireshark

"È stato un corso molto molto molto interessante, tenuto dal numero uno"

- Matthew Steenwijk

Corso:

"È stato un vero piacere ricevere la formazione su Wireshark da un formatore molto dedicato"

- Wim de Vries

Corso: Analisi di reti Voice & Video over IP

"Pensavo di conoscere già Wireshark. Mi sbagliavo, mi sbagliavo di grosso"

- Jeroen Valkonet

Corso: TCP/IP Analysis and Troubleshooting with Wireshark

"Questo corso è assolutamente da non perdere per chiunque lavori nell'IT"

- Johan den Besten

Corso: TCP/IP Analysis and Troubleshooting with Wireshark

"Ottimo per analisi di rete o indagini forensi"

- Sven Schneider

Corso: Masterclass – Reti Avanzate e Introduzione all'Analisi della Sicurezza

"Di gran lunga il corso migliore che abbia mai seguito"

- Joachim van Doeselaar

Corso: TCP/IP Analysis and Troubleshooting with Wireshark

"Se c'è un pacchetto, può essere intercettato con WireShark!!"

- Elena Petrova

Corso: Analisi di reti WiFi e wireless tramite Wireshark

"Estremamente soddisfatto della formazione. Istruttore molto disponibile e ottimi metodi di insegnamento"

- Lars Mikkelsen

Corso: Masterclass – Reti Avanzate e Introduzione all'Analisi della Sicurezza

More courses within category Wireshark training

durata: 5 giorni
T.B.A.
Network and Forensics Analysis encompasses the skills of capturing data and the ability to discern unusual patterns hidden within seemingly normal network traffic. This course provides the student with an..
durata: 5 giorni
T.B.A.
This course is for Networking and Security personnel who must develop packet investigation techniques by studying the WiFi and Wireless Networking Protocols (IEEE 802.11a, b, g, n, ac, ad, az)..
durata: 5 giorni
T.B.A.
Wireshark Certified Analyst: WCA, incl. WCA-101 exam voucher € 350,00 Successful completion of the Wireshark Certification certifies that an individual possesses an in-depth knowledge of TCP/IP and network/protocol analysis, troubleshooting communications,..
durata: 5 giorni
T.B.A.
This course is for Networking and Security personnel who need to develop a set of packet investigation techniques to support recognition, analysis, and threat recognition for many of the next..
durata: 5 giorni
T.B.A.
Effective Network TCP/IP Analysis and Optimization Effective TCP/IP network analysis and optimization requires more than capturing network traffic. Network professionals need to understand how to interpret packets, identify communication patterns,..
durata: 5 giorni
T.B.A.
The realities of modern traffic analysis require interpreting encrypted network traffic correctly. A detailed knowledge of how key protocols such as HTTP can provide valuable insights into what is happening..

Sign up and register for Workshop PCAP: Analisi del traffico cifrato con Wireshark

Choose a course date *
First name *
Last name *
Company *
Country *
Email address *
Phone number
Attendees *
Comment
How did you hear about this course *
A course only takes place if there is sufficient participation.
*
= required

Request information for Workshop PCAP: Analisi del traffico cifrato con Wireshark

*
= required

Do you want to request information for more than one course? Click here