man die laptop gebruikt om code te schrijven

Masterclass – Geavanceerd Netwerk & Introductie tot Beveiligingsanalyse

Categorie: Wireshark-training
Formaat Open Klaslokaal / Virtueel / In-house
The realities of modern traffic analysis require interpreting encrypted network traffic correctly. A detailed knowledge of how key protocols such as HTTP can provide valuable insights into what is happening in a suspect traffic capture. This workshop provides an introduction.. lees hieronder meer
Amsterdam / In-house / Virtueel
duur: 5 dagen
5-12 class size
Engels

Nog geen gegevens beschikbaar.

Bent u geïnteresseerd in deze cursus? Vraag meer informatie aan. 

The realities of modern traffic analysis require interpreting encrypted network traffic correctly. A detailed knowledge of how key protocols such as HTTP can provide valuable insights into what is happening in a suspect traffic capture. This workshop provides an introduction to techniques for the evaluation of encrypted traffic using open-source tools such as Wireshark to provide insight into the following areas:

  • Specialized software configuration and new Wireshark Profiles to make Analysis faster
  • Encryption techniques, including SSL / TLS / WEP / WPA.x
  • Specialized encrypted traffic analysis techniques using Wireshark 4.x
  • Specialized filtering and Analysis techniques, including data traffic reconstruction and viewing
  • Recognition, analysis, and threat recognition for many of the following generation user protocol issues, including DHCPv6, IPv6/Ipv10, ICMPv6, SCTP/DCCP/RUDP, DNSSec/MDNS/DDNS/LLMNR, Email Protocols (POP / SMTP / IMAP), and standard Internet-based User Protocols such as HTTP2/HTTP3

The course uses Real-world examples and numerous hands-on exercises to provide field-proven, practical analysis skills. Attendees receive a student guide, including numerous reference files, Networking and forensics tools, and a library of reference documents.

This course is for Networking, Government, and Security personnel that need to develop advanced packet investigation techniques by studying the Next Generation Networking Protocols using Wireshark and other Open-Source Analysis tools. Successful completion of this course provides these individuals with a path-way into the field of both Network and Forensics Analysis.

Section 1: Introduction to Advanced Network Analysis

 

Logistics

Open-Source Tool Recommendations

 

Network Analysis Challenges – Nomenclature, Terminology, and Next Generation Protocols

 

Section 2: Recap: Collecting the Data – Data Capture

 

Taking it to the Next Level – Advanced Profile Construction

 

Data Collection

Configuring Wireshark – Standard Captures vs. Stealth and Silent Collection of Data

New types of capture filters – Offset and String-Matching

 

Section 3: Network Analysis Methodology

 

Analyzing Conversations and Activities for Indicators of Compromise (IOC)

Analyzing Conversations and Activities using the Expert Systems to determine unusual activity

Determining Which Conversations Are Suspect – Analyzing Latency and Throughput to recognize suspicious traffic

 

A Sample Advanced Network Forensic Methodology

Answering the key questions – A Sample Network Analysis Methodology

 

Forensic Diagramming – A Picture is worth 1024 Words

 

What’s Normal vs. Abnormal – The Role of Baseline Files

Building a Baseline Library – Where do I find Samples?

 

Recognizing IOCs of Intrusions

Forensic Analysis of an Intrusion

Scouting the Target – Network Reconnaissance and Scanning Tools

Recognizing Scanning Signatures of standard scanning tools – NMAP, Nessus, Retina, and others

 

Bot, Botnets – Command and Control Traffic

Recognizing Bots and Botnet activity – the key IOC’s

Identifying, tracking, and reassembling Command and Control Traffic

 

Section 4: Analysis of Network Applications and User Traffic – The Next Generation Networking Protocols

 

The Networking Protocols – Original vs. Next Generation – New Protocols and New Functions

Configuration Protocols

Structure and Analysis of DHCPv6

Common DHCP-based exploits, Attacks and Examples of Intrusion Signatures

 

Resolving Addresses – DNSSec / DDNS / MDNS / LLMNR

Structure and Analysis of DNS vs. DNSSec, DDNS. mDNS, and LMNR

Common DNS-type Exploits, Attacks, and Examples of Intrusion Signatures

 

The Network Layer – IPv6 / IPv10

Structure and Analysis of IPv4 vs. IPv6 and IPv10

IP Options – What’s the Big Deal?

Common IP Exploits and Examples of Intrusion Signatures

 

Utility and Troubleshooting Protocols – Internet Control Message Protocol (ICMPv6)

Structure and Analysis of ICMPv4 vs. ICMPv6

Network Analysis Using the ICMP Analysis – Types and Codes

Common ICMP Exploits and Examples of Intrusion Signatures

 

The Transport Layer – Moving the Data –SCTP / RUDP / DCCP / QUIC / SPDY

Structure and Advanced Analysis of TCP vs. UDP

TCP Options – What’s the Big Deal?

Advanced TCP Analysis Using Expert Systems

Structure and Advanced Analysis of SCTP

Structure and Analysis of the RUDP and DCCP

Google Transport Protocols SPDY / QUIC

Common Transport Layer Exploits and Examples of Intrusion Signatures

 

The Application Layer – Analyzing Common User Protocols

Email Applications Using POP / SMTP / IMAP

Structure and Analysis of the Email Cloud

Assembling and evaluating Email traffic

 

Web-Based Applications Using HTTP2 / HTTP3

Structure and Analysis of HTTPS – Decrypting TLS

Extracting and using Session Keys

Response Codes – The answer to analyzing HTTP-based protocols

Reassembling and Exporting of Objects

 

 

Where do I go from here? – Continuing Your Wireshark Education

 

Wireshark 0 – TCP/IP Networking Fundamentals Using Wireshark

Wireshark 1 – TCP/IP Troubleshooting & Network Optimization Using Wireshark

Wireshark 2 – Masterclass – Advanced Network & Security Analysis

Wireshark 3 – Network Forensics Analysis

Wireshark 4 – Mobile Device Forensics Analysis

Wireshark 5 – Cloud and Internet of Things (IoT) Advanced Network Analysis

Wireshark 6 – VoIP Advanced Network Analysis

Wireshark 7 – WiFi Advanced Network Analysis

Wireshark 8 – SCADA and ICS Advanced Network Analysis

Wireshark 9 – Wireshark Command Line Tools

Studentenquotes

"Ik vond Phill de beste leraar, en ik leer erg veel van hem. Dank je wel, Phill"

- Paul Broyd

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Het is absoluut de meest interessante cursus die ik heb gevolgd"

- Karin van der Plas

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Het was een zeer, zeer, zeer interessante cursus, en gegeven door de absolute topman"

- Matthew Steenwijk

Cursus

"Het was een waar genot om de Wireshark-training te krijgen van een zeer toegewijde trainer"

- Wim de Vries

Cursus: Voice & Video over IP Netwerkanalyse

"Ik dacht dat ik Wireshark al kende. Ik had het mis, heel erg mis"

- Jeroen Valkonet

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Deze cursus is een absolute must-have voor iedereen in de IT"

- Johan den Besten

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Geweldig voor netwerkanalyses of forensisch onderzoek"

- Sven Schneider

Cursus Masterclass – Geavanceerd Netwerk & Introductie tot Beveiligingsanalyse

"Veruit de allerbeste cursus die ik ooit heb gevolgd"

- Joachim van Doeselaar

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Als er een datapakket is, kan het worden gewireswarked!!"

- Elena Petrova

Cursus: WiFi & Wireless Network Analysis Using Wireshark

"Extreem tevreden over de training. Zeer behulpzame instructeur en geweldige lesmethoden"

- Lars Mikkelsen

Cursus Masterclass – Geavanceerd Netwerk & Introductie tot Beveiligingsanalyse

Meer cursussen in de categorie Wireshark-training

duur: 1 dag
Nog te bepalen.
PCAP of het is niet gebeurd. Wat is PCAP? Het analyseren van versleuteld verkeer met Wireshark Modern netwerkverkeer wordt in toenemende mate versleuteld, wat traditionele pakketanalyse uitdagender maakt. Versleuteld verkeer biedt echter nog steeds..
Amsterdam / In-house / Virtueel
duur: 5 dagen
Nog te bepalen.
Netwerk- en forensische analyse omvat de vaardigheden van het vastleggen van data en het vermogen om ongewone patronen te onderscheiden die verborgen zijn in schijnbaar normaal netwerkverkeer. Deze cursus biedt de student een..
duur: 5 dagen
Nog te bepalen.
Deze cursus is bedoeld voor netwerk- en beveiligingspersoneel dat technieken voor pakketonderzoek moet ontwikkelen door wifi- en draadloze netwerkprotocollen (IEEE 802.11a, b, g, n, ac, ad, az) te bestuderen.
duur: 5 dagen
Nog te bepalen.
Wireshark Certified Analyst: WCA, incl. WCA-101 examen voucher € 350,00 Met het met succes afronden van de Wireshark-certificering wordt gecertificeerd dat een persoon over diepgaande kennis beschikt van TCP/IP en netwerk-/protocolanalyse, het oplossen van communicatieproblemen,..
duur: 5 dagen
Nog te bepalen.
Deze cursus is bedoeld voor netwerk- en beveiligingspersoneel dat een reeks pakketonderzoekstechnieken moet ontwikkelen ter ondersteuning van herkenning, analyse en bedreigingsdetectie voor veel van de volgende..
duur: 5 dagen
Nog te bepalen.
Effectieve Netwerk TCP/IP Analyse en Optimalisatie Effectieve TCP/IP netwerkanalyse en -optimalisatie vereist meer dan het vastleggen van netwerkverkeer. Netwerkprofessionals moeten begrijpen hoe ze pakketten moeten interpreteren, communicatiepatronen identificeren,..

Meld je aan en registreer je voor Masterclass – Geavanceerd Netwerk & Introductie tot Beveiligingsanalyse

Kies een cursusdatum *
Voornaam *
Achternaam *
Bedrijf *
Land *
E-mailadres *
Telefoonnummer
Aanwezigen *
Opmerking
Hoe heb je over deze cursus gehoord? *
Een cursus gaat alleen door bij voldoende deelname.
*
= verplicht

Informatie aanvragen voor Masterclass – Geavanceerd Netwerk & Introductie tot Beveiligingsanalyse

*
= verplicht

Wilt u informatie aanvragen voor meer dan één cursus? Klik hier