Beveiligingsslot op het digitaal scherm

Cyberbeveiliging en Netwerkforensische Analyse

Categorie: Netwerk / Training, Security / Forensics
Formaat Open Klaslokaal / Virtueel / In-house
Advanced Network Forensics Training with Wireshark Network forensics is the process of collecting, analyzing, and interpreting network traffic to determine what happened on a network, how an incident occurred, and which systems and communications were involved. The Cyber Security &.. lees hieronder meer
Amsterdam / In-house / Virtueel
duur: 5 dagen
5-12 class size
Engels

Nog geen gegevens beschikbaar.

Bent u geïnteresseerd in deze cursus? Vraag meer informatie aan. 

Advanced Network Forensics Training with Wireshark

Network forensics is the process of collecting, analyzing, and interpreting network traffic to determine what happened on a network, how an incident occurred, and which systems and communications were involved.

The Cyberbeveiliging en Netwerkforensische Analyse course provides practical, hands-on training in network traffic analysis, PCAP investigation, and digital network forensics using Wireshark and other vendor-neutral tools.

Participants learn how to investigate network activity from a forensic perspective. Starting with raw packet captures, they learn how to identify relevant hosts and communications, reconstruct network activity, detect suspicious behavior, and extract information that can support cybersecurity and forensic investigations.

The course combines network forensics theory with realistic packet captures, practical investigation scenarios, and extensive hands-on exercises.

From Network Traffic to Forensic Evidence

A PCAP file can contain a detailed record of network communications, but identifying the relevant evidence requires a structured investigation methodology.

During the course, participants learn how to:

  • Collect and analyze network traffic.
  • Identify hosts, protocols, services, and conversations.
  • Use Wireshark capture and display filters to isolate relevant traffic.
  • Follow TCP streams and reconstruct network communications.
  • Analyze network behavior and communication patterns.
  • Identify suspicious and potentially malicious traffic.
  • Investigate indicators of compromise.
  • Reconstruct events and establish a timeline from packet-level evidence.
  • Extract relevant information from PCAP files.
  • Interpret technical findings in a forensic context.

The emphasis is on understanding what the network traffic means, rather than simply identifying individual packets.

Practical, Investigation-Focused Training

Network forensics is best learned by investigating realistic network traffic.

Throughout the course, participants work with PCAP files and practical investigation scenarios. They analyze network communications, identify relevant evidence, reconstruct events, and formulate conclusions based on packet-level information.

The course can be delivered as Open Classroom, Virtual, or In-house training.

In-house training can also be adapted to an organization’s specific security environment, investigation requirements, and operational scenarios.

The Cyberbeveiliging en Netwerkforensische Analyse course is designed for professionals who need to investigate, analyze, or understand network traffic as part of cybersecurity, digital forensics, incident response, or security operations.

The course is particularly relevant for professionals who need to move beyond basic packet capture and develop practical skills in network investigation, PCAP analysis, and forensic network traffic analysis.

Target Audience

This course is suitable for:

  • Network security professionals
  • Cybersecurity professionals
  • Security analysts
  • SOC analysts
  • Incident responders
  • Digital forensic investigators
  • Network engineers
  • Network administrators
  • IT security specialists
  • Threat hunters
  • Law enforcement investigators
  • Intelligence analysts
  • Government security professionals
  • Defense and military personnel
  • Technical investigators

Law Enforcement, Intelligence and Defense

Network traffic can provide valuable evidence during criminal, intelligence, and security investigations.

The course is particularly suitable for law enforcement, intelligence services, government organizations, and defense organizations that need to investigate network-based activity and analyze digital evidence.

For these organizations, the training can be delivered as a tailored in-house course using relevant investigation scenarios and network traffic.

Prerequisites

Participants should have a basic understanding of:

  • TCP/IP networking
  • The OSI model
  • IP addressing
  • Common network protocols
  • Basic network communication concepts



The course provides practical guidance throughout the exercises, allowing participants to develop their Wireshark and network forensic analysis skills during the training.

After completing the Cyberbeveiliging en Netwerkforensische Analyse course, participants will be able to apply a structured methodology to network forensic investigations and use Wireshark to analyze network traffic and PCAP files.

Network Forensics Fundamentals

  • Understand the principles of network forensics.
  • Understand network forensic terminology and methodology.
  • Identify the role of packet captures as network evidence.
  • Understand the difference between real-time and post-capture analysis.
  • Apply a structured approach to network forensic investigations.

Network Traffic Collection

  • Configure Wireshark for network investigations.
  • Select appropriate capture interfaces.
  • Understand capture filters.
  • Collect relevant network traffic.
  • Work with multiple packet captures.
  • Identify and preserve traffic relevant to an investigation.

Packet and Protocol Analysis

  • Analyze IPv4 and IPv6 communications.
  • Investigate ARP, DHCP, DNS, TCP, UDP and ICMP traffic.
  • Analyze HTTP and other application-layer protocols.
  • Understand normal protocol behavior.
  • Identify protocol anomalies.
  • Interpret packet-level information in a forensic context.

Wireshark Filtering and Investigation

  • Use Wireshark display filters effectively.
  • Use capture filters.
  • Filter traffic by IP address, host, protocol and port.
  • Identify conversations between systems.
  • Follow TCP streams.
  • Locate relevant packets in large PCAP files.
  • Apply advanced filtering techniques during investigations.

Network Conversation Reconstruction

  • Identify communicating systems.
  • Reconstruct network conversations.
  • Follow application-level communications.
  • Analyze TCP connection establishment and termination.
  • Understand communication sequences.
  • Reconstruct events from packet captures.
  • Build a timeline of relevant network activity.

Detecting Suspicious Network Activity

  • Distinguish normal from unusual network behavior.
  • Identify suspicious communication patterns.
  • Investigate network scanning and reconnaissance.
  • Identify suspicious connections.
  • Analyze malware-related network traffic.
  • Investigate command-and-control communications.
  • Analyze data transfers and potential data exfiltration.
  • Identify indicators of compromise.
  • Recognize abnormal protocol behavior.

Cybersecurity Incident Investigation

  • Investigate potentially compromised systems.
  • Analyze suspicious network behavior.
  • Identify evidence of attack activity.
  • Examine network communications before, during, and after an incident.
  • Correlate network activity with investigation findings.
  • Extract relevant evidence from PCAP files.
  • Apply a structured methodology to incident investigations.

Advanced Network Forensic Analysis

  • Perform traffic reconstruction.
  • Analyze network conversations and communication patterns.
  • Recognize relevant traffic within large captures.
  • Reconstruct timelines from network traffic.
  • Analyze network behavior.
  • Interpret packet-level evidence.
  • Document and communicate forensic findings.

Praktisch resultaat

At the end of the course, participants will be able to start with a network capture, systematically identify relevant traffic, isolate suspicious communications, reconstruct network activity, and use packet-level evidence to support a cybersecurity or forensic investigation.

They will have developed practical skills for using Wireshark for network forensics, PCAP analysis, incident response, cybersecurity investigations, and network traffic analysis.

Studentenquotes

"Ik vond Phill de beste leraar, en ik leer erg veel van hem. Dank je wel, Phill"

- Paul Broyd

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Het is absoluut de meest interessante cursus die ik heb gevolgd"

- Karin van der Plas

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Het was een zeer, zeer, zeer interessante cursus, en gegeven door de absolute topman"

- Matthew Steenwijk

Cursus

"Het was een waar genot om de Wireshark-training te krijgen van een zeer toegewijde trainer"

- Wim de Vries

Cursus: Voice & Video over IP Netwerkanalyse

"Ik dacht dat ik Wireshark al kende. Ik had het mis, heel erg mis"

- Jeroen Valkonet

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Deze cursus is een absolute must-have voor iedereen in de IT"

- Johan den Besten

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Geweldig voor netwerkanalyses of forensisch onderzoek"

- Sven Schneider

Cursus: Masterclass – Geavanceerd Netwerk & Introductie tot Beveiligingsanalyse

"Veruit de allerbeste cursus die ik ooit heb gevolgd"

- Joachim van Doeselaar

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Als er een datapakket is, kan het worden gewireswarked!!"

- Elena Petrova

Cursus: WiFi & Wireless Network Analysis Using Wireshark

"Extreem tevreden over de training. Zeer behulpzame instructeur en geweldige lesmethoden"

- Lars Mikkelsen

Cursus: Masterclass – Geavanceerd Netwerk & Introductie tot Beveiligingsanalyse

Meer cursussen binnen categorie Netwerk / Training

Amsterdam / In-house / Virtueel
duur: 5 dagen
Nog te bepalen.
Netwerk- en forensische analyse omvat de vaardigheden van het vastleggen van data en het vermogen om ongewone patronen te onderscheiden die verborgen zijn in schijnbaar normaal netwerkverkeer. Deze cursus biedt de student een..
duur: 5 dagen
Nog te bepalen.
This course is for Networking, Engineering, and Security personnel who need to develop a set of packet investigation techniques through study of the Industrial Control Systems and SCADA networking Protocols..
duur: 5 dagen
Nog te bepalen.
Deze cursus is bedoeld voor netwerk- en beveiligingspersoneel dat een reeks pakketonderzoekstechnieken moet ontwikkelen ter ondersteuning van herkenning, analyse en bedreigingsdetectie voor veel van de volgende..
Amsterdam / In-house / Virtueel
duur: 5 dagen
Nog te bepalen.
Deze cursus is bedoeld voor netwerk- en beveiligingsprofessionals die vaardigheden willen ontwikkelen op het gebied van pakketonderzoek door IoT- en domoticaprotocollen te bestuderen met behulp van Wireshark en andere opensource-analysetools...
duur: 5 dagen
Nog te bepalen.
Deze cursus biedt de student een reeks analysetechnieken die zich richten op het gebruik van leverancierneutrale open-sourcetools om inzicht te geven in de volgende gebieden:

Meld je aan en registreer je voor Cyberbeveiliging en Netwerkforensische Analyse

Kies een cursusdatum *
Voornaam *
Achternaam *
Bedrijf *
Land *
E-mailadres *
Telefoonnummer
Aanwezigen *
Opmerking
Hoe heb je over deze cursus gehoord? *
Een cursus gaat alleen door bij voldoende deelname.
*
= verplicht

Informatie aanvragen voor Cyberbeveiliging en Netwerkforensische Analyse

*
= verplicht

Wilt u informatie aanvragen voor meer dan één cursus? Klik hier