PCAP it or it didn’t happen.
Analyzing Encrypted Traffic with Wireshark
Modern network traffic is increasingly encrypted, making traditional packet analysis more challenging. However, encrypted traffic still contains valuable information that can help network professionals understand communication patterns, troubleshoot connectivity and performance problems, and identify potentially suspicious activity.
This hands-on workshop teaches practical techniques for analyzing encrypted network traffic and PCAP files with Wireshark. Participants learn how to identify and interpret the information that remains visible in encrypted communications and how to use Wireshark to investigate network behavior when packet payloads cannot be directly read.
The workshop covers:
- Wireshark configuration and analysis profiles designed to make encrypted traffic analysis faster and more efficient.
- The fundamentals of network encryption, including SSL/TLS, HTTPS, WEP, WPA, WPA2, and WPA3.
- Techniques for analyzing encrypted traffic and identifying useful packet-level information even when the payload is encrypted.
- Wireshark filtering and analysis techniques for isolating relevant encrypted communications.
- Analysis of communication patterns, endpoints, protocols, timing, packet sizes, and other observable characteristics of encrypted traffic.
- Traffic reconstruction and conversation analysis to understand network communications and application behavior.
- Identification of unusual or suspicious data flows that may warrant further investigation.
- Practical methodologies for applying encrypted traffic analysis to network troubleshooting, cybersecurity, threat hunting, and network forensics.
Throughout the workshop, participants work with real-world encrypted traffic and practical PCAP examples. Extensive hands-on exercises allow attendees to apply Wireshark techniques and develop a structured methodology for investigating encrypted network communications.
The workshop provides a practical foundation for professionals who need to understand what can be learned from encrypted network traffic, how to investigate it efficiently, and how to recognize patterns that may indicate network problems or security threats.