Security Lock on digital screen

Cyber Security & Network Forensics Analysis

Category: Network / Training, Security / Forensics
Format: Open Classroom / Virtual / In-house
Advanced Network Forensics Training with Wireshark Network forensics is the process of collecting, analyzing, and interpreting network traffic to determine what happened on a network, how an incident occurred, and which systems and communications were involved. The Cyber Security &.. read more below
Amsterdam / In-House / Virtual
duration: 5 days
5-12 class size
English

No data available yet.

Or you interested in this course? Request more information. 

Advanced Network Forensics Training with Wireshark

Network forensics is the process of collecting, analyzing, and interpreting network traffic to determine what happened on a network, how an incident occurred, and which systems and communications were involved.

The Cyber Security & Network Forensics Analysis course provides practical, hands-on training in network traffic analysis, PCAP investigation, and digital network forensics using Wireshark and other vendor-neutral tools.

Participants learn how to investigate network activity from a forensic perspective. Starting with raw packet captures, they learn how to identify relevant hosts and communications, reconstruct network activity, detect suspicious behavior, and extract information that can support cybersecurity and forensic investigations.

The course combines network forensics theory with realistic packet captures, practical investigation scenarios, and extensive hands-on exercises.

From Network Traffic to Forensic Evidence

A PCAP file can contain a detailed record of network communications, but identifying the relevant evidence requires a structured investigation methodology.

During the course, participants learn how to:

  • Collect and analyze network traffic.
  • Identify hosts, protocols, services, and conversations.
  • Use Wireshark capture and display filters to isolate relevant traffic.
  • Follow TCP streams and reconstruct network communications.
  • Analyze network behavior and communication patterns.
  • Identify suspicious and potentially malicious traffic.
  • Investigate indicators of compromise.
  • Reconstruct events and establish a timeline from packet-level evidence.
  • Extract relevant information from PCAP files.
  • Interpret technical findings in a forensic context.

The emphasis is on understanding what the network traffic means, rather than simply identifying individual packets.

Practical, Investigation-Focused Training

Network forensics is best learned by investigating realistic network traffic.

Throughout the course, participants work with PCAP files and practical investigation scenarios. They analyze network communications, identify relevant evidence, reconstruct events, and formulate conclusions based on packet-level information.

The course can be delivered as Open Classroom, Virtual, or In-house training.

In-house training can also be adapted to an organization’s specific security environment, investigation requirements, and operational scenarios.

The Cyber Security & Network Forensics Analysis course is designed for professionals who need to investigate, analyze, or understand network traffic as part of cybersecurity, digital forensics, incident response, or security operations.

The course is particularly relevant for professionals who need to move beyond basic packet capture and develop practical skills in network investigation, PCAP analysis, and forensic network traffic analysis.

Target Audience

This course is suitable for:

  • Network security professionals
  • Cybersecurity professionals
  • Security analysts
  • SOC analysts
  • Incident responders
  • Digital forensic investigators
  • Network engineers
  • Network administrators
  • IT security specialists
  • Threat hunters
  • Law enforcement investigators
  • Intelligence analysts
  • Government security professionals
  • Defense and military personnel
  • Technical investigators

Law Enforcement, Intelligence and Defense

Network traffic can provide valuable evidence during criminal, intelligence, and security investigations.

The course is particularly suitable for law enforcement, intelligence services, government organizations, and defense organizations that need to investigate network-based activity and analyze digital evidence.

For these organizations, the training can be delivered as a tailored in-house course using relevant investigation scenarios and network traffic.

Prerequisites

Participants should have a basic understanding of:

  • TCP/IP networking
  • The OSI model
  • IP addressing
  • Common network protocols
  • Basic network communication concepts



The course provides practical guidance throughout the exercises, allowing participants to develop their Wireshark and network forensic analysis skills during the training.

After completing the Cyber Security & Network Forensics Analysis course, participants will be able to apply a structured methodology to network forensic investigations and use Wireshark to analyze network traffic and PCAP files.

Network Forensics Fundamentals

  • Understand the principles of network forensics.
  • Understand network forensic terminology and methodology.
  • Identify the role of packet captures as network evidence.
  • Understand the difference between real-time and post-capture analysis.
  • Apply a structured approach to network forensic investigations.

Network Traffic Collection

  • Configure Wireshark for network investigations.
  • Select appropriate capture interfaces.
  • Understand capture filters.
  • Collect relevant network traffic.
  • Work with multiple packet captures.
  • Identify and preserve traffic relevant to an investigation.

Packet and Protocol Analysis

  • Analyze IPv4 and IPv6 communications.
  • Investigate ARP, DHCP, DNS, TCP, UDP and ICMP traffic.
  • Analyze HTTP and other application-layer protocols.
  • Understand normal protocol behavior.
  • Identify protocol anomalies.
  • Interpret packet-level information in a forensic context.

Wireshark Filtering and Investigation

  • Use Wireshark display filters effectively.
  • Use capture filters.
  • Filter traffic by IP address, host, protocol and port.
  • Identify conversations between systems.
  • Follow TCP streams.
  • Locate relevant packets in large PCAP files.
  • Apply advanced filtering techniques during investigations.

Network Conversation Reconstruction

  • Identify communicating systems.
  • Reconstruct network conversations.
  • Follow application-level communications.
  • Analyze TCP connection establishment and termination.
  • Understand communication sequences.
  • Reconstruct events from packet captures.
  • Build a timeline of relevant network activity.

Detecting Suspicious Network Activity

  • Distinguish normal from unusual network behavior.
  • Identify suspicious communication patterns.
  • Investigate network scanning and reconnaissance.
  • Identify suspicious connections.
  • Analyze malware-related network traffic.
  • Investigate command-and-control communications.
  • Analyze data transfers and potential data exfiltration.
  • Identify indicators of compromise.
  • Recognize abnormal protocol behavior.

Cybersecurity Incident Investigation

  • Investigate potentially compromised systems.
  • Analyze suspicious network behavior.
  • Identify evidence of attack activity.
  • Examine network communications before, during, and after an incident.
  • Correlate network activity with investigation findings.
  • Extract relevant evidence from PCAP files.
  • Apply a structured methodology to incident investigations.

Advanced Network Forensic Analysis

  • Perform traffic reconstruction.
  • Analyze network conversations and communication patterns.
  • Recognize relevant traffic within large captures.
  • Reconstruct timelines from network traffic.
  • Analyze network behavior.
  • Interpret packet-level evidence.
  • Document and communicate forensic findings.

Practical Outcome

At the end of the course, participants will be able to start with a network capture, systematically identify relevant traffic, isolate suspicious communications, reconstruct network activity, and use packet-level evidence to support a cybersecurity or forensic investigation.

They will have developed practical skills for using Wireshark for network forensics, PCAP analysis, incident response, cybersecurity investigations, and network traffic analysis.

Student qoutes

" I found Phill to be the best teacher, and I learn so much from him. Thank you Phill"

- Paul Broyd

Course: TCP/IP Analysis and Troubleshooting with Wireshark

"It's sure the most interesting course that i have followed"

- Karin van der Plas

Course: TCP/IP Analysis and Troubleshooting with Wireshark

"It was a very very very interesting course, and done by the top guy"

- Matthew Steenwijk

Course:

"It was a real pleasure to receive the Wireshark training from a very dedicated trainer"

- Wim de Vries

Course: Voice & Video over IP Network Analysis

"I thought I already knew Wireshark. I was wrong, very wrong"

- Jeroen Valkonet

Course: TCP/IP Analysis and Troubleshooting with Wireshark

"This course is a must have for everyone in IT"

- Johan den Besten

Course: TCP/IP Analysis and Troubleshooting with Wireshark

"Great for network analyses or forensic investigations"

- Sven Schneider

Course: Masterclass – Advanced Network & Intro to Security Analysis

"By far the very best course I ever took"

- Joachim van Doeselaar

Course: TCP/IP Analysis and Troubleshooting with Wireshark

"If there’s a packet, it can be WireSharked!!"

- Elena Petrova

Course: WiFi & Wireless Network Analysis Using Wireshark

"Extremely satisfied with the training. Very helpful instructor and great teaching methods"

- Lars Mikkelsen

Course: Masterclass – Advanced Network & Intro to Security Analysis

More courses within category Network / Training

Amsterdam / In-House / Virtual
duration: 5 days
T.B.A.
Network and Forensics Analysis encompasses the skills of capturing data and the ability to discern unusual patterns hidden within seemingly normal network traffic. This course provides the student with an..
duration: 5 days
T.B.A.
This course is for Networking, Engineering, and Security personnel who need to develop a set of packet investigation techniques through study of the Industrial Control Systems and SCADA networking Protocols..
Amsterdam / In-House / Virtual
duration: 5 days
T.B.A.
This course is for Networking and Security personnel who need to develop a set of packet investigation techniques to support recognition, analysis, and threat recognition for many of the next..
Amsterdam / In-House / Virtual
duration: 5 days
T.B.A.
This course is for Networking and Security personnel who need to develop packet investigation techniques by studying the IoT and Home Automation Protocols using Wireshark and other OpenSource Analysis tools...
duration: 5 days
T.B.A.
This course will provide the student with a set of analysis techniques focusing on the use of vendor-neutral, Open-Source Tools to provide insight into the following areas:

Sign up and register for Cyber Security & Network Forensics Analysis

Choose a course date *
First name *
Last name *
Company *
Country *
Email address *
Phone number
Attendees *
Comment
How did you hear about this course *
A course only takes place if there is sufficient participation.
*
= required

Request information for Cyber Security & Network Forensics Analysis

*
= required

Do you want to request information for more than one course? Click here