Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Wireshark: Malware and Forensics

Wireshark: Malware and Forensics

2hIntermediate2021-02-08

Authors

Lisa Bock

Lisa Bock

Security ambassador with a broad range of IT skills and knowledge

Course details

Security devices on a network scoop up traffic and then analyze the field values to allow or deny specific traffic. As smart as the devices are, there are times when some threats slip through the cracks. Wireshark is a free protocol analysis tool that is used to baseline a network, actively monitor changes, identify common attack signatures, build firewall rules, detect issues, and quickly remove threats from the network. This course covers how to use Wireshark for deep packet analysis, capturing, and forensics. Learn how to keep your networks secure against malware and cyberattacks by implementing solutions that detect and handle unusual traffic.

Topics include:
Trends in cyberattacks
Preventing system compromise
Analyzing packets
Using Wireshark
Creating firewall rules
Baselining a network
Using capture filters
Using a ring buffer
Handling OSI layer attacks
Identifying attack signatures
Using VirusTotal
Handling unwanted TOR activity

Skills covered

WiresharkNetwork SecurityIncident ResponseNetwork AdministrationCybersecurityNetwork and System AdministrationOpen SourceDeep Dive (X:Y)

Concepts

0. Introduction

  • 01 - Sniffing out the bad guys
  • 02 - What you should know

1. Recognizing Today's Threats

  • 03 - Exploring cyberattacks and trends
  • 04 - Understanding malware and cyber threats
  • 05 - Packet analysis overview
  • 06 - Outlining the benefits of Wireshark
  • 07 - Tshark
  • 08 - Tap into your network
  • 09 - Create firewall rules
  • 10 - Challenge - Email forensics
  • 11 - Response - Email forensics

2. Diving into the Network

  • 12 - Baseline your network
  • 13 - Displaying data using filters
  • 14 - Creating complex filters
  • 15 - Capture filters
  • 16 - Using statistics
  • 17 - Save, export, and print
  • 18 - Coloring rules
  • 19 - Using a ring buffer
  • 20 - Challenge - HTTP packets
  • 21 - Solution - HTTP packets
  • 22 - Challenge - Firewall rules
  • 23 - Solution - Firewall rules

3. Examining Unusual Traffic

  • 24 - OSI layer attacks
  • 25 - Indications of compromise
  • 26 - Ports related to malicious activity
  • 27 - Understanding port scans
  • 28 - Investigating attacks
  • 29 - Using VirusTotal
  • 30 - Challenge - Analyze
  • 31 - Solution - Analyze

4. Case Studies

  • 32 - Fast flux DNS
  • 33 - Trojan in the house
  • 34 - Unwanted TOR activity
  • 35 - Challenge - Packets and filters
  • 36 - Solution - Packets and filters

Conclusion

  • 37 - Next steps

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal