Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend

This course is coming soon. It is not yet open for enrollment, and no payment is taken.

The outline and outcomes below reflect what this course will cover. Check back soon.

Coming soonIntermediate

Network Traffic Analysis Deep-Dive

Read packets and flows to find C2, exfil and lateral movement.

By LearnDefend Security Team · Network Security

About this course

Extend your Wireshark skills into investigation: follow a conversation, spot beaconing in flow data, recognize exfiltration and tunnelling, and separate noisy-but-benign traffic from a real intrusion.

What you'll learn

  • Follow and interpret a full network conversation.
  • Detect beaconing and tunnelling in traffic.
  • Distinguish benign anomalies from intrusion.

Course outline

  1. 1Conversations and stream following
  2. 2Beaconing and flow analysis
  3. 3Exfiltration and tunnelling
  4. 4Benign vs malicious

Prerequisites

  • The Wireshark Tool Academy or equivalent packet-reading basics.
Network Traffic Analysis Deep-Dive | LearnDefend