Threats are everywhere within your IT infrastructures. There are many security devices to help detect and prevent these threats, but what happens when you need to dig into the details? What happens when you're faced with analyzing a threat, conducting a forensic investigation, or troubleshooting an issue? In this course, Getting Started with Packet Analysis, you will learn the basic skills needed to be able to capture, read, and interpret packets within your environments. First, you will learn the structure of datagrams in your environments. Next, you will explore how to use your analysis tools, and how to interpret the information within a datagram. Finally, you will discover how to identify certain risks by looking at datagrams. When you're finished with this course, you will have the foundational knowledge to be able to hone your skills in interpreting data that crosses your network. Software required: Security Onion with netsniff-ng, tcpdump, and Wireshark.
Learning Objectives
- Capturing Packets
- Reading Packet Captures
- IPv6 Packets
- Encrypted Packets
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):
Specialty Areas
- Cyber Defense Analysis
- Incident Response
- Network Services
Feedback
If you would like to provide feedback on this course, please e-mail the NICCS team at NICCS@mail.cisa.dhs.gov. Please keep in mind that NICCS does not own this course or accept payment for course entry. If you have questions related to the details of this course, such as cost, prerequisites, how to register, etc., please contact the course training provider directly. You can find course training provider contact information by following the link that says “Visit course page for more information...” on this page.