Course Code: advwireshark
Duration: 21 hours
Prerequisites:
  • An understanding of network TCP/IP.
Overview:

Format of the Course

  • Interactive lecture and discussion.
  • Lots of exercises and practice.
  • Hands-on implementation in a live-lab environment.

Course Customization Options

  • To request a customized training for this course, please contact us to arrange.
Course Outline:

1.VoIP and Video


• Troubleshooting VoIP and Streaming Problems
• SIP analysis and troubleshooting
• RTP, RTCP and media analysis
• Creating VoIP filters and analysis profiles
• Video transmissions


2. Wi-Fi


• Monitor mode
• Wi-Fi control traffic


3. Latency Issues


• Calculating latency
• Plotting high latency times
• frame.time_delta filter


4. Packet Loss and Retransmissions


• Packet loss and recovery - UDP and TCP
• Previous segment lost and Out-of-Order Segments events
• Duplicate ACKs and Fast Retransmissions
• TCP Retransmissions
• Zero window, Window changes and other window problems


5.Bandwidth Issues
• Bandwidth measurement
• Creating statistical charts and graphs
• User/flow throughput calculations
• Applications throughput calculations
• TCP Time-Sequence graphs
• Bandwidth and throughput problems
• Consistently slow connections over prolonged periods of time


6. Scanning
• IP, port, mutant Scans
• Protocol scans
• Application Mapping
• OS Fingerprinting


7. Secured Network Environments


• Checking for Machines Infected with a Virus
• Inspecting ARP traffic
• Broken/misconfigured software (network flooding)
• Proxies, firewalls and clients


8.Network Security and Forensics Basics


• Forensics Techniques for Security Analysis
• Gathering information – what to look for
• Unusual traffic patterns
• Complementary tools
• Security Suspicious Patterns
• MAC and IP address spoofing
• Attacks signatures and signature locations
• ARP poisoning
• Header and sequencing signatures
• Attacks and exploits
• TCP splicing and unusual traffic
• DoS and DDoS Attacks
• maliciously malformed packets