Description
Advanced Wireshark for Threat Hunting and Network Forensics is a course on basic packet analysis and using Wireshark as a powerful tool for threat detection, attack investigation, and network forensics published by Udemy Online Academy. This is an in-depth and comprehensive course designed for cybersecurity professionals who want to move beyond basic packet analysis and use Wireshark as a powerful tool for threat detection, attack investigation, and network forensics. The course focuses on real-world scenarios and teaches individuals how to analyze complex traffic patterns, uncover malicious behavior, and accurately interpret network evidence. This course is ideal for SOC analysts, incident responders, penetration testers, and anyone looking to master modern traffic analysis and threat detection.
This course covers advanced filtering techniques, protocol-level analysis, and traffic reconstruction, while also teaching individuals how to identify indicators of compromise, detect anomalies, and analyze malware communications. This course covers extracting artifacts from PCAP files, tracking attacker movement, understanding encryption patterns, and using Wireshark with threat intelligence to validate and investigate suspicious activity. Students will gain hands-on experience with forensic workflows, decrypting hidden traffic, examining lateral movement, and detecting common attack patterns such as DNS tunneling, C2 channels, and data mining. By the end, students will be equipped to perform high-level threat hunting and network forensic investigations with confidence and accuracy.
What you will learn in Advanced Wireshark for Threat Hunting and Network Forensics:
- Master Wireshark’s advanced filtering to identify indicators of intrusion (IOC) from millions of packets
- Use TShark and TCPDump to remotely and stealthily obtain packets for field forensics.
- Analyze complex protocols (DNS, HTTP, TCP) to detect tunneling, data leaks, and C2 signals.
- Reconstruct attacker conversations and securely extract malicious payloads for incident response.
- Use Wireshark IO graphs and statistics to quickly identify anomalies and unknown attack patterns.
- Perform in-depth analysis of TCP state transitions to identify connection hijacking and stealth attacks.
- Identify and analyze network reconnaissance, including stealth port scans and attacker intent mapping.
- Apply a forensic mindset to maintain evidence integrity from capture to final report generation.
- Configure custom Wireshark profiles and coloring rules to efficiently hunt down and prioritize evidence.
- Distinguishing between normal traffic and subtle malicious patterns such as DNS egress (DGA).
- And …
Course specifications
Publisher: Udemy
Instructors: OCSALY Academy | 550.000+ Students
Language: English
Level: Intermediate
Number of Lessons: 34
Duration: 7 hours and 10 minutes
Course topics

Advanced Wireshark for Threat Hunting and Network Forensics Prerequisites
A computer capable of running Wireshark (Windows, macOS, or Linux).
Basic understanding of TCP/IP and the OSI Model.
Pictures

Advanced Wireshark for Threat Hunting and Network Forensics introduction video
Installation guide
After Extract, watch with your favorite Player.
Subtitle: None
Quality: 720p
Downloadly link
Rapidgator link
File password (s): www.downloadly.ir
Size
4.7 GB