Curso Network Forensics

  • Redes & Infraestrutura de TI

Curso Network Forensics

24h
Visão Geral

Este curso apresenta técnicas de análise forense de tráfego e evidências de rede para investigação de incidentes, detecção de ataques, reconstrução de sessões e identificação de atividades maliciosas.

Objetivo

Após realizar este curso, você será capaz de:

  • Analisar tráfego de rede
  • Identificar comportamentos suspeitos
  • Reconstruir atividades de ataque
  • Apoiar investigações forenses
Publico Alvo
  • Network Security Professionals
  • DFIR Professionals
  • SOC Analysts
  • Threat Hunters
Pre-Requisitos
  • Conhecimentos de TCP/IP
  • Familiaridade com protocolos de rede
  • Conhecimentos básicos de Linux e Windows
  • Noções de Wireshark
  • Conhecimentos básicos de incident response
Conteúdo Programatico

Module 1: Network Forensics Fundamentals

  1. Network forensics concepts
  2. Network evidence
  3. Packet capture
  4. Traffic analysis
  5. Network investigation lifecycle
  6. Evidence preservation
  7. Network artifacts
  8. Forensic integrity
  9. Investigation methodology
  10. Network forensic documentation

Module 2: Network Protocol Analysis

  1. TCP
  2. UDP
  3. DNS
  4. HTTP
  5. HTTPS
  6. TLS
  7. SMB
  8. LDAP
  9. Kerberos
  10. Protocol-based investigation

Module 3: Packet Analysis

  1. Packet structure
  2. Packet capture analysis
  3. TCP sessions
  4. Network flows
  5. Session reconstruction
  6. Packet filtering
  7. Traffic patterns
  8. Anomalous packets
  9. Protocol anomalies
  10. Packet investigation

Module 4: Attack Detection

  1. Port scanning
  2. Network reconnaissance
  3. Brute Force
  4. Command and Control
  5. Malware traffic
  6. Data exfiltration
  7. Lateral Movement
  8. Suspicious DNS
  9. Network anomalies
  10. Attack detection

Module 5: Web and Application Traffic

  1. HTTP investigation
  2. HTTPS metadata
  3. Web sessions
  4. Application protocols
  5. Suspicious requests
  6. Malicious downloads
  7. Web-based attacks
  8. Application traffic anomalies
  9. Web evidence
  10. Application traffic investigation

Module 6: Network Threat Hunting

  1. Hunting hypotheses
  2. IOC-based hunting
  3. Behavioral hunting
  4. DNS hunting
  5. Network connection hunting
  6. C2 hunting
  7. Exfiltration hunting
  8. Lateral Movement hunting
  9. Network telemetry
  10. Threat hunting methodology

Module 7: Incident Investigation

  1. Incident scoping
  2. Traffic correlation
  3. Timeline reconstruction
  4. Endpoint correlation
  5. Network-to-host analysis
  6. Attack path reconstruction
  7. Evidence validation
  8. IOC identification
  9. Investigation reporting
  10. Incident response integration

Module 8: Practical Network Forensics

  1. Packet capture analysis
  2. Protocol investigation
  3. DNS investigation
  4. HTTP investigation
  5. C2 analysis
  6. Lateral Movement investigation
  7. Exfiltration analysis
  8. Timeline reconstruction
  9. Evidence documentation
  10. Network forensics case study
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas