CONTACT US

Blue Team

With this training, participants will understand the analysis of attacks and detection of anomalies on the network using network logs before or during a cyber attack. 

Who Should Participate?

Cyber Security Analysts, SOC Analysts, Network Security Specialists, Security Incident Management Teams

Program

1) Tcpdump 101 
•    Pcap file format 
•    Berkeley Packet Filter (BPF)

2) Wireshark 101 
•    User Array 
•    Screen Filters 
•    Useful Features for Network Analysis

3) Network Related Log Types and Sources
•    Hub, Switch, Tap 
•    Flow Records 
•    Full Package Registration 
•    Log Files  

4) Hypertext Transfer Protocol (HTTP)
•    Forensic Importance
•    Request / Response Packages
•    Important HTTP Domains
•    Finding Extraction

5) File Transfer Protocol (FTP)
•    Past and Present Use 
•    Analyzing the Shortcomings in Today's Networks

6) Analysis of Web Proxy Logs
•    Useful Protocol Fields 
•    Natural Weaknesses

7) Simple Mail Transfer Protocol (SMTP)
•    Life Cycle of an Email

8) Netflow Based Network Analysis  
•    What is Netflow
•    Netflow Based Analysis Details

9) Wireless Network Analysis 
•    Applying the Analysis of Wired Networks to Wireless Networks 
•    Log Collection Methods 
•    What is Netflow 
•    Netflow Based Analysis Details 

10) Analyzing Network Log Files
•    Analyzing IIS Log Files 
•    FTP Log Analysis 
•    DHCP Log Files Analysis 
•    Using Microsoft Log Parser
 

TRAINING DETAILS
QUOTA
Last 2 places
DATE
DURATION
5 Days
LEVEL
LANGUAGE
TYPE OF TRAINING
Online and Classroom
CERTIFICATE

FEATURED TRAININGS

Plan and implement the trainings you desire for your organization!

You can plan the trainings you need at different durations and with content that is specific to your institution. Please contact us for detailed content and planning.

GET INFORMATION

Eğitim Formu


Add an ally to your defense

Add an ally to your defense


Experience first-hand how ADEO's 24x7 end-to-end security approach can help you achieve better results. Enhance your security coverage with our team of security experts, who work as an extension of your team, and reduce your risks with their rapid response capabilities. Maximize the value of your current security products by incorporating operational functionality into your telemetry data.

Reduce your average remediation time with our automation, playbooks, and incident response expertise. Take control of all your security alerts by managing, prioritizing, and viewing them from a single dashboard across your entire security infrastructure.