With this training, participants will understand the analysis of attacks and detection of anomalies on the network using network logs before or during a cyber attack.
Who Should Participate?
Cyber Security Analysts, SOC Analysts, Network Security Specialists, Security Incident Management Teams
Program
1) Tcpdump 101
• Pcap file format
• Berkeley Packet Filter (BPF)
2) Wireshark 101
• User Array
• Screen Filters
• Useful Features for Network Analysis
3) Network Related Log Types and Sources
• Hub, Switch, Tap
• Flow Records
• Full Package Registration
• Log Files
4) Hypertext Transfer Protocol (HTTP)
• Forensic Importance
• Request / Response Packages
• Important HTTP Domains
• Finding Extraction
5) File Transfer Protocol (FTP)
• Past and Present Use
• Analyzing the Shortcomings in Today's Networks
6) Analysis of Web Proxy Logs
• Useful Protocol Fields
• Natural Weaknesses
7) Simple Mail Transfer Protocol (SMTP)
• Life Cycle of an Email
8) Netflow Based Network Analysis
• What is Netflow
• Netflow Based Analysis Details
9) Wireless Network Analysis
• Applying the Analysis of Wired Networks to Wireless Networks
• Log Collection Methods
• What is Netflow
• Netflow Based Analysis Details
10) Analyzing Network Log Files
• Analyzing IIS Log Files
• FTP Log Analysis
• DHCP Log Files Analysis
• Using Microsoft Log Parser