Choose your language
Network Traffic Analysis with Wireshark Course
More than 2 million learners worldwide

Network Traffic Analysis with Wireshark Course

Master network traffic analysis from packet fundamentals to advanced threat detection using Wireshark. This course takes you through protocol dissection, performance diagnostics, TLS decryption, and security investigation with hands-on capture data. Whether you're troubleshooting slow connections or hunting malicious activity, you'll build the skills that real-world analysts rely on every day.

Dedika for businesses

What you will learn:

  • Configure Wireshark capture interfaces, filters, and profiles for efficient, targeted packet collection.

  • Decode TCP, UDP, IP, and application-layer protocols to accurately interpret any network capture.

  • Build display and capture filters that isolate relevant traffic and eliminate analytical noise.

  • Detect reconnaissance scans, ARP spoofing, C2 beaconing, and credential exfiltration from packet evidence.

  • Analyze TLS handshakes, evaluate cipher suite strength, and decrypt sessions where key material is available.

  • Automate repetitive analysis tasks using TShark, shell scripting, and Python with Scapy.

How you study in a practical way Network Traffic Analysis with Wireshark Course

How you practice Network Traffic Analysis with Wireshark Course

For companies who want to train their team

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Wireshark Fundamentals and Setup

  • Lesson 1 • Installing and Configuring Wireshark

    Covers installation on Windows, macOS, and Linux with privilege configuration. Ensures a functional capture environment before any hands-on work.

  • Lesson 2 • Saving and Managing Capture Files

    Teaches pcap and pcapng file formats, file splitting, and basic file management. Students can preserve and share captures for collaborative analysis.

  • Lesson 3 • Capture Interfaces and Options

    Explains interface selection, promiscuous mode, and capture buffer settings. Proper configuration here prevents data loss in all subsequent captures.

  • Lesson 4 • Navigating the Wireshark Interface

    Maps every major UI panel and toolbar to its analytical function. Students gain fluency in the interface needed to work efficiently in later chapters.

  • Lesson 5 • Network Traffic Analysis Overview

    Defines packet analysis, its role in network operations, and key use cases. Establishes the analytical mindset needed throughout the course.

Chapter 2See details

Packet Structure and Protocol Layers

  • Lesson 1 • OSI and TCP/IP Model Review

    Maps OSI layers to TCP/IP layers and explains encapsulation. This framework is the reference model for every protocol discussed in the course.

  • Lesson 2 • Ethernet and Layer 2 Frames

    Dissects Ethernet frame structure including MAC addresses and EtherType fields. Understanding Layer 2 is essential for interpreting raw captures.

  • Lesson 3 • ICMP and ARP Packet Structures

    Analyzes ICMP message types and ARP request/reply mechanics. These protocols appear frequently in troubleshooting and attack scenarios.

  • Lesson 4 • TCP and UDP Header Analysis

    Covers port numbers, flags, sequence numbers, and checksums for both transport protocols. Students distinguish normal from abnormal transport-layer behavior.

  • Lesson 5 • IP Header Analysis

    Examines IPv4 and IPv6 header fields and their significance in routing and fragmentation. Students can identify addressing and TTL anomalies in captures.

Chapter 3See details

Capture Filters and Display Filters

  • Lesson 1 • Filtering by IP, Port, and Protocol

    Applies filter syntax to common analyst tasks: isolating hosts, services, and protocols. Students build filters for the most frequent real-world scenarios.

  • Lesson 2 • Display Filter Syntax and Logic

    Teaches Wireshark's display filter language for post-capture packet isolation. Display filters are the primary tool for focused analysis in every chapter.

  • Lesson 3 • Capture Filter Syntax and Logic

    Introduces BPF syntax used for capture-time filtering to limit collected data. Efficient capture filters reduce file size and processing overhead.

  • Lesson 4 • Advanced Display Filter Techniques

    Covers string matching, byte offsets, and field existence checks for complex queries. These techniques handle edge cases that simple filters cannot address.

  • Lesson 5 • Filter Profiles and Workflow Efficiency

    Organizes filters into named profiles and color rules for repeatable workflows. Students leave with a personal filter library ready for production use.

Chapter 4See details

Protocol Dissection and Stream Analysis

  • Lesson 1 • Exporting Objects and Files

    Uses Wireshark's export objects feature to recover files transferred over HTTP, SMB, and FTP. Recovered files support deeper forensic investigation.

  • Lesson 2 • Following TCP and UDP Streams

    Demonstrates stream reassembly to view full application conversations. This technique is foundational for all application-layer analysis tasks.

  • Lesson 3 • HTTP and HTTPS Traffic Analysis

    Dissects HTTP request and response headers, methods, and status codes. Students identify web application behavior and detect anomalies in HTTP traffic.

  • Lesson 4 • DNS Query and Response Analysis

    Examines DNS message structure, record types, and resolution timing. Students detect misconfigured resolvers and suspicious DNS patterns.

  • Lesson 5 • FTP, SMTP, and Telnet Dissection

    Analyzes cleartext application protocols to extract commands and credentials. These protocols illustrate the risk of unencrypted communication.

Chapter 5See details

Network Performance and Baseline Analysis

  • Lesson 1 • Measuring TCP Performance Metrics

    Uses TCP stream graphs to measure throughput, RTT, and window scaling. Students pinpoint the root cause of slow TCP connections.

  • Lesson 2 • Wireshark Statistics Tools Overview

    Surveys the Statistics menu: summary, protocol hierarchy, conversations, and endpoints. These tools provide the high-level view needed before deep-dive analysis.

  • Lesson 3 • Identifying Retransmissions and Errors

    Filters for TCP retransmissions, duplicate ACKs, and out-of-order segments. These indicators reveal packet loss and congestion on the network path.

  • Lesson 4 • Building Traffic Baselines

    Establishes normal traffic profiles using I/O graphs and conversation statistics. Baselines enable rapid detection of deviations in later security analysis.

  • Lesson 5 • Analyzing Application Response Times

    Measures server response time and client processing delay using packet timestamps. Students isolate whether latency originates at the network or application layer.

Chapter 6See details

Encrypted Traffic and TLS Analysis

  • Lesson 1 • Analyzing Encrypted Threat Traffic

    Uses metadata, timing, and JA3 fingerprints to profile encrypted malicious sessions. Students assess threats without requiring full plaintext decryption.

  • Lesson 2 • TLS Handshake Dissection

    Breaks down ClientHello, ServerHello, and certificate exchange packets step by step. Understanding the handshake is prerequisite to any TLS-based analysis.

  • Lesson 3 • Cipher Suite and Certificate Analysis

    Evaluates negotiated cipher suites and certificate metadata for security weaknesses. Students flag deprecated algorithms and expired or self-signed certificates.

  • Lesson 4 • Decrypting TLS with Pre-Master Keys

    Configures Wireshark to use SSLKEYLOGFILE for session decryption. Decrypted sessions expose application-layer content for full protocol analysis.

  • Lesson 5 • Detecting TLS Anomalies and Attacks

    Identifies downgrade attacks, invalid certificates, and unusual TLS extensions in captures. These anomalies indicate interception or misconfiguration.

Chapter 7See details

Security Analysis and Threat Detection

  • Lesson 1 • Reconnaissance and Scanning Detection

    Identifies port scans, ping sweeps, and OS fingerprinting attempts in captures. Recognizing scan patterns is the first step in incident triage.

  • Lesson 2 • Denial-of-Service Attack Analysis

    Analyzes SYN floods, UDP floods, and amplification attacks using traffic volume and pattern data. Students distinguish DoS traffic from legitimate bursts.

  • Lesson 3 • Credential and Data Exfiltration Detection

    Locates cleartext credentials and large outbound data transfers in packet captures. Students build filters targeting exfiltration-specific traffic signatures.

  • Lesson 4 • ARP and DHCP Attack Detection

    Detects ARP spoofing, ARP poisoning, and rogue DHCP servers from packet evidence. These Layer 2 attacks enable man-in-the-middle interception.

  • Lesson 5 • Malware and C2 Traffic Patterns

    Identifies beaconing, DNS tunneling, and command-and-control communication in captures. These patterns reveal compromised hosts within the network.

Chapter 8See details

Advanced Wireshark Techniques and Automation

  • Lesson 1 • Handling Large-Scale Captures

    Applies file splitting, ring buffers, and selective extraction to manage multi-gigabyte captures. Students maintain analytical performance on enterprise traffic volumes.

  • Lesson 2 • Automating Analysis with TShark and Shell

    Combines TShark with shell scripting to automate repetitive extraction and reporting tasks. Automation reduces analyst time on high-volume capture processing.

  • Lesson 3 • Command-Line Capture with TShark

    Uses TShark for headless capture, filtering, and field extraction on remote systems. TShark enables analysis in environments where a GUI is unavailable.

  • Lesson 4 • Writing Custom Wireshark Dissectors

    Creates Lua-based dissectors to decode proprietary or undocumented protocols. Custom dissectors make Wireshark useful for specialized enterprise environments.

  • Lesson 5 • Processing Captures with Python and Scapy

    Reads and manipulates pcap files programmatically using Python and Scapy. Students build custom analysis scripts beyond Wireshark's built-in capabilities.

Certification

Your valid completion certificate

This course is for you:

  • Network administrator: wants to move beyond ping and traceroute for diagnostics.

  • SOC analyst: needs to validate alerts by examining actual packet-level evidence.

  • IT support technician: ready to graduate from guesswork to evidence-based troubleshooting.

  • Cybersecurity student: building a practical skill set to complement certification study.

  • Systems engineer: responsible for uptime and wants deeper visibility into traffic behavior.

  • Career changer: transitioning from general IT into a network security or analyst role.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQs

Who is Dedika?

Is the certificate valid in the Philippines?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course