Choose your language
Network forensics Course
More than 2 million learners worldwide

Network forensics Course

Master the tools, techniques, and methodologies used by professional network forensic investigators. This course takes you from TCP/IP fundamentals through advanced threat detection, cloud forensics, and automated analysis workflows. Whether you're responding to an active intrusion or reconstructing a past breach, you'll have the skills to find the evidence and tell the full story.

Dedika for businesses

What you will learn:

You'll learn how to capture and preserve network traffic as forensically sound evidence, analyze protocols with Wireshark and tshark, and detect threats ranging from port scans to encrypted command-and-control channels. The course covers intrusion detection, log analysis, wireless forensics, and cloud network investigations using VPC flow logs and API audit trails. You'll build Python-based automation scripts to handle large-scale PCAP analysis and apply machine learning concepts to traffic classification. By the end, you'll know how to correlate evidence across multiple sources, extract indicators of compromise, and deliver structured forensic reports that hold up under scrutiny.

How you study in a practical way Network forensics Course

How you practice Network forensics Course

For companies who want to train their team

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Network Forensics

  • Lesson 1 • Evidence Types in Network Investigations

    Identifies categories of network evidence including full packet captures, flow records, and logs. Students understand what each evidence type reveals and its forensic limitations.

  • Lesson 2 • Forensic Investigation Methodology

    Introduces a structured, repeatable process for conducting network forensic investigations. Establishes the workflow that organizes all practical skills taught in later chapters.

  • Lesson 3 • Legal and Ethical Principles

    Addresses authorization requirements, chain of custody, and privacy obligations in network investigations. Ensures students apply forensic techniques within lawful and ethical boundaries.

  • Lesson 4 • Network Communication Fundamentals

    Reviews TCP/IP stack layers, protocols, and packet structure essential for forensic analysis. Provides the technical baseline required for all capture and analysis tasks ahead.

  • Lesson 5 • Defining Network Forensics

    Covers the definition, goals, and boundaries of network forensics as a discipline. Anchors the chapter by distinguishing it from related fields like log analysis and malware forensics.

Chapter 2See details

Packet Capture and Data Collection

  • Lesson 1 • Packet Capture Tools and Techniques

    Introduces command-line and GUI tools for capturing live traffic and saving PCAP files. Students practice capturing filtered and full-session traffic in lab environments.

  • Lesson 2 • Preserving Evidence Integrity

    Teaches cryptographic hashing, write-blocking, and documentation practices for network evidence. Integrity preservation ensures evidence remains admissible and defensible throughout an investigation.

  • Lesson 3 • Network Flow Collection

    Covers NetFlow, sFlow, and IPFIX export configuration and collection infrastructure. Flow data complements full packet capture when storage or bandwidth is constrained.

  • Lesson 4 • Log Aggregation and Centralization

    Addresses collection of firewall, DNS, proxy, and authentication logs into a central repository. Centralized logs enable correlation across evidence types in later analysis stages.

  • Lesson 5 • Capture Architecture and Placement

    Explains where and how to position capture sensors within a network topology. Correct placement determines evidence completeness and is foundational to all collection tasks.

Chapter 3See details

Protocol Analysis and Traffic Decoding

  • Lesson 1 • Identifying Protocol Anomalies

    Teaches recognition of malformed packets, protocol tunneling, and non-standard port usage. Anomaly detection bridges protocol knowledge with threat identification in later chapters.

  • Lesson 2 • Wireshark Deep Dive

    Covers advanced Wireshark features including display filters, stream reassembly, and statistics. Mastery of this tool accelerates all subsequent protocol analysis and artifact extraction tasks.

  • Lesson 3 • Automated Protocol Dissection

    Introduces scripted and automated approaches to protocol parsing using Python and tshark. Automation scales analysis beyond what manual inspection can achieve in large captures.

  • Lesson 4 • Analyzing Core Network Protocols

    Examines DNS, HTTP, SMTP, FTP, and SMB traffic patterns and forensic indicators. Understanding normal protocol behavior enables detection of misuse and anomalies.

  • Lesson 5 • Encrypted Traffic Analysis

    Addresses TLS/SSL handshake analysis, certificate inspection, and metadata extraction from encrypted flows. Students learn what forensic value remains when payload decryption is not possible.

Chapter 4See details

Network Intrusion Detection and Log Analysis

  • Lesson 1 • DNS and Proxy Log Investigation

    Focuses on extracting threat indicators from DNS query logs and web proxy access logs. These sources reveal command-and-control communication, data exfiltration, and malicious domain use.

  • Lesson 2 • Firewall and Perimeter Log Analysis

    Teaches extraction of connection records, deny events, and policy violations from firewall logs. Perimeter logs establish the timeline and scope of external and lateral network activity.

  • Lesson 3 • Event Correlation and Timeline Building

    Introduces techniques for correlating events across IDS, firewall, DNS, and proxy logs into a unified timeline. Timelines are the primary analytical product used to reconstruct attack sequences.

  • Lesson 4 • Configuring and Tuning Detection Rules

    Covers writing and tuning detection rules to reduce noise and improve alert fidelity. Well-tuned rules directly improve the quality of forensic leads available during an investigation.

  • Lesson 5 • Intrusion Detection System Fundamentals

    Explains signature-based and anomaly-based IDS architectures and their forensic output. IDS alerts serve as primary investigative leads that drive deeper packet and log analysis.

Chapter 5See details

Traffic Analysis for Threat Detection

  • Lesson 1 • Scanning and Reconnaissance Detection

    Covers identification of port scans, host discovery, and service enumeration in traffic data. Recognizing reconnaissance activity enables early detection before exploitation occurs.

  • Lesson 2 • Lateral Movement and Internal Threats

    Identifies traffic patterns associated with credential theft, pass-the-hash, and internal scanning. Internal threat detection requires analysis of east-west traffic often missed at the perimeter.

  • Lesson 3 • Malware Command-and-Control Traffic

    Teaches identification of beaconing, C2 protocols, and malware communication patterns in traffic. C2 detection is a critical skill for confirming active compromise during an investigation.

  • Lesson 4 • Baseline and Behavioral Profiling

    Establishes methods for profiling normal network behavior to enable anomaly detection. A reliable baseline is the prerequisite for distinguishing malicious from legitimate traffic patterns.

  • Lesson 5 • Data Exfiltration Detection

    Covers detection of large outbound transfers, covert channels, and protocol-based exfiltration. Identifying exfiltration completes the attack lifecycle analysis and informs containment decisions.

Chapter 6See details

Wireless and Cloud Network Forensics

  • Lesson 1 • Investigating Cloud Network Incidents

    Applies forensic methodology to cloud-based intrusions using flow logs and audit trails. Students reconstruct attacker activity within cloud environments using available log evidence.

  • Lesson 2 • Wireless Network Forensics Fundamentals

    Covers 802.11 frame types, wireless capture methods, and forensic artifacts unique to Wi-Fi. Wireless evidence requires specialized capture hardware and protocol knowledge not needed for wired analysis.

  • Lesson 3 • Wireless Attack Pattern Recognition

    Identifies traffic signatures of deauthentication attacks, rogue APs, and evil-twin scenarios. Recognizing these patterns enables investigators to determine how wireless access was compromised.

  • Lesson 4 • Cloud Network Architecture Overview

    Explains virtual networks, security groups, and traffic flow in major cloud environments. Understanding cloud architecture is required before collecting or interpreting cloud network evidence.

  • Lesson 5 • Cloud Flow and Audit Log Collection

    Teaches enabling and collecting VPC flow logs, cloud DNS logs, and API audit trails. Cloud logs replace traditional PCAP as the primary evidence source in cloud-hosted environments.

Chapter 7See details

Incident Reconstruction and Attribution

  • Lesson 1 • Attack Lifecycle Reconstruction

    Applies kill-chain and attack-framework models to map evidence to attacker stages. Structured mapping transforms raw evidence into an organized narrative of attacker behavior.

  • Lesson 2 • Evidence Correlation Across Sources

    Teaches joining PCAP, flow, log, and endpoint data into a unified evidence picture. Cross-source correlation fills gaps that no single evidence type can resolve on its own.

  • Lesson 3 • Indicator of Compromise Extraction

    Covers systematic extraction of IPs, domains, hashes, and behavioral indicators from evidence. Extracted IOCs support detection, blocking, and threat intelligence sharing after an investigation.

  • Lesson 4 • Forensic Report Writing

    Covers structure, language, and standards for producing defensible forensic investigation reports. A well-written report is the final deliverable that communicates findings to technical and non-technical audiences.

  • Lesson 5 • Network Attribution Techniques

    Examines infrastructure analysis, TTPs, and passive DNS to support attacker attribution. Students understand the limits of attribution and how to present findings with appropriate confidence levels.

Chapter 8See details

Advanced Forensic Analysis and Automation

  • Lesson 1 • Scripting Forensic Workflows

    Teaches building Python-based pipelines that automate evidence extraction, parsing, and enrichment. Scripted workflows reduce analyst time and improve consistency across repeated investigation tasks.

  • Lesson 2 • Threat Hunting with Network Data

    Applies hypothesis-driven hunting techniques to proactively find threats in network evidence. Threat hunting extends forensic skills beyond reactive investigation into proactive discovery.

  • Lesson 3 • Large-Scale PCAP Analysis Strategies

    Addresses indexing, splitting, and querying large capture files that exceed manual analysis capacity. Efficient large-scale analysis is essential for enterprise-level incident investigations.

  • Lesson 4 • Machine Learning in Network Forensics

    Introduces supervised and unsupervised ML techniques applied to network traffic classification. Students understand where ML adds value and where human analysis remains essential.

  • Lesson 5 • Forensic Lab and Tool Validation

    Covers building a repeatable forensic lab environment and validating tool accuracy. Tool validation ensures that analysis results are defensible and reproducible in legal or regulatory contexts.

Certification

Your valid completion certificate

This course is for you:

  • SOC Analyst: wants to move beyond alerts into full network investigations.

  • Incident Responder: needs structured methodology for reconstructing breaches from traffic.

  • IT Security Engineer: ready to add deep forensic investigation skills to their toolkit.

  • Penetration Tester: wants to understand how defenders trace and document attacker activity.

  • Career Changer: transitioning into cybersecurity from a networking or IT background.

  • Digital Forensics Student: has covered disk forensics and now wants to master network evidence.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQs

Who is Dedika?

Is the certificate valid in the Philippines?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course