
Network forensics Course
Master the tools, techniques, and methodologies used by professional network forensic investigators. This course takes you from TCP/IP fundamentals through advanced threat detection, cloud forensics, and automated analysis workflows. Whether you're responding to an active intrusion or reconstructing a past breach, you'll have the skills to find the evidence and tell the full story.
What you will learn:
You'll learn how to capture and preserve network traffic as forensically sound evidence, analyze protocols with Wireshark and tshark, and detect threats ranging from port scans to encrypted command-and-control channels. The course covers intrusion detection, log analysis, wireless forensics, and cloud network investigations using VPC flow logs and API audit trails. You'll build Python-based automation scripts to handle large-scale PCAP analysis and apply machine learning concepts to traffic classification. By the end, you'll know how to correlate evidence across multiple sources, extract indicators of compromise, and deliver structured forensic reports that hold up under scrutiny.
How you study in a practical way Network forensics Course
How you practice Network forensics Course
For companies who want to train their team
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of Network Forensics
Foundations of Network Forensics
Lesson 1 • Evidence Types in Network Investigations
Identifies categories of network evidence including full packet captures, flow records, and logs. Students understand what each evidence type reveals and its forensic limitations.
Lesson 2 • Forensic Investigation Methodology
Introduces a structured, repeatable process for conducting network forensic investigations. Establishes the workflow that organizes all practical skills taught in later chapters.
Lesson 3 • Legal and Ethical Principles
Addresses authorization requirements, chain of custody, and privacy obligations in network investigations. Ensures students apply forensic techniques within lawful and ethical boundaries.
Lesson 4 • Network Communication Fundamentals
Reviews TCP/IP stack layers, protocols, and packet structure essential for forensic analysis. Provides the technical baseline required for all capture and analysis tasks ahead.
Lesson 5 • Defining Network Forensics
Covers the definition, goals, and boundaries of network forensics as a discipline. Anchors the chapter by distinguishing it from related fields like log analysis and malware forensics.
Chapter 2HideHide detailsSee detailsPacket Capture and Data Collection
Packet Capture and Data Collection
Lesson 1 • Packet Capture Tools and Techniques
Introduces command-line and GUI tools for capturing live traffic and saving PCAP files. Students practice capturing filtered and full-session traffic in lab environments.
Lesson 2 • Preserving Evidence Integrity
Teaches cryptographic hashing, write-blocking, and documentation practices for network evidence. Integrity preservation ensures evidence remains admissible and defensible throughout an investigation.
Lesson 3 • Network Flow Collection
Covers NetFlow, sFlow, and IPFIX export configuration and collection infrastructure. Flow data complements full packet capture when storage or bandwidth is constrained.
Lesson 4 • Log Aggregation and Centralization
Addresses collection of firewall, DNS, proxy, and authentication logs into a central repository. Centralized logs enable correlation across evidence types in later analysis stages.
Lesson 5 • Capture Architecture and Placement
Explains where and how to position capture sensors within a network topology. Correct placement determines evidence completeness and is foundational to all collection tasks.
Chapter 3HideHide detailsSee detailsProtocol Analysis and Traffic Decoding
Protocol Analysis and Traffic Decoding
Lesson 1 • Identifying Protocol Anomalies
Teaches recognition of malformed packets, protocol tunneling, and non-standard port usage. Anomaly detection bridges protocol knowledge with threat identification in later chapters.
Lesson 2 • Wireshark Deep Dive
Covers advanced Wireshark features including display filters, stream reassembly, and statistics. Mastery of this tool accelerates all subsequent protocol analysis and artifact extraction tasks.
Lesson 3 • Automated Protocol Dissection
Introduces scripted and automated approaches to protocol parsing using Python and tshark. Automation scales analysis beyond what manual inspection can achieve in large captures.
Lesson 4 • Analyzing Core Network Protocols
Examines DNS, HTTP, SMTP, FTP, and SMB traffic patterns and forensic indicators. Understanding normal protocol behavior enables detection of misuse and anomalies.
Lesson 5 • Encrypted Traffic Analysis
Addresses TLS/SSL handshake analysis, certificate inspection, and metadata extraction from encrypted flows. Students learn what forensic value remains when payload decryption is not possible.
Chapter 4HideHide detailsSee detailsNetwork Intrusion Detection and Log Analysis
Network Intrusion Detection and Log Analysis
Lesson 1 • DNS and Proxy Log Investigation
Focuses on extracting threat indicators from DNS query logs and web proxy access logs. These sources reveal command-and-control communication, data exfiltration, and malicious domain use.
Lesson 2 • Firewall and Perimeter Log Analysis
Teaches extraction of connection records, deny events, and policy violations from firewall logs. Perimeter logs establish the timeline and scope of external and lateral network activity.
Lesson 3 • Event Correlation and Timeline Building
Introduces techniques for correlating events across IDS, firewall, DNS, and proxy logs into a unified timeline. Timelines are the primary analytical product used to reconstruct attack sequences.
Lesson 4 • Configuring and Tuning Detection Rules
Covers writing and tuning detection rules to reduce noise and improve alert fidelity. Well-tuned rules directly improve the quality of forensic leads available during an investigation.
Lesson 5 • Intrusion Detection System Fundamentals
Explains signature-based and anomaly-based IDS architectures and their forensic output. IDS alerts serve as primary investigative leads that drive deeper packet and log analysis.
Chapter 5HideHide detailsSee detailsTraffic Analysis for Threat Detection
Traffic Analysis for Threat Detection
Lesson 1 • Scanning and Reconnaissance Detection
Covers identification of port scans, host discovery, and service enumeration in traffic data. Recognizing reconnaissance activity enables early detection before exploitation occurs.
Lesson 2 • Lateral Movement and Internal Threats
Identifies traffic patterns associated with credential theft, pass-the-hash, and internal scanning. Internal threat detection requires analysis of east-west traffic often missed at the perimeter.
Lesson 3 • Malware Command-and-Control Traffic
Teaches identification of beaconing, C2 protocols, and malware communication patterns in traffic. C2 detection is a critical skill for confirming active compromise during an investigation.
Lesson 4 • Baseline and Behavioral Profiling
Establishes methods for profiling normal network behavior to enable anomaly detection. A reliable baseline is the prerequisite for distinguishing malicious from legitimate traffic patterns.
Lesson 5 • Data Exfiltration Detection
Covers detection of large outbound transfers, covert channels, and protocol-based exfiltration. Identifying exfiltration completes the attack lifecycle analysis and informs containment decisions.
Chapter 6HideHide detailsSee detailsWireless and Cloud Network Forensics
Wireless and Cloud Network Forensics
Lesson 1 • Investigating Cloud Network Incidents
Applies forensic methodology to cloud-based intrusions using flow logs and audit trails. Students reconstruct attacker activity within cloud environments using available log evidence.
Lesson 2 • Wireless Network Forensics Fundamentals
Covers 802.11 frame types, wireless capture methods, and forensic artifacts unique to Wi-Fi. Wireless evidence requires specialized capture hardware and protocol knowledge not needed for wired analysis.
Lesson 3 • Wireless Attack Pattern Recognition
Identifies traffic signatures of deauthentication attacks, rogue APs, and evil-twin scenarios. Recognizing these patterns enables investigators to determine how wireless access was compromised.
Lesson 4 • Cloud Network Architecture Overview
Explains virtual networks, security groups, and traffic flow in major cloud environments. Understanding cloud architecture is required before collecting or interpreting cloud network evidence.
Lesson 5 • Cloud Flow and Audit Log Collection
Teaches enabling and collecting VPC flow logs, cloud DNS logs, and API audit trails. Cloud logs replace traditional PCAP as the primary evidence source in cloud-hosted environments.
Chapter 7HideHide detailsSee detailsIncident Reconstruction and Attribution
Incident Reconstruction and Attribution
Lesson 1 • Attack Lifecycle Reconstruction
Applies kill-chain and attack-framework models to map evidence to attacker stages. Structured mapping transforms raw evidence into an organized narrative of attacker behavior.
Lesson 2 • Evidence Correlation Across Sources
Teaches joining PCAP, flow, log, and endpoint data into a unified evidence picture. Cross-source correlation fills gaps that no single evidence type can resolve on its own.
Lesson 3 • Indicator of Compromise Extraction
Covers systematic extraction of IPs, domains, hashes, and behavioral indicators from evidence. Extracted IOCs support detection, blocking, and threat intelligence sharing after an investigation.
Lesson 4 • Forensic Report Writing
Covers structure, language, and standards for producing defensible forensic investigation reports. A well-written report is the final deliverable that communicates findings to technical and non-technical audiences.
Lesson 5 • Network Attribution Techniques
Examines infrastructure analysis, TTPs, and passive DNS to support attacker attribution. Students understand the limits of attribution and how to present findings with appropriate confidence levels.
Chapter 8HideHide detailsSee detailsAdvanced Forensic Analysis and Automation
Advanced Forensic Analysis and Automation
Lesson 1 • Scripting Forensic Workflows
Teaches building Python-based pipelines that automate evidence extraction, parsing, and enrichment. Scripted workflows reduce analyst time and improve consistency across repeated investigation tasks.
Lesson 2 • Threat Hunting with Network Data
Applies hypothesis-driven hunting techniques to proactively find threats in network evidence. Threat hunting extends forensic skills beyond reactive investigation into proactive discovery.
Lesson 3 • Large-Scale PCAP Analysis Strategies
Addresses indexing, splitting, and querying large capture files that exceed manual analysis capacity. Efficient large-scale analysis is essential for enterprise-level incident investigations.
Lesson 4 • Machine Learning in Network Forensics
Introduces supervised and unsupervised ML techniques applied to network traffic classification. Students understand where ML adds value and where human analysis remains essential.
Lesson 5 • Forensic Lab and Tool Validation
Covers building a repeatable forensic lab environment and validating tool accuracy. Tool validation ensures that analysis results are defensible and reproducible in legal or regulatory contexts.
Your valid completion certificate
This course is for you:
SOC Analyst: wants to move beyond alerts into full network investigations.
Incident Responder: needs structured methodology for reconstructing breaches from traffic.
IT Security Engineer: ready to add deep forensic investigation skills to their toolkit.
Penetration Tester: wants to understand how defenders trace and document attacker activity.
Career Changer: transitioning into cybersecurity from a networking or IT background.
Digital Forensics Student: has covered disk forensics and now wants to master network evidence.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top trainings
FAQs
Who is Dedika?
Is the certificate valid in the Philippines?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















