Choose your language
Wireshark Training
More than 2 million students worldwide

Wireshark Training

Master Wireshark from installation to advanced threat detection with hands-on packet analysis training. Learn to capture, filter, and decode real network traffic across every major protocol. Whether you're troubleshooting slow applications or hunting security incidents, this course gives you the skills to find answers at the packet level.

Dedika for businesses

What you will learn:

This course covers every stage of network packet analysis using Wireshark, from initial setup and interface navigation to advanced automation with TShark and Python. You will learn to write capture and display filters, decode TCP/IP and application-layer protocols, and use Wireshark's built-in statistics tools to visualize traffic patterns. The course includes dedicated modules on performance troubleshooting, security threat detection, and evidence documentation. You will also explore TLS decryption, Lua scripting for custom dissectors, and packet capture in cloud and virtual environments. By the end, you will be able to conduct end-to-end network investigations and produce clear, evidence-backed analysis reports.

How you study in practice Wireshark Training

How you practice Wireshark Training

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course Content

8 Chapters • 36 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Introduction to Wireshark and Packet Analysis

  • Lesson 1 • Starting and Stopping Captures

    Teaches how to select interfaces and control capture sessions. Connects interface selection to the types of traffic visible in each capture.

  • Lesson 2 • Navigating the Wireshark Interface

    Introduces all major UI panels and toolbar controls. Students gain confidence moving through the interface before capturing live traffic.

  • Lesson 3 • Wireshark Installation and Setup

    Guides installation on Windows, macOS, and Linux with required dependencies. Ensures every student has a functional, correctly configured Wireshark environment.

  • Lesson 4 • Network Traffic Fundamentals

    Covers packets, frames, and data flow across network layers. Establishes the conceptual baseline needed to interpret Wireshark captures meaningfully.

Chapter 2See details

Capture Filters and Display Filters

  • Lesson 1 • Understanding Display Filters

    Covers Wireshark's display filter language for post-capture analysis. Students apply filters to large captures without discarding any packets.

  • Lesson 2 • Advanced Display Filter Techniques

    Introduces complex expressions, slicing, and regex matching in display filters. Enables precise isolation of anomalous or protocol-specific traffic patterns.

  • Lesson 3 • Understanding Capture Filters

    Explains BPF syntax used to limit traffic collected at capture time. Reduces noise before data is stored, improving performance on busy networks.

  • Lesson 4 • Filter Troubleshooting and Optimization

    Addresses common filter errors and performance pitfalls. Students learn to validate filter syntax and choose between capture vs. display filters strategically.

Chapter 3See details

Protocol Analysis: TCP/IP Suite

  • Lesson 1 • Ethernet and ARP Analysis

    Examines Layer 2 frames, MAC addressing, and ARP request/reply cycles. Provides the link-layer context required for higher-layer protocol interpretation.

  • Lesson 2 • UDP and ICMP Behavior

    Analyzes connectionless UDP datagrams and ICMP control messages. Connects these protocols to DNS, DHCP, and network diagnostic workflows.

  • Lesson 3 • IP Header Deep Dive

    Dissects IPv4 and IPv6 header fields including TTL, flags, and fragmentation. Students correlate header values with routing behavior and packet loss indicators.

  • Lesson 4 • TCP Flow Control and Windowing

    Explains receive window scaling, zero-window conditions, and congestion signals. Students recognize throughput bottlenecks directly from TCP header values.

  • Lesson 5 • TCP Three-Way Handshake and Teardown

    Traces SYN, SYN-ACK, ACK, FIN, and RST sequences in captures. Students identify connection establishment, graceful teardown, and abrupt resets.

Chapter 4See details

Application Layer Protocol Analysis

  • Lesson 1 • FTP and SMTP Protocol Inspection

    Analyzes plaintext FTP commands and SMTP message exchanges. Highlights credential exposure risks in unencrypted application protocols.

  • Lesson 2 • HTTP and HTTPS Traffic Analysis

    Decodes HTTP request and response headers, methods, and status codes. Introduces TLS handshake visibility and limitations when analyzing encrypted traffic.

  • Lesson 3 • DHCP Lease Process Analysis

    Traces the DORA sequence and DHCP option fields in captures. Students verify correct IP assignment and diagnose lease failures from packet data.

  • Lesson 4 • DNS Query and Response Analysis

    Examines DNS query types, response records, and resolution timing. Students identify misconfigured resolvers, slow lookups, and suspicious domain patterns.

Chapter 5See details

Wireshark Statistics and IO Graphs

  • Lesson 1 • IO Graphs for Traffic Visualization

    Builds time-series graphs of packet rates, byte rates, and filtered streams. Students correlate traffic spikes with specific events in the capture timeline.

  • Lesson 2 • Capture File Summary Statistics

    Explores the Summary, Protocol Hierarchy, and Conversations dialogs. Provides a rapid overview of capture composition before deep-dive analysis begins.

  • Lesson 3 • TCP Stream Graphs and Analysis

    Uses Stevens, throughput, RTT, and window-scaling graphs for TCP sessions. Students diagnose retransmission storms and window stalls from visual patterns.

  • Lesson 4 • Expert Information and Event Alerts

    Leverages Wireshark's Expert Information system to surface protocol anomalies. Students triage color-coded alerts to prioritize investigation targets.

Chapter 6See details

Network Performance Troubleshooting

  • Lesson 1 • Measuring Latency with Wireshark

    Calculates round-trip time and server response time from TCP timestamps. Students distinguish network latency from application processing delays.

  • Lesson 2 • Bandwidth and Throughput Analysis

    Measures actual throughput against theoretical capacity using IO graphs and TCP graphs. Students identify bottlenecks caused by window size, MTU, or congestion.

  • Lesson 3 • Wireless Network Troubleshooting

    Captures 802.11 frames in monitor mode and interprets signal and retry fields. Students diagnose wireless-specific issues invisible in wired captures.

  • Lesson 4 • Diagnosing Slow Application Performance

    Isolates application-layer delays from network-layer delays using time columns. Students build a structured methodology for slow-application investigations.

  • Lesson 5 • Identifying Packet Loss and Retransmissions

    Detects retransmissions, out-of-order packets, and duplicate ACKs in captures. Students quantify loss rates and trace loss to specific network segments.

Chapter 7See details

Security Analysis and Threat Detection

  • Lesson 1 • Credential and Data Exfiltration Detection

    Extracts credentials from plaintext protocols and detects large outbound transfers. Students apply filters to surface data theft indicators in captures.

  • Lesson 2 • Malware and C2 Traffic Patterns

    Analyzes beaconing intervals, DNS tunneling, and unusual protocol usage. Students recognize command-and-control communication patterns in captured traffic.

  • Lesson 3 • Detecting Network Reconnaissance

    Identifies port scans, ping sweeps, and OS fingerprinting attempts in captures. Students distinguish scan types by their TCP flag and timing signatures.

  • Lesson 4 • Intrusion Evidence Documentation

    Structures packet-level evidence into a defensible incident report. Students export marked packets, annotate findings, and preserve capture integrity.

  • Lesson 5 • ARP Poisoning and Spoofing Detection

    Detects gratuitous ARP and conflicting MAC-to-IP mappings in captures. Students trace man-in-the-middle positioning attempts at Layer 2.

Chapter 8See details

Advanced Wireshark Techniques and Automation

  • Lesson 1 • Automating Analysis with Python and PyShark

    Uses PyShark to parse PCAP files programmatically and extract metrics. Students build scripts that automate repetitive filtering and reporting tasks.

  • Lesson 2 • TShark Command-Line Analysis

    Uses TShark to capture, filter, and export data without the GUI. Enables scripted, automated analysis of large capture files in server environments.

  • Lesson 3 • Decrypting TLS Traffic

    Configures Wireshark to decrypt TLS sessions using pre-master secret logs. Students analyze HTTPS, encrypted DNS, and other TLS-wrapped protocols.

  • Lesson 4 • Lua Scripting for Custom Dissectors

    Introduces Lua scripting to parse proprietary or undocumented protocols. Students write a basic dissector that registers fields in the Wireshark protocol tree.

  • Lesson 5 • Managing Large Capture Files

    Applies ring-buffer capture, file splitting, and mergecap to handle high-volume traffic. Students maintain analysis performance on multi-gigabyte capture datasets.

Certification

Your valid completion certificate

This course is for you:

  • Network engineer: needs packet-level proof to resolve recurring connectivity complaints.

  • SOC analyst: wants to move beyond alert dashboards into raw traffic investigation.

  • IT support technician: ready to graduate from ping tests to real capture analysis.

  • Cybersecurity student: building hands-on skills to stand out in a competitive job market.

  • DevOps engineer: troubleshoots microservice communication issues in containerized environments.

  • Career changer: transitioning into networking or security from a non-technical background.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the presentation style and video transcription, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in United States?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course