
Wireshark Training
Master Wireshark from installation to advanced threat detection with hands-on packet analysis training. Learn to capture, filter, and decode real network traffic across every major protocol. Whether you're troubleshooting slow applications or hunting security incidents, this course gives you the skills to find answers at the packet level.
What you will learn:
This course covers every stage of network packet analysis using Wireshark, from initial setup and interface navigation to advanced automation with TShark and Python. You will learn to write capture and display filters, decode TCP/IP and application-layer protocols, and use Wireshark's built-in statistics tools to visualize traffic patterns. The course includes dedicated modules on performance troubleshooting, security threat detection, and evidence documentation. You will also explore TLS decryption, Lua scripting for custom dissectors, and packet capture in cloud and virtual environments. By the end, you will be able to conduct end-to-end network investigations and produce clear, evidence-backed analysis reports.
How you study in practice Wireshark Training
How you practice Wireshark Training
For companies looking to train their teams
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.
Course Content
8 Chapters • 36 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsIntroduction to Wireshark and Packet Analysis
Introduction to Wireshark and Packet Analysis
Lesson 1 • Starting and Stopping Captures
Teaches how to select interfaces and control capture sessions. Connects interface selection to the types of traffic visible in each capture.
Lesson 2 • Navigating the Wireshark Interface
Introduces all major UI panels and toolbar controls. Students gain confidence moving through the interface before capturing live traffic.
Lesson 3 • Wireshark Installation and Setup
Guides installation on Windows, macOS, and Linux with required dependencies. Ensures every student has a functional, correctly configured Wireshark environment.
Lesson 4 • Network Traffic Fundamentals
Covers packets, frames, and data flow across network layers. Establishes the conceptual baseline needed to interpret Wireshark captures meaningfully.
Chapter 2HideHide detailsSee detailsCapture Filters and Display Filters
Capture Filters and Display Filters
Lesson 1 • Understanding Display Filters
Covers Wireshark's display filter language for post-capture analysis. Students apply filters to large captures without discarding any packets.
Lesson 2 • Advanced Display Filter Techniques
Introduces complex expressions, slicing, and regex matching in display filters. Enables precise isolation of anomalous or protocol-specific traffic patterns.
Lesson 3 • Understanding Capture Filters
Explains BPF syntax used to limit traffic collected at capture time. Reduces noise before data is stored, improving performance on busy networks.
Lesson 4 • Filter Troubleshooting and Optimization
Addresses common filter errors and performance pitfalls. Students learn to validate filter syntax and choose between capture vs. display filters strategically.
Chapter 3HideHide detailsSee detailsProtocol Analysis: TCP/IP Suite
Protocol Analysis: TCP/IP Suite
Lesson 1 • Ethernet and ARP Analysis
Examines Layer 2 frames, MAC addressing, and ARP request/reply cycles. Provides the link-layer context required for higher-layer protocol interpretation.
Lesson 2 • UDP and ICMP Behavior
Analyzes connectionless UDP datagrams and ICMP control messages. Connects these protocols to DNS, DHCP, and network diagnostic workflows.
Lesson 3 • IP Header Deep Dive
Dissects IPv4 and IPv6 header fields including TTL, flags, and fragmentation. Students correlate header values with routing behavior and packet loss indicators.
Lesson 4 • TCP Flow Control and Windowing
Explains receive window scaling, zero-window conditions, and congestion signals. Students recognize throughput bottlenecks directly from TCP header values.
Lesson 5 • TCP Three-Way Handshake and Teardown
Traces SYN, SYN-ACK, ACK, FIN, and RST sequences in captures. Students identify connection establishment, graceful teardown, and abrupt resets.
Chapter 4HideHide detailsSee detailsApplication Layer Protocol Analysis
Application Layer Protocol Analysis
Lesson 1 • FTP and SMTP Protocol Inspection
Analyzes plaintext FTP commands and SMTP message exchanges. Highlights credential exposure risks in unencrypted application protocols.
Lesson 2 • HTTP and HTTPS Traffic Analysis
Decodes HTTP request and response headers, methods, and status codes. Introduces TLS handshake visibility and limitations when analyzing encrypted traffic.
Lesson 3 • DHCP Lease Process Analysis
Traces the DORA sequence and DHCP option fields in captures. Students verify correct IP assignment and diagnose lease failures from packet data.
Lesson 4 • DNS Query and Response Analysis
Examines DNS query types, response records, and resolution timing. Students identify misconfigured resolvers, slow lookups, and suspicious domain patterns.
Chapter 5HideHide detailsSee detailsWireshark Statistics and IO Graphs
Wireshark Statistics and IO Graphs
Lesson 1 • IO Graphs for Traffic Visualization
Builds time-series graphs of packet rates, byte rates, and filtered streams. Students correlate traffic spikes with specific events in the capture timeline.
Lesson 2 • Capture File Summary Statistics
Explores the Summary, Protocol Hierarchy, and Conversations dialogs. Provides a rapid overview of capture composition before deep-dive analysis begins.
Lesson 3 • TCP Stream Graphs and Analysis
Uses Stevens, throughput, RTT, and window-scaling graphs for TCP sessions. Students diagnose retransmission storms and window stalls from visual patterns.
Lesson 4 • Expert Information and Event Alerts
Leverages Wireshark's Expert Information system to surface protocol anomalies. Students triage color-coded alerts to prioritize investigation targets.
Chapter 6HideHide detailsSee detailsNetwork Performance Troubleshooting
Network Performance Troubleshooting
Lesson 1 • Measuring Latency with Wireshark
Calculates round-trip time and server response time from TCP timestamps. Students distinguish network latency from application processing delays.
Lesson 2 • Bandwidth and Throughput Analysis
Measures actual throughput against theoretical capacity using IO graphs and TCP graphs. Students identify bottlenecks caused by window size, MTU, or congestion.
Lesson 3 • Wireless Network Troubleshooting
Captures 802.11 frames in monitor mode and interprets signal and retry fields. Students diagnose wireless-specific issues invisible in wired captures.
Lesson 4 • Diagnosing Slow Application Performance
Isolates application-layer delays from network-layer delays using time columns. Students build a structured methodology for slow-application investigations.
Lesson 5 • Identifying Packet Loss and Retransmissions
Detects retransmissions, out-of-order packets, and duplicate ACKs in captures. Students quantify loss rates and trace loss to specific network segments.
Chapter 7HideHide detailsSee detailsSecurity Analysis and Threat Detection
Security Analysis and Threat Detection
Lesson 1 • Credential and Data Exfiltration Detection
Extracts credentials from plaintext protocols and detects large outbound transfers. Students apply filters to surface data theft indicators in captures.
Lesson 2 • Malware and C2 Traffic Patterns
Analyzes beaconing intervals, DNS tunneling, and unusual protocol usage. Students recognize command-and-control communication patterns in captured traffic.
Lesson 3 • Detecting Network Reconnaissance
Identifies port scans, ping sweeps, and OS fingerprinting attempts in captures. Students distinguish scan types by their TCP flag and timing signatures.
Lesson 4 • Intrusion Evidence Documentation
Structures packet-level evidence into a defensible incident report. Students export marked packets, annotate findings, and preserve capture integrity.
Lesson 5 • ARP Poisoning and Spoofing Detection
Detects gratuitous ARP and conflicting MAC-to-IP mappings in captures. Students trace man-in-the-middle positioning attempts at Layer 2.
Chapter 8HideHide detailsSee detailsAdvanced Wireshark Techniques and Automation
Advanced Wireshark Techniques and Automation
Lesson 1 • Automating Analysis with Python and PyShark
Uses PyShark to parse PCAP files programmatically and extract metrics. Students build scripts that automate repetitive filtering and reporting tasks.
Lesson 2 • TShark Command-Line Analysis
Uses TShark to capture, filter, and export data without the GUI. Enables scripted, automated analysis of large capture files in server environments.
Lesson 3 • Decrypting TLS Traffic
Configures Wireshark to decrypt TLS sessions using pre-master secret logs. Students analyze HTTPS, encrypted DNS, and other TLS-wrapped protocols.
Lesson 4 • Lua Scripting for Custom Dissectors
Introduces Lua scripting to parse proprietary or undocumented protocols. Students write a basic dissector that registers fields in the Wireshark protocol tree.
Lesson 5 • Managing Large Capture Files
Applies ring-buffer capture, file splitting, and mergecap to handle high-volume traffic. Students maintain analysis performance on multi-gigabyte capture datasets.
Your valid completion certificate
This course is for you:
Network engineer: needs packet-level proof to resolve recurring connectivity complaints.
SOC analyst: wants to move beyond alert dashboards into raw traffic investigation.
IT support technician: ready to graduate from ping tests to real capture analysis.
Cybersecurity student: building hands-on skills to stand out in a competitive job market.
DevOps engineer: troubleshoots microservice communication issues in containerized environments.
Career changer: transitioning into networking or security from a non-technical background.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.

I like the content and the presentation style and video transcription, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top trainings
FAQ
Who is Dedika?
Is the certificate valid in United States?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















