Catalogue · MOD-DEF-06

Network Forensics

Network traffic keeps the memory of an intrusion. This module teaches you to investigate from packets: session reconstruction, detection without decryption, and reporting.

Defence (Blue) Praticien 5 bricks 9 labs 17.2 h 5 real cases

Objectives

• Reconstruct sessions from a capture • Detect without decrypting (JA3, DNS) • Write network detections (Zeek/Snort) • Correlate and report an investigation

Module bricks