Network Forensics Training
Mục Lục
REGISTRATION
To register for a Live Online Training, please send an email to [email protected] with:
- Training Dates
- Name of Student(s)
- Company Name
- Invoice Address
We will then send out a payment link.
Your registration is complete after your payment has been received.

Instructor: Erik Hjelmvik
Erik is the creator of NetworkMiner and an experienced incident handler who has specialized in the field of network forensics.
A hands-on network forensics course that allows you to deep dive into analyzing captured full content network traffic in PCAP files. The training data is a unique data set captured during 30 days on an Internet connected network with multiple clients, an AD server, a web server, an android tablet and some embedded devices.
We will analyze traffic from multiple intrusions by various attackers, including APT style attackers and botnet operators. The initial attack vectors are using techniques like exploitation of web vulnerabilities, spear phishing, a supply chain attack and a man-on-the-side attack!
Each attendee will be provided with a free single user license of NetworkMiner Professional and CapLoader. These licenses will be valid for six months from the first training day.
Network Forensics for Incident Response
Part 1 (4 hours)
- Investigating spear phishing email with malware attachment
- Reassembling exfiltrated data
- Identifying C2 traffic in decrypted HTTPS traffic
- Analyzing decrypted HTTPS traffic from a transparent TLS inspection proxy
- Tracking lateral movement with stolen Windows credentials
- Searching application layer data with Wireshark, tshark, tcpflow and ngrep
Part 2 (4 hours)
- Threat Hunting with Security Onion
- Leveraging passive DNS to track C2 domains
- Decoding proprietary C2 traffic from a RAT
- Extracting files from PCAP with NetworkMiner
- Sandbox execution of malware and behavioral analysis
- Supply chain attacks
- Extracting files from SMB and SMB2 traffic
- Analyzing exfiltration by an APT style attacker
- Investigating a spear phishing attack with credential theft
Part 3 (4 hours)
- Theory: HTTP Cookies
- Analyzing Cobalt Strike beacons
- Investigation of botnet infection (TrickBot)
- Tracking botnet C2 traffic using JA3
- Extracting and verifying X.509 certificates from network traffic
Part 4 (4 hours)
- Learning about Man-on-the-Side (MOTS) attacks, such as NSA’s QUANTUMINSERT and HackingTeam’s “Network Injection”
- Investigating a brute force attack on a web CMS
- Analyzing exploitation of a web server
- Tracking commands sent to web shells
- Tracking lateral movement via Linux servers
- Using JA3 to track TLS encrypted malware traffic
Upcoming Training Events
March 20-23, 2023. Live Online Network Forensics Training “PCAP in the Morning US”
Duration: Four half-days
Times: 9:30 AM to 1:30 PM EDT (US Eastern Daylight Time / UTC-4)
Price: $1,000 USD per student
Course outline: Network Forensics for Incident Response, parts 1, 2, 3 and 4, as detailed above
- Monday, March 20, 9:30 AM to 1:30 PM (EDT) : Network Forensics for IR, Part 1
- Tuesday, March 21, 9:30 AM to 1:30 PM (EDT) : Network Forensics for IR, Part 2
- Wednesday, March 22, 9:30 AM to 1:30 PM (EDT) : Network Forensics for IR, Part 3
- Thursday, March 23, 9:30 AM to 1:30 PM (EDT) : Network Forensics for IR, Part 4
April 17-20, 2023. Live Online Network Forensics Training “PCAP in the Morning Europe”
Duration: Four half-days
Times: 8:30 AM to 12:30 PM CEST (Central European Summer Time / UTC+2)
Price: € 950 EUR per student (€ 855 EUR if registering before March 17)
Course outline: Network Forensics for Incident Response, parts 1, 2, 3 and 4, as detailed above
- Monday, April 17, 8:30 AM to 12:30 PM (CEST) : Network Forensics for IR, Part 1
- Tuesday, April 18, 8:30 AM to 12:30 PM (CEST) : Network Forensics for IR, Part 2
- Wednesday, April 19, 8:30 AM to 12:30 PM (CEST) : Network Forensics for IR, Part 3
- Thursday, April 20, 8:30 AM to 12:30 PM (CEST) : Network Forensics for IR, Part 4
To register for a Live Online Training, please send an email to [email protected] with the training dates, your name and invoice address.
We will then send out a payment link. Your registration is complete after your payment has been received.
Training Notification
Would you like to get notified about future training events?
Simply send an email to [email protected] letting us know that you would to receive an email when we have scheduled a new training event.
On Site Training (EU only)
Would you like us to visit your facility to do on-site training?
If you’re in the European Union, then that can be arranged.
Please contact us for further details.
Live Online Training (worldwide)
Would you like us to teach our network forensics class as a private live online training exclusively to your team?
Please contact us for further details.
The live online training is also available as part of our Network Forensics Bundle.
Frequently Asked Questions (FAQ)
Q: Who is the training designed for?
A: The network forensics course is built for blue teams, incident responders and SOC analysts, but can also be relevant for law enforcement investigators.
Q: What prerequisites or skills are required to take the class?
A: Students should be familiar with Linux command line tools and have basic TCP/IP knowledge.
Q: Will there be a test?
A: No.
Q: Will I receive a certificate after the training?
A: Yes, active students receive a Certificate of Completion after having completed the training.
Read what others are saying about this class
- “Took this training in May, highly recommend it! Fair warning though, any work you do after this without PCAPs will feel empty 😂”
Tweet by Greg Lesnewich (2021) - “I was fortunate to take this training at last years CS3STHLM SCADA Security Conference. @netresec Erik is a great instructor, the course materials and his tools are excellent. Highly recommended!”
Tweet by Mitch Impey (2019) - “Great class! I took it in 2017. More than recommended!”
Tweet by @warmstart_eu (2018) - “I had the chance to follow a 2-day training in Network Forensics by Erik Hjelmvik. I’m glad I did! […] When I returned home after the training, I tried out this technique on my own web server. I definitely found some interesting stuff: stuff that I wouldn’t have found going through my log files by hand.”
Judith van Stegeren in Rinse and Repeat: threat hunting with CapLoader and Wireshark (2017).
Training Preparations
Attendees will need to bring a computer that fits the following specs:
- A PC running any 64 bit Windows OS (can be a Virtual Machine)
- At least 16GB RAM
- At least 100 GB free disk space
- VirtualBox (64 bit) installed
(VMWare will not be supported in the training)
A VirtualBox VM will be provided on USB flash drives at the beginning of On-Site trainings.
In Live Virtual Trainings, however, we deliver the training VM as a download one week ahead of the training.
A VirtualBox VM will be provided on USB flash drives at the beginning of On-Site trainings. In Live Virtual Trainings, however, we deliver the training VM as a download one week ahead of the training.
Please note that having a 64-bit CPU and a 64-bit OS is not always enough to support 64-bit virtualization.
You might need to enable features such as ”AMD-V”, ”VT-x” or ”Hyper-V” in BIOS in order to run virtual machines in 64-bit mode.
You might also need to turn off “Intel Trusted Execution” in BIOS.
One way to verify that your laptop supports 64-bit virtualization is to download the
SecurityOnion ISO and see if it boots up in VirtualBox.
Cancellation Policy
Please read our Terms and Conditions,
which also include details regarding our training cancellation policy.



















![Toni Kroos là ai? [ sự thật về tiểu sử đầy đủ Toni Kroos ]](https://evbn.org/wp-content/uploads/New-Project-6635-1671934592.jpg)


