Network Forensics and Investigation II Training
Learn how to use advanced features, apply threat intelligence, and identify and investigate more complex or hard-to-detect intrusions. There are a tremendous number of network-based attacks occurring every day, and that number is increasing rapidly. To defend against these attacks, they must be understood at the packet level. This course teaches you how to analyze, detect, and understand the network-based attacks that have become pervasive on today’s Internet.
Network Forensics and Investigation II
Course Overview
- Identify and analyze events at all stages of the attack lifecycle
- Apply threat intelligence feeds to focus monitoring, investigation, and hunt activities
Detect and investigate tunneling, botnet command and control traffic, and other forms of covert communications being employed in a network
Use fingerprinting techniques to detect the use of encrypted traffic flows by malware or an active intruder
Accurately correlate and reconstruct multiple stages of malicious activity in order to build a complete picture of the scope and impact of complex network intrusions
Course Outline
- OVERVIEW AND LIFECYCLE
- Trends in Malicious Traffic
- Network Attack Lifecycle
- Targeted vs. Large-Scale Attack
- Network Intrusion Analysis Process
- Analytic Tools of the Trade
- Wireshark Exercises 1 and 2
- Analyze a Packet Capture Lab
- ANALYZING RECONNAISSANCE
- Beginning Phase of Attacks – Recon
- Host Discovery
- Port Scans
- OS & Service Discovery
- Vulnerability Discovery
- HairSalon.com Lab
- BlendTec 1 Lab
- BlendTec 2 Lab
- Big Bad Recon Scan Lab
- Global Consulting - 1 Lab
- Transport Layer Attacks Demo
- Global Consulting 2 Lab
- Input Validation Attacks Demo
- Holophone 1 Lab
- Holophone 2 Lab
- Blendtec 3 Lab
- HoloPhone 3 Lab
- Analyzing XSS Javascript
- HoloPhone 4 Lab
- ATTACKER METHODOLOGY
- Social Engineering-Enabled Exploitation
- Physical Layer Attacks
- Data-Link Layer Attacks
- Network Layer Attacks
- Transport Layer Attacks
- Session Layer Attacks
- Presentation Layer Attacks
- Application Layer Attacks
- Global Consulting 1 Lab
- Global Consulting 2 Lab
- HoloPhone 1 Lab
- HoloPhone 2 Lab
- BlendTec 3 Lab
- HoloPhone 3 Lab
- HoloPhone 4 Lab
- BOTNETS
- Analysis Techniques
- History and Evolution
- Architecture and Design
- Malicious Uses
- Communications
- Examples
- Botnet Lab
- Global Consulting 3 Lab
- Data Mining Lab
- ADVANCED COMMUNICATIONS
- Transport Layer Security (TLS)
- Advanced Communication Methods
- Network Layer Tunneling
- Transport Layer Tunneling
- Application Layer Tunneling
- Traffic Cloaking
- Transport Layer Security Lab
- Johnson Trucking Lab
- STUDENT PRACTICAL DEMONSTRATION
- Using the tools, skills, and methodologies taught in Days 1 through 4 of the class students will uncover a
- multi-part network intrusion. In the intrusion capture files there will be multiple application-layer attacks,
- multiple advanced communications methods, and a hacker toolkit to discover. Students will have to prepare
- a report detailing the attack from start to finish as well as document what things the hacker did as well as what
- information was leaked if any.
Intended Audience
- Threat operation analysts seeking a better understanding of network-based malware and attacks
- Incident responders who need to quickly address a system security breach
- Forensic investigators who need to identify malicious network attacks
- Individuals who want to learn what malicious network activity looks like and how to identify it
Prerequisites
- Successful completion of the Network Forensics and Investigation I course is highly recommended
- Thorough knowledge of TCP/IP networking is required
- Skills and experience with Wireshark display filtering is required
- CompTIA’s Network+ and Security+ certifications would be beneficial, but are not required
Follow-On Courses
Related training topics
Justify your training
Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.
Sample training request letter
Subject: Request for Digital Forensics & Reverse Engineering training from Applied Technology Academy
[Decision Maker Name],
I'm writing to request time and budget approval to complete Applied Technology Academy's course, Network Forensics and Investigation II Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.
Course Description
Learn how to use advanced features, apply threat intelligence, and identify and investigate more complex or hard-to-detect intrusions. There are a tremendous number of network-based attacks occurring every day, and that number is increasing rapidly. To defend against these attacks, they must be understood at the packet level. This course teaches you how to analyze, detect, and understand the network-based attacks that have become pervasive on today’s Internet. Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2008) whose instructors are active practitioners; the course is hands-on with virtual labs and a learn-by-doing methodology.
Course Objectives
Once I've completed the course, I'll have hands-on, job-ready skills in digital forensics & reverse engineering that I can apply immediately to our work.
Expected Organizational Benefits
After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.
Expected Cost & Funding
Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.
Conclusion
This training provides practical, hands-on experience I can apply immediately to strengthen our work in digital forensics & reverse engineering. Additional course information is available at https://appliedtechnologyacademy.com/network-forensics-and-investigation-ii/.
Thank you for your consideration,
[Your Name]
Related Digital Forensics & Reverse Engineering courses
Design training around your team, not the other way around.
Talk to a training advisor about private cohorts, funding paths and program management.