Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Advanced

Advanced Network Forensics and Threat Hunting

Network forensics matters most when the endpoint evidence is gone. Wiped disks, reimaged laptops and destroyed logs still leave a record on the wire, and this course teaches you to read it.

Across ten weeks you work with full packet capture, flow and metadata, DNS and infrastructure pivoting, and encrypted traffic, finishing with an intrusion you reconstruct from network evidence alone.

Duration
10 weeks
Format
Live online, instructor-led
Prerequisites
Advanced Incident Response and Threat Hunting
Class size
Capped at 12 learners
Advanced Network Forensics and Threat Hunting

What you will be able to do

  • Choose sensor placement and explain what each position cannot see
  • Reassemble sessions and extract transferred files from packet data
  • Detect beaconing and covert channels in flow and metadata
  • Use DNS evidence and passive data to pivot across adversary infrastructure
  • Assess encrypted sessions using handshake and behavioural evidence
  • Estimate data volumes exfiltrated when payloads are unavailable
  • Correlate network findings with endpoint evidence to raise confidence
  • Present packet level evidence clearly to non-specialist audiences

Course outline

6 modules

  • Where to tap and what each placement misses
  • Full packet capture versus flow and metadata
  • Retention, storage and sampling trade-offs
  • Time synchronisation across sensors
  • Preserving network evidence defensibly

What you need before you start

  • Solid TCP/IP knowledge and comfort reading protocol headers
  • Incident response experience, ideally the advanced hunting course
  • A machine with 16 GB of RAM and 150 GB free for capture sets
  • Basic command line skills on Linux

Who this course is for

  • Incident responders working cases with limited endpoint evidence
  • Network security monitoring and detection engineering staff
  • SOC analysts moving into deeper traffic analysis
  • Threat hunters who want a second evidence source
  • Consultants investigating intrusions in environments without EDR

Where this leads

Prepares you for

CySA+

Awarded by CompTIA

Traffic analysis, detection and response content here overlaps the CySA+ objectives. CompTIA writes that exam and awards the certification directly to candidates who pass it. What you receive from us is the instruction and the lab time behind it.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.