Advanced Network Forensics and Threat Hunting
Network forensics matters most when the endpoint evidence is gone. Wiped disks, reimaged laptops and destroyed logs still leave a record on the wire, and this course teaches you to read it.
Across ten weeks you work with full packet capture, flow and metadata, DNS and infrastructure pivoting, and encrypted traffic, finishing with an intrusion you reconstruct from network evidence alone.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Advanced Incident Response and Threat Hunting
- Class size
- Capped at 12 learners

What you will be able to do
- Choose sensor placement and explain what each position cannot see
- Reassemble sessions and extract transferred files from packet data
- Detect beaconing and covert channels in flow and metadata
- Use DNS evidence and passive data to pivot across adversary infrastructure
- Assess encrypted sessions using handshake and behavioural evidence
- Estimate data volumes exfiltrated when payloads are unavailable
- Correlate network findings with endpoint evidence to raise confidence
- Present packet level evidence clearly to non-specialist audiences
Course outline
6 modules
- Where to tap and what each placement misses
- Full packet capture versus flow and metadata
- Retention, storage and sampling trade-offs
- Time synchronisation across sensors
- Preserving network evidence defensibly
What you need before you start
- Solid TCP/IP knowledge and comfort reading protocol headers
- Incident response experience, ideally the advanced hunting course
- A machine with 16 GB of RAM and 150 GB free for capture sets
- Basic command line skills on Linux
Who this course is for
- Incident responders working cases with limited endpoint evidence
- Network security monitoring and detection engineering staff
- SOC analysts moving into deeper traffic analysis
- Threat hunters who want a second evidence source
- Consultants investigating intrusions in environments without EDR
Where this leads
Prepares you for
CySA+
Awarded by CompTIA
Traffic analysis, detection and response content here overlaps the CySA+ objectives. CompTIA writes that exam and awards the certification directly to candidates who pass it. What you receive from us is the instruction and the lab time behind it.
Questions about this course
More in digital forensics and incident response
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



