Network Detection and Forensics

Master Network Detection and Forensics

See what others miss. Master network investigation methodology to detect, analyze, and reconstruct attacks using PCAPs, Zeek, Suricata, and network telemetry; turning raw network traffic into clear evidence and high-fidelity detections.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Practice included: scored investigation scenarios, plus the Practice Hub.
View Pricing Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Apply a structured network investigation methodology to rapidly analyze suspicious network activity
✓Capture, dissect, and forensically examine PCAP files to reconstruct attacker sessions and actions
✓Deploy, configure, and tune Zeek and Suricata to generate high-value network logs and detections
✓Identify stealthy network-based threats including C2 communications, lateral movement, and data exfiltration
✓Correlate network artifacts with endpoint and cloud data to build complete attack timelines
✓Build and implement high-fidelity network detections and hunting queries for your SOC
FOR403 | Premium tier | 13 modules across 4 phases | 36–40 hours at your own pace | 40 CPE credits | 2 free preview - no account needed

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Free Phase 1: Foundations

Phase 2: Protocol Analysis

Phase 3: Detection & Hunting

Module 7Email Protocols and Phishing Investigation

Investigate phishing campaigns through email-layer network evidence. SMTP traffic analysis with Zeek smtp.log, header extraction from captures, attachment detection, SPF/DKIM/DMARC validation, IMAP-based exfiltration patterns, the M365 visibility gap, and the INC-NE-2026-0227 email delivery reconstruction, the phishing emails that preceded the DNS queries NF3 traced and the HTTP redirects NF4 investigated.

Show 13 lessonsHide lessons
  1. 7.1NF7.1 Email Protocol Fundamentals for Investigators
  2. 7.2NF7.2 Zeek smtp.log Deep Dive
  3. 7.3NF7.3 Email Headers From Network Evidence
  4. 7.4NF7.4 Phishing Email Indicators in Network Data
  5. 7.5NF7.5 Attachment Analysis From Network Captures
  6. 7.6NF7.6 SPF, DKIM, DMARC. Validation From DNS
  7. 7.7NF7.7 Mail Exfiltration Detection
  8. 7.8NF7.8 The M365 Mail Evidence Gap and How to Close It
  9. 7.9NF7.9 The INC-NE-2026-0227 Email Delivery Reconstruction
  10. 7.10NF7.10 Modern Phishing Variants. BEC, Thread Hijacking, Quishing, and VEC
  11. 7.11NF7.11 Interactive Lab. Phishing Investigation Workflow
  12. 7.12Module Summary
  13. 7.13Check My Knowledge
Module 10NetFlow, IPFIX, and Traffic Analytics

Detect beaconing, exfiltration, and policy violations when full packet capture isn't available. NetFlow and IPFIX fundamentals, traffic baselines, top-talker analysis, flow-only beacon detection, exfiltration indicators, long-lived connections, egress policy validation, cloud VPC flow logs, and the INC-NE-2026-0418 capstone catching rclone exfil from flow data alone.

Show 13 lessonsHide lessons
  1. 10.1NF10.1 NetFlow and IPFIX Fundamentals
  2. 10.2NF10.2 What You Lose (and Keep) Without Full PCAP
  3. 10.3NF10.3 Building Traffic Baselines
  4. 10.4NF10.4 Top-Talker Analysis and Volume Anomalies
  5. 10.5NF10.5 Beacon Detection from Flow Data
  6. 10.6NF10.6 Data Exfiltration Indicators
  7. 10.7NF10.7 Long-Lived Connections from Flow Data
  8. 10.8NF10.8 Egress Policy Validation
  9. 10.9NF10.9 Cloud VPC Flow Logs (AWS, Azure, GCP)
  10. 10.10NF10.10 Capstone. Catching the rclone Exfil from Flow Data
  11. 10.11NF10.11 Interactive Lab. Flow-Only Triage
  12. 10.12Module Summary
  13. 10.13Check My Knowledge

Phase 4: Investigation & Capstone

Module 12Network Evidence in Incident Response

Integrate network evidence into the incident response workflow. When to pull full PCAP versus when Zeek metadata suffices, correlating Zeek conn.log to Defender XDR DeviceNetworkEvents, network-to-identity correlation against Entra sign-in logs, building the DNS-to-connection-to-transfer investigation timeline, cloud network evidence from VPC flow logs and CDN logs, evidence preservation and chain-of-custody for network artifacts, legal and regulatory posture for network monitoring, and writing the network section of the IR report. Capstone: re-investigating INC-NE-2026-0418 through the IR lens, same ransomware attack, network-evidence-led investigation, deliverable is the IR report section.

Show 13 lessonsHide lessons
  1. 12.1NF12.1 From Hunt to Incident. The Posture Shift
  2. 12.2NF12.2 PCAP vs Metadata. When to Pull Full Packet Capture
  3. 12.3NF12.3 Correlating Zeek to Defender XDR
  4. 12.4NF12.4 Correlating Zeek to Identity Evidence
  5. 12.5NF12.5 Building the Investigation Timeline
  6. 12.6NF12.6 Cloud Network Evidence
  7. 12.7NF12.7 Evidence Preservation and Chain of Custody
  8. 12.8NF12.8 Legal and Regulatory Posture
  9. 12.9NF12.9 Writing the IR Report. Network Section
  10. 12.10NF12.10 Capstone Walkthrough. INC-NE-2026-0418 Through the IR Lens
  11. 12.11NF12.11 Interactive Lab. Running an IR Engagement Against Fresh Network Evidence
  12. 12.12Module Summary
  13. 12.13Check My Knowledge

Course overview

The Network Detection and Forensics course teaches practical Network Investigation Methodology specifically for SOC Analysts, Incident Response Cybersecurity professionals, and Detection Engineers working with PCAP, Zeek, and Suricata. You'll gain hands-on expertise to:

✓ Capture, analyze, and interpret network traffic for threat detection and investigation
✓ Use Zeek and Suricata to generate powerful network logs and detections
✓ Perform deep forensic analysis on PCAP files to reconstruct attacker activity
✓ Build network-based detections and hunting queries that identify stealthy threats

By the end, you'll have the skills and methodology to confidently investigate network activity, uncover hidden attacker behavior, and strengthen your organization's network detection and response capabilities.

Who this course is for

You're a SOC Analyst, Incident Response Cybersecurity professional, or Detection Engineer who works with network traffic and wants to master network-level investigation and detection. This course is built for you if you want to:

✓ Move beyond basic log review to professional-grade network forensics and detection
✓ Gain deep expertise working with PCAP, Zeek, and Suricata
✓ Learn a repeatable network investigation methodology you can use under pressure
✓ Uncover attacker activity that endpoint tools alone cannot see

In short: if you're ready to become highly effective at network detection and forensics, this course is for you.

What you'll learn

By the end of this Network Detection and Forensics course you will be able to:

✓ Execute a proven network investigation methodology for efficient and thorough analysis
✓ Capture and analyze PCAP files to extract artifacts, sessions, and attacker behavior
✓ Deploy and optimize Zeek for rich network logging and intelligence
✓ Configure and tune Suricata for high-performance network intrusion detection
✓ Identify common and advanced attacker techniques in network traffic (C2, tunnelling, exfiltration, etc.)
✓ Build network-based detections, hunting queries, and correlation rules for Microsoft Sentinel and other SIEMs

Key course takeaways

✓ Master a repeatable, professional network investigation methodology you can apply immediately
✓ Confidently analyze PCAPs, Zeek logs, and Suricata alerts to uncover hidden threats
✓ Build and tune high-value network detections that improve your overall detection posture
✓ Significantly enhance your ability to reconstruct attacks and reduce dwell time
✓ Bridge the gap between network telemetry and endpoint/cloud data for complete visibility
✓ Become the go-to network detection and forensics expert on your team

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course teaches network investigation from first principles. Familiarity with TCP/IP fundamentals and basic command-line usage will help you move faster, but neither is required. Every protocol, tool, and technique is explained at first use.

What are the device requirements?

A device with a modern browser. For hands-on practice, a Linux VM (or WSL) with Zeek, Suricata, and Wireshark installed. The course walks you through setup and provides PCAP datasets for all exercises.

How will the course benefit your career?

Network forensics is one of the most in-demand and least common skills in security operations. Most analysts investigate from endpoint and identity logs. This course gives you the network perspective that completes the picture, the ability to detect C2, prove exfiltration, and reconstruct attacks from network evidence when endpoint data is unavailable or compromised.

Network investigation capability is a differentiator for senior IR, detection engineering, and SOC roles.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy detection rules, Suricata signatures, and analysis workflows in your production environment. You may not redistribute course content or share account credentials.

PCAP files: All packet captures contain fictional data from the Northgate Engineering environment. No real network traffic. All IP addresses use RFC 5737 documentation ranges.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.