Network Detection and Forensics
Master Network Detection and Forensics
See what others miss. Master network investigation methodology to detect, analyze, and reconstruct attacks using PCAPs, Zeek, Suricata, and network telemetry; turning raw network traffic into clear evidence and high-fidelity detections.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Free Phase 1: Foundations
Why network evidence matters when endpoint evidence is gone, encrypted, or lying. The five network evidence types, the NSM philosophy, the investigation methodology, the toolchain, and the Northgate Engineering scenarios that thread through this course.
Show 13 lessonsHide lessons
- 0.1NF0.1 Why Network Evidence Matters
- 0.2NF0.2 The Five Network Evidence Types
- 0.3NF0.3 The NSM Philosophy
- 0.4NF0.4 The Investigation Methodology
- 0.5NF0.5 The Toolchain Overview
- 0.6NF0.6 Normal vs Malicious Traffic
- 0.7NF0.7 Network Architecture for Investigators
- 0.8NF0.8 Northgate Engineering Scenarios
- 0.9NF0.9 Evidence Integrity and Legal Context
- 0.10NF0.10 What Network Forensics Cannot Do. Honest Limits
- 0.11NF0.11 Interactive Lab. Exploring Zeek Logs
- 0.12Module Summary
- 0.13Check My Knowledge
Build the Zeek and Suricata network security monitoring sensor you'll use for the entire course. SPAN port vs TAP deployment, Zeek installation and configuration, Suricata rule management, the Zeek log directory structure, BPF capture filters, sensor validation, and your first investigation queries against live data.
Show 13 lessonsHide lessons
- 1.1NF1.1 Sensor Architecture and Deployment Models
- 1.2NF1.2 VM Setup and Linux Preparation
- 1.3NF1.3 Zeek Installation and Configuration
- 1.4NF1.4 The Zeek Log Directory Structure
- 1.5NF1.5 Suricata Installation and Rule Management
- 1.6NF1.6 Capture Interfaces and BPF Filters
- 1.7NF1.7 Sensor Validation
- 1.8NF1.8 First Investigation Queries
- 1.9NF1.9 Sensor Maintenance and Monitoring
- 1.10NF1.10 Sensor Performance Tuning and Troubleshooting
- 1.11NF1.11 Interactive Lab. Build and Validate Your Sensor
- 1.12Module Summary
- 1.13Check My Knowledge
Phase 2: Protocol Analysis
Full-packet capture with tcpdump and dumpcap: capture strategies, rolling captures with file rotation, BPF filter syntax for targeted investigation, PCAP file management with editcap and mergecap, evidence-grade capture procedures, and forensic acquisition from network devices and cloud environments.
Show 13 lessonsHide lessons
- 2.1NF2.1 tcpdump Fundamentals
- 2.2NF2.2 Capture Strategies
- 2.3NF2.3 BPF Filters for Investigation
- 2.4NF2.4 Rolling Captures and File Rotation
- 2.5NF2.5 dumpcap and Wireshark Capture
- 2.6NF2.6 editcap and mergecap. PCAP File Management
- 2.7NF2.7 Evidence-Grade Capture Procedures
- 2.8NF2.8 Network Evidence from Cloud and Devices
- 2.9NF2.9 The PCAP Analysis Workflow
- 2.10NF2.10 Long-Term PCAP Archive and Search at Scale
- 2.11NF2.11 Interactive Lab. PCAP Capture and Investigation Workflow
- 2.12Module Summary
- 2.13Check My Knowledge
DNS investigation methodology using Zeek dns.log: query pattern analysis, domain reputation, DNS tunnelling detection, passive DNS investigation, DGA detection, DNS-over-HTTPS challenges, and the DNS trail from the INC-NE-2026-0227 AiTM phishing campaign.
Show 13 lessonsHide lessons
- 3.1NF3.1 DNS Investigation Fundamentals
- 3.2NF3.2 Zeek dns.log Deep Dive
- 3.3NF3.3 Normal DNS Patterns
- 3.4NF3.4 Domain Reputation and Intelligence
- 3.5NF3.5 DNS Tunnelling Detection
- 3.6NF3.6 Passive DNS Investigation
- 3.7NF3.7 DGA and Domain Analysis
- 3.8NF3.8 Encrypted DNS. DoH and DoT
- 3.9NF3.9 The INC-NE-2026-0227 DNS Trail
- 3.10NF3.10 DNS Infrastructure Takedown Coordination
- 3.11NF3.11 Interactive Lab. DNS Investigation
- 3.12Module Summary
- 3.13Check My Knowledge
Investigate web-based attacks through Zeek http.log and ssl.log. HTTP request analysis, file extraction from streams, TLS fingerprinting with JA3/JA4+, certificate analysis, TLS inspection architecture, and the HTTP redirect chain from the INC-NE-2026-0227 AiTM proxy attack.
Show 13 lessonsHide lessons
- 4.1NF4.1 HTTP in the Clear. Zeek http.log
- 4.2NF4.2 HTTP Request and Response Analysis
- 4.3NF4.3 File Extraction from Network Streams
- 4.4NF4.4 TLS Fundamentals for Investigators
- 4.5NF4.5 Zeek ssl.log and Certificate Analysis
- 4.6NF4.6 JA3 and JA4+ TLS Fingerprinting
- 4.7NF4.7 TLS Inspection Architecture and Tradeoffs
- 4.8NF4.8 Web Shell and Web Application Attack Traffic
- 4.9NF4.9 The INC-NE-2026-0227 HTTP/HTTPS Trail
- 4.10NF4.10 HTTP/2, HTTP/3, and QUIC Forensics
- 4.11NF4.11 Interactive Lab. HTTP/HTTPS Investigation
- 4.12Module Summary
- 4.13Check My Knowledge
Investigate lateral movement through Windows network protocols. PsExec traffic patterns in SMB, WMI-over-DCOM execution, RDP session forensics, Windows authentication on the wire (NTLM vs Kerberos), and the INC-NE-2026-0418 ransomware lateral movement chain from IT03 to FIN01 and FS01.
Show 13 lessonsHide lessons
- 5.1NF5.1 SMB Protocol Fundamentals for Investigators
- 5.2NF5.2 Zeek SMB Logs, smb_mapping and smb_files
- 5.3NF5.3 PsExec Traffic Patterns
- 5.4NF5.4 WMI and DCOM Lateral Movement
- 5.5NF5.5 RDP Traffic Analysis
- 5.6NF5.6 Windows Authentication on the Wire
- 5.7NF5.7 Pass-the-Hash and NTLM Relay
- 5.8NF5.8 Lateral Movement Detection Methodology
- 5.9NF5.9 INC-NE-2026-0418 Lateral Movement Trail
- 5.10NF5.10 Kerberos and Active Directory Authentication on the Wire
- 5.11NF5.11 Interactive Lab. Lateral Movement Investigation
- 5.12Module Summary
- 5.13Check My Knowledge
Investigate SSH brute force, tunnelling, reverse shells, and encrypted channel abuse from network evidence. Zeek ssh.log analysis, HASSH client fingerprinting, detection without decryption through timing and volume analysis, VPN protocol identification, and the INC-NE-2026-0402 SSH brute force and cryptominer lateral movement investigation.
Show 13 lessonsHide lessons
- 6.1NF6.1 SSH Protocol Fundamentals for Investigators
- 6.2NF6.2 Zeek ssh.log Deep Dive
- 6.3NF6.3 SSH Brute Force Detection
- 6.4NF6.4 SSH Tunnelling. Local, Remote, and Dynamic Forwarding
- 6.5NF6.5 Reverse Shells Over SSH
- 6.6NF6.6 Encrypted Channel Analysis Without Decryption
- 6.7NF6.7 VPN and Tunnelling Protocols
- 6.8NF6.8 HASSH Fingerprinting and Tool Identification
- 6.9NF6.9 INC-NE-2026-0402: SSH Brute Force and Cryptominer Lateral Movement
- 6.10NF6.10 Windows Encrypted Remote-Management Channels
- 6.11NF6.11 Interactive Lab. SSH and Tunnel Investigation
- 6.12Module Summary
- 6.13Check My Knowledge
Phase 3: Detection & Hunting
Investigate phishing campaigns through email-layer network evidence. SMTP traffic analysis with Zeek smtp.log, header extraction from captures, attachment detection, SPF/DKIM/DMARC validation, IMAP-based exfiltration patterns, the M365 visibility gap, and the INC-NE-2026-0227 email delivery reconstruction, the phishing emails that preceded the DNS queries NF3 traced and the HTTP redirects NF4 investigated.
Show 13 lessonsHide lessons
- 7.1NF7.1 Email Protocol Fundamentals for Investigators
- 7.2NF7.2 Zeek smtp.log Deep Dive
- 7.3NF7.3 Email Headers From Network Evidence
- 7.4NF7.4 Phishing Email Indicators in Network Data
- 7.5NF7.5 Attachment Analysis From Network Captures
- 7.6NF7.6 SPF, DKIM, DMARC. Validation From DNS
- 7.7NF7.7 Mail Exfiltration Detection
- 7.8NF7.8 The M365 Mail Evidence Gap and How to Close It
- 7.9NF7.9 The INC-NE-2026-0227 Email Delivery Reconstruction
- 7.10NF7.10 Modern Phishing Variants. BEC, Thread Hijacking, Quishing, and VEC
- 7.11NF7.11 Interactive Lab. Phishing Investigation Workflow
- 7.12Module Summary
- 7.13Check My Knowledge
Write, tune, and operate Suricata detection rules at production quality. Rule anatomy and lifecycle, HTTP/DNS/TLS/file detection patterns, performance and false-positive management, rule management at scale with suricata-update, Community ID integration with Zeek, environment-specific tuning, and converting the INC-NE-2026-0227 investigation into deployable detection rules.
Show 13 lessonsHide lessons
- 8.1NF8.1 Where Suricata Fits in the Detection Stack
- 8.2NF8.2 Suricata Rule Anatomy
- 8.3NF8.3 Writing Rules for HTTP Attacks
- 8.4NF8.4 Writing Rules for DNS, TLS, and File Transfer
- 8.5NF8.5 Rule Performance and False Positives
- 8.6NF8.6 Rule Management at Scale
- 8.7NF8.7 Integrating Suricata with Zeek via Community ID
- 8.8NF8.8 Tuning Rules for Your Environment
- 8.9NF8.9 INC-NE-2026-0227: Building Detection From an Investigation
- 8.10NF8.10 Detection-as-Code. Rule Testing, CI/CD, and MITRE ATT&CK Mapping
- 8.11NF8.11 Interactive Lab. Build a Rule Pack
- 8.12Module Summary
- 8.13Check My Knowledge
Detect command-and-control traffic that signature-based rules miss. Beacon behavior on the wire, statistical detection methodology, long-duration connection analysis, domain fronting, Cobalt Strike malleable C2, DNS-based C2, protocol tunnelling, and the INC-NE-2026-0418 capstone that catches the ransomware campaign's pre-encryption beacons 48 hours earlier.
Show 13 lessonsHide lessons
- 9.1NF9.1 How C2 Beacons Behave on the Wire
- 9.2NF9.2 Beacon Detection Methodology
- 9.3NF9.3 Long-Duration Connections and Persistent C2
- 9.4NF9.4 Domain Fronting
- 9.5NF9.5 Cobalt Strike and Malleable C2
- 9.6NF9.6 DNS-Based C2
- 9.7NF9.7 Protocol Tunnelling Beyond DNS
- 9.8NF9.8 Building a C2 Detection Pipeline
- 9.9NF9.9 Capstone. Catching INC-NE-2026-0418 48 Hours Early
- 9.10NF9.10 Legitimate-Service Abuse as C2. Discord, Telegram, GitHub, and Other Cloud-Service C2
- 9.11NF9.11 Interactive Lab. Beacon Hunt Against Unseen Traffic
- 9.12Module Summary
- 9.13Check My Knowledge
Detect beaconing, exfiltration, and policy violations when full packet capture isn't available. NetFlow and IPFIX fundamentals, traffic baselines, top-talker analysis, flow-only beacon detection, exfiltration indicators, long-lived connections, egress policy validation, cloud VPC flow logs, and the INC-NE-2026-0418 capstone catching rclone exfil from flow data alone.
Show 13 lessonsHide lessons
- 10.1NF10.1 NetFlow and IPFIX Fundamentals
- 10.2NF10.2 What You Lose (and Keep) Without Full PCAP
- 10.3NF10.3 Building Traffic Baselines
- 10.4NF10.4 Top-Talker Analysis and Volume Anomalies
- 10.5NF10.5 Beacon Detection from Flow Data
- 10.6NF10.6 Data Exfiltration Indicators
- 10.7NF10.7 Long-Lived Connections from Flow Data
- 10.8NF10.8 Egress Policy Validation
- 10.9NF10.9 Cloud VPC Flow Logs (AWS, Azure, GCP)
- 10.10NF10.10 Capstone. Catching the rclone Exfil from Flow Data
- 10.11NF10.11 Interactive Lab. Flow-Only Triage
- 10.12Module Summary
- 10.13Check My Knowledge
Phase 4: Investigation & Capstone
Hunt network evidence for attacker activity you haven't built a detection rule for yet. Hypothesis-driven, data-driven, and intelligence-driven hunting across Zeek logs. User-agent hunting, DNS rarity, TLS and JA3 fingerprints, certificate anomalies, long-and-slow connections, LOLBin network signatures, lateral movement hunts, and automating hunts with Zeek scripts.
Show 13 lessonsHide lessons
- 11.1NF11.1 The Hunting Mindset. Hypothesis vs Detection
- 11.2NF11.2 Building Network Baselines for Hunting
- 11.3NF11.3 User-Agent and HTTP Header Hunting
- 11.4NF11.4 DNS Hunting. Rare Destinations and Query Patterns
- 11.5NF11.5 Certificate and TLS Hunting
- 11.6NF11.6 Long-Duration and Low-and-Slow Connection Hunting
- 11.7NF11.7 LOLBin Network Signatures
- 11.8NF11.8 Lateral Movement Hunting
- 11.9NF11.9 Automating Hunts with Zeek Scripts
- 11.10NF11.10 Capstone. The Davison Insider Hunt
- 11.11NF11.11 Interactive Lab. Three Hunts Against Fresh Zeek Data
- 11.12Module Summary
- 11.13Check My Knowledge
Integrate network evidence into the incident response workflow. When to pull full PCAP versus when Zeek metadata suffices, correlating Zeek conn.log to Defender XDR DeviceNetworkEvents, network-to-identity correlation against Entra sign-in logs, building the DNS-to-connection-to-transfer investigation timeline, cloud network evidence from VPC flow logs and CDN logs, evidence preservation and chain-of-custody for network artifacts, legal and regulatory posture for network monitoring, and writing the network section of the IR report. Capstone: re-investigating INC-NE-2026-0418 through the IR lens, same ransomware attack, network-evidence-led investigation, deliverable is the IR report section.
Show 13 lessonsHide lessons
- 12.1NF12.1 From Hunt to Incident. The Posture Shift
- 12.2NF12.2 PCAP vs Metadata. When to Pull Full Packet Capture
- 12.3NF12.3 Correlating Zeek to Defender XDR
- 12.4NF12.4 Correlating Zeek to Identity Evidence
- 12.5NF12.5 Building the Investigation Timeline
- 12.6NF12.6 Cloud Network Evidence
- 12.7NF12.7 Evidence Preservation and Chain of Custody
- 12.8NF12.8 Legal and Regulatory Posture
- 12.9NF12.9 Writing the IR Report. Network Section
- 12.10NF12.10 Capstone Walkthrough. INC-NE-2026-0418 Through the IR Lens
- 12.11NF12.11 Interactive Lab. Running an IR Engagement Against Fresh Network Evidence
- 12.12Module Summary
- 12.13Check My Knowledge
Design the network security monitoring architecture that produces the evidence used across NF3-NF12.
Show 13 lessonsHide lessons
- 13.1NF13.1 Architecture Decisions That Determine Visibility
- 13.2NF13.2 Sensor Placement
- 13.3NF13.3 Capture Scaling, 1, 10, 40, 100 Gbps
- 13.4NF13.4 Storage Architecture for Full-Packet Capture
- 13.5NF13.5 Arkime for Enterprise PCAP
- 13.6NF13.6 Security Onion as Integrated NSM
- 13.7NF13.7 Encrypted Traffic Visibility
- 13.8NF13.8 Cloud and Hybrid NSM
- 13.9NF13.9 The Zeek-to-Suricata-to-SIEM Detection Pipeline
- 13.10NF13.10 Design Walkthrough. Building Northgate Engineering's NSM
- 13.11NF13.11 Interactive Lab. NSM Design for a Different Organization
- 13.12Module Summary
- 13.13Check My Knowledge
The NF course capstone. A multi-stage attack against Northgate Engineering, AiTM credential phishing, Cobalt Strike C2 domain-fronted through a compromised CDN, OAuth persistence, internal lateral movement via SMB and RDP, staging on the engineering file server, and exfiltration via DNS tunnelling. You work the investigation against network evidence only, no endpoint telemetry, no identity logs, no Defender XDR alerts.
Show 13 lessonsHide lessons
- 14.1NF14.1 Detection and First Triage. The DNS-Tunnel Alert
- 14.2NF14.2 Scoping the Investigation. From Alert to Investigation Plan
- 14.3NF14.3 Initial Access. AiTM Reconstruction From the Wire
- 14.4NF14.4 C2 Analysis. Cobalt Strike Over Domain-Fronted HTTPS
- 14.5NF14.5 OAuth Persistence. Finding the Rogue App From Network Evidence
- 14.6NF14.6 Lateral Movement. SMB and RDP From the Finance Endpoint
- 14.7NF14.7 Staging and Exfiltration. The DNS Tunnel Decoded
- 14.8NF14.8 Cross-Phase Correlation. Stitching the Chain
- 14.9NF14.9 IR Report Production. Writing the Document the Board Reads
- 14.10NF14.10 Retrospective and Architecture Changes. What Should Be Different in 90 Days
- 14.11NF14.11 Interactive Lab. Variant Multi-Stage Investigation
- 14.12Module Summary
- 14.13Check My Knowledge
Course overview
The Network Detection and Forensics course teaches practical Network Investigation Methodology specifically for SOC Analysts, Incident Response Cybersecurity professionals, and Detection Engineers working with PCAP, Zeek, and Suricata. You'll gain hands-on expertise to:
By the end, you'll have the skills and methodology to confidently investigate network activity, uncover hidden attacker behavior, and strengthen your organization's network detection and response capabilities.
Who this course is for
You're a SOC Analyst, Incident Response Cybersecurity professional, or Detection Engineer who works with network traffic and wants to master network-level investigation and detection. This course is built for you if you want to:
In short: if you're ready to become highly effective at network detection and forensics, this course is for you.
What you'll learn
By the end of this Network Detection and Forensics course you will be able to:
Key course takeaways
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course teaches network investigation from first principles. Familiarity with TCP/IP fundamentals and basic command-line usage will help you move faster, but neither is required. Every protocol, tool, and technique is explained at first use.
What are the device requirements?
A device with a modern browser. For hands-on practice, a Linux VM (or WSL) with Zeek, Suricata, and Wireshark installed. The course walks you through setup and provides PCAP datasets for all exercises.
How will the course benefit your career?
Network forensics is one of the most in-demand and least common skills in security operations. Most analysts investigate from endpoint and identity logs. This course gives you the network perspective that completes the picture, the ability to detect C2, prove exfiltration, and reconstruct attacks from network evidence when endpoint data is unavailable or compromised.
Network investigation capability is a differentiator for senior IR, detection engineering, and SOC roles.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy detection rules, Suricata signatures, and analysis workflows in your production environment. You may not redistribute course content or share account credentials.
PCAP files: All packet captures contain fictional data from the Northgate Engineering environment. No real network traffic. All IP addresses use RFC 5737 documentation ranges.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.