Traffic Analysis, IDS/IPS Alerts & Forensic Artifacts
Kill chain stages, MITRE ATT&CK tactics, and SOC triage decision matrices.
TOPIC 4.1SIEM, event sources, Windows Event IDs, and log collection architecture.
TOPIC 4.2Packet filtering, stateful inspection, application-layer firewalls, and IDS/IPS integration.
LINK → ShieldFlow analysis, DPI, behavioral patterns, JA3 fingerprinting, and beaconing detection.
TOPIC 4.4File carving, magic bytes, HTTP object export, and PCAP evidence extraction.
TOPICIDS/IPS alert anatomy, SID research, triage workflow, and false positive analysis.
TOPIC 4.6Forensic artifacts, MAC times, Windows/Linux locations, and anti-forensics awareness.
TOPIC 4.7Pattern matching, security-focused regex, log filtering, and live regex tester.
TOPICCapture DNS traffic, identify tunneling indicators, and analyze UDP protocols.
Analyze TCP handshake, sequence numbers, and protocol behavior differences.
Extract files from HTTP, analyze TLS handshakes, and detect web attacks.
Visualize packet encapsulation and routing decisions through network layers.
Interactive ACL rule processing, wildcard masks, and placement decisions.
Complete all topics and labs, then take the Week 4 assessment to test your network intrusion analysis skills.
Begin Evaluation