Visão Geral
Este curso apresenta técnicas de análise forense de tráfego e evidências de rede para investigação de incidentes, detecção de ataques, reconstrução de sessões e identificação de atividades maliciosas.
Conteúdo Programatico
Module 1: Network Forensics Fundamentals
- Network forensics concepts
- Network evidence
- Packet capture
- Traffic analysis
- Network investigation lifecycle
- Evidence preservation
- Network artifacts
- Forensic integrity
- Investigation methodology
- Network forensic documentation
Module 2: Network Protocol Analysis
- TCP
- UDP
- DNS
- HTTP
- HTTPS
- TLS
- SMB
- LDAP
- Kerberos
- Protocol-based investigation
Module 3: Packet Analysis
- Packet structure
- Packet capture analysis
- TCP sessions
- Network flows
- Session reconstruction
- Packet filtering
- Traffic patterns
- Anomalous packets
- Protocol anomalies
- Packet investigation
Module 4: Attack Detection
- Port scanning
- Network reconnaissance
- Brute Force
- Command and Control
- Malware traffic
- Data exfiltration
- Lateral Movement
- Suspicious DNS
- Network anomalies
- Attack detection
Module 5: Web and Application Traffic
- HTTP investigation
- HTTPS metadata
- Web sessions
- Application protocols
- Suspicious requests
- Malicious downloads
- Web-based attacks
- Application traffic anomalies
- Web evidence
- Application traffic investigation
Module 6: Network Threat Hunting
- Hunting hypotheses
- IOC-based hunting
- Behavioral hunting
- DNS hunting
- Network connection hunting
- C2 hunting
- Exfiltration hunting
- Lateral Movement hunting
- Network telemetry
- Threat hunting methodology
Module 7: Incident Investigation
- Incident scoping
- Traffic correlation
- Timeline reconstruction
- Endpoint correlation
- Network-to-host analysis
- Attack path reconstruction
- Evidence validation
- IOC identification
- Investigation reporting
- Incident response integration
Module 8: Practical Network Forensics
- Packet capture analysis
- Protocol investigation
- DNS investigation
- HTTP investigation
- C2 analysis
- Lateral Movement investigation
- Exfiltration analysis
- Timeline reconstruction
- Evidence documentation
- Network forensics case study