03 · Digital Forensics

Network Forensics & IDS/IPS

Packet capture, intrusion detection and prevention with Suricata, Snort and Wireshark; firewalls and honeypots.

  • Wireshark & NetworkMiner
  • Suricata / Snort
  • Firewalls & honeypots

Programme outline

  1. Information security primer for network defenders
  2. Intrusion detection & prevention systems (Suricata, Snort)
  3. Firewalls: from packet filters to next-generation firewalls
  4. Endpoint security and EDR
  5. Honeypots deployment and honeypot forensics
  6. Network forensics with Wireshark and NetworkMiner