دوره FOR572: Advanced Network Forensics: Threat Hunting, Analysis, and Incident Response

FOR572 is an advanced course designed for cybersecurity professionals seeking to master network forensics, threat hunting, and incident response. The course focuses on deep packet analysis, intrusion detection, and uncovering adversary activity within large-scale enterprise environments. Participants will learn how to analyze network traffic, identify anomalies, and reconstruct cyber attacks using tools such as Zeek (Bro), Suricata, Wireshark, and Security Information and Event Management (SIEM) solutions.

Syllabus

  1. Off the Disk and Onto the Wire
  2. Core Protocols & Log Aggregation/Analysis
  3. NetFlow and File Access Protocols
  4. Commercial Tools, Wireless, and Full-Packet Hunting
  5. Encryption, Protocol Reversing, OPSEC, and Intel
  6. Network Forensics Capstone Challenge