◈ Path Bundle

Network Security

From reading a packet capture in Wireshark to writing the Suricata and Zeek rules that catch beaconing, exfiltration and lateral movement — traffic analysis, detection engineering and incident response, practised on real captures in isolated cloud labs.

Not on sale yet. Leave your email and we will tell you the day Network Security opens — nothing else.

One email, only when it launches. No newsletter.

Lab tools you will use

WiresharkNetworkNmapScannerSuricataIDS/IPSZeekNetworktcpdumpCaptureSnortIDS/IPSOpenVASScannerMetasploitExploitationWiresharkNetworkNmapScannerSuricataIDS/IPSZeekNetworktcpdumpCaptureSnortIDS/IPSOpenVASScannerMetasploitExploitation
Burp SuiteProxyNessusScannerSecurity OnionMonitoringWazuhSIEMntopngMonitoringNetworkMinerForensicsOSSECHIDSArgusFlow analysisBurp SuiteProxyNessusScannerSecurity OnionMonitoringWazuhSIEMntopngMonitoringNetworkMinerForensicsOSSECHIDSArgusFlow analysis

Courses Included

Beginner

Network Security

◎ BEGINNER500 XPAudio:ES

Network Security Beginner

Practical network security foundations with guided hands-on labs.

1 guided lab10h of content

119 EUR

View course →
Intermediate

Network Security

L7 HTTP/TLS :443
L4 TCP SYN scan?
L3 IPv4 10.0.0.0/24
▲ INTERMEDIATE750 XPAudio:ES

Network Security Intermediate

Intermediate network security with complex real-world scenarios and professional workflow.

2 guided labs12h of content

159 EUR

View course →

Why Choose the Full Pack?

Get the Beginner + Intermediate courses bundled together and unlock exclusive extras.

Beginner + Intermediate courses (22h of content)
All 4 guided labs with isolated VMs
2 HTK certificates (Beginner + Intermediate)
1 exclusive bonus consolidation lab
Direct instructor support
Access to the HTK community

Not on sale yet. Leave your email and we will tell you the day Network Security opens — nothing else.

One email, only when it launches. No newsletter.

Your Learning Roadmap

Each phase maps to a course module. Scroll to assemble your full progression — from beginner fundamentals to intermediate mastery.

1

Phase 1

Beginner

Capturing what you actually need

Bad captures produce confident wrong answers. This is about getting evidence you can stand behind.

  • Place a sensor where the interesting traffic genuinely passes
  • Capture on a headless server without filling the disk
  • Decide what to keep when full capture is not affordable
2

Phase 2

Beginner

Reading a conversation

Following a session field by field until the protocol stops being a wall of hex and starts telling a story.

  • Follow a stream from handshake to teardown
  • Read the protocols attackers most often abuse
  • Reconstruct files and credentials that crossed in the clear
3

Phase 3

Beginner

Establishing what normal is here

Every network has its own rhythm. Knowing it is what turns a curiosity into a finding.

  • Profile who normally talks to whom, and when
  • Recognise the chatty protocols that look alarming but are not
  • Build a reference you can compare against later
4

Phase 4

Beginner

The first things that do not fit

Turning captures into structured logs so anomalies become searchable rather than something you hope to notice.

  • Convert raw traffic into queryable records
  • Spot scanning, enumeration and unusual destinations
  • Investigate a suspicious host from its traffic alone
5

Phase 5

Intermediate

Finding the heartbeat

Command channels betray themselves through regularity. This phase is about seeing it without knowing the address in advance.

  • Identify beaconing from interval and jitter rather than reputation
  • Recognise data smuggled inside DNS and HTTP
  • Distinguish malicious persistence from ordinary polling
6

Phase 6

Intermediate

When you cannot read the payload

Nearly everything is encrypted now, so the discipline is extracting meaning from what encryption still leaves exposed.

  • Read certificates and handshake characteristics for clues
  • Fingerprint clients by how they negotiate, not what they send
  • Infer behaviour from size, timing and direction alone
7

Phase 7

Intermediate

Automating what you found by hand

A finding that only exists in your head does not scale. Here it becomes something that watches the wire for you.

  • Write signature and behavioural rules against real traffic
  • Tune them until the alerts are worth reading
  • Stand up a monitoring stack end to end
8

Phase 8

Intermediate

Answering the question after a breach

The final exercise is the one that matters commercially: what left the network, and when.

  • Reconstruct an intrusion timeline from capture alone
  • Quantify what was exfiltrated and through which channel
  • Produce evidence that survives scrutiny after the fact

What this path is

The Network Security path is about the traffic layer: reading what actually crossed the wire, spotting the patterns that do not belong, and building the monitoring that surfaces them without a human watching. Network evidence has a property endpoint evidence lacks — an attacker who owns a host can tamper with its logs, but the packets have already left.

The emphasis is analytical rather than architectural. You will spend far more time reading captures and writing detection logic than configuring appliances, because the skill that transfers between employers is being able to look at traffic and say what happened, not knowing one vendor's console.

There is a reason network evidence keeps its value while other sources degrade. Endpoint telemetry can be disabled, logs can be cleared, and a sufficiently privileged attacker can make a host lie about its own history. Traffic that has already crossed a monitored link cannot be retracted. That is why network monitoring remains the control most likely to answer the question everyone asks after an incident — what actually left the building, and when.

This path is in development. The two courses are being built to the same standard as the rest of the catalogue — isolated labs, flag-validated exercises, real traffic rather than textbook examples — and we would rather ship them late than ship them thin.

Who it's for

  • Network and system administrators moving toward a security role
  • SOC analysts who want to read a packet capture with confidence rather than guessing
  • Detection engineers extending coverage from endpoint into network telemetry
  • Incident responders who need to establish what left the network, and when

Who it's not for

  • ·Anyone without networking fundamentals — you need TCP/IP before you can find anomalies in it
  • ·People looking for penetration testing content; the focus here is detection and response

What you need before starting

  • Solid TCP/IP fundamentals: the layers, the handshake, common protocols and ports
  • Comfortable with the Linux command line
  • Familiarity with how DNS and HTTP work in practice
  • No prior packet analysis experience required

The tools, and what each one is for

The path uses more tools than fit here. These are the ones that define the work.

ToolCategoryWhat for
WiresharkPacket analysisInspecting traffic down to individual fields — the reference tool of the discipline
ZeekNetwork monitoringTurning raw traffic into structured logs you can actually query at volume
SuricataIntrusion detectionApplying signatures and behavioural rules to live traffic
tcpdumpCaptureCapturing precisely what you need on a server with no interface
NetworkMinerForensicsReconstructing transferred files and sessions from a capture
Security OnionPlatformA complete monitoring stack for practising at realistic scale
NmapDiscoveryUnderstanding what scanning looks like from both ends, attacker and defender
ntopngFlow analysisSeeing traffic volumes and relationships when full capture is impractical

What you finish with

Traffic analysis reports

Reconstructing an intrusion from packet capture alone

Suricata detection rules

Written against behaviour you identified yourself and tested

A monitoring deployment

Sensor placement, capture strategy and what to retain when you cannot keep everything

A C2 traffic profile

Identifying beaconing by timing and jitter rather than by known addresses

Where it leads

Network analysis is one of the most durable skills in defensive security: protocols outlive products, so what you learn here stays relevant far longer than any specific platform.

Network Security Analyst

Monitors and investigates traffic for signs of compromise

SOC Analyst

Correlates network evidence with endpoint and identity telemetry

Incident Responder

Establishes what was exfiltrated and over which channel

Detection Engineer

Builds and maintains network detection coverage

Frequently Asked Questions

Complete answers about this path, labs, certificates, and refunds

It is in development. Both courses are being built to the same standard as the rest of the catalogue, with isolated labs and flag-validated exercises, and we would rather delay than release something thin. The other three paths are available now.

Yes, more so than for the other paths. You need to be comfortable with TCP/IP, DNS and HTTP before anomalies in them mean anything to you. If that is missing, cover it first — it is the one genuine prerequisite here.

No. The focus is analytical: reading traffic, identifying malicious patterns and building detection. Product configuration varies by employer and dates quickly; protocol analysis does not.

They complement each other directly. Threat Hunting is weighted toward endpoint telemetry, this one toward network. Real investigations use both, and either is a reasonable starting point.

Yes — necessarily, since most traffic is encrypted now. The material covers what remains visible without decryption: certificates, JA3-style fingerprints, timing, volume and destination patterns, which is often enough to identify malicious activity.

Yes. Join the community from the link on this site and you will hear when the courses open, along with early access to the labs.