Network Security
Network Security Beginner
Practical network security foundations with guided hands-on labs.
119 EUR
From reading a packet capture in Wireshark to writing the Suricata and Zeek rules that catch beaconing, exfiltration and lateral movement — traffic analysis, detection engineering and incident response, practised on real captures in isolated cloud labs.
Lab tools you will use
Practical network security foundations with guided hands-on labs.
119 EUR
Intermediate network security with complex real-world scenarios and professional workflow.
159 EUR
Get the Beginner + Intermediate courses bundled together and unlock exclusive extras.
Each phase maps to a course module. Scroll to assemble your full progression — from beginner fundamentals to intermediate mastery.
Phase 1
BeginnerBad captures produce confident wrong answers. This is about getting evidence you can stand behind.
Phase 2
BeginnerFollowing a session field by field until the protocol stops being a wall of hex and starts telling a story.
Phase 3
BeginnerEvery network has its own rhythm. Knowing it is what turns a curiosity into a finding.
Phase 4
BeginnerTurning captures into structured logs so anomalies become searchable rather than something you hope to notice.
Phase 5
IntermediateCommand channels betray themselves through regularity. This phase is about seeing it without knowing the address in advance.
Phase 6
IntermediateNearly everything is encrypted now, so the discipline is extracting meaning from what encryption still leaves exposed.
Phase 7
IntermediateA finding that only exists in your head does not scale. Here it becomes something that watches the wire for you.
Phase 8
IntermediateThe final exercise is the one that matters commercially: what left the network, and when.
The Network Security path is about the traffic layer: reading what actually crossed the wire, spotting the patterns that do not belong, and building the monitoring that surfaces them without a human watching. Network evidence has a property endpoint evidence lacks — an attacker who owns a host can tamper with its logs, but the packets have already left.
The emphasis is analytical rather than architectural. You will spend far more time reading captures and writing detection logic than configuring appliances, because the skill that transfers between employers is being able to look at traffic and say what happened, not knowing one vendor's console.
There is a reason network evidence keeps its value while other sources degrade. Endpoint telemetry can be disabled, logs can be cleared, and a sufficiently privileged attacker can make a host lie about its own history. Traffic that has already crossed a monitored link cannot be retracted. That is why network monitoring remains the control most likely to answer the question everyone asks after an incident — what actually left the building, and when.
This path is in development. The two courses are being built to the same standard as the rest of the catalogue — isolated labs, flag-validated exercises, real traffic rather than textbook examples — and we would rather ship them late than ship them thin.
The path uses more tools than fit here. These are the ones that define the work.
| Tool | Category | What for |
|---|---|---|
| Wireshark | Packet analysis | Inspecting traffic down to individual fields — the reference tool of the discipline |
| Zeek | Network monitoring | Turning raw traffic into structured logs you can actually query at volume |
| Suricata | Intrusion detection | Applying signatures and behavioural rules to live traffic |
| tcpdump | Capture | Capturing precisely what you need on a server with no interface |
| NetworkMiner | Forensics | Reconstructing transferred files and sessions from a capture |
| Security Onion | Platform | A complete monitoring stack for practising at realistic scale |
| Nmap | Discovery | Understanding what scanning looks like from both ends, attacker and defender |
| ntopng | Flow analysis | Seeing traffic volumes and relationships when full capture is impractical |
Reconstructing an intrusion from packet capture alone
Written against behaviour you identified yourself and tested
Sensor placement, capture strategy and what to retain when you cannot keep everything
Identifying beaconing by timing and jitter rather than by known addresses
Network analysis is one of the most durable skills in defensive security: protocols outlive products, so what you learn here stays relevant far longer than any specific platform.
Monitors and investigates traffic for signs of compromise
Correlates network evidence with endpoint and identity telemetry
Establishes what was exfiltrated and over which channel
Builds and maintains network detection coverage
Complete answers about this path, labs, certificates, and refunds
It is in development. Both courses are being built to the same standard as the rest of the catalogue, with isolated labs and flag-validated exercises, and we would rather delay than release something thin. The other three paths are available now.
Yes, more so than for the other paths. You need to be comfortable with TCP/IP, DNS and HTTP before anomalies in them mean anything to you. If that is missing, cover it first — it is the one genuine prerequisite here.
No. The focus is analytical: reading traffic, identifying malicious patterns and building detection. Product configuration varies by employer and dates quickly; protocol analysis does not.
They complement each other directly. Threat Hunting is weighted toward endpoint telemetry, this one toward network. Real investigations use both, and either is a reasonable starting point.
Yes — necessarily, since most traffic is encrypted now. The material covers what remains visible without decryption: certificates, JA3-style fingerprints, timing, volume and destination patterns, which is often enough to identify malicious activity.
Yes. Join the community from the link on this site and you will hear when the courses open, along with early access to the labs.