15
A P Co [as of All Pas ours f April 20 Ac ss se L 014] cc s ist ce ss s

A ll Ac cccess assss - wiresharktraining.com · Lab Solu Analyzin Build W Wiresha Adjust K ... sector to view s. ) ST (WCNA ing this accele ... Network mo Wireshark to traffic on

Embed Size (px)

Citation preview

AP

Co[as of

All Pas

oursf April 20

Acss

se L014]

ccs

ist

cesss

All Access

Table Welcome t

All AcceTrain Yo

All Access

In DevelWCNA ELab SoluAnalyzinBuild WWireshaAdjust KDetectinCreate aFind StuWireshaCS42: HaCS43: AnCS44: ToCS45: TCCS46: DHCS47 NmCS48: WCS50: WCS52: WCS54: ICCS55: AnCS56: SlCS57: TCCS58: PaCS59: CaCS60: TrCS61: TsCS62: TrCS63: 10CS64: ReTrace FiTrace FiTrace FiWhiteboCore 1: WCore 2: T[Retired[Retired[Retired

Pass (www.lcu

of Contto the All Acce

ss Pass Featureour Entire IT Te

Pass Course Lis

opment–WireExam Prep Queutions for Wireng the Windowireshark Filters

ark Display FilteKey TCP Settingng Delays: Troua Security Profiff Fast with W

ark 1.8 Update acked Hosts ...nalyze and Impop 10 Reasons CP Analysis in-DHCP/ARP Analy

map Network SWireshark 101 JWLAN Analysis 1Wireshark 201 FCMP Analysis ...nalyzing Googlow Networks -CP Vulnerabilitacket Crafting tapturing Packeroubleshootingshark Commanroubleshooting0 Essential Wiregex Primer ....le Analysis - Sele Analysis - Sele Analysis - Seoard Lecture SeWireshark FunTroubleshoot/] CS53: New W] Wireshark 1.] CS41: Wiresh

uportal2.com) -

ents ss Pass (AAP) .

es ...................eam .................

st (as of April 2

shark Certifiedestions ............shark 101: Ess

w Zero Conditios from Snort Ruer Tips and Tricgs ....................ubleshooting wile ...................ireshark Filter - 19 Hot Featu.......................

prove ThroughYour Network

Depth .............ysis .................Scanning 101 ..umpstart ........101 .................Filtering .................................e Secure Searc- NOPs/SACK ..ies ..................to Test Firewa

ets (Security Fog with Coloringnd-Line Captureg with Expert Inreshark Skills ..........................

et 1 ..................et 2 ..................et 3 ..................eries 1 ............

nctionality and /Secure NetwoWireshark 1.4 F

7 Update........hark 101 Jumps

- Dated April 2

.......................

.......................

.......................

2014) ..............

d Network Ana.......................ential Skills for

on ....................ules .................cks .........................................

with Time ...............................Expression Bu

ures ........................................put .................

k is Slow ............................................................................................................................................................................

ch ..................................................................lls ...................

ocus) ................g ......................e .....................nfo ............................................................................................................................................................TCP/IP Analysrks with Wires

Features .................................start - Original

014

.......................

.......................

.......................

.......................

lyst (WCNA) B.......................r Network Ana..........................................................................................................................................ttons .............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................is ....................

shark ............................................................. ......................

.......................

.......................

.......................

.......................

oot Camp ..............................

alysis ..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

........................

P a

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

.......................

a g e 1

........ 2

........ 2

........ 2

........ 3

........ 3

........ 3

........ 3

........ 3

........ 4

........ 4

........ 4

........ 4

........ 5

........ 5

........ 5

........ 5

........ 6

........ 6

........ 6

........ 7

........ 7

........ 7

........ 8

........ 8

........ 8

........ 8

........ 9

........ 9

........ 9

........ 9

...... 10

...... 10

...... 10

...... 10

...... 11

...... 11

...... 11

...... 11

...... 12

...... 12

...... 12

...... 13

...... 13

...... 13

All Access

Welco

ALL ACC

• O• V• D• In• CP• Co• Co• Ca• U• Li

TRAIN Y

Get your enetwork fo

• H• In• Se• Se• N

Group discafter the c

Pass (www.lcu

ome to th

CESS PASS

Online training ideos filled wiownloadable c

ndustry-leadingPE credit trackourse transcripourse Completategorized counlimited accesve events – jo

YOUR ENTIR

ntire team traorensics.

elp Desk teamnfrastructure Terver Team: Qecurity Team: etwork Design

counts are avaiover page).

uportal2.com) -

he All Ac

S FEATURE

on key IT topith demonstratcourse documg training from

king system – spts with in-protion Certificateurses – focus oss to recorded in Laura online

RE IT TEAM

ined on Wiresh

m: Learn to captTeam: Learn to

Quickly identify Detect recon p

n Team: Determ

ilable when yo

- Dated April 2

ccess Pa

Save tSave mAcquirAcquire videntify bapplicatio

ES

cs – master in-tions – watch hents – referen

m Laura Chappsubmit credits ogress percentes – print seria

on specific topicourses – rep

e for live cours

M

hark, network

ture traffic ando identify probl

server error reprocesses and mine network

u sign up 5 or

014

ass (AAP

ime. money. re in-demavaluable skills tbreached hostsons.

-demand skillshow key skills ace course supp

pell, Founder oto certification

tages – track yoalized certificatcs eat courses as e on hot topics

analysis, TCP/

d identify the pems related to

esponses and hindications of capabilities an

more students

P)

and skills.to quickly spot s and determin

are performedplements offlin

of Wireshark Un programs our progress ttes for each co

needed s

IP communicat

primary cause o infrastructurehigh server latebreached host

nd application

s. See the All A

the source of ne the overhea

d ne

University – lea

hrough classesompleted cours

tions, troubles

of performance devices ency ts loads

Access Pass Ord

P a

network probad of network

arn from an exp

s se

shooting and

ce problems

der Form (loca

a g e 2

lems,

pert

ted

All Access

All Ac

IN DEVE

WCNA E

LAB SO

ANALYZ

Pass (www.lcu

cess Pa

ELOPMENT–

EXAM PREP

LUTIONS F

ZING THE W

uportal2.com) -

ss Cours

–WIRESHAR

Author: Category: CPE Credits:

This course itraining couDivided intotest your proexam recom

P QUESTION

Author: Category: CPE Credits:

Many of ourAnalyst desithirty-three After answedetailed exptimes as you

OR WIRESH

Author: Category: CPE Credits:

This course cEssential Ski

WINDOW ZE

Author: Category: CPE Credits:

This course idepicting Wnetwork datLaura takes ynotifications

- Dated April 2

se List (

RK CERTIF

Laura ChappeWireshark Ce

50 (ESTIMAT

is currently in drse focused on the 33 sectionogress, demon

mmending area

NS

Laura ChappeBook Videos

4

r All Access Pasgnation. This mareas of studyring each ques

planation of theu wish.

HARK 101:

Laura ChappeBook Videos

3

contains the vills for Network

ERO CONDIT

Laura ChappeTroubleshoot

1.5

is based on anindow Zero co

ta flow and howyou into the pas regarding win

014

(as of Ap

IED NETWO

ell ertification ED)

development. n the Wiresharns covered in tnstrations of kes for further st

ell

ss members armodule providey defined for thstion you will be correct answ

ESSENTIA

ell

ideo solutions k Analysis.

TION

ell ting

AAP Live Evennditions. You ww to find thoseacket-tcp.c disndow size issue

pril 2014

ORK ANALY

Laura is recordk Certified Net

the Exam, this cey skills coveretudy.

re seeking the Wes over 300 pr

he Wireshark Cbe informed if y

wer. You can ta

AL SKILLS F

to the 46 labs

nt. In this courswill learn that e issues quicklyssector to viewes.

4)

YST (WCNA

ding this acceletwork Analyst course include

ed in the WCNA

Wireshark Cerractice quiz queCertified Netwoyou answered ke the practice

FOR NETWO

contained in W

se you will anaeven small winy with a colorin

w each of the Ex

W

W

P a

A) BOOT CA

erated online (WCNA) progr

es section quizzA Exam, and a

tified Networkestions based oork Analyst™ Ecorrectly or gi

e exam as man

ORK ANALY

Wireshark 101

alyze three tracndow sizes canng rule. Finallyxpert Info

Wireshark Certif

Book Video

Troubleshoot

Wireshark Certif

a g e 3

AMP

am. zes to final

k on the

Exam. iven a

ny

YSIS

:

ce files n stop y,

fication

os

ting

fication

All Access

BUILD W

WIRESH

ADJUST

DETECT

Pass (www.lcu

WIRESHARK

HARK DISPL

T KEY TCP S

TING DELAY

uportal2.com) -

K FILTERS

Author: Category: CPE Credits:

Interpret, trafor more advRimecud, SyBuddy; Colas

LAY FILTER

Author: Category: CPE Credits:

Learn new dthe dreadedtwo Notepadbuttons and

SETTINGS

Author: Category: CPE Credits:

Examine Wiranalysis. Inctimestamps.

YS: TROUB

Author: Category: CPE Credits:

In this recorresponse timcustom colutime.

- Dated April 2

FROM SNO

Laura ChappeSecurity and

1

anslate and buvanced filterin

ykipot, LDPinchsoft Packet Bu

R TIPS AND

Laura ChappeWireshark Fu

1

display filteringd "!=" operatord++ macros th convert Filter

Laura ChappeWireshark Fu

1

reshark’s 12 TCludes coverage.

LESHOOTI

Laura ChappeWireshark Fu

1

ded AAP eventme delays. We mns for sortin

014

ORT RULES

ell Network Foren

uild Wireshark g. Test your fil

h and LOIC (by ilder.

D TRICKS

ell unctionality an

g techniques inr, and building at you can useExpression bu

ell unctionality an

CP preference e of TCP reasse

NG WITH T

ell unctionality an

t, we look at twwill adjust reqg, and build ne

S

nsics

filters from Snters on the incAnonym9us). O

d Tips

ncluding filterinoffset (and bit

e to convert couttons to colori

d Tips

settings and thembly, bytes in

TIME

d Tips

wo types of dequired protocoew buttons to

nort rules. Learcluded trace filOther tools co

ng based on fiet-level) filters. T

oloring rules to ing rules.

heir effect on tn flight usage, a

elays - round trl/application pquickly identif

Security an

Wireshark Fu

Wireshark Fu

P a

rn how to use Rle. Filters incluvered: Regex

elds/strings, usThis course inc Filter Expressi

the traffic and and TCP calcul

rip time delays preferences, adfy issues relate

d Network Fore

unctionality and

unctionality and

Troubleshoot

a g e 4

Regex de

sing cludes ion

your ated

and dd ed to

ensics

d Tips

d Tips

ting

All Access

CREATE

FIND ST

WIRESH

CS42: H

Pass (www.lcu

E A SECURI

TUFF FAST

HARK 1.8 UP

ACKED HO

uportal2.com) -

ITY PROFIL

Author: Category: CPE Credits:

Learn how tocourse, buildcoloring rulelocate packeto find the la

WITH WIRE

Author: Category: CPE Credits:

Learn how toThe course iButtons and

PDATE - 19

Author: Category: CPE Credits:

Learn the newere added

OSTS

Author: Category: CPE Credits:

Network fornumerous tridentifying ssigns that a port 80, or 2This online cthe security

- Dated April 2

LE

Laura ChappeSecurity and

1

o get the best d a Security proe names and coets of concern.atest security d

ESHARK FI

Laura ChappeWireshark Fu

1

o locate the nencludes a set o instructions to

9 HOT FEAT

Laura ChappeWireshark Fu

1

ewest featuresto Wireshark

Laura ChappeSecurity and

1.5

rensics comes irace files of bresuspect traffic pbot has invade

25, or 21? Whacourse will getof your netwo

014

ell Network Foren

out of Wireshaofile and creatolors. Finally, b Learn to use rdetection rules

LTER EXPR

ell unctionality an

eedle(s) in the of general, trouo import these

TURES

ell unctionality an

s of Wireshark 1.8.

ell Network Foren

into play in thieached hosts, patterns. How

ed your networat is the first st

you up to speeork through net

nsics

ark by making te key security build a set of Fregex in your cs.

RESSION B

d Tips

haystack fasteubleshooting ae into your Wir

d Tips

- at least 19 of

nsics

s online courseMs. Chappell e do you identifrk? How can yoep to dealing wed on the top twork forensic

it a security tocoloring rules ilter Expressio

coloring rules a

UTTONS

er with Filter Exand security Filreshark profile

f the hottest ne

e by Laura Chaexplains the firfy a breached hou find IRC trawith a comproitems to look f

cs.

Security an

Wireshark Fu

Wireshark Fu

Security an

P a

ool. In this 1-housing specific

n buttons to qand filters and

xpression Buttlter Expressions.

ew features th

appell. Based orst steps to host? What areffic running ovmised machinefor when analy

nd Network For

unctionality and

unctionality and

nd Network Fore

a g e 5

our

uickly where

tons. n

hat

on

e the ver e?

yzing

rensics

d Tips

d Tips

ensics

All Access

CS43: A

CS44: T

CS45: T

Pass (www.lcu

NALYZE AN

OP 10 REA

CP ANALYS

uportal2.com) -

ND IMPROV

Author: Category: CPE Credits:

What are ththroughput What about you use the the networkACK help easaffecting penetworks anThis course iWireshark, i

SONS YOU

Author: Category: CPE Credits:

Network moWireshark totraffic on poinside tips amonitoring athis online c

SIS IN-DEP

Author: Category: CPE Credits:

TCP is the badatabase actrace files ofprocess, TCPsession tear 'scream the

- Dated April 2

VE THROUG

Laura ChappeTroubleshoot

1.5

e main factorsis so low? Howgraphing out tBDP calculatio

k recover from se the pain of rformance? La

nd performs soincludes live trPerf and NetSc

R NETWOR

Laura ChappeTroubleshoot

1.5

onitoring helpso monitor netw

oorly performinnd tricks on locand latency moourse is worth

TH

Laura ChappeTCP/IP Comm

1.5

asic communiccess, email, filef normal and aP options, wind

down processstory' of why c

014

GHPUT

ell ting

s affecting throw do you take athe round trip

on to determinpacket loss onpacket loss? Hura examines

ome live througrace file analyscanTools Pro.

RK IS SLOW

ell ting

s discover the cwork communing networks. Scating the causonitoring to pa

h your time to a

ell munications

cation used fore transfers, etcbnormal TCP c

dow size, packeses and TCP reacommunicatio

oughput and hoa quick snapshtimes calculate the ideal TCP

n UDP and TCPow can you tenumerous trac

ghput tests dursis, latency test

W

cause of slow nications, Lauraave yourself hse of network acket loss and wattend.

r most importac. In this courscommunicationet loss and recassembly. Laurns are so lousy

ow can you pinot of round tried from trafficP receive buffe networks? Ho

ell if queuing alce files from loring this detailting and throug

network perfora Chappell demours of researcproblems. Frowireless netwo

ant network trae, Laura takes ns and explaincovery, selectivra shows graphy.

TCP

P a

npoint why youip latency timec captured? Hoer size? How doow does Selectong a path is

ow-throughputed training coughput tests usi

rmance. Usingmonstrates netw

ch by getting tm bandwidth ork interferenc

affic - web broyou through vs the handshak

ve ACKs, timeohs of TCP traffi

Troubleshoot

Troubleshoot

P/IP Communic

a g e 6

ur es? ow do oes ive

t urse. ing

work he

ce,

wsing, various ke

outs, c that

ting

ting

cations

All Access

CS46: D

CS47 NM

CS48: W

Pass (www.lcu

HCP/ARP A

MAP NETWO

WIRESHARK

uportal2.com) -

ANALYSIS

Author: Category: CPE Credits:

Accelerate yfiles. In this analyzes theoptions seenmethods to how ARP canlike on the n

ORK SCAN

Author: Category: CPE Credits:

It's time to ga budget, okscanning youhosts runninNmap/ZenmOS fingerpri

K 101 JUMP

Author: Category: CPE Credits:

Laura and Gwebinar. WidemonstrateDownload th

- Dated April 2

Laura ChappeTCP/IP Comm

1.5

your learning scourse Laura c

e DHCP processn in DHCP bootfilter on varioun be used to di

network.

NING 101

Laura ChappeOther Tools

1.5

get a handle onk? No... this isnur network using and their semap. This cours

nting, service d

PSTART

Laura ChappeWireshark Fu

1.5

erald Combs (cthin 48 hours oes capture filtehe Event Notes

014

ell munications

peed by watchconcentrates os and the gratutup processes us DHCP packeiscover firewal

ell

n that tangled n't a drug-inducng OS fingerprrvices. Her we

se includes livediscovery and g

ell unctionality an

creator of Wireover 5,000 peoers, display filtes document fo

hing Laura open the typical st

uitous ARP pro- including the

et fields. In exalled local devic

mess you call aced fantasy - Lrinting and serapon of choice

e mapping procgraphing of ne

d Tips

eshark) hostedople had registers, IO graphinr 60-pages of i

n and analyze tartup sequen

ocess. Laura exe use of DHCP Ramining ARP traces and what a

a network! OhLaura will showrvice scans to ide in this onlinecesses of remoetwork devices

d a new Wireshtered for the eng, coloring trainstructions, Q

TCP

Wireshark Fu

P a

a series of tracce of a host anplains the variRelay Agents aaffic, Laura sho

an ARP scan loo

h... and let's dow you methodsdentify the typ course will be

ote and local hos using Nmap.

hark Jumpstartvent. Laura

affic and more.Q&A and more.

P/IP Communic

Other

unctionality and

a g e 7

ce nd ous

and ows oks

o it on for

pes of e osts,

t

cations

r Tools

d Tips

All Access

CS50: W

CS52: W

CS54: IC

CS55: A

Pass (www.lcu

WLAN ANAL

WIRESHARK

CMP ANALY

NALYZING

uportal2.com) -

LYSIS 101

Author: Category: CPE Credits:

In this coursChanalyzer ainterferenceWireshark - capture andthe two typetypes of WLA

K 201 FILTE

Author: Category: CPE Credits:

Learn how Wvarious situanumerous h

YSIS

Author: Category: CPE Credits:

Laura explaitypes of ICMugly color fil

GOOGLE S

Author: Category: CPE Credits:

This course aat the commfeatures of Ginformation really hide o

- Dated April 2

Laura ChappeOther

1.5

se Laura beginsand the Wi-Spye. Next, Laura texplaining the aggregate trafes of WLAN heAN traffic and

ERING

Laura ChappeWireshark Fu

1.5

Wireshark applations, where tot filters includ

Laura ChappeTCP/IP Comm

1.5

ns the newest MP traffic you D

ters to identify

SECURE SE

Laura ChappeOther

1.5

analyzes a stanmunications duGoogle's Securbeing passed

our search term

014

ell

s from the grouy Adapter usedtakes you into purpose of thffic on multipleaders (Radiotaapply decrypti

ell unctionality an

ies capture anthe capture/diding coloring f

ell munications

dissector for IDON'T want to y suspect ICMP

EARCH

ell

ndard Google sring a "Google

re Search wereon to the targe

ms and not let t

und up - begind to identify Wthe world of ce AirPcap adape channels, creap and PPI). Yoion methods to

d Tips

d display filtersplay filter fileilters.

CMP traffic (insee and how t

P traffic.

search (http://e Secure Searche touted as "enet site. We exathe target kno

ning with a deWLAN signal stre

apturing WLANpters and the seate a WLAN-sou'll learn the to the traffic.

rs, what filters s are kept, how

ncluding LE/BE to create three

/www.google.ch" (announced

ncrypted searchamine the traffw from whenc

Wireshark Fu

TCP

P a

monstration oength and N traffic using set-up processpecific profile

tricks to identif

you might usew to create

designations),e must-have bu

com) and then d in 2010). Key hes" and no REfic to see if we ce we came.

unctionality and

O

P/IP Communic

O

a g e 8

of

s to for fy the

e in

, what utt-

looks

EFER can

d Tips

Other

cations

Other

All Access

CS56: S

CS57: T

CS58: P

CS59: C

Pass (www.lcu

LOW NETW

CP VULNER

ACKET CRA

APTURING

uportal2.com) -

WORKS - NO

Author: Category: CPE Credits:

Learn how 4problems. Inrule.

RABILITIES

Author: Category: CPE Credits:

This course cneed to knoit’s not just aand how to communicatthe Recordeas part of yothe 3 DoS at

AFTING TO

Author: Category: CPE Credits:

Learn to usecapture the (Tools: Wire

PACKETS

Author: Category: CPE Credits:

This course iangle to pac

- Dated April 2

OPS/SACK

Laura ChappeTroubleshoot

1.5

4 NOPs indicatencludes TCP Op

S

Laura ChappeSecurity and

1.5

covers the TCPw that one of ta Microsoft isscreate Wireshations easier. Th

ed Wireshark Juour membershittacks listed in

O TEST FIRE

Laura ChappeSecurity and

1.5

e a seed packetpacket in Wireshark, Colasof

(SECURITY

Laura ChappeSecurity and

2

is based on thecket capture in

014

ell ting

e problems witptions analysis

ell Network Foren

P vulnerabilitiethe vulnerabiliue. The video ark filters (disphere are trace umpstart + Bonip. the profile iMS09-048.

EWALLS

ell Network Foren

t, edit the packeshark and locat Packet Builde

Y FOCUS)

ell Network Foren

e Jumpstart 10cluding inform

th interconnecand creation o

nsics

s announced bities affects Cisshows you wh

play and color files in the Counus (you all haincluded with t

nsics

ket contents, rate it quickly uer, NetScanToo

nsics

01 Course (CS4mation on captu

cting devices anof a "4 NOPs" b

by Microsoft - sco, Linux, Ope

hat the vulnerafilters) to see purse Guides seve access to ththat video will

eplay the packusing a color filols Pro)

41), this courseuring in stealth

Security an

Security an

Security an

P a

nd create traffbutt-ugly color

MS09-048. YouenBSD, and mobilities are basproblem ction. I referen

hat course - CS already catch

ket on the netwter in Wiresha

takes a securih mode.

nd Network Fore

d Network Fore

d Network Fore

Troubleshoot

a g e 9

fic ring

u ore – sed on

nce S41 -

2 of

work, rk.

ty

ensics

ensics

ensics

ting

All Access

CS60: T

CS61: T

CS62: T

CS63: 10

Pass (www.lcu

ROUBLESH

SHARK CO

ROUBLESH

0 ESSENTIA

uportal2.com) -

HOOTING W

Author: Category: CPE Credits:

Learn to specourse, Laurnumerous e

MMAND-LI

Author: Category: CPE Credits:

Learn to useinterface seltraffic statist

HOOTING W

Author: Category: CPE Credits:

The nine seccause of netdetails in theand fabuloudetails.

AL WIRESH

Author: Category: CPE Credits:

This course iWireshark skProfile ImpoScales, TCP Dstream” to FName Extrac

- Dated April 2

WITH COLOR

Laura ChappeTroubleshoot

1.5

eed up your trora goes throughxamples of col

NE CAPTUR

Laura ChappeWireshark Fu

1.5

e Tshark - Wirelection, saving tics and export

WITH EXPER

Laura ChappeWireshark Fu

1.5

ctions in this cotwork performe TCP dissectos graphing tec

HARK SKILL

Laura ChappeWireshark Fu

1.5

is based on a likills: Key Word

orting, Add FilteDelta GraphingFilter out Normction and Use (

014

RING

ell ting

oubleshooting h the fundameloring rules you

RE

ell unctionality an

shark's commato file sets, us

ting specific fie

RT INFO

ell unctionality an

ourse focus onance problemsr, causes of vahniques to cor

LS

ell unctionality an

ive AAP event.d Filtering, Set er Expression Bg, Export Colum

mal Traffic, Split(Tshark).

processes by centals of coloriu absolutely m

d Tips

and-line captusing the ring bueld information

d Tips

using the Exps. This course irious Expert In

rrelate through

d Tips

. Laura demonsup UnattendeButtons, Advanmn Informationtting Trace File

coloring packetng in Wireshar

must have.

re tool. This couffer, filtering tn.

ert Info to quicincludes readinnfo Errors, Warhput problems

strates the folld Capture withnced IO Graphn to .csv Formaes (Capinfos th

Wireshark Fu

Wireshark Fu

Wireshark Fu

P a

ts of interest. Irk and gives yo

ourse covers traffic, viewing

ckly detect theng Expert Info rnings and Not with Expert In

lowing 10 esseh the Ring Buffing with Logarat, Use “Follow

hen Editcap), H

Troubleshoot

unctionality an

unctionality and

unctionality and

g e 10

In this ou

g

e

tes, nfo

ential fer, ithmic

w ost

ting

d Tips

d Tips

d Tips

All Access

CS64: R

TRACE F

TRACE F

TRACE F

Pass (www.lcu

EGEX PRIM

FILE ANALY

FILE ANALY

FILE ANALY

uportal2.com) -

MER

Author: Category: CPE Credits:

This course tWireshark. Tthreats.net Swith a wildca Regex with

YSIS - SET

Author: Category: CPE Credits:

Watch Laura* a printing network * a sequence * Apassword cricon toolbar

YSIS - SET

Author: Category: CPE Credits:

Watch Laurabreached cliboot procesDNS MX recoDocuments

YSIS - SET

Author: Category: CPE Credits:

Watch LauraSloooow DNComparing Hfor a poisontrace files (c

- Dated April 2

Laura ChappeWireshark Fu

1.5

takes you throTopics include Snort rule, seaard/group/inteh Wireshark Qu

1

Laura ChappeTrace File An

1

a analyze varioproblem * illegnetwork scan

ARP used to piracking This clar) for you to pra

2

Laura ChappeTrace File An

1

a analyze varioent * DHCP ses * DHCP reneord lookup * Dbutton on the

3

Laura ChappeTrace File An

1

a analyze varioNS response * DHTTP performaer * Another blick the Docum

014

ell unctionality an

ugh the key coRegex flavors, rching for a chegral qualifier/uick Reference

ell alysis

ous traffic pattegal source IP ad* a lousy hote

ing a local hostass includes theactice on!

ell alysis

ous traffic patterver discoveryw to rebind pr

DNS PTR querieicon toolbar) f

ell alysis

ous traffic patteDNS TTL issue *ance * Somewhbreached host *ments button o

d Tips

oncepts of usinmetacharacte

haracter/word//anchors/charae Guide.

erns including:ddress * some

el network * ARt * ARP used foe trace files (cl

erns including:y types * DHCProcess * dictiones. This class infor you to prac

erns including:* DNS walking hat OK HTTP p* FTP cracking

on the icon too

ng Regular Expers, sample use/hex string/nuacter classes. T

: * honeypots aeone sneaking tRP process duror discovery * ick the Docum

: character gen ACK informatnary attack * Dncludes the tractice on!

: * DNS root se* Lousy HTTP

performance * g attempt This colbar) for you t

Wireshark Fu

P a

ressions with e in emerging-mber, and seaThis course inc

attacking eachtraffic throughring a bootup brute force

ments button on

nerator behavioion * normal D

DNS domain erce files (click t

erver queries *file download Ettercap checkclass includes to practice on!

Trace File Ana

Trace File Ana

Trace File Ana

unctionality and

g e 11

rching ludes

other h the

n the

or * DHCP rors * he

*

king the

alysis

alysis

alysis

d Tips

All Access

WHITEB

CORE 1:

CORE 2:

Pass (www.lcu

OARD LEC

: WIRESHA

: TROUBLE

uportal2.com) -

TURE SER

Author: Category: CPE Credits:

In this seriesconcepts sucframe struct

RK FUNCT

Author: Category: CPE Credits:

[To be replacourse, you communicatprepare for tfeatures of Won reviewingand most coSMTP. With this course,

ESHOOT/SE

Author: Category: CPE Credits:

[To be replacourse, you securing netfile evidencestrong emphyou'll gain sk

- Dated April 2

IES 1

Laura ChappeWhiteboard L

1.5

s of courses, Lach as switchingture.

IONALITY A

Laura ChappeWireshark Ce

23

ced with the Wwill discover etions by examithe WiresharkWireshark, theg both the nor

ommon applicaa strong emphyou'll gain skil

ECURE NET

Laura ChappeWireshark Ce

25

ced with the Wwill discover e

tworks by exame of reconnaisshasis on handskills that can b

014

ell Lecture Series

aura takes to thg vs. routing, M

AND TCP/IP

ell ertification

WCNA Boot Cameffective Wiresning both propCertification E

e world's most mal and abnor

ations, includinhasis on handsls that can be u

WORKS WI

ell ertification

WCNA Boot Cameffective Wiresmining both prsance processe-on lab exercise used immed

he whiteboardManchester en

P ANALYSIS

mp Class in 20hark operationperly and poorExam. One-halfpopular analyzrmal communing DHCP, DNS, -on lab exercisused immediat

ITH WIRESH

mp Class in 20hark techniqueoperly and poo

es and evidencses and real-woiately followin

d to draw out scoding and the

S

13] In this selfns and packet-rly performing f of this class fzer. After that,ication patternFTP, Telnet, H

ses and real-wotely following t

HARK

13] In this selfes for troublesorly performin

ce of breached orld case studig the class.

W

W

White

P a

some basic nete beloved Ethe

-based lab-intelevel TCP/IP networks as yo

focuses on the , this course fo

ns of the TCP/IPTTP, POP, and orld case studithe class.

-based lab-inteshooting and ng networks, tr

security. Withies in this cour

Wireshark Certif

Wireshark Certif

board Lecture

g e 12

twork ernet

ensive

ou

ocuses P suite

ies in

ensive

race h a rse,

fication

fication

Series

All Access

[RETIRE

[RETIRE

[RETIRE

Pass (www.lcu

ED] CS53: N

ED] WIRESH

ED] CS41: W

uportal2.com) -

NEW WIRES

Author: Category: CPE Credits:

This course c

HARK 1.7 U

Author: Category: CPE Credits:

Learn the nerelease - che

WIRESHARK

Author: Category: CPE Credits:

Bonus: Laura"Laura's Stufattend this cwet with Wifilters used thow WireshWireshark toInfo Composcapabilities a

- Dated April 2

SHARK 1.4

Laura ChappeWireshark Fu

1.5

covers the new

PDATE

Laura ChappeWireshark Fu

1.5

ew features of eck out the hot

K 101 JUMP

Laura ChappeWireshark Fu

2

a's Capture, Diff" profile and class live. Now reshark - learnto focus on netark does whato show you hosite and specifand begin trou

014

FEATURES

ell unctionality an

w features of W

ell unctionality an

Wireshark 1.8t Filter Express

PSTART - O

ell unctionality an

splay and Coloimporting thesyou can take i

n where and hotwork traffic, tit does - dissew to quickly spic Time Colum

ubleshooting a

S

d Tips

Wireshark vers

d Tips

8 by looking at sion buttons fe

ORIGINAL

d Tips

or Filter sets plse files. Over 7it anytime. Thiow to tap into the basic layouectors, engine apot network prn settings. Getnd optimizing

ion 1.4.0.

the Wiresharkeature!

us video instru7,000 people hs is the ideal cnetwork traffi

ut of the Wiresand graphing. roblems using t up to speed fyour networks

Wireshark Fu

Wireshark Fu

Wireshark Fu

P a

k 1.7 developm

uctions on creaave registeredlass to get youc, the two typehark configuraLaura works wWireshark's Ex

fast on Wireshas today!

unctionality an

unctionality an

unctionality and

g e 13

ment

ating a d to r feet es of

ation, with

xpert ark's

d Tips

d Tips

d Tips