
Explore digital evidence concepts and complete the digital evidence module to clarify key ideas for network investigations.
Explore the concepts of digital evidence, key definitions, and terminologies in this introductory module, with topics to be explored more deeply in later modules.
Maintain a court-ready mindset, treating every action as potential evidence. Learn real, best, direct, circumstantial, and hearsay evidence, plus business records and network-based digital evidence.
Understand digital evidence as information admissible in court, and learn how to form hypotheses and test them against network traffic to build a credible theory.
Real evidence is tangible and verifiable, from murder weapons and fingerprints to digital packets showing IP addresses, MAC addresses, ports, and services, validating your hypothesis.
Identify best evidence as the supporting materials that validate the real, tangible evidence in a network forensics case, including photos, timestamps, locations, and captured videos.
Direct evidence is first-hand testimonial evidence, including witness accounts or digital data, and network-found data can also serve as direct evidence.
Circumstantial evidence is non-direct, yet supports the direct and real evidence with digital clues such as email signatures or files found on a device.
Explore hearsay as second-hand evidence and its variable acceptability in court. Show its usefulness for digital investigators in guiding inquiries toward relevant evidence.
View business records as logs and day-to-day network communications, not just contracts, and use anomalies in applications, services, and ports, like telnet on port 23, to guide forensic investigations.
Identify digital evidence in network packets by examining every captured packet, including email, instant messaging, and call files, and analyze packet types to uncover information.
Capture and analyze network traffic to uncover network-based digital evidence. Learn how captured communications become digital evidence using pcap files and standard analysis tools.
Frame a narrative from defined terminology and evidence types, treat everything touched as evidence for court, then form a hypothesis, gather supporting evidence, and evolve it into a theory.
Explore network evidence challenges within the certified network forensics examiner program. This module from the CNFE curriculum emphasizes understanding and addressing network evidence challenges.
Explore the challenges of gathering evidence in a networking environment, interpreting communications between entities, and building a narrative to turn observations into a theory.
Explore network forensics storage and acquisition, focusing on data captured from devices within the network to reveal traffic evidence, while respecting privacy and preserving chain-of-evidence.
Identify and capture network evidence across wireless, internal and external traffic, web-proxy traffic, logs, and configurations, while collaborating with admins to access data and preserve evidence for forensic analysis.
Capture the environment and real-time traffic to view content, including payload, metadata, and headers such as IP, MAC, ports, and TTL, painting the full picture to support the hypothesis.
Identify and preserve volatile and nonvolatile storage in a network, including device configurations, IDS rules, and logs, while safely capturing memory and switch information without altering evidence.
Navigate privacy in network forensics by balancing rights to touch and capture evidence, with internal investigations guided by HR and legal teams, and external cases requiring legal counsel.
Evaluate seizure scenarios by determining if you seize first-hand evidence or a copied network capture, and minimize interruption while preserving data integrity.
Ensure admissibility by lawfully capturing network evidence and preserving the chain of custody. Prove the evidence remains unchanged and objective to support hypotheses in court.
Review key definitions, acquisition, and content and storage, with emphasis on volatile information and careful capture. Address privacy and seizure concerns and stress collaboration with HR and the legal department.
Explore network forensics through investigative methodology and module three, applying focused techniques to analyze network events and evidence.
Oscar methodology provides a universal framework for any investigation, including network forensics and digital forensics, guiding the investigative process.
Obtain information, strategize, collect and analyze evidence, and report findings as part of a generalized, big-picture methodology for network forensics investigations.
Plan what information to capture and prepare the tools for evidence collection. Document every step with timestamps, consider legal issues, and build a timeline and hypothesis to guide court-ready inquiry.
Obtain information by understanding the investigation's scope, goals, and business process, then identify relevant networks, machines, servers, services, and logs to reveal anomalies and timing patterns.
Strategize the collection of information by mapping evidence sources, selecting tools, and planning steps to capture volatile data without powering off devices, while remaining flexible as new evidence emerges.
Develop a strategy for gathering information by identifying evidence sources, including firewall logs and ARP caches, and capturing volatile data in a table to avoid missing data.
Document every action during evidence collection, using handwritten notes or tool-generated logs to support a court-ready report. Assume the process may go to court and capture the steps clearly.
Capture digital evidence without altering it, focusing on volatile memory and hard drives, and create bit-level copies for investigation so the original remains intact for court.
Master chain-of-custody principles by capturing network evidence, owning the originals, creating a bit-level image, working on copies, and logging access for court-ready investigations.
Document every step from data capture to safekeeping and copy creation, detailing who had access and what they did. Maintain a rigorous chain of custody to ensure court admissibility.
Analyze evidence by applying metadata properties, arranging data in chronological order to build a timeline, test the hypothesis, and reveal where, when, and why events occurred.
Identify normal business processes and environment to detect anomalies and odd behaviors. Follow the evidence across devices, servers, and logs to guide the investigation and reveal key insights.
Investigators capture all data and logs upfront, then analyze to decide what is relevant, managing false positives and following every lead until evidence fits the scenario.
Adopt a flexible, evidence-led approach to network forensics analysis, following clues wherever they lead to new environments and investigations without rigid constraints.
Explore the human side of digital forensics by interpreting cases, updating hypotheses with evolving evidence, and upholding objectivity and ethics.
Craft a stand-alone report that documents how we found information, the evidence, chain of custody, and methods, so diverse audiences from judges to technical teams can understand without extra explanation.
The module covers obtaining information, strategizing, collecting the evidence, analyzing, and reporting it using the Oscar methodologies.
Attend the network-based evidence lecture within the certified network forensics examiner program and explore the network base evidence module.
Explore the network’s structure, its segments and devices, to identify where evidence is found, with upcoming modules examining network protocols in detail.
Explore cabling types and wireless networks, assess how the lack of a physical boundary affects security, and identify anomalies in day-to-day servers, switches, and protocols for forensic investigation.
Develop a network blueprint through documentation and a bird's-eye view, leveraging admins and penetration testers to identify networks, data types, and normal versus abnormal usage for forensic investigations.
Recognize common network forensics elements across different environments, focusing on devices, authentication types, ids/ips, firewalls, and the importance of centralized and volatile logs for investigations.
Explore how physical media, including twisted pair, coaxial, fiber, ATM, and token ring, carry packets, and analyze protocol and addresses while considering tapping and electromagnetic sensing for data capture.
Explore how wireless networks lack physical boundaries, making packet capture easier, and examine how forensic analysts inspect access point advertising, client authentication, and packet headers.
Explore how switches differ from hubs by using MAC address tables to minimize traffic, and learn how forensics investigators analyze switch logs and flooding attacks to reveal attacker activity.
Routers connect subnets and networks with a routing table stored in volatile memory to forward packets, share routing tables, risk loops that cause denial of service, and preserve volatile evidence.
Explore how the DHCP server assigns IP addresses from a pool to devices booting with dynamic addressing, and how leases and logs reveal who got addresses and when.
Explore how name servers and the dns zone file map host names to ip addresses, flag tampering, and detect dns poisoning in enterprise forensics.
Examine authentication servers to identify active directory, single sign-on, username/password, certificates, multifactor authentication, and smart cards; then audit logs for anomalies and brute-force patterns.
Explore how intrusion detection and prevention systems inspect packets, apply rules, log events, and alert on anomalies, guiding network forensics investigators with IP addresses and logs to detect DoS.
Understand how perimeter firewalls inspect each crossing packet and enforce rules based on origin, destination, port, application, or subnet, and how rules target application to network layers.
Explore various application servers, from web servers and SharePoint to SQL Server and Exchange, and learn how logs reveal who connected, what rights, and data transferred across server communications.
Central log servers consolidate volatile and file logs from devices, enabling forensic analysis by preserving in-memory data and allowing fast searching to trace events across machines.
Explore how to recognize normal network protocols, traffic, and services within your environment, and use logs and investigations to identify anomalies that guide forensic analysis.
Analyze packet layers in the Internet Protocol Suite to identify IP and MAC addresses, ports, and transport protocols. Understand how headers, payloads, and checksums ensure data integrity across transmission.
Compare ipv4 and ipv6 addressing, noting 32-bit versus 128-bit schemes and the enormous ipv6 address space; forensics highlights anomalies when ipv6 appears in ipv4 networks and discusses security implications.
Examine how IPv4 and IPv6 packets differ, illustrating overhead and security implications through example packets.
This lecture contrasts tcp and udp, describing tcp as reliable transport with packets, while udp is a broadcast lacking reliability, involving source and destination ip addresses and 32-128-bit variants.
Compare TCP and UDP, noting that UDP streams with lower overhead and faster delivery but is unreliable, while TCP carries more header information and offers reliability.
Examine physical cabling evidence, review cable types, and compare wired and wireless network security. Gather data from switches, dns, and other network devices to detect anomalies across machines and servers.
Master network principles in module five of the certified network forensics examiner program. Align your skills with CNFE curriculum.
Explore the principles of Internet connectivity and networking within networks, and understand how these concepts enable reliable data exchange in digital communications.
Explore the oocyte model, an internationally accepted standard for any new computer communication in telecommunication that will be publicly available and must satisfy this standard.
Explore the western model and TCAP, based on the OSI model, standardized in the 1980s to ensure interoperable communication across hardware and applications.
Trace the history of communication protocols from early Darpa efforts to the first standards, emphasizing interoperability across hardware and software through universal models.
Explore the seven-layer functionality model for transforming raw machine data into tangible signals, converting binaries into electrical, optical, or radio forms to travel across media.
Explore the seven OSI model layers from physical to application. Learn how firewall rules target layer two and layer three to control traffic.
Establishes the foundation of a standard where publicly used communications must satisfy the ASI model and the ozone model, ensuring interoperability between hardware and software.
Describe how the OSI model formats raw data into packets across seven layers, enabling end-to-end communication over media such as ether, wifi, or fiber.
Explore how the seven-layer OSI model encapsulates data from the application layer to the physical layer, passing it layer by layer until bits become tangible signals for transmission.
Describe how data starts at the application layer, selecting the right tool and application, then undergoes encapsulation through successive layers until it reaches the physical layer.
Explore how the OSI model encapsulates data layer by layer from application to physical, adding headers and footers that carry destination addresses like IP and MAC and a checksum.
Explore encapsulation and de-encapsulation as data moves through every layer until the physical layer, the tangible part that actually travels across networks.
Describe encapsulation from the application down to the physical layer at the source and de-encapsulation from the physical layer to the application at the destination, per the seven-layer model.
Each layer, from application to physical, has a specific function and carries information about that function, and layers communicate only with their peer during encapsulation and de-encapsulation.
Illustrates how the OSI model's peer layers' logical channels exchange encapsulated data from source to destination, with each layer understanding the other's formatting through the same standard.
Define data stream, segment, datagram, packet, and frame, and align them with the application, transport, network, and data link layers, using Wireshark to analyze captured traffic.
Illustrate the OSI model data names from application to physical, detailing application data stream, transport segment, network packet, data link frame, and bits for forensic packet analysis.
Explore the seven-layer encapsulation model and how each layer, from physical to application, communicates with its peer to move data across a network.
Explore the internet protocol suite in module six, as part of the certified network forensics examiner course.
Explore the TCAP IP suite and how IP addressing is configured from the bindery level to the machine. Compare the IP, TCAP, and UDP layers with the OS side model.
Explore the VIP suite and its components, and learn to distinguish normal from abnormal network traffic. Recognize anomalies to uncover attacks or unauthorized access.
Trace the defense department's creation of the tcp/ip suite, its four-layer view, and its contrast with the seven-layer osi model across application, transport, ip, and network access.
discover how the tcap ip suite, with four layers—application, transport, ip, and hardware—encapsulates data, chooses tcap or udp transport, and uses arp and ttl to deliver packets.
The tool selects the application for us and provides examples of different applications. The application layer formats and encapsulates data according to the chosen application to reach the raw data.
Explore how the transport layer decides how data packets reach the destination, with users unable to control this choice; browsers typically use tcp, while some tools use udp.
Identify layer 4 protocols, with a focus on udp traffic, and note that tcap udp is the most commonly encountered among other protocols.
Explore the internet layer, focusing on IP, ICMP, and ARP, and examine how ARP cache dynamics, with dynamic versus static entries, use MAC addresses and have limited lifetimes.
The network access layer converts binary data into tangible signals that travel over media, including electrical signals, light (photons), or radio waves in wireless environments.
Compare OSI layers with tcp/ip layers by mapping application, presentation, and session to the application layer, transport to transport, internet to network, and data link plus physical to tcp/ip.
Explore the similarities of the OSI and TCP/IP models, highlighting layered encapsulation and how both perform the same function in different steps.
Compare the OSI and TCP/IP models, highlighting how the application, presentation, and session layers relate to the same end result despite different steps.
Explain how identical encapsulation and formatting across sender and receiver with the TPP suite enables packets to traverse routers and subnets unchanged across networks.
Examine IPv4 structure, its 32-bit addressing, and how packets are broken down, then compare IPv4 with IPv6.
Examine how IP version four uses 32-bit binary addressing with four octets to separate network and host parts, using subnet masks, classful A/B/C schemes, and classless addressing.
Convert decimal to binary by following the machine's first steps. Take the IP, apply the subnet mask, and perform the addition to produce the results.
Discover IP address classes A, B, and C, and the rarely discussed class D, which represents a network-only or broadcast-like environment with no hosts.
Discover IP address classes a, b, and c and learn which parts designate the network versus the host.
Decode ip addresses as decimal numbers by breaking down the bits, exploring how decimal representations relate to network forensics concepts.
Explore classful ip addressing, compare class a, b, and c networks, and explain why we moved to classless addressing with subnet masks and host portions.
Break down the network and host parts to identify network IDs and broadcast addresses, building practical understanding from the demonstration.
Private IP addresses power internal networks; internet access requires a publicly leased IP from an ISP. The lecture highlights private internal ranges like 10, 172, 192, and 121.
Learn about reserved address space, including reserved IPs and DNS-specific ranges, and how route and DNS IP addresses starting with 192 are designated for special uses.
Learn the basics of subnetting to control traffic by splitting an IP address space into subnets, using the network portion and subnet mask, and route traffic between subnets via routers.
Break down the subnetwork by examining how to create and designate portions of a network for clear subnetwork design.
Learn how subnets divide a large network into smaller, distinct networks, including virtual subnet environments managed by switches that separate devices on the same physical network.
Explain how the subnet mask reveals which portion of an IP address is the network and which is the host, clarifying the mask's objective.
Explain subnet masks and classful addressing, showing how changing the mask shifts host counts and applying two to the power of n minus two to calculate available hosts.
Compare IPv6’s 128-bit addressing to IPv4, highlighting the hex environment and larger overhead for security. Explain IPsec policy since 2008 and encrypting the entire packet in peer-to-peer communications.
Compare IPv4 and IPv6, noting IPv4's 32-bit addresses and IPv6's 128-bit expansion to more addresses, enabling stronger security and encryption.
Explore the transmission control protocol as a connection-oriented, session-oriented protocol, where the packet header declares source and destination IP addresses and includes the MAC address.
Explore UDP packet structure from a forensics perspective, using Wireshark to identify the header and the source and destination ports in the hex bytes.
Explain how arp finds the mac address of the destination machine before a session, using a special type of broadcast to contact the target.
Explain ARP communication within a subnet, where a broadcast request discovers the destination and a reply returns from the destination, with routers allowing the message to pass.
Explore the arp process within the TCAP suite and VIP communication suites, and review how our process was explained.
Explain how the default gateway directs traffic to other networks via the router's first IP address. Note that this address, often 192.168.1.1, identifies the gateway on the router's network card.
Review the default gateway as discussed in the CNFE course, highlighting its role within network forensics.
Explore how arp uses broadcast to reach the destination and receive the reply, showing the data flow back to remote networks.
Explore how routers act as proxy ARP, listen for broadcasts, and regenerate and pass them to the next network card to enable signal flow between networks.
Trace the history of the TCAP IP and explain how the TCAP IP suite works, including IP addressing, binary breakdown, and subnet mask.
Engage with physical interception concepts in module seven of the certified network forensics examiner course.
examine the physical layer of networks, including cables and radio frequency in wifi environments, and understand hubs and switches and related attacks on switches versus hubs.
As a forensic network forensics investigator, capture packets within the network while minimizing changes to avoid altering evidence, balancing active and passive sniffing.
Explore physical interception of network traffic by capturing packets on the cable or at the switch using inline network taps, vampire taps, induction coils, and fiber optic taps.
Pigeon sniffing targets traffic between a specific source and destination, challenging forensics and often requiring active sniffing in metropolitan networks using avian carrier RF C11.49.
Explores the physical layer of networks, detailing copper and optical fiber cables, and demonstrates methods to tap and sniff traffic directly from cables with minimal footprint.
Explore copper cables, including coaxial and twisted pair, highlighting shielding and the ability to deter electromagnetic field detection, while twisted pairs reduce interference and protect data transmissions.
Explore optical fiber technology, including how light signals travel through glass or plastic cables, bounce off walls, and lose energy, necessitating repeaters every 50 kilometers.
Explains radio frequency signals, their megahertz ranges, and how data passes through channels. Highlights how the lack of a physical boundary enables passive sniffing for forensic investigators while aiding attackers.
Capture wifi packets reveals rich information, including the ssid advertised by access points, and header data such as source and destination ip addresses and mac addresses.
Inline network taps duplicate packets and sniff traffic without interrupting communication, using a four-port device that copies traffic to a monitoring system.
Explore the vampire tap technique by intercepting copper lines in coaxial or twisted pair cables to sense electrical signals and recapture data packets.
Examine radio frequency in wireless environments, including passive sniffing and promiscuous mode to capture all traffic, and weigh the implications for forensics investigators.
Learn how forensic investigators capture wireless traffic to reveal access point identifiers, source/destination IP and MAC addresses, and security details like encryption and authentication, by analyzing captured packets.
Explore how hubs broadcast every packet to all ports, enabling passive sniffing and easy capture of all network traffic for monitoring and forensics.
Understand how switches build a mac address table to forward traffic, why flooding converts a switch to a hub for sniffing, and how poisoning and dns poisoning enable traffic capture.
Learn how newer switches use span port analyzer (port mirroring) to duplicate packets and send them to a dedicated port for traffic capture, enabling full network visibility without flooding.
This lecture explains mac flooding: flooding the switch with bogus mac addresses fills the mac address table, forcing broadcasts and misrouting of traffic.
Explore the main cable types, copper, coaxial, twisted pair, and fiber, and how to intercept traffic via taps or electromagnetic sensing, with noninvasive advantages for hubs and switches.
Delve into traffic acquisition software in module eight of the certified network forensics examiner program.
Explore the core packet capture technologies behind sniffing, including libpcap and winpcap, the Berkeley packet filter language, and tools such as tcpdump, windump, Wireshark, and tshark.
Explore libpcap and WinPcap in network forensics, focusing on packet capture capabilities and their role in analyzing traffic for investigations.
Learn how libpcap and WinPcap enable packet capture and saving traffic for analysis across layer 2 through layer 3, including header details and ports, using tcpdump, wireshark, mergecap, and grep.
Explore libpcap and winpcap installation across Linux and Windows environments, outlining the setup steps for each tool in a practical introduction.
Install libpcap using the rpm in a Linux Red Hat environment, requiring root privileges and proper rights to execute install via rpm commands.
Install the correct rpm version for libpcap using rpm -iv, download the right rpm, then verify the installation with rpm -q to ensure no errors.
Learn how to download and install libpcap from a tarball, understand tarball concepts, and run the configure, make, and make install steps in a Lennix environment.
Configure libpcap from the source by downloading, unzipping, extracting to a directory, changing to that directory, and running the configure script to prepare for installation.
Compile the libpcap source code with make, then run make install to place files into the required directories, using sudo when root access is needed.
Discover how to install winpcap, download the Windows version of pcap, and install this free tool.
Install WinPcap on Windows is far simpler than on Linux; download the file, double-click it, accept licensing, and finish to complete the installation.
Explore how the core engine enables packet capture, with files saved as .pcap, to dissect and examine the details of captured network packets.
Explore the Berkeley Packet Filter language, a syntax that allows us to search for details of what we want.
Learn to extract specific information from network packets using packet filtering, comparing bite-value and bit-value filters to efficiently sort and locate data.
Learn to use filters across layer two, three and four to pull targeted data, combining single or multiple queries with and/or logic to narrow by host or IP range.
Explore bpf primitives to narrow capture filters using type, direction, and protocol qualifiers. Define hosts, ports, subnets, and ip addresses, then combine source and destination filters for specific traffic.
Explain how a byte contains eight bits, where each bit position (zero to seven) has meaning, and how to filter packets by byte value using those bit-level rules.
Show how byte-level filtering uses bit positions within a byte to locate information such as host name, port, network, subnet, IP address, and protocol using the BPF language.
Learn bit-level filtering by targeting bit offsets (0 to 7) and hex values, enabling precise file-definition searches beyond byte-level methods.
Learn to filter packets by bit positions, such as the 13th bit with value two and the 18th for sin acknowledgment, using tools like Wireshark that translate bit-level filters automatically.
Explore how PPF primitives enable search operations and filtering by bit values, highlighting practical approaches to apply these techniques in network forensics.
Explore the tcpdump tool and related tools in the context of network forensics as the session reviews practical usage and tool capabilities.
Discover the tools for tcp dump, understand straightforward installation in Windows and Lennix environments, and review practical filter examples for tcp dump usage.
Trace the background of TCAP dump and its analysis tools, including Linux lipcap and Windows windump, and explain their emergence from the early 1990s to the late 1990s.
Declare which network card to capture traffic on when performing a TCAP dump; otherwise it defaults to the first card, typically eth0, in a Linux environment.
Learn tcpdump basics: list interfaces with -D, select a specific interface with -i, or use -i any to capture across subnets; disable name lookups with -n to speed captures.
Install tcpdump on Windows by downloading it from the provided link; the Windows version is a wind dump, and some IT guys just look at the installation part of it.
Installing tcpdump on Windows is straightforward: download the executable, run it with default settings, and complete the installation.
Install tcpdump on Linux using a detailed step-by-step guide, mirroring the proven installation process shown in the source files.
Install tcpdump on Linux by unzipping and extracting the tarball, changing into the directory, and running ./configure, then make and make install, following the exact same installation process.
Install tcpdump on Linux by following the make and make install steps, using sudo as needed. The steps are identical across Linux installations.
Use a dedicated interface to filter packets with tcpdump, applying validated filtering criteria and viewing results produced by the underlying technology.
Learn to filter packets with tcpdump by capturing all traffic while excluding tcap ports, such as 445, and apply the familiar syntax for these filters.
Explore the TCAP dump interface and its function, with syntax examples. Review the installation on Windows and Linux and examine the syntax demonstrated.
Explore Wireshark, the widely used free tool for sniffing and analyzing network packets, and learn how its gooey interface eases packet inspection.
Install Wireshark and perform protocol analysis to identify the types of information that can be found in captured traffic.
Understand how Wireshark runs identically on Windows and Linux for effective traffic capture. Compare promiscuous and non-promiscuous modes, including MAC address filtering and silent traffic behavior.
Install Wireshark on Windows by downloading the software, accepting the licensing terms, and completing the straightforward installation on Windows.
Install wireshark on Linux systems using common package managers like apt-get or rpm. The lecture explains that Linux installation is straightforward and similar across methods.
Explore how the Wireshark protocol analyzer uses filter syntax to search and analyze data, highlighting a user-friendly graphical interface that enables byte- and bit-level inspection with click-based filtering.
Explore Wireshark, its purpose, and the installation process, then perform initial analysis of captured data. Observe that the syntax remains identical across steps.
Explore Tshark, the command line version of Wireshark, and understand why this tool is described as the command line counterpart to Wireshark.
Explore the tshark command line interface for Wireshark and examine what information it can and cannot provide in network forensics.
Use tshark, the command-line equivalent of Wireshark, on Linux; use the -h option to view switches and pipe to a manual for more detail on filtering and analysis.
Tshark, the command-line counterpart to Wireshark, uses the same syntax to build capture filters. See examples that show typing -f filters and excluding tcp port 445 with a not operator.
Explore using tshark filtering to narrow traffic data and reveal what you’re looking for. Discover how the -z option displays specific statistics and trends from filtered results.
Explore practical examples of using tshark for network forensics, showcasing command-line filtering and the lightweight, powerful alternative to Wireshark.
We examined tshark and used the -z option to obtain detailed statistics of the filtering we perform.
Master live acquisition in module nine of the certified network forensics examiner (CNFE) program. Apply core live acquisition concepts within the CNFE curriculum.
Explore three areas of network forensics by examining interfaces investigators encounter across server and client environments, and practice information gathering without accessing a machine via import and vulnerability scanning.
Explore common interfaces in network forensics to understand how different systems expose data for analysis within the CNFE framework.
Explore console connections, ssh and sftp usage, and web-based management interfaces, then assess the security weaknesses of telnet and snmp and information exposure.
Network forensic investigators assess the big picture by collecting logs and data from firewalls, routers, and intrusion systems to reconstruct events, while minimizing disruption and enabling live acquisition.
Identify which devices generate network information, determine how it is created, and plan live acquisitions, packet capture, and bit-level imaging while preserving evidence for court admissibility.
Secure shell encrypts command-line traffic to protect remote administration. Forensic investigators assess SSH by examining source and destination to confirm normal usage and spot abnormal client-to-client patterns.
Explore securing file transfers with SCP and SFTP, emphasizing encryption, private keys, and algorithms, and discuss network forensics questions about whether encrypted communication is normal and why.
Telnet remains a powerful, old tool accessed via command lines to modify configurations and services, often unused by clients but flagged by investigators when port 23 traffic appears.
Monitor SNMP traffic to a centralized management server and expose MIBs for server health; note that v1/v2 clear text, while v3 offers encryption.
Assess SNMP activity to distinguish normal from anomalous traffic, highlighting that SNMP v1/v2 uses clear text and community strings, and advocate upgrading to SNMP v3 for encrypted communications.
Explore how web interfaces on routers, switches, and access points reveal unencrypted information for forensic investigations. Learn how attackers could exploit these interfaces and guide next steps.
Explore network interfaces and environments from a technology perspective, then secure the data we upload and download with secure copy and ftp, while evaluating telnet and web interface encryption.
Explore methods to inspect information without physically accessing a device, enabling remote data gathering from that machine.
Identify open ports and infer services from a Windows environment, noting reserved ports 1–1024, the 1025–65535 range, and the Beast trojan on port 6666.
Explore port scanning by examining the three-way handshake and tcp flags, showing how attackers probe ports with minimal communication using map or zenmap, and guide log investigations.
Conduct vulnerability scanning to identify weaknesses, such as open ports and unpatched Office 2010 software with a buffer overflow vulnerability, using multimode scanning to infer operating systems from packets.
Explore how vulnerability scanning tools aid forensic investigators by analyzing port scanning, three-way handshake abuse, and how minimal communication reveals a porous open without establishing a session.
Develop your strategic approach by outlining key to-dos and don'ts for effective network forensics practice.
Identify essential dos and don'ts for forensic and digital investigators to focus attention on key practices.
Avoid powering down active machines in digital forensics and minimize changes; only power off if attack is evident to salvage data, and perform bit-level imaging on copies to preserve evidence.
Connect remotely to gather information without physically accessing the machine or altering its logs, using import scanning as the strategy.
Document every action and result, recording precise time stamps from the machine, noting time zone differences and any log discrepancies or manual records to ensure an accurate final forensic report.
Examine volatile data in memory, avoid powering off devices to preserve evidence, and create a bit-level image of memory using a tool like in case to recover memory-level artefacts.
Record investigative activity at every step and make conscious notes. Document the end result in notes or reports, and create records if tools don’t generate them.
We review the dos and don'ts and strategies presented in this section, offering practical guidance for applying network forensics practices.
Explore layer 2 protocol concepts through module 10. Apply practical techniques relevant to network forensics within this course.
Examine the wireless environment from a forensic perspective, focusing on packets captured at the data link layer (layer 2) and issues related to the ATO 211 suite.
Explore wireless frequency ranges—2.5 GHz, 3.7 GHz, and 5 GHz—and recognize that higher frequencies reduce coverage, aiding detection of rogue access points in forensic investigations.
Explore layer 2 protocols and how collision detection enables reliable wired communication with csma/cd, while wireless networks rely on collision avoidance due to the limitations of detection.
Learn how csma/cd uses Aloha-inspired packet trailers and voltage sensing on the wire to detect collisions and employs random delays to avoid simultaneous transmissions.
Observe that wireless nodes see only the access point and cannot transmit and receive simultaneously, so collision detection fails; they rely on collision avoidance with backoff.
Investigate the 802.11 protocol suite by identifying management, control, and data frames, and learn to capture packets and identify forensics-relevant portions in wireless networks.
Explore 802.11 management frames and their header role in wireless communication, including ip addresses, mac addresses, and the service set id that reveals which access point the node communicates with.
Explore 802.11 protocol suite frame types, with a focus on management frames and the information revealed by hex data for forensic investigators.
Explore how 802.11 control frames manage wireless access with request to send, clear to send, and acknowledgement, enabling collision avoidance.
Examine the data portion of the frame—the payload or raw data sent in a packet—and understand the three main areas and the information types within the data portion.
Explore how data bits and payloads are transmitted and stored in memory within the 802.11 protocol suite. Examine how NDIS governs this process and compare two primary NDIS types used.
Explore big-endian and little-endian byte order, revealing how memory storage and packet assembly influence decoding in wireless forensics. Understand why correct endianness matters for accurate data reconstruction.
Explore how 802.11 protocol endianness affects packet framing and forensic analysis, showing how Wireshark and other tools detect big-endian versus little-endian data to present correctly ordered frames.
Explore how wireshark interprets 802.11 protocol data, revealing protocols, applications, and port usage, and recognizing endianness to display frames.
Explore why wired equivalent privacy (wep) failed to secure wireless networks: weak algorithms, small initialization vectors, and repetitive key digests exposed encryption details through packet capture.
See an 802.11 frame captured in Wireshark and identify its use of WPA, illustrating how wireless traffic is analyzed in network forensics.
Explore how the extensible authentication protocol (EAP) extends authentication and encryption beyond username-password or certificates, enabling additional protocols like TLS to secure wired and wireless networks under 802.1X.
The section examines the wireless environment, focusing on the layer 2 plane and the 802.11 protocol suite. It highlights collision detection and collision avoidance and notes wireless-specific problems to watch.
This course was originally designed only for the U.S. Agency for Government Intelligence. The CNFE certification program is designed to prepare students to master true advanced networking forensics strategies through the use of open source laboratories in an exclusive cyber-range.
The CNFE takes digital and network forensic skills to the next level by navigating through over twenty network forensic theme modules.
The CNFE provides practical training through our laboratory simulations that replicate real-world situations that include the inspection and recovery of network data, Physical Surveillance, Information Collection, Analysis, Wireless Attacks and SNORT.
The course focuses on the centralization and analysis of monitoring mechanisms and networking devices. SIGN UP NOW!
This course was originally designed only for the U.S. Agency for Government Intelligence. The CNFE certification program is designed to prepare students to master true advanced networking forensics strategies through the use of open source laboratories in an exclusive cyber-range.
The CNFE takes digital and network forensic skills to the next level by navigating through over twenty network forensic theme modules.
The CNFE provides practical training through our laboratory simulations that replicate real-world situations that include the inspection and recovery of network data, Physical Surveillance, Information Collection, Analysis, Wireless Attacks and SNORT.
The course focuses on the centralization and analysis of monitoring mechanisms and networking devices. SIGN UP NOW!