
Learn digital evidence concepts for network forensics, including real, best, direct, circumstantial evidence, and hearsay. Analyze network traffic and logs to form hypotheses that become court-ready theories supported by evidence.
Navigate network evidence challenges: acquisition and storage of content from traffic and devices, including volatile data, with privacy, seizure, and chain of custody considerations.
Explore how network forensics investigators identify normal vs anomalous network activity across switches, routers, DNS, DHCP, Active Directory, logs, and intrusion detection and prevention systems.
Discover the OSI seven-layer model, encapsulation, and how data moves from the application to the physical layer, with headers, footers, and layer-specific analysis.
Explore the TCAP IP suite and IP addressing from binary to layered models, covering IP layer, ARP, ICMP, IGMP, MAC addresses, TTL, and how investigators identify normal versus anomalous traffic.
Examine how physical interception covers copper and optical fiber media, radio frequency, hubs and switches, and passive versus active sniffing with in-line network taps and vampire taps.
Learn traffic acquisition with libpcap and winpcap, capture packets using tcpdump and wireshark, and filter with berkeley packet filter language to analyze headers across layers 2–4.
Explore live acquisition techniques for network forensics. Confirm interfaces, encryption, and minimal footprint while inspecting ports, logs, and web interfaces to uncover evidence.
Explore the layer 2 wireless protocol 802.11 forensics focusing on collision avoidance vs detection. Examine management, control, and data frames, SSIDs, and encryption evolution from WEP to WPA2 with EAP.
This course is provided directly by Mile2®. This official Mile2® video includes an authorized exam prep and exam simulator, available upon request.
The Certified Network Forensics Examiner vendor-neutral certification was developed for a U.S. classified government agency. The C)NFE takes a digital and network forensic skill set to the next level by navigating through over twenty modules of network forensic topics. The CNFE provides practical experience through our lab exercises that simulate real-world scenarios that cover investigation and recovery of data in a network, Physical Interception, Traffic Acquisition, Analysis, Wireless Attacks, and SNORT. The course focuses on the centralizing and investigating of logging systems as well as network devices.
The Certified Network Forensics Examiner exam is taken online through Mile2’s Assessment and Certification System (“MACS”), which is accessible on your mile2 account. The exam will take 2 hours and consist of 100 multiple choice questions. The cost is $400 USD and must be purchased directly from Mile2®.