
Learn to use Wireshark for traffic analysis and packet sniffing in digital substations. Explore basic settings, IEC 6150 message analysis, sampling values, and reporting in a practical session.
Learn how packet sniffing captures and interprets live network data to troubleshoot and analyze communication patterns in substation networks, using tools like Wireshark to inspect protocols, stacks, and Ethernet frames.
Master Wireshark filters, including capture filters to limit data during capture and display filters to visualize packets, using BPF syntax and saved toolbar buttons for goose messages and SV frames.
Mark and navigate packets, add in-packet commands, and filter commanded frames in Wireshark; share captures with command data, apply friendly name resolution, and colorize conversations for substation traffic analysis.
Learn to manage capture files in Wireshark by saving, exporting subsets of displayed packets, and exporting packet dissections to CSV, JSON, or XML for analysis.
Master digital substation traffic capture analysis with Wireshark, troubleshooting Vlan tag visibility, identifying goose and rms messages, and decoding IEC 6150 data elements and control frames.
In this video we show to create Display Filter buttons and how to organise them in nested structure.
This course has been crafted with the aim not just to provide you with the basics of packet sniffing and Wireshark operation, but also to give you the knowledge on Wireshark outstanding features that boost your productivity! In less than 2 hours you will feel confident on using the tool and will make your colleagues ask you how to do this and that in Wireshark.
We will focus on packet sniffing approaches and tools; how to connect to switched network infrastructure to capture required data, including the usage of port mirroring and network TAPs; how to start with Wireshark and its basic settings; how to you use capture and display filters in Wireshark; tips and tricks on working with packets and captures. We will also learn how to analyze digital substation specific communications like Sampled Values, GOOSE and MMS with Wireshark. The theory will be backed up by hands-on session in the end of the course.
The course is recommended for the protection and control engineers, SCADA engineers, OT/IT security engineers and other categories of specialists, dealing with network traffic analysis. Even if you do not work with IEC 61850 and digital substations, this course will be useful for you in regard to analysis of all other types of communications.