Wireshark - Masterclass
Speaker: Paul Fennell
Wireshark is a popular network protocol analyser that can be used by security professionals to identify and analyse network traffic in order to detect and defend potential security threats.
1. Network monitoring:
Wireshark can be used to monitor network traffic in real-time. This helps security professionals to detect and analyse any unusual network behaviour, such as traffic patterns, unusual protocols, or unusual port usage, and play back captured packets in real-time.
2. Traffic analysis:
Wireshark can be used to analyse network traffic to identify potential security threats. Security professionals can use the tool to examine network packets and look for anomalies, such as malicious payloads or unexpected network traffic.
3. Forensic analysis:
Wireshark can be used to capture and store network traffic for later analysis. This allows security professionals to examine network traffic and identify potential security incidents that may have occurred in the past.
4. Vulnerability scanning:
Wireshark can be used to identify vulnerabilities in network protocols and applications. Security professionals can use the tool to examine network traffic and identify weaknesses that could be exploited by attackers.
5. Intrusion detection:
Wireshark can be used to identify and detect intrusion attempts by analysing network traffic. Security professionals can use the tool to look for specific signatures of known attacks.
About Paul:
Holding a MSc in Cybercrime forensics and MPhil in Information Security, Paul worked in the field as a cyber investigator as both a network and digital forensic examiner, with notable success in conducting and directing a broad range of criminal and civil investigations. With over 7 years’ experience in multi-platform digital forensics in serious and complex multi-region cyber-crime cases on behalf of the MPCCU (Metropolitan Police Cybercrime Unit) holding the rank of Detective Constable. Later in the private sector as a Critical Incident consultant and prior as Head of Digital forensics and Incident response (EMEA).
Specialist areas: Cyber Awareness, Cyber Intelligence, Secure Developer, Digital Forensics. Security+, CASP+, National Cybercrime programme.
https://info.qa.com/thecyberpulse