1
1

00:00:00,090  -->  00:00:01,410
<v ->In this section of the course,</v>
2

2

00:00:01,410  -->  00:00:03,120
we're going to cover network forensics
3

3

00:00:03,120  -->  00:00:05,940
with a focus on Domain 1 security operations
4

4

00:00:05,940  -->  00:00:08,430
and specifically objective 1.3.
5

5

00:00:08,430  -->  00:00:11,100
Objective 1.3 states that given a scenario,
6

6

00:00:11,100  -->  00:00:13,110
you must be able to use appropriate tools
7

7

00:00:13,110  -->  00:00:16,080
or techniques to determine malicious activity.
8

8

00:00:16,080  -->  00:00:17,760
Now, as we begin this section,
9

9

00:00:17,760  -->  00:00:19,170
we're going to be focused on the different types
10

10

00:00:19,170  -->  00:00:21,390
of network forensic tools that you may be using
11

11

00:00:21,390  -->  00:00:24,360
as a cybersecurity analyst out in the real world.
12

12

00:00:24,360  -->  00:00:26,130
Next, we'll be describing the usage
13

13

00:00:26,130  -->  00:00:28,410
of tcpdump and Wireshark for you
14

14

00:00:28,410  -->  00:00:30,120
to be able to conduct network forensics
15

15

00:00:30,120  -->  00:00:32,010
as well as providing you the short demonstration
16

16

00:00:32,010  -->  00:00:34,170
of how to use each of these tools.
17

17

00:00:34,170  -->  00:00:35,580
After that, we're going to explore
18

18

00:00:35,580  -->  00:00:37,020
the different tools and techniques
19

19

00:00:37,020  -->  00:00:39,540
that are used to conduct flow analysis of a network,
20

20

00:00:39,540  -->  00:00:40,680
and then we're going to learn
21

21

00:00:40,680  -->  00:00:43,290
how to conduct IP address and DNS analysis
22

22

00:00:43,290  -->  00:00:45,450
as part of our security monitoring activities,
23

23

00:00:45,450  -->  00:00:47,760
as well as how to conduct URL analysis
24

24

00:00:47,760  -->  00:00:50,190
as part of those security monitoring activities.
25

25

00:00:50,190  -->  00:00:52,470
Next, we're going to head into a demonstration
26

26

00:00:52,470  -->  00:00:54,330
where I'm going to show you how to analyze output
27

27

00:00:54,330  -->  00:00:56,250
from our network security monitoring tools
28

28

00:00:56,250  -->  00:00:58,620
by conducting packet analysis on the data
29

29

00:00:58,620  -->  00:01:00,450
that's being sent across the network.
30

30

00:01:00,450  -->  00:01:02,250
After all, so many of the attacks
31

31

00:01:02,250  -->  00:01:03,720
you're going to be facing on your systems
32

32

00:01:03,720  -->  00:01:05,370
are going to come over the network,
33

33

00:01:05,370  -->  00:01:06,690
so learning how to identify them
34

34

00:01:06,690  -->  00:01:08,130
using these various techniques
35

35

00:01:08,130  -->  00:01:10,740
is going to be really helpful, not just for the exam,
36

36

00:01:10,740  -->  00:01:12,660
but also for you to be able to identify things
37

37

00:01:12,660  -->  00:01:15,240
in your own networks when they're under attack.
38

38

00:01:15,240  -->  00:01:17,130
Finally, we're going to take a short quiz
39

39

00:01:17,130  -->  00:01:19,230
to see what you learned during this section of the course
40

40

00:01:19,230  -->  00:01:21,600
and then we'll review each of those quiz questions fully
41

41

00:01:21,600  -->  00:01:22,500
to ensure that you can explain
42

42

00:01:22,500  -->  00:01:24,090
why the right answers were right.
43

43

00:01:24,090  -->  00:01:25,950
So let's dive into our discussion
44

44

00:01:25,950  -->  00:01:27,660
of the concepts surrounding network forensics
45

45

00:01:27,660  -->  00:01:29,160
in this section of the course.
