I’ve been teaching protocol classes for the better part of my career — but let’s be honest about where the excellent, comprehensive Wireshark courseware already comes from: my old friend Rolf Leutert. If you want the definitive, ground-up Wireshark and protocol training in Switzerland, Rolf is the Koryphäe. Nobody covers the tool itself better, and I have no intention of competing with that.
What I built instead, a few years back, is narrower and more specific: The Packet Factor. It’s a hands-on course that looks exclusively at the wire to detect and analyze security incidents — less “how does Wireshark work,” more “what does an attack actually look like once it hits the network, and how do you find it.” Wireshark is the main tool, but we also bring in a stack of open-source utilities, and we look at some attacks from the attacker’s side first, so the traces they leave behind make more sense afterward.
These days I run The Packet Factor as modular, custom training: pick the modules that matter to you — protocol review, TLS inspection, threat-intel correlation, exfiltration analysis, AI-assisted workflows, whatever’s relevant — and I build a session or two around them, drawn from the full original curriculum. The complete two-day course is still there if you want the whole path.
Get your Kali lab running, then get comfortable with tshark and scapy for filtering and stripping PCAPs.
Capture live HTTP traffic and walk the session from DNS lookup through the TCP handshake to HTTP/1.1 vs HTTP/2.
Build compound display filters, port-based exclusions, and substring matches to cut straight to what matters.
Correlate captured IOCs against threat intel using my own ASK and Vulnerability Correlator plugins.
Classify a set of trace files by scan technique and justify the call from the packets alone.
Analyze a live ProFTP exploit, then craft and detect the data exfiltration that follows.
Use AI to draft tshark filters, generate analysis scripts, and help write up findings.
One tangled capture, four tasks: find the TLS error, the malware, the DNS abuse, and the exfil.
Book the two-day course, or get in touch about a focused single session.