Training

The Packet Factor

A hands-on course that looks exclusively at the wire to detect and analyze security incidents.

I’ve been teaching protocol classes for the better part of my career — but let’s be honest about where the excellent, comprehensive Wireshark courseware already comes from: my old friend Rolf Leutert. If you want the definitive, ground-up Wireshark and protocol training in Switzerland, Rolf is the Koryphäe. Nobody covers the tool itself better, and I have no intention of competing with that.

What I built instead, a few years back, is narrower and more specific: The Packet Factor. It’s a hands-on course that looks exclusively at the wire to detect and analyze security incidents — less “how does Wireshark work,” more “what does an attack actually look like once it hits the network, and how do you find it.” Wireshark is the main tool, but we also bring in a stack of open-source utilities, and we look at some attacks from the attacker’s side first, so the traces they leave behind make more sense afterward.

Full disclosure: some of the courseware is due for an update — especially the parts touching on how AI is changing both attacks and defenses, which has moved fast even in the last year or two. What hasn’t changed, and won’t: the protocol-level view. TCP is still TCP, a TLS handshake still looks like a TLS handshake, and a port scan still leaves the same fingerprint it did a decade ago. That’s most of the course content, and it’s as relevant now as when I wrote it.

These days I run The Packet Factor as modular, custom training: pick the modules that matter to you — protocol review, TLS inspection, threat-intel correlation, exfiltration analysis, AI-assisted workflows, whatever’s relevant — and I build a session or two around them, drawn from the full original curriculum. The complete two-day course is still there if you want the whole path.

Who this is for

  • Network engineers adding a security lens to skills they already have
  • Security engineers who usually live at the endpoint and want wire-level visibility
  • Incident responders who need to read packet-level evidence, not just alerts

Prerequisites

  • A working understanding of networks and protocols
  • Comfort with Linux — some exercises run in a Linux environment
  • Laptop with hypervisor software for a Kali Linux VM (some exercises also work from provided PCAPs without Kali)

Format

  • Modular by default — built from the full two-day curriculum
  • Course book & exercise book (PDF, English) plus PCAP files, provided electronically
  • Taught in German or English
  • Physical or virtual delivery
  • Course material in English
  • Book by module, or run the complete two-day course
Curriculum

What’s covered

  • Why packet analysis matters for security, and how to capture the right data
  • Tools for analyzing and manipulating trace files
  • Protocol fields and what they mean for security
  • SSL/TLS and the challenges of encrypted traffic
  • Techniques for decrypting and analyzing encrypted data
  • Wireshark as the primary analysis tool — filters, search, pattern recognition
  • Working with Indicators of Compromise (IoCs) in Wireshark
  • Wireshark plugins for threat intel & vulnerability context — my own ASK and Vulnerability Correlator, plus MISP integration
  • Identifying malicious behavior in traffic, and what real attacks look like on the wire
  • Data exfiltration techniques and how to spot them
  • Where AI fits into network and security analysis today
  • Filtering and profile management best practices, plus tips and tricks
Practice

Hands-on exercises

Lab setup & PCAP tooling

Get your Kali lab running, then get comfortable with tshark and scapy for filtering and stripping PCAPs.

Protocol review

Capture live HTTP traffic and walk the session from DNS lookup through the TCP handshake to HTTP/1.1 vs HTTP/2.

Advanced filters

Build compound display filters, port-based exclusions, and substring matches to cut straight to what matters.

Threat intelligence integration

Correlate captured IOCs against threat intel using my own ASK and Vulnerability Correlator plugins.

Identifying network scans

Classify a set of trace files by scan technique and justify the call from the packets alone.

Exploit & exfiltration traffic

Analyze a live ProFTP exploit, then craft and detect the data exfiltration that follows.

AI use cases

Use AI to draft tshark filters, generate analysis scripts, and help write up findings.

"The Messy Trace Challenge"

One tangled capture, four tasks: find the TLS error, the malware, the DNS abuse, and the exfil.

Preview

From the course materials

Packet Factor course material, sample page 1 Packet Factor course material, sample page 2 Packet Factor course material, sample page 3 Packet Factor course material, sample page 4

Student guide and hands-on exercise book, PCAPs included — click a page for full size.

Interested in The Packet Factor?

Book the two-day course, or get in touch about a focused single session.