Skip to main content
Course

Network & Endpoint Security Monitoring

Spot the attacker on the wire and on the host, and turn raw telemetry into detections you can act on.

Intermediate

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

8 hours

Estimated time

What you will be able to do

  • Capture and read network traffic with packet and flow tools, and follow a suspect session end to end
  • Tell normal protocol behaviour from attacker abuse across DNS, HTTP, TLS and SMB
  • Explain how IDS/IPS work and where sensors sit, and read Snort- and Suricata-style signatures and Zeek notices
  • Detect scanning, command-and-control beaconing, lateral movement and data exfiltration on the wire, including in encrypted traffic
  • Map the endpoint telemetry that matters (process creation, command lines, process trees, and file, registry and network events) across Windows Event Logs, Sysmon and auditd
  • Explain how EDR collects telemetry, raises detections and enables response, and recognise living-off-the-land (LOLBin) activity
  • Map observed activity to MITRE ATT&CK and recognise attacker techniques on both the host and the wire
  • Correlate endpoint and network evidence into one incident timeline and separate true positives from false positives with a structured triage workflow

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    Network Traffic & Protocol Analysis for Defenders

    You cannot detect what you cannot read, so this module starts on the wire. You will learn to capture and interpret traffic at three altitudes (full packet capture, NetFlow/IPFIX flows, and Zeek's protocol-aware logs), then read the protocols attackers lean on hardest. By the end you can tell normal DNS, HTTP, TLS, and SMB behavior from the tunneling, beaconing, fingerprint-evasion, and lateral-movement patterns that give intrusions away, using tcpdump, Wireshark, Zeek, and flow data the way a working SOC analyst does.

    2 lessons · 5 quiz questions

  2. 02

    Network-Based Detection: IDS/IPS and Attacks on the Wire

    Now that you can read traffic, this module turns it into detection. You will learn how intrusion detection and prevention systems actually work (signatures, anomalies, and the inline decision), how the core tools differ (Snort, Suricata, and Zeek), and where to place sensors so they see the traffic that matters. You then apply that foundation to the four behaviors that define an intrusion on the wire: scanning, command-and-control beaconing, lateral movement, and exfiltration, including how to keep detecting when the traffic is encrypted and the payload is hidden from you.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Endpoint Telemetry, Processes and EDR

    The wire only shows half the picture. This module pivots from the network to the host: the endpoint telemetry that matters (process creation, command lines, and process trees, plus file, registry, and network events), where it comes from in Windows Event Logs, Sysmon, and Linux auditd, and how EDR collects it, turns it into detections, and enables response.

    2 lessons · 5 quiz questions

  4. 04

    Recognising Malicious Behaviour on the Host and the Wire

    Fuse endpoint and network monitoring into a single SOC workflow. Using MITRE ATT&CK as a shared language, you will recognise attacker techniques on the host and on the wire, correlate the two into one ATT&CK-mapped incident timeline, then triage, document, and escalate it the way a working analyst does.

    2 lessons · 5 quiz questions · assignment