Training

Network-monitoring training for SOC and Blue Team analysts

Hands-on network security monitoring training, taught on real traffic. Analysts spend the day in a lab with packets in front of them, not watching slides about packets.

We have been developing and delivering this kind of course since 2014, for audiences ranging from junior SOC staff to the technical teams inside large international cyber defence exercises. Some of the course material we have authored is public, under an MIT licence, at github.com/ccdcoe/CDMCS; it is a fair sample of the level and the style.

Courses are built to order. The modules below are what we teach; a course is a selection of them sized to your team, your traffic and the tooling you actually run.

Modules

Reading traffic

Protocol behaviour as it appears in capture rather than in a textbook diagram: TCP state and what its failure modes look like, fragmentation and reassembly, tunnelling and encapsulation, and the everyday protocols where the interesting details live. Tooling: tcpdump, Wireshark and tshark as an analysis language rather than a button.

Flow-level visibility

Where full packet capture stops being affordable, flow starts. NetFlow and IPFIX, connection logs, what each field really measures, and the class of question flow can answer that packets cannot: long-horizon behaviour, beaconing, volumetric patterns, lateral movement across a period no capture buffer covers.

DNS telemetry

DNS is the highest-yield telemetry most teams already have and do not use. Query and response logging, what resolver placement does to your visibility, detecting domain-generation behaviour and tunnelling, and the practical limits imposed by encrypted DNS.

Encrypted traffic

What is still visible once payloads are not: TLS handshake metadata, certificate details, SNI, client fingerprinting, and traffic-shape analysis. Where each of those holds up and where it produces confident nonsense.

Running an NSM stack

Deploying and operating open-source network security monitoring: sensor placement and what each position can and cannot see, capture sizing, rule management, and tuning a signature set until its output is worth reading. Emphasis on the tuning, because that is what decides whether a stack helps or drowns the team.

Alert triage

Turning alerts into decisions: building the context an analyst needs at hand, working from alert to evidence to verdict, recognising the recurring false-positive patterns that eat a shift, and knowing when to escalate. Includes the reputation-data trap: why public IP lists flag legitimate infrastructure, and what that does to a triage queue.

Threat hunting

Hypothesis-driven work across the telemetry from the modules above: forming a question the data can answer, scoping it, running it, and knowing when a negative result is actually a negative result. Pivoting between packet, flow, DNS and IDS evidence.

Capture at scale

For teams that run their own capture: architecture and sizing, lossless capture on high-throughput links, integrity monitoring while capture is running, storage and retention trade-offs, and turning a raw capture into an analysis-ready dataset afterwards.

Formats

FormatLengthFits
Foundation2 daysNew SOC staff, or a mixed team that needs shared vocabulary
Analyst intensive4–5 daysWorking analysts going from tool operation to analysis
Focused workshop1 dayOne module in depth, usually for a team with a specific gap

How it runs

Prerequisites

Participants should be comfortable on a Linux command line and have working TCP/IP fundamentals: addressing, routing, the transport layer. No prior experience with any specific monitoring tool is assumed; the point of the course is to build that.

For the capture-at-scale and NSM-stack modules, some participants should have administrative access to the systems they will be operating afterwards, or the knowledge does not survive contact with their own environment.

What you get

An outline agreed before the course, the lab environment for its duration, the exercise material afterwards, and a written summary of what the group struggled with, which is usually the more actionable deliverable, because it tells you where the gaps in your monitoring actually are.

Tell us about your team

Courses are built to order around the traffic and the tooling you actually run. Email what your analysts need to get better at and we will come back with an outline, a duration and a price.

trainings@sciscope.ee or see the other services