Training
Network-monitoring training for SOC and Blue Team analysts
Hands-on network security monitoring training, taught on real traffic. Analysts spend the day in a lab with packets in front of them, not watching slides about packets.
We have been developing and delivering this kind of course since 2014, for audiences ranging from junior SOC staff to the technical teams inside large international cyber defence exercises. Some of the course material we have authored is public, under an MIT licence, at github.com/ccdcoe/CDMCS; it is a fair sample of the level and the style.
Courses are built to order. The modules below are what we teach; a course is a selection of them sized to your team, your traffic and the tooling you actually run.
Modules
Reading traffic
Protocol behaviour as it appears in capture rather than in a textbook diagram: TCP state and what its failure modes look like, fragmentation and reassembly, tunnelling and encapsulation, and the everyday protocols where the interesting details live. Tooling: tcpdump, Wireshark and tshark as an analysis language rather than a button.
Flow-level visibility
Where full packet capture stops being affordable, flow starts. NetFlow and IPFIX, connection logs, what each field really measures, and the class of question flow can answer that packets cannot: long-horizon behaviour, beaconing, volumetric patterns, lateral movement across a period no capture buffer covers.
DNS telemetry
DNS is the highest-yield telemetry most teams already have and do not use. Query and response logging, what resolver placement does to your visibility, detecting domain-generation behaviour and tunnelling, and the practical limits imposed by encrypted DNS.
Encrypted traffic
What is still visible once payloads are not: TLS handshake metadata, certificate details, SNI, client fingerprinting, and traffic-shape analysis. Where each of those holds up and where it produces confident nonsense.
Running an NSM stack
Deploying and operating open-source network security monitoring: sensor placement and what each position can and cannot see, capture sizing, rule management, and tuning a signature set until its output is worth reading. Emphasis on the tuning, because that is what decides whether a stack helps or drowns the team.
Alert triage
Turning alerts into decisions: building the context an analyst needs at hand, working from alert to evidence to verdict, recognising the recurring false-positive patterns that eat a shift, and knowing when to escalate. Includes the reputation-data trap: why public IP lists flag legitimate infrastructure, and what that does to a triage queue.
Threat hunting
Hypothesis-driven work across the telemetry from the modules above: forming a question the data can answer, scoping it, running it, and knowing when a negative result is actually a negative result. Pivoting between packet, flow, DNS and IDS evidence.
Capture at scale
For teams that run their own capture: architecture and sizing, lossless capture on high-throughput links, integrity monitoring while capture is running, storage and retention trade-offs, and turning a raw capture into an analysis-ready dataset afterwards.
Formats
| Format | Length | Fits |
|---|---|---|
| Foundation | 2 days | New SOC staff, or a mixed team that needs shared vocabulary |
| Analyst intensive | 4–5 days | Working analysts going from tool operation to analysis |
| Focused workshop | 1 day | One module in depth, usually for a team with a specific gap |
How it runs
- On site or remote. On site is better when the team is learning together; remote works when it has to, with the same labs.
- A lab per participant, prepared in advance and reachable throughout the course. Each participant keeps their own environment for the duration.
- Real traffic. Exercises run against realistic captures and live lab traffic rather than sanitised teaching datasets, including the noise, the malformed packets and the ambiguity that make the job hard.
- Small groups. Hands-on teaching stops working above a certain class size, so we cap it and say so up front rather than overselling the room.
- Delivered in English.
Prerequisites
Participants should be comfortable on a Linux command line and have working TCP/IP fundamentals: addressing, routing, the transport layer. No prior experience with any specific monitoring tool is assumed; the point of the course is to build that.
For the capture-at-scale and NSM-stack modules, some participants should have administrative access to the systems they will be operating afterwards, or the knowledge does not survive contact with their own environment.
What you get
An outline agreed before the course, the lab environment for its duration, the exercise material afterwards, and a written summary of what the group struggled with, which is usually the more actionable deliverable, because it tells you where the gaps in your monitoring actually are.
Tell us about your team
Courses are built to order around the traffic and the tooling you actually run. Email what your analysts need to get better at and we will come back with an outline, a duration and a price.
trainings@sciscope.ee or see the other services