In this course, we’ll go over the TCP/IP stack and learn how to recognize normal network traffic. We will then use that foundation and attempt to detect suspicious network traffic patterns. Additionally, we will also look at how to detect web shells and C2 channels hiding in our environment using various tools. During web shell hunting, we will also cover how you can combine threat intelligence with statistical analysis to hunt for threats on the wire.
This course is part of the Threat Hunting Professional Learning path which prepares you for the eCTHPv2 exam and certification.