Skip to main content
10151133 Network Forensics and Threat Hunting
Course Information
Description
Investigate network and Windows artifacts to reconstruct malicious activity and support threat hunting. Collect, filter, and correlate PCAP, event log, file system, registry, browser, and endpoint evidence. Use forensic and security monitoring tools to build timelines, identify indicators of compromise, evaluate hypotheses, and report evidence-based findings.
Total Credits
3

Course Competencies (Course Outcomes)
  1. Collect and validate digital forensic evidence
    Assessment Strategies
    Skill Demonstration and/or Written Product
    Criteria
    Acquire or export forensic data using methods appropriate to the evidence source
    Verify evidence integrity using cryptographic hashes when applicable
    Preserve original evidence while conducting analysis on working copies
    Document evidence sources and collection actions sufficiently to support repeatability

  2. Analyze packet capture data using command-line tools
    Assessment Strategies
    Skill Demonstration and/or Written Product
    Criteria
    Extract capture metadata including time range, packet counts, hosts, and protocols
    Filter PCAP data using protocol, host, port, field, or content criteria
    Extract focused packet sets or transaction data for further analysis
    Interpret command output to identify activity relevant to an investigation

  3. Analyze network traffic using graphical forensic tools
    Assessment Strategies
    Skill Demonstration and/or Written Product
    Criteria
    Use Wireshark, NetworkMiner, or equivalent tools to examine sessions and transferred content
    Identify hosts, users, domains, files, and protocols represented in network evidence
    Reconstruct relevant conversations or application transactions
    Identify anomalous or malicious behavior from network evidence

  4. Analyze security monitoring data for threat hunting
    Assessment Strategies
    Skill Demonstration and/or Scenario Response
    Criteria
    Query Security Onion or equivalent monitoring data for events of interest
    Use alerts, network metadata, and endpoint telemetry to develop investigative leads
    Pivot between related events using fields such as IP address, domain, filename, Community ID, or process identifier
    Refine searches to test investigative hypotheses

  5. Analyze Windows event log evidence
    Assessment Strategies
    Skill Demonstration and/or Written Product
    Criteria
    Identify Windows event sources relevant to authentication, account, process, and system activity
    Interpret event fields and identifiers within the context of an investigation
    Correlate related events across users, hosts, logon sessions, or timestamps
    Identify patterns consistent with failed access, privilege changes, lateral movement, or other suspicious activity

  6. Analyze Windows file system and execution artifacts
    Assessment Strategies
    Skill Demonstration and/or Written Product
    Criteria
    Extract and interpret forensic metadata from Windows artifacts
    Use artifacts such as LNK files, Prefetch, or related execution evidence to reconstruct user or process activity
    Correlate artifact timestamps and paths with other investigative evidence
    Identify artifacts that persist after files or folders have been modified or removed

  7. Analyze registry and browser artifacts
    Assessment Strategies
    Skill Demonstration and/or Written Product
    Criteria
    Locate registry or browser artifacts relevant to user and system activity
    Interpret artifact fields, timestamps, paths, URLs, or configuration data
    Correlate registry and browser findings with file system, log, or network evidence
    Identify evidence of persistence, downloads, browsing activity, or other actions relevant to an investigation

  8. Correlate multi-source evidence to reconstruct attack activity
    Assessment Strategies
    Case Study and/or Report
    Criteria
    Combine PCAP, event log, endpoint, and forensic artifact evidence into a chronological sequence
    Identify relationships among hosts, users, processes, files, domains, and network connections
    Use MITRE ATT&CK or equivalent models to organize observed adversary behavior
    Revise investigative hypotheses as supporting or contradictory evidence is discovered
    Limit conclusions to claims supported by the available evidence

  9. Conduct hypothesis-driven threat hunting
    Assessment Strategies
    Scenario Response and/or Project
    Criteria
    Formulate a testable hypothesis from an alert, anomaly, indicator, or known adversary behavior
    Select data sources and queries appropriate to the hypothesis
    Evaluate evidence that supports or disproves the hypothesis
    Identify additional evidence needed to increase confidence in findings
    Document the investigative path and resulting conclusions

  10. Produce professional forensic investigation documentation
    Assessment Strategies
    Report and/or Presentation
    Criteria
    Document the environment, affected systems, and evidence sources
    Create a clear timeline of significant investigative events
    Record indicators of compromise and supporting technical evidence
    Distinguish confirmed findings from assumptions and unresolved questions
    Communicate findings and implications clearly to technical and non-technical audiences