All Modules NETWORKING

Networking · Complete Guide

Ten chapters covering the networking foundation every detection is built on: TCP/IP and the OSI model, routing and switching, DNS internals, TLS in practice, hands-on packet analysis with Wireshark, the protocols attackers abuse most, network telemetry and detection, firewalls and segmentation, and wireless security. Built for analysts who can use a network but have never had to explain why it works.

10 CHAPTERS
~13 HRS CONTENT
BEGINNER to ADVANCED SKILL RANGE
SEP 2026 LAST UPDATED
MODULE PROGRESS 0 / 10 chapters complete
TCP/IP OSI model DNS TLS Wireshark NetFlow Zeek packet analysis

ALL CHAPTERS

/
01
BEGINNER 30 min

TCP/IP Fundamentals & the OSI Model

The OSI and TCP/IP models layer by layer, how encapsulation actually works, IP addressing and subnetting, and the TCP three-way handshake that underlies almost everything else in this module.

OSI model TCP/IP subnetting
02
BEGINNER 30 min

Routing, Switching & VLANs

How switches forward frames and routers forward packets, ARP and MAC tables, VLAN segmentation, and why flat networks make lateral movement trivial for an attacker.

routing switching VLANs
03
BEGINNER 30 min

DNS Internals & Resolution

The full DNS resolution path from stub resolver to authoritative server, record types that matter for security work, and why DNS is one of the most abused protocols on any network.

DNS resolution record types
04
INTERMEDIATE 35 min

TLS in Practice: Handshakes, Certificates & Interception

TLS on the wire: the handshake as captured packets, SNI and certificate validation, where mutual TLS and TLS interception fit, and what a TLS downgrade actually looks like in traffic.

TLS handshake SNI interception
05
INTERMEDIATE 40 min

Packet Analysis with Wireshark

Reading a capture with intent: display filters that matter, following a TCP stream, spotting anomalies in a conversation, and building a repeatable workflow for triaging a PCAP.

Wireshark display filters PCAP triage
06
INTERMEDIATE 35 min

Protocols Attackers Abuse

How HTTP, SMB, and RDP get abused for delivery, lateral movement, and remote access, and how DNS tunneling smuggles data through a protocol almost nobody blocks.

SMB RDP DNS tunneling
07
INTERMEDIATE 35 min

Network Detection: NetFlow, Zeek & IDS/IPS

Flow data versus full packet capture, what Zeek logs actually contain, signature-based IDS versus behavioral detection, and where each telemetry source earns its storage cost.

NetFlow Zeek IDS/IPS
08
ADVANCED 40 min

Advanced Topics: VPNs, Proxies, NAT & Full-PCAP Analysis

How VPN tunnels and forward/reverse proxies reshape what you can see, NAT traversal and why it complicates attribution, and a full walkthrough of an incident from a captured PCAP.

VPN NAT full-PCAP
09
INTERMEDIATE 40 min

Firewalls & Network Segmentation

Stateful vs next-gen firewalls, rule architecture, DMZ design, and how PCI-DSS-driven segmentation shapes real enterprise network layouts.

firewalls NGFW segmentation
10
INTERMEDIATE 35 min

Wireless Security

WPA2/WPA3, the 4-way handshake, evil twin attacks, and 802.1X enterprise authentication over RADIUS, closing the module.

WPA3 evil twin 802.1X

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • The Fundamentals module, or equivalent comfort with core security vocabulary (threat, vulnerability, attack surface)
  • General comfort using a computer on a network; you do not need prior networking or IT experience
  • No prior Wireshark, CLI, or scripting experience required, this module builds it from zero

WHAT YOU WILL KNOW AFTER

  • How data actually moves across a network, from OSI layers to a captured TCP handshake
  • How DNS resolution and TLS negotiation look in real traffic, not just in theory
  • How to open a PCAP in Wireshark and triage it with a repeatable workflow
  • Which protocols attackers abuse most, and what that abuse looks like on the wire
  • The difference between flow data, full packet capture, and IDS/IPS, and when to reach for each
  • Enough network fluency to read almost any other H3AD-LEARN module's traffic examples without translation

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.