Ten chapters covering the networking foundation every detection is built on: TCP/IP and the OSI model, routing and switching, DNS internals, TLS in practice, hands-on packet analysis with Wireshark, the protocols attackers abuse most, network telemetry and detection, firewalls and segmentation, and wireless security. Built for analysts who can use a network but have never had to explain why it works.
No chapters match “”.
The OSI and TCP/IP models layer by layer, how encapsulation actually works, IP addressing and subnetting, and the TCP three-way handshake that underlies almost everything else in this module.
How switches forward frames and routers forward packets, ARP and MAC tables, VLAN segmentation, and why flat networks make lateral movement trivial for an attacker.
The full DNS resolution path from stub resolver to authoritative server, record types that matter for security work, and why DNS is one of the most abused protocols on any network.
TLS on the wire: the handshake as captured packets, SNI and certificate validation, where mutual TLS and TLS interception fit, and what a TLS downgrade actually looks like in traffic.
Reading a capture with intent: display filters that matter, following a TCP stream, spotting anomalies in a conversation, and building a repeatable workflow for triaging a PCAP.
How HTTP, SMB, and RDP get abused for delivery, lateral movement, and remote access, and how DNS tunneling smuggles data through a protocol almost nobody blocks.
Flow data versus full packet capture, what Zeek logs actually contain, signature-based IDS versus behavioral detection, and where each telemetry source earns its storage cost.
How VPN tunnels and forward/reverse proxies reshape what you can see, NAT traversal and why it complicates attribution, and a full walkthrough of an incident from a captured PCAP.
Stateful vs next-gen firewalls, rule architecture, DMZ design, and how PCI-DSS-driven segmentation shapes real enterprise network layouts.
WPA2/WPA3, the 4-way handshake, evil twin attacks, and 802.1X enterprise authentication over RADIUS, closing the module.
WHAT YOU SHOULD KNOW
WHAT YOU WILL KNOW AFTER
H3AD-SEC tools that pair directly with this module's content.
Passive DNS history, subdomain enumeration, and WHOIS in one place. The direct hands-on companion to Chapter 3's DNS internals.
Infrastructure and certificate intelligence. Useful for seeing TLS and PKI concepts from Chapter 4 applied to real internet-facing hosts.
Real detection rules for network-based threats. See how the abused protocols and telemetry sources from Chapters 6 and 7 become production queries.
Visual pivot graph for investigations. Map infrastructure relationships once you can read the traffic that connects them.