Mastering Network Forensics
A practical approach to investigating and defending against network attacks, with topics across traffic analysis, log analysis, wireless forensics, malware, ransomware, and incident response.
These books anchor the NetForensics learning path. The site turns their concepts into practical tools, checklists, and labs for analysts who learn best by working through evidence.
A practical approach to investigating and defending against network attacks, with topics across traffic analysis, log analysis, wireless forensics, malware, ransomware, and incident response.
A hands-on path for investigating network attacks and finding evidence using common network forensic tools, including PCAP analysis, protocol review, tunneling, malware traffic, and correlation.
The site complements the books with hands-on material: utilities, filters, sample-capture workflows, and repeatable investigation methods.
Topic pages can map book themes to modern tools and 2026-era changes.
Small tools help readers practice evidence review without leaving the learning path.
Guides can connect readers to the book chapters that cover a topic in more depth.
Start with sources of evidence, capture metadata, chain of custody, hashing, and analyst notes.
Work through conversations, protocol fields, endpoints, authentication traces, and time-based correlation.
Move into malware traffic, covert channels, wireless forensics, exploit activity, ransomware, and reporting.