Lab

Wireless forensics evidence review lab.

Use the analyzer demo or your own authorized capture to practice reviewing wireless evidence without making unsupported claims from incomplete packet data.

Lab tasks

  1. Identify observed SSIDs and BSSIDs.
  2. Review beacon timing and probe response patterns.
  3. Inspect authentication, association, deauthentication, and EAPOL activity.
  4. Assess WPA/WPA2/WPA3, PMF, and legacy cipher posture.
  5. Classify rogue AP candidates only as candidates until validated against authorized AP inventory.
  6. Write a short investigation summary with limitations and validation filters.