Wireless forensics evidence review lab.
Use the analyzer demo or your own authorized capture to practice reviewing wireless evidence without making unsupported claims from incomplete packet data.
Lab tasks
- Identify observed SSIDs and BSSIDs.
- Review beacon timing and probe response patterns.
- Inspect authentication, association, deauthentication, and EAPOL activity.
- Assess WPA/WPA2/WPA3, PMF, and legacy cipher posture.
- Classify rogue AP candidates only as candidates until validated against authorized AP inventory.
- Write a short investigation summary with limitations and validation filters.