Cyber Security · PPL

Wireshark Network Analysis Certification

A practical program focused on capturing, analyzing, and interpreting network traffic with Wireshark for troubleshooting, security monitoring, and threat investigation.

  • 3 DaysDuration
  • PPLAccredited
  • 3 LanguagesArabic · English · Hindi
  • ₹7,999.00 Per delegate

This course is accredited by PPL

This is for all ppl accredited courses
2M+ Delegates trained worldwide
15,000+ Corporate clients
490+ Training locations
4.8 ★ Average learner rating
20% OFF Limited-time launch offer
— The journey

Course Outline

What the programme covers, module by module.

Module 1: Introduction to Network Analysis

  • Network analysis fundamentals
  • Packet analysis concepts
  • Network visibility
  • Traffic monitoring
  • Analysis use cases
  • Troubleshooting methodology

Module 2: Introduction to Wireshark

  • Wireshark overview
  • Interface navigation
  • Main windows and panels
  • Capture options
  • Packet details
  • Analysis workflow

Module 3: Networking Fundamentals

  • OSI model
  • TCP/IP model
  • Network communication
  • Ports and protocols
  • Encapsulation
  • Packet flow

Module 4: Packet Capture Fundamentals

  • Network interfaces
  • Capture configuration
  • Starting and stopping captures
  • Capture files
  • Packet timestamps
  • Capture best practices

Module 5: Capture Filters

  • Capture filter concepts
  • Host filtering
  • Port filtering
  • Protocol filtering
  • Network filtering
  • Filter combinations

Module 6: Display Filters

  • Display filter syntax
  • Protocol filters
  • Address filters
  • Port filters
  • Comparison operators
  • Complex filter expressions

Module 7: Ethernet & ARP Analysis

  • Ethernet frames
  • MAC addresses
  • Frame headers
  • ARP requests
  • ARP responses
  • ARP troubleshooting

Module 8: IPv4 & IPv6 Analysis

  • IP headers
  • Source and destination addresses
  • Fragmentation
  • TTL analysis
  • IPv6 fundamentals
  • IP troubleshooting

Module 9: TCP Analysis

  • TCP headers
  • Three-way handshake
  • Sequence numbers
  • Acknowledgements
  • TCP flags
  • Connection termination

Module 10: TCP Performance Analysis

  • Retransmissions
  • Duplicate acknowledgements
  • Window size
  • Round-trip time
  • Packet loss indicators
  • Performance bottlenecks

Module 11: UDP Analysis

  • UDP fundamentals
  • UDP headers
  • Datagram analysis
  • UDP-based services
  • Traffic patterns
  • Troubleshooting

Module 12: DNS Traffic Analysis

  • DNS fundamentals
  • DNS queries
  • DNS responses
  • Record types
  • Resolution issues
  • Suspicious DNS activity

Module 13: DHCP Analysis

  • DHCP fundamentals
  • Discover process
  • Offer process
  • Request process
  • Acknowledgement
  • DHCP troubleshooting

Module 14: HTTP Traffic Analysis

  • HTTP fundamentals
  • Requests and responses
  • HTTP methods
  • Status codes
  • Headers
  • Web traffic analysis

Module 15: HTTPS & TLS Analysis

  • TLS fundamentals
  • TLS handshake
  • Certificates
  • Encryption concepts
  • TLS versions
  • Secure traffic analysis

Module 16: ICMP & Network Troubleshooting

  • ICMP fundamentals
  • Echo requests and replies
  • Error messages
  • Connectivity analysis
  • Latency investigation
  • Troubleshooting workflows

Module 17: Wireshark Statistics & Visualization

  • Protocol hierarchy
  • Conversations
  • Endpoints
  • I/O graphs
  • Flow graphs
  • Traffic statistics

Module 18: Network Security Analysis

  • Suspicious connections
  • Unusual traffic patterns
  • Port scanning indicators
  • Network anomalies
  • Unexpected protocols
  • Security investigation workflow

Module 19: Malware Traffic Analysis

  • Malware communication concepts
  • Command-and-control indicators
  • Suspicious DNS requests
  • Abnormal HTTP traffic
  • Network indicators
  • Investigation techniques

Module 20: SOC Investigations with Wireshark

  • Alert investigation
  • Packet evidence
  • Traffic correlation
  • Incident timelines
  • Indicators of compromise
  • Investigation documentation

Module 21: Advanced Wireshark Techniques

  • Follow TCP streams
  • Packet reassembly
  • Expert information
  • Custom profiles
  • Coloring rules
  • Advanced filtering

Module 22: Practical Network Analysis

  • Packet capture
  • Protocol identification
  • Filter development
  • Performance troubleshooting
  • Suspicious traffic investigation
  • Analysis reporting
— 01.2 · Is it right for you?

Who it's for & what's included

Pick a delivery method to see exactly who it suits and everything you receive.

Who it's for

Classroom

Best for learners who want face-to-face tuition and to network with peers in person.

What's included

Everything you get

  • Live instructor on-site
  • Printed workbook & materials
  • Group exercises & case studies
Who it's for

Online Instructor-Led

Best for learners who want a live instructor and a fixed schedule, without the travel.

What's included

Everything you get

  • Live instructor via video call
  • Digital workbook & resources
  • Session recordings
Who it's for

Self-Paced

Best for self-motivated learners who need maximum flexibility around work and life.

What's included

Everything you get

  • On-demand video lessons
  • Interactive quizzes
  • 24/7 access on any device
— What you will master

Course Objectives

01

Understand packet analysis and network communication fundamentals.

02

Capture and inspect network traffic effectively using Wireshark.

03

Create capture and display filters to isolate relevant network traffic.

04

Analyze Ethernet, ARP, IP, TCP, UDP, DNS, DHCP, HTTP, and TLS communications.

05

Identify network performance problems such as retransmissions, latency, and packet loss.

06

Recognize suspicious traffic patterns and potential security indicators.

07

Use Wireshark statistics and advanced analysis features for network investigations.

08

Perform structured network troubleshooting and security analysis using packet captures.

— Your learning path

Where this fits in your Cyber Security journey

Click any stage to open its detail page. You are at Wireshark Network Analysis Certification.

Start Build Advanced Mastery
— Questions answered

Frequently Asked Questions

What is Wireshark?
Wireshark is a network protocol analyzer used to capture and inspect network traffic for troubleshooting, performance analysis, security monitoring, and technical investigations.
Who should attend this course?
This course is suitable for network engineers, administrators, cybersecurity analysts, SOC analysts, IT security professionals, and professionals responsible for network troubleshooting.
What prior knowledge is recommended?
Basic knowledge of networking, TCP/IP, ports, protocols, and common network services is helpful for this practitioner-level program.
What protocols will I learn to analyze?
The course covers Ethernet, ARP, IPv4, IPv6, TCP, UDP, DNS, DHCP, ICMP, HTTP, HTTPS, and TLS traffic.
What practical skills will I develop?
You will develop skills in packet capture, traffic filtering, protocol analysis, TCP troubleshooting, performance investigation, suspicious traffic detection, and network security analysis.
— Trusted by learners

What our delegates say

★★★★★

"The structure, the practice exams, the instructor — all top tier. Passed first try."

AS
Aarti SharmaSenior Project Manager · TCS
★★★★★

"Best training I have attended. The content is exactly what modern projects need."

JD
James DonovanProgramme Director · Capgemini
★★★★★

"24/7 support actually means 24/7 — got help on my mock exam at 2am. Worth every dollar."

MO
Maya OkaforPMO Lead · Standard Bank

★ 4.8 / 5 from 12,000+ verified learner reviews on Trustpilot & Google.

PPL Academy enquiry form

Get the course
that's right for you.

Our advisors respond within one business day.

Full name
Work email
Contact number
Message (optional)
Your details are never shared with third parties.
< 24h Response
Live & online Delivery
Certified Instructors