Network & Host Analysis: Network Analysis Formats
A variety of formats and protocols are used to help manage networks. Knowing what you have at your disposal to integrate into your operational duties is essential in defensive CyberOps. In this course youll learn the format and tools required to manage operate and analyze your networks. Youll start by recognizing the purpose and characteristics of NetFlow and IPFIX network flow protocols. Youll then outline how NetFlow is used to baseline a network. Next youll identify the importance of logging access control and event queues. Youll examine techniques for tapping network traffic and collecting and forwarding logs. Youll explore SNMP the PCAP format and whitelisting. Finally youll set up Wireshark to detect potentially harmful events and import and export captured traffic in the PCAP format.