

Learn your anatomy.įor a Doctor to diagnose a patient, they spend years studying and learning anatomy. I recommend using kali in your virtual machine – it comes with Wireshark pre-loaded! Pro Tip #3.

When an infected box is found, a packet capture is conducted, and the analysis of the machine is done in virtual space so as not to alter the forensic evidence. When you replay traffic, you could be injecting packets into your own network! Better to be safe, spin up a virtual machine, and load the packet captures in a safe sandbox. There are several places where you can download packet captures but you need to be careful. This is where our very good tutorial ( I may be biased) on Virtual Machines comes in handy. Wireshark also has some great features that help to visualize and inspect traffic in way that make your job much easier. Being so widely used in the industry I have found tutorials on YouTube, Lynda, Udemy, Cybrary, and included in many ethical hacker training bundles. It supports multiple platforms (Windows, Linux, Mac OS, etc) and is free! In addition, you can get basic training and tutorials on how to use it from the developer.

That beings said, if you are looking to use the NCL Games to learn skills for the real world, I would recommend that you install Wireshark. I have used CloudShark to solve some challenges and it works well enough.ĬloudShark is based on an open source tool called Wireshark which is an industry standard. This is how you can compete with a ten-year-old laptop or a tablet all you need to do is use the tool that is provided to you at no additional cost or hassle. NCL is very forgiving when it comes to not requiring software downloads and commercial software – they offer a tool called CloudShark for the NTA challenges that require it. This is like looking into the wires of your home and seeing the electricity flowing back and forth – but please don’t try to see (or touch) electricity, network traffic analysis is much less dangerous! I would even say that it can be fun, once you learn some basics. When you absolutely need to know what is going on in your network, there is no substitute for a packet capture (or pcap). Network Traffic Analysis (or NTA for short) is a fundamental skill. It destroys accuracy, wrecks friendships, and will eat your lunch without leaving a note. Newbies and veterans alike fear this category.
