One-day intensive · Hands-on throughout · Network forensics
Threat Hunting with Wireshark
Hunt. Map. Automate.
The alert didn't fire, the logs look clean, and the traffic is still there. This day is about finding it in the capture — the sweep, the hostname nobody recognises, the POST going somewhere it shouldn't, and the heartbeat every sixty seconds.
Reserve your seat Early bird CGREER $100 off Registration is open
- Date
- Sunday 27 June 2027
8am–5pm, doors 7:30am - Venue
- AC Hotel Bellevue
Bellevue, Washington - Instructor
- Chris Greer
Packet Pioneer - Price
- $1,500
per seat · $2,000 both days
Abstract
A one-day, all-labs training in using Wireshark for cybersecurity forensics. You start where the IDS stops: baselining what normal looks like on your own wire, then hunting scan activity, botnet behaviour and command-and-control beacons in traffic designed to look ordinary.
Every topic is a hunt you run yourself, against prepared captures of scan, enumeration and C2 traffic. By the end you'll have mapped an intrusion to MITRE ATT&CK from packets alone, and automated the hunt in Tshark so it runs without you next time. No live malware is used — the captures are safe to open and to take home.
Who it's for
Analysts and responders who investigate rather than just triage, and the network people who get pulled in when an investigation reaches the wire.
SOC analysts
Analysts who want to work the packets behind an alert, or hunt where no alert fired at all.
Incident response
Responders reconstructing an intrusion from capture rather than from logs alone.
Network engineers
Engineers pulled into security investigations who already know the traffic better than anyone.
You should be generally familiar with routing and switching, IP addressing and TCP port assignments, SPAN and mirror functions, firewalls and load balancers, and basic cybersecurity principles. Comfort with the packet list helps — if you're new to Wireshark, take the Saturday course first.
What you'll
be able to do
Hunt
Capture for the hunt rather than for troubleshooting, baseline what normal looks like, and pull the suspicious session out of a haystack of legitimate traffic.
Map
Recognise scan patterns, botnet behaviour and beacon intervals, and map what you find to the MITRE ATT&CK framework from initial access through callback.
Automate
Turn the hunt you ran by hand into Tshark that runs on its own, and work alongside Snort and Suricata rather than around them.
Outline
Course outline
The day runs in two movements: find the anomaly, then follow the intrusion.
Morning · Find the anomaly
Where IDS and IPS coverage ends and how to think like the attacker. Capture placement for hunting, baselining normal, and then the traffic that gives itself away — port sweeps, failed connections, botnet behaviour and beacon intervals.
Afternoon · Follow the intrusion
Mapping findings to MITRE ATT&CK and walking a malware infection from delivery to callback. Web enumeration and the filters that expose it. Then Tshark automation, and working alongside Snort and Suricata.
What you'll work through
Each module is anchored to the filter or command it's taught with.
Why the alert didn't fire
Where IDS and IPS coverage ends, and how to think like the attacker whose traffic is designed to look ordinary.
ip.dst != 10.0.0.0/8
How and where to capture for threat hunting, and how to spot the suspicious session in a haystack of legitimate traffic.
tcp.flags.syn == 1 && tcp.window_size <= 1024
Network scan activity and botnet behaviour — sweep patterns, failed connections, and the beacon intervals that give an implant away.
MITRE ATT&CK › Initial Access
Mapping what you find in the capture to the ATT&CK framework, and walking a malware infection from delivery through callback.
http.response.code == 404
Web enumeration and directory brute-forcing, and building the display filters that make the pattern jump off the screen.
tshark -r hunt.pcapng -Y "dns" -T fields
Tshark for analysis and automation, so the hunt you ran by hand can run on its own next time.
alert tcp any any -> $HOME_NET
Working alongside Snort and Suricata, and where AI genuinely helps in pcap-based threat hunting — plus where it will confidently mislead you.
Every hunt is performed live and in class. You leave with the captures, the filters you wrote, and Tshark commands that run against your own traffic.
Before you
arrive
Prerequisites
Comfort with routing and switching, IP addressing and TCP ports, SPAN and mirror functions, firewalls and load balancers, and basic cybersecurity principles. Some familiarity with Wireshark is assumed.
What to bring
A laptop running Linux, Windows or macOS with a current build of Wireshark, local admin rights so you can capture, and Tshark available from the command line.
Provided on the day: all hunt captures and training material. No live malware is used. Sessions are not recorded, and materials go only to people who attend in person.
Certificate
Every student who completes the training receives a continuing education certificate in both forms — a printed copy and a digital version you can file for CPE records or add to your LinkedIn profile.
Your trainer
Chris Greer
Network analyst · Packet Pioneer
Chris is a network analyst and Wireshark instructor at Packet Pioneer, a Wireshark University Certified Training Partner. He spends his working life in other people's captures, chasing latency, retransmissions and the traffic nobody meant to send.
He teaches the way he troubleshoots: open the file, ask a question, filter, prove it. Both of his Switchback courses run as labs from the first session, on captures you keep.
- Role
- Network analyst and Wireshark instructor
- Company
- Packet Pioneer LLC
- Partner
- Wireshark University Certified Training Partner
- Teaches
- TCP/IP Deep Dive · Threat Hunting
Register
One day · AC Hotel Bellevue, WA
A one-day, 8 hour training on Sunday 27 June, 8am to 5pm, with doors at 7:30am. $1,500 per seat, or $2,000 booked together with TCP/IP Deep Dive with Wireshark on the Saturday. The code CGREER takes $100 off, through 28 November.
Part of the June 26–27, 2027 event — see the full event, venue and the other training that weekend.
Reserve your seat Early bird CGREER $100 off Ask a question