- 13 Sections
- 72 Lessons
- Lifetime
- NFIR Mission, Governance, Safety and Lifecycle
Outcome: Define a governed network-forensics and incident-response mission, lifecycle, authority model, roles, safety controls and decision records.
Case: Project Netrakshak opens when a fictional Indian logistics company reports unusual authentication, DNS and outbound traffic. The learner receives a written mandate and synthetic evidence only.
Tools: NFIR charter, role-and-escalation matrix, lifecycle decision log
7 - Network Architecture, Protocol Evidence and Sensor Placement
Outcome: Explain how network architecture, protocols, addressing and sensor placement determine what evidence exists and what conclusions are supportable.
Case: Netrakshak has segmented offices, cloud workloads, VPN users, NAT, proxies and asymmetric routing. The team must map what each sensor can and cannot observe.
Tools: logical topology, protocol-evidence map, sensor coverage register
7- 2.1Read the architecture as an evidence map
- 2.2Use layers without treating them as rigid boxes
- 2.3Reason about addressing and identity
- 2.4Reconstruct sessions and flows
- 2.5Understand infrastructure protocols
- 2.6Place sensors deliberately
- 2.7Module 2 Assessment — Network Architecture, Protocol Evidence and Sensor Placement5 Minutes5 Questions
- Evidence Readiness, Time, Logging and Network Telemetry
Outcome: Design evidence-ready logging, time synchronisation, telemetry coverage, retention, access and baseline controls.
Case: The company has inconsistent clocks, short retention and different log schemas. Learners must design a minimum-necessary evidence-readiness plan before more events occur.
Tools: telemetry catalogue, time-quality register, readiness and retention plan
7 - Packet Capture Acquisition, Preservation and Integrity
Outcome: Acquire, preserve, validate and document packet captures and network records without changing originals or exceeding authority.
Case: A volatile traffic window may contain command-and-control and data-transfer evidence. Learners plan and document a bounded capture without touching a live target.
Tools: capture plan, PCAP evidence log, integrity and custody record
7 - Packet Analysis with Wireshark and TShark
Outcome: Analyse packet evidence with Wireshark and TShark using reproducible filters, statistics and protocol reasoning.
Case: A verified synthetic PCAP contains ordinary business traffic mixed with suspicious DNS, TLS and outbound sessions. Learners create repeatable findings, not screenshots alone.
Tools: filter notebook, conversation worksheet, reproducible packet findings
7 - Zeek, NetFlow/IPFIX and DNS Metadata Analysis
Outcome: Correlate Zeek, NetFlow/IPFIX, DNS and related metadata to identify patterns while accounting for visibility and interpretation limits.
Case: Full packet data is unavailable for part of Netrakshak, but Zeek logs, flow records and DNS telemetry cover the relevant period with documented gaps.
Tools: Zeek correlation sheet, flow-analysis matrix, metadata limitations statement
7 - Suricata, SIEM Correlation and ATT&CK Mapping
Outcome: Triage and validate Suricata and SIEM detections, map observed behaviour to ATT&CK and improve detection logic without overclaiming.
Case: Suricata EVE records and SIEM correlations flag possible phishing delivery, remote access and exfiltration. Learners validate each alert against evidence and coverage.
Tools: alert-triage queue, correlation notebook, ATT&CK and detection map
7 - Scoping Compromise and Building the Incident Timeline
Outcome: Scope affected assets, identities and time ranges, test competing incident hypotheses and build a normalized, source-linked timeline.
Case: Evidence suggests a compromised VPN account, internal discovery and outbound staging, but records conflict. Learners define confirmed, suspected and unaffected scope.
Tools: scope matrix, normalized event timeline, hypothesis and confidence register
7 - Containment, Eradication and Recovery with Evidence Preservation
Outcome: Select and document proportionate containment, eradication and recovery actions while preserving evidence and operational safety.
Case: The incident commander must choose between immediate isolation, selective blocking and monitored continuity for a time-critical logistics service.
Tools: containment options paper, remediation tracker, recovery validation plan
7 - Cloud, VPN, Wireless, Email and Encrypted-Traffic Investigations
Outcome: Investigate cloud, VPN, wireless, email, proxy, IPv6 and encrypted-traffic scenarios using provider-aware and privacy-aware evidence plans.
Case: Netrakshak evidence spans cloud flow logs, VPN authentication, a branch Wi-Fi network, secure email gateways, proxies and mostly encrypted application traffic.
Tools: provider evidence plan, multi-domain correlation worksheet, visibility limitations brief
7- 10.1Investigate cloud network evidence
- 10.2Correlate VPN and remote access
- 10.3Handle wireless evidence
- 10.4Investigate email network paths
- 10.5Analyse encrypted traffic metadata
- 10.6Account for proxies, tunnels and IPv6
- 10.7Module 10 Assessment — Cloud, VPN, Wireless, Email and Encrypted-Traffic Investigations5 Minutes5 Questions
- Incident Reporting, Coordination and Lessons Learned
Outcome: Produce technical and executive incident products, coordinate lawful notifications and handoffs, and turn lessons learned into measurable improvement.
Case: The team must brief leaders, hand evidence to specialists, assess current CERT-In obligations and improve controls without exposing unnecessary personal data.
Tools: incident report set, coordination and notification matrix, after-action improvement register
7- 11.1Write for the decision-maker
- 11.2Use precise incident language
- 11.3Coordinate handoffs
- 11.4Assess India-specific notification duties
- 11.5Conduct a blameless after-action review
- 11.6Measure and sustain improvement
- 11.7Module 11 Assessment — Incident Reporting, Coordination and Lessons Learned5 Minutes5 Questions
- Capstone - Project Netrakshak
Outcome: Defend an end-to-end network-forensics and incident-response case for Project Netrakshak using synthetic evidence and documented uncertainty.
Case: A final synthetic evidence drop combines a VPN anomaly, DNS and TLS metadata, Zeek and Suricata records, cloud flows, a packet excerpt, business constraints and conflicting explanations. Learners must defend a safe response.
Tools: integrated case file, executive and technical brief, after-action defence
7 - Final ExaminationFinal assessment for Network Forensics & Incident Response. Passing score: 70%.1
