Skip to main content
CYB-0352ExpertCurrent Intake
XNFA

Xcademia Network Forensics Analyst

5-Day Instructor-Led Programme

The XNFA Certification Programme is the practitioner standard for network forensics analysts who investigate cyber incidents through network traffic analysis, protocol dissection, C2 communication identification, and adversary campaign reconstruction from PCAP, Zeek logs, NetFlow, and proxy data. Assessed on Day 5 through a supervised network forensic investigation producing a professional findings report. No MCQs. No exam.

Duration

5 Days

Price

$4,495

Xcademia Network Forensics Analyst
Duration
5 Days
Complete in 5 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

Network traffic is the most honest witness in a cyber investigation. Attackers can clear logs, delete files, and wipe systems, but network flows, PCAP captures, and DNS queries often remain as evidence of what occurred, when, and through which systems. The analyst who can read this evidence fluently has a significant investigative advantage. XNFA is built for DFIR professionals, SOC analysts, and threat hunters who want to develop network forensics as a core specialism.

Across five instructor-led days, participants build capability from network protocol fundamentals through advanced traffic analysis with Wireshark, Zeek, and NetworkMiner, encrypted traffic analysis using JA3 and JA3S fingerprinting, DNS forensics, web proxy log analysis, NetFlow analysis, lateral movement and data exfiltration detection in network evidence, and network evidence timeline reconstruction for investigation. Every session uses real PCAP files from real incidents in a structured forensics workflow.

On Day 5, participants investigate a simulated breach through network evidence only: PCAPs, DNS logs, proxy logs, and NetFlow records. They reconstruct the attack, identify attacker infrastructure, map to MITRE ATT&CK, and produce a professional network forensics report. A senior practitioner assesses methodology and report quality. XNFA certificate and Practitioner Assessment Report issued together.

Hands-On Learning

Hands-on Wireshark display filter construction, Zeek log analysis and scripting, NetworkMiner session reconstruction, DNS forensics, JA3/JA3S fingerprinting, NetFlow analysis with SiLK, and a supervised network investigation exercise on Day 5.

Mentor-Led Sessions

Mentor-led sessions reconstructing real adversary campaigns from network evidence only, examining C2 traffic patterns, lateral movement in packet captures, and data exfiltration detection through encrypted channels.

Career-Ready Skills

Investigate cyber incidents through structured network traffic analysis, reconstruct adversary campaigns from multi-source network evidence, and produce professional network forensics reports that satisfy incident investigation and regulatory requirements.

Learning Outcomes

Conduct structured network traffic analysis using Wireshark, Zeek, and NetworkMiner to identify adversary activity in enterprise PCAP captures

Analyse DNS, web proxy, and NetFlow data to reconstruct adversary campaigns and identify attacker infrastructure from multi-source network evidence

Detect and analyse C2 communication patterns including beaconing, DNS tunnelling, and TLS-obscured traffic using JA3/JA3S fingerprinting

Reconstruct multi-stage attack timelines from network evidence across PCAP, Zeek logs, NetFlow records, and proxy log sources

Map network-layer adversary techniques to MITRE ATT&CK v14 for attribution and detection engineering

Produce professional network forensics investigation reports aligned to ACPO digital evidence guidelines and regulatory evidence requirements

Prerequisites

1

Minimum 12 months in a SOC, DFIR, network security, or IT infrastructure role

2

Working knowledge of TCP/IP networking and basic familiarity with Wireshark or equivalent packet analysis

3

Basic understanding of common network protocols: HTTP, DNS, SMTP, and SMB

Detailed Syllabus

Organized by professional domains with comprehensive coverage

Topics Covered:
  • TCP/IP stack forensically relevant header fields: flags, sequence numbers, window sizes, and TTL analysis
  • TCP connection forensics: SYN/ACK/RST anomalies, half-open connections, and session hijacking indicators
  • UDP and ICMP forensics: ICMP tunnelling detection and UDP-based protocol anomalies
  • IPv6 forensics considerations: dual-stack environments and IPv6-specific attack indicators
  • ARP poisoning and VLAN hopping detection from network captures and switching infrastructure logs
Stage 5Final Capstone

Xcademia Network Forensics Analyst — Capstone Project

On Day 5, participants receive a multi-source network evidence package: PCAP captures, Zeek logs, NetFlow records, DNS query logs, and web proxy logs from a simulated enterprise breach spanning multiple days. They must independently identify the attack, reconstruct the full attack chain, identify attacker infrastructure, map techniques to MITRE ATT&CK v14, extract IOCs, and produce a professional network forensics investigation report. The senior practitioner assesses methodology and report quality throughout.

Assessed by a senior Xcademia practitioner

Framework Alignment

This course is mapped directly onto the standards your organisation already answers to. No invented frameworks, no proprietary jargon.

  • MITRE ATT&CK v14

    Global

    Network-layer technique attribution from PCAP and Zeek evidence: C2, lateral movement, and exfiltration mapping

  • NIST SP 800-61

    Global

    Network forensics as an incident response component: methodology integration with IR lifecycle

  • ISO 27035

    Global

    Information security incident management: network evidence role in investigation phases

  • ACPO Digital Evidence Guidelines

    Global

    UK Police digital evidence principles: chain of custody applied to network forensic evidence collection

  • Zeek Project

    Global

    Zeek network security monitoring framework: Day 2 primary tool coverage with scripting exercises

  • JA3/JA3S Project

    Global

    TLS fingerprinting methodology: encrypted traffic analysis and C2 identification methodology

  • SiLK (System for Internet-Level Knowledge)

    Global

    CERT NetFlow analysis toolkit: flow-based investigation methodology throughout

  • RFC Standards

    Global

    TCP/IP and protocol RFCs: forensically relevant header and behaviour analysis foundation

Skills You'll Gain

Master these in-demand skills through hands-on practice

Wireshark advanced analysisZeek log analysis and scriptingC2 beaconing detectionDNS forensicsJA3/JA3S encrypted traffic fingerprintingNetFlow analysis (SiLK)Lateral movement detection in network evidenceData exfiltration detectionNetworkMiner session reconstructionMITRE ATT&CK network technique mappingNetwork timeline construction (Plaso)Network forensics report writing

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

Network Forensics AnalystDFIR SpecialistSOC L2/L3 AnalystThreat HunterNetwork Security EngineerIncident Responder
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

5 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$4,495+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised Xcademia Network Forensics Analyst learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Xcademia Certification Programme

Xcademia Certification Programme

On successful completion of Xcademia Network Forensics Analyst, learners are assessed on the final day through a supervised practitioner scenario. Three outcomes are possible, Certificate Awarded, Certificate Deferred, or Not Awarded. The Practitioner Assessment Report and certificate are issued together. Verified at xcademia.com/verify.

Certificate Awarded

Assessed competent on the final day.

Certificate Deferred

Resit available on a future cohort.

Not Awarded

Attendance record issued. Reassessment possible.

Frequently Asked Questions

Everything you need to know about this course

SANS FOR572 costs approximately $9,779 total. XNFA is 5 instructor-led days ending in a supervised network forensics investigation on Day 5. Participants analyse real PCAP captures and multi-source log data to reconstruct a simulated breach, producing a professional findings report. Less than a third of the GNFA total cost. The Practitioner Assessment Report documents investigation methodology and report quality.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options