Wireshark, baseline traffic, network attacks, and the attack lifecycle · Approx. 2–3 class days
StarringARP Poisoning · MAC Flooding · DNS PoisoningDoS vs. DDoS
Use this as a quick reference for network attack types, adversary types, the attack lifecycle, and reading baseline traffic in Wireshark.
🧭 Plot Summary
This activity puts Wireshark in your hands for the first time — the tool professionals use to capture and inspect network traffic packet by packet. You'll start by establishing a baseline: what normal traffic on this network actually looks like. Once you know normal, you can recognize what isn't.
ARP Poisoning
Enables an on-path (MITM) attack
MAC Flooding
Forces broadcast mode, enables eavesdropping
DNS Poisoning
Redirects to a fake site for credential harvesting
Smurf / DoS / DDoS
Floods a network to deny service
You'll also come back to two concepts from way back in Unit 1 — adversary types and the six-phase attack lifecycle — and this time see them grounded in actual packet data instead of just discussion.
What you will do in this lesson
Capture baseline network traffic using Wireshark for the first time.
Identify common protocols and normal traffic patterns in real packet data.
Recognize ARP poisoning, MAC flooding, and DNS poisoning as they appear in packet captures.
Distinguish DoS from DDoS, and see why firewalls matter in preventing network floods.
Revisit adversary types and the six-phase attack lifecycle — now grounded in real traffic.
Why it matters
This is the first real log/traffic-reading skill in the course. Wireshark comes back again later, and every network attack you learn to spot here shows up repeatedly for the rest of the unit.
✅ Self-Check Before You Roll On
Check off each item as you get there. These are not grades — they are your own signal.