Passive Analysis

Wireshark, baseline traffic, network attacks, and the attack lifecycle  ·  Approx. 2–3 class days

StarringARP Poisoning · MAC Flooding · DNS PoisoningDoS vs. DDoS

Use this as a quick reference for network attack types, adversary types, the attack lifecycle, and reading baseline traffic in Wireshark.

Passive Analysis: Network Attacks, Adversaries, and Attack Phases infographic

🧭 Plot Summary

This activity puts Wireshark in your hands for the first time — the tool professionals use to capture and inspect network traffic packet by packet. You'll start by establishing a baseline: what normal traffic on this network actually looks like. Once you know normal, you can recognize what isn't.

ARP Poisoning
Enables an on-path (MITM) attack
MAC Flooding
Forces broadcast mode, enables eavesdropping
DNS Poisoning
Redirects to a fake site for credential harvesting
Smurf / DoS / DDoS
Floods a network to deny service

You'll also come back to two concepts from way back in Unit 1 — adversary types and the six-phase attack lifecycle — and this time see them grounded in actual packet data instead of just discussion.

What you will do in this lesson

  • Capture baseline network traffic using Wireshark for the first time.
  • Identify common protocols and normal traffic patterns in real packet data.
  • Recognize ARP poisoning, MAC flooding, and DNS poisoning as they appear in packet captures.
  • Distinguish DoS from DDoS, and see why firewalls matter in preventing network floods.
  • Revisit adversary types and the six-phase attack lifecycle — now grounded in real traffic.

Why it matters

This is the first real log/traffic-reading skill in the course. Wireshark comes back again later, and every network attack you learn to spot here shows up repeatedly for the rest of the unit.

Self-Check Before You Roll On

Check off each item as you get there. These are not grades — they are your own signal.