Domain

Network Analysis

Reading traffic at the packet level.

Logs show what an application decided to write down. A capture shows what actually crossed the wire. When the two disagree, the capture is right, and being able to read one is what separates explaining an incident from guessing at it.

Coursework: graduate Computer Networking at Eller — TCP congestion analysis, an HTTP client built from scratch, BGP, OpenFlow, IPv6 tunneling, TLS and IKE labs, wireless, and data center networking.
Roadmap

What's next

Listed before it exists so you can tell the difference.

Packet forensics walkthrough

Rebuilding an incident timeline using only a capture file.

Network Analysis Planned
Protocol security analysis

What's still visible in a TLS handshake and an IPsec/IKE negotiation.

Network Analysis Planned