Wireshark Labs Aren't Busywork—Here's Why

Welcome to another cybersecurity learning session with Dr. K. This video is designed to help students understand how SOC analysts think when investigating network traffic using Wireshark, not how to blindly click through lab questions. 📂 Follow Along (PCAP Download) The PCAP file used in this lab is available so you can follow along step by step in Wireshark: 👉 Download the PCAP used in this lab: https://dr-k-cybersecurity.kit.com/3e... These are the same PCAP files I use in my Wireshark lab walkthroughs and coursework. This is not a Wireshark tutorial and it is not an answer key. Instead, we walk through why common Wireshark lab questions exist and how analysts extract answers during real investigations. If you’ve ever felt like Wireshark labs were just busywork, this video reframes them as incident investigation exercises. 🔍 What you’ll learn in this session How SOC analysts approach packet captures during investigations How a single HTTP request can answer multiple analysis questions Identifying client vs server behavior in network traffic Understanding Host headers, User-Agent strings, and requested resources Interpreting HTTP status codes and authentication flows Analyzing embedded content and hostname pivots Understanding TCP streams, segmentation, and reassembled data Explaining conditional requests and caching behavior Reading DNS traffic to understand intent and infrastructure Using ports and protocols to confirm what service was actually used 🧠 SOC Analyst Perspective Every question covered in this video maps to a real investigation need, such as: Who initiated the connection? What system was contacted? What resource was requested? Did access succeed or fail? Was content pulled from unexpected locations? How much data was actually transferred? What infrastructure was involved? The goal is not memorization — it’s calm, methodical analysis based on evidence. 🧪 Lab Environment Used Ubuntu client with Wireshark Ubuntu Apache web server Internal lab-only hostnames VirtualBox NAT Network Intentionally generated PCAP for training No external domains. No reused lab artifacts. 🎯 Who this video is for Students working through Wireshark labs Aspiring SOC analysts Entry-level cybersecurity professionals Anyone struggling to understand why Wireshark questions are asked 📚 Recommended Resources (Optional) CompTIA Network+ (N10-009) – Udemy Course Build strong protocol and traffic fundamentals that make Wireshark analysis easier. https://trk.udemy.com/kOn1QV?u=https:... Hack The Box – Hands-On Cybersecurity Labs Practice investigation skills in realistic environments. https://hacktheboxltd.sjv.io/zxzMb6 Subscribe for weekly cybersecurity labs, SOC investigations, and practical security training. Learn. Secure. Grow. Disclosure: Some links above are affiliate links that help support the channel at no extra cost to you.