🚀 Project 3: Network Scanning & Traffic Analysis Lab (Nmap + Wireshark)
In this project, you'll learn how security professionals discover devices, understand network traffic, and troubleshoot communication using two of the most widely used networking tools:
🔍 Nmap
🌐 Wireshark
⚠️ Important: Perform these activities only in your own lab or on systems you have explicit permission to assess.
🎯 Project Objective
By the end of this project, you'll be able to:
Understand network traffic
Capture packets
Identify common protocols
Perform basic network discovery in a lab
Analyze communication between devices
🛠️ Lab Requirements
Kali Linux VM
Ubuntu or Windows VM
Wireshark
Nmap
Internet or local virtual network
📚 Part 1: Understanding Packet Capture
Open Wireshark and start capturing traffic on your active network interface.
Observe common protocols such as:
DNS
HTTP
HTTPS
TCP
UDP
ICMP
👉 Notice how different applications generate different types of traffic.
🌐 Part 2: Generate Normal Network Activity
Perform normal tasks like:
Browse a website
Search on Google
Ping another machine in your lab
Download a small file
Then observe how those actions appear in Wireshark.
📊 Part 3: Analyze Traffic
Look for:
Source IP Address
Destination IP Address
Protocol used
Packet size
Time between packets
Ask yourself:
Which protocol is most common?
Which device initiated the communication?
Is the traffic encrypted (HTTPS) or unencrypted (HTTP)?
🔍 Part 4: Network Discovery
Using Nmap in your authorized lab, explore how it can help identify:
Active hosts
Open ports
Running services
The goal is to understand network visibility, not to attack systems.
🌍 Real-Life Example
A company reports that employees cannot access an internal website.
A security analyst may:
Capture traffic with Wireshark
Check whether DNS resolution succeeds
Verify that communication reaches the correct server
Review whether the required service is responding
This helps identify where the communication is failing.
🛡️ Skills You'll Build
✅ Packet analysis
✅ Protocol identification
✅ Network troubleshooting
✅ Basic network discovery
✅ Understanding encrypted vs unencrypted traffic
📋 Project Deliverable
Create a short report containing:
Number of devices observed
Protocols identified
Examples of encrypted traffic
Examples of unencrypted traffic (if any)
Key observations from your packet capture
This is excellent practice for documenting security findings.
📝 Mini Challenge
Complete these tasks:
✅ Capture network traffic
✅ Identify at least 5 different protocols
✅ Explain the purpose of each protocol
✅ Write one interesting observation from your packet capture
💡 Easy Trick to Remember
👀 Nmap tells you "what is available."
📦 Wireshark shows you "what is happening."
Using both together gives you a much better understanding of a network.
🚀 Pro Tip
Network traffic analysis is one of the most valuable skills in cybersecurity.
Whether you're a SOC Analyst, Penetration Tester, Incident Responder, or Network Security Engineer, understanding packets and protocols will help you investigate problems and recognize suspicious activity more effectively.
Double Tap ❤️ For More