Welcome to TCPDump Cyber Lab
A hands-on training environment where you learn to read network traffic the way real cybersecurity analysts do — across IT, ICS/SCADA, and IoT systems.
What is this lab?
This is a free, fully client-side cybersecurity training lab that simulates tcpdump packet analysis. No installation needed — everything runs in your browser.
You will work through 4 modules, progressing from basic command practice to advanced threat identification across three security domains:
By the end, you'll understand how to spot password leaks, malware beacons, DNS tunneling, Modbus register attacks, MQTT hijacking, and port scanning — just from reading packet captures.
Lab Architecture — How the 4 modules connect
Terminal Simulation
Practice 6 tcpdump commands in a realistic terminal. Outputs are randomized — run the same command twice and you'll see different traffic each time.
tcpdump -i eth0
port 80
-A
host <ip>
port 502
port 1883
Traffic Scenarios (8 incidents)
Real-world packet captures organized by severity and domain. Read the logs carefully before clicking "Reveal Analysis."
Interactive Analysis (8 challenges)
Multiple-choice questions on real packet snippets. You get immediate feedback explaining why the correct answer is correct — this is where deep learning happens.
Final Assessment (15 questions)
Comprehensive quiz covering all domains. Your score determines your analyst rating:
Quick tips from CertInstructor
Port = Protocol. Memorize the critical ones: 80 (HTTP), 443 (HTTPS), 502 (Modbus), 1883 (MQTT), 47808 (BACnet), 53 (DNS), 22 (SSH).
If you can read it, it's not encrypted. Seeing payload text in tcpdump means the connection is NOT using TLS. That's often the first red flag.
Know your baselines. Normal traffic looks predictable. Attacks show anomalies: wrong source IPs, extreme values, unusual User-Agents, rapid port sequences.
ICS has no auth. Modbus, BACnet, and many SCADA protocols were designed without authentication. Anyone who can reach port 502 can control a PLC.
IoT defaults kill. Default credentials (admin/admin) on MQTT brokers give attackers full publish/subscribe control over your entire sensor and actuator network.
Think like an attacker. For each scenario, ask: "What would I do next if I saw this data?" That mindset turns packet analysis into threat hunting.
Ready? Start with the Terminal to get familiar with tcpdump syntax, then work through each module in order.
Terminal Simulation
Practice tcpdump commands in a sandboxed environment. Capture packets from IT networks, ICS/SCADA protocols (Modbus TCP port 502), and IoT traffic (MQTT port 1883).
Traffic Scenarios
Review 8 real-world packet captures spanning IT networks, ICS/SCADA industrial systems, and IoT devices. Study each scenario, then reveal the analysis.
Interactive Analysis
For each scenario — from HTTP credential leaks to Modbus register overwrites and MQTT command injection — determine whether the traffic is malicious or benign.
Final Assessment
15 questions testing your tcpdump knowledge across IT, ICS/SCADA, and IoT security domains.