CI

Welcome to TCPDump Cyber Lab

A hands-on training environment where you learn to read network traffic the way real cybersecurity analysts do — across IT, ICS/SCADA, and IoT systems.

◆

What is this lab?

This is a free, fully client-side cybersecurity training lab that simulates tcpdump packet analysis. No installation needed — everything runs in your browser.

You will work through 4 modules, progressing from basic command practice to advanced threat identification across three security domains:

IT Networks ICS / SCADA IoT Devices

By the end, you'll understand how to spot password leaks, malware beacons, DNS tunneling, Modbus register attacks, MQTT hijacking, and port scanning — just from reading packet captures.

☰

Lab Architecture — How the 4 modules connect

01

Terminal Simulation

Practice 6 tcpdump commands in a realistic terminal. Outputs are randomized — run the same command twice and you'll see different traffic each time.

tcpdump -i eth0 port 80 -A host <ip> port 502 port 1883
? After running each command, ask yourself: What protocol is being used? What are the source and destination? Can I see any payload data? Why or why not?
02

Traffic Scenarios (8 incidents)

Real-world packet captures organized by severity and domain. Read the logs carefully before clicking "Reveal Analysis."

CRITICALIT Password Leak (HTTP plaintext)
CRITICALIT Malware C2 Beacon
HIGHIT DNS Tunneling Exfiltration
NORMALIT Normal HTTPS Traffic
HIGHIT Port Scanning (incl. ICS ports)
CRITICALICS SCADA Modbus Register Overwrite
HIGHICS PLC Firmware Reconnaissance
CRITICALIoT MQTT Command Injection
? Before revealing: What port is being used? Is the source IP expected? Are the values/commands normal for this protocol? What would you alert on?
03

Interactive Analysis (8 challenges)

Multiple-choice questions on real packet snippets. You get immediate feedback explaining why the correct answer is correct — this is where deep learning happens.

? For each challenge: Is this traffic malicious or normal? What specific indicator tells you? Could a legitimate system produce this same pattern?
04

Final Assessment (15 questions)

Comprehensive quiz covering all domains. Your score determines your analyst rating:

0 — 5 Beginner Analyst
6 — 10 Intermediate Analyst
11 — 15 Advanced OT/IT Analyst
? After the quiz: Which questions did I get wrong? Do they cluster in IT, ICS, or IoT? What should I study next?
★

Quick tips from CertInstructor

01

Port = Protocol. Memorize the critical ones: 80 (HTTP), 443 (HTTPS), 502 (Modbus), 1883 (MQTT), 47808 (BACnet), 53 (DNS), 22 (SSH).

02

If you can read it, it's not encrypted. Seeing payload text in tcpdump means the connection is NOT using TLS. That's often the first red flag.

03

Know your baselines. Normal traffic looks predictable. Attacks show anomalies: wrong source IPs, extreme values, unusual User-Agents, rapid port sequences.

04

ICS has no auth. Modbus, BACnet, and many SCADA protocols were designed without authentication. Anyone who can reach port 502 can control a PLC.

05

IoT defaults kill. Default credentials (admin/admin) on MQTT brokers give attackers full publish/subscribe control over your entire sensor and actuator network.

06

Think like an attacker. For each scenario, ask: "What would I do next if I saw this data?" That mindset turns packet analysis into threat hunting.

Ready? Start with the Terminal to get familiar with tcpdump syntax, then work through each module in order.

Terminal Simulation

Practice tcpdump commands in a sandboxed environment. Capture packets from IT networks, ICS/SCADA protocols (Modbus TCP port 502), and IoT traffic (MQTT port 1883).

root@cyberlab:~# tcpdump
╔════════════════════════════════════════════════════════╗
║ TCPDump Cyber Lab v4.0 — IT / ICS-SCADA / IoT ║
║ Type a command or click a quick-launch above ║
║ Type 'help' for all available commands ║
╚════════════════════════════════════════════════════════╝
root@cyberlab:~#

Traffic Scenarios

Review 8 real-world packet captures spanning IT networks, ICS/SCADA industrial systems, and IoT devices. Study each scenario, then reveal the analysis.

1 / 8

Interactive Analysis

For each scenario — from HTTP credential leaks to Modbus register overwrites and MQTT command injection — determine whether the traffic is malicious or benign.

Challenge 1 / 8
Score: 0 / 8

Final Assessment

15 questions testing your tcpdump knowledge across IT, ICS/SCADA, and IoT security domains.

Question 1 / 15
Score: 0 / 15