Skip to content

Latest commit

 

History

History

README.md

This material has been designed to be taught in a classroom environment... hands-on 80% + talk 40% + slides 0% = 120% hard work

The online material is missing some of the contextual concepts and ideas that will be covered in class.

This course holds ~5 days of material for any intermediate-level dev-ops who has some experience with other security|monitoring tools and wants to learn Arkime. We believe these classes are perfect for anyone who wants a jump start in learning Arkime or who wants a more thorough understanding of it internals.

Analyzing the most recent Locked Shields dataset is an added bonus all participants get. Furthermore, in the class we've also had dedicated session by LS red teamers shining a light on what sneaky things they did in the recent exercise.

Arkime is a large scale, open source, full packet capturing, indexing, and database system

Arkime was formerly named Moloch, so the materials on this site may still refer to it as Moloch in various ways or forms. Same holds true for the Arkime codebase. Arkime is not meant to replace Intrusion Detection Systems (IDS). Arkime augments your current security infrastructure by storing and indexing network traffic in standard PCAP format, while also providing fast indexed access.

Provided timeline is preliminary and will develop according to the actual progress of the class. On-site participation only.

Attention: Initial start time of 13:00 has changed to 09:00 as communicated via e-mail.

Day 1 :: Intro, singlehost, basic Viewer usage :: June 15 2026 :: 09:00 Local time

Day 2 :: Install, basic configuration :: June 16 2026

Day 3 :: Advanced configuration, enrichment :: June 17 2026

Day 4 :: Suricata, SSL/TLS proxy :: June 18 2026

Day 5 :: Last but not least :: June 19 2026, ends at 12:00

Orphan topics, topics from previous iterations that we might or might not cover

For trying out locally -- not needed for classroom!


Before You Come To Class