Packet capture analysis: handshakes, retransmissions and resets
Read capture output line by line to prove where a connection fails: unanswered SYNs, resets, retransmissions, zero windows, DNS errors and TLS server names.
- Level
- Advanced
- Length
- About 60 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 1 Oct 2026
Skills you'll practise
- Interpret TCP flags, sequence numbers and timestamps in tcpdump and tshark output
- Distinguish a dropped connection, a refused connection and a slow receiver from capture evidence
- Write capture filters and display filters that isolate one conversation
- Handle captures safely, collecting only what's needed and protecting what's collected
Course outline
- 1.Reading packet capturesVideo · 2 min
- 2.Reading TCP in capture outputLesson · 20 min
- 3.Loss, retransmissions and windowsLesson · 20 min
- 4.Filters, DNS and TLS, and handling captures safelyLesson · 20 min
- 5.Packet capture analysis: handshakes, retransmissions and resets: knowledge checkKnowledge check · 17 questions
- 6.Packet capture analysis: handshakes, retransmissions and resets: practical exerciseKnowledge check · 1 question
- 7."The network is slow" for the claims appScenario
- 8.Final exam7 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- RFC 9293: Transmission Control Protocol (TCP)
- RFC 1035: Domain Names: Implementation and Specification
- tcpdump and pcap-filter manual pages
- Wireshark User's Guide: display filters
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.