Wireshark Starter Guide Polymath Studies Cybersecurity Academy OBJECTIVE Capture and interpret CyberLab network traffic. AUTHORIZED USE Use this guide only with CyberLab targets, systems you own, or systems for which you have explicit written permission. WORKFLOW 1. Select the CyberLab interface. 2. Start a short capture. 3. Generate a DNS lookup and visit the assigned HTTPS page. 4. Stop the capture. 5. Apply dns, tcp, and tls display filters. 6. Follow one permitted stream. 7. Record endpoints, ports, timestamps, and protocol layers. LAB RECORD Target and authorization: Tool version: Date and time: Commands or actions: Evidence collected: Result: Defensive recommendation: REMEMBER A tool result is evidence to evaluate—not automatic proof. Verify important findings independently.