In this hands-on cybersecurity lab, we’ll walk through how to detect and analyze an ARP spoofing attack using Wireshark and a provided PCAP file.
You’ll learn:
✅ What ARP spoofing is and how it works
✅ How attackers use ARP replies to hijack traffic
✅ How to filter and identify spoofed packets in Wireshark
✅ How to spot duplicate IP address warnings
✅ Mitigations like static ARP entries and dynamic ARP inspection
This lab is perfect for cybersecurity students, red team learners, and blue team defenders looking to strengthen their network defense skills!
Subscribe for more hands-on cybersecurity training and real-world attack walkthroughs!
00:00 – Intro: What is ARP Spoofing?
00:06 – Tools Needed: PCAP File & Wireshark
00:18 – ARP Recap: Broadcasts & MAC-IP Mapping
00:48 – ARP Poisoning Analogy: City and Mailman
01:32 – Wireshark Setup & Opening PCAP
02:12 – Reading ARP Broadcast & Reply Packets
03:43 – Filtering by ARP Opcode in Wireshark
04:29 – Spotting Spoofed Replies & MAC Conflicts
05:44 – Duplicate IP Address Detection
06:35 – How Switches React to ARP Spoofing
06:40 – How to Prevent ARP Poisoning Attacks
07:29 – Wrap-Up: Congrats on Your Packet Investigation!