Introduction
Network diagrams hide more than they show. A packet capture does not. If you can read a capture you can answer questions no diagram will settle, and the skill takes an afternoon to start and a career to finish.
How it works
Each layer wraps the one above it. Ethernet carries IP, IP carries TCP or UDP, and TCP carries whatever the application speaks. Reading a packet is peeling that wrapping in order and asking, at each layer, who is talking to whom and about what.
Ports are convention. Nothing forces a web server onto 443, and attackers rely on people assuming otherwise. What identifies a protocol is the shape of the traffic, not the number it arrived on.
Common risks
Assuming a port implies a protocol misses tunnelled traffic entirely. Assuming TLS means safe misses everything happening inside a legitimately encrypted channel to a malicious destination.
How to detect it
Baseline what normal looks like on your network before you need to spot abnormal. Watch for protocol on unusual ports, long-lived connections to unfamiliar destinations, and DNS queries with unusual entropy.
How to defend
Segment so that a compromised host cannot reach everything. Log DNS. Terminate and inspect TLS where law and policy allow. Alert on new outbound destinations from server subnets rather than trying to enumerate bad ones.