Products
-
FAT File System Forensics
CourseExplore FAT32 & VFAT file system internals in this hands‑on forensic lab. Learn to parse directory and allocation structures, recover deleted files, and uncover FAT‑specific artifacts. Lab-based training ideal for DFIR professionals.
$50
-
Pre-order available now!
Anti-Forensics
CourseLearn how attackers hide evidence and how defenders expose it. This Anti‑Forensics course covers data hiding, steganography, encryption, filesystem and memory evasion techniques—with hands-on virtual labs to detect manipulation and recover hidden dat
$50
-
Investigating File Systems
CourseUnderstand Windows file systems in detail, including FAT32 and NTFS. Learn to parse, analyze partitions and metadata, recover files, and investigate corrupted disks. Hands-on labs reinforce core forensics skills.
$50
-
Disk Forensic Analysis
CourseLearn how to analyze disk structures, identify and recover digital evidence, repair corrupted disks, and interpret metadata, all through hands‑on virtual labs designed for DFIR practitioners.
$50
-
Investigating Windows Recycle Bin
Course4.8 average rating (12 reviews)Investigate Windows Recycle Bin artifacts in this hands-on course. Learn to parse $R and $I files, decode timestamps, and use tools like RBCmd.exe and Rifiuti2 to recover or analyze permanently deleted items. Ideal for entry-level DFIR learners.
Free
-
Investigating Windows Program Executions
CourseInvestigate Windows execution artifacts like Prefetch, AmCache, ShimCache, UserAssist & BAM in hands-on labs. Learn tool-based analysis and forensic significance of each artifact. Ideal for DFIR analysts.
$50
-
Time Zone Conversions
Course4.5 average rating (2 reviews)This course covers the required digital forensic skills to inspect and understand the different timestamps that could be seen during an investigation and learn how to convert between timezones.
Free
-
Investigating Windows LNK Files and JumpLists
CourseInvestigate Windows LNK and JumpList artifacts in hands‑on labs. Learn to parse .lnk files and JumpLists, trace file usage, determine storage paths, even for deleted files. Essential training in user activity forensic analysis.
$50
-
Investigating Windows Thumb Caches
CourseDive into Windows thumbnail cache forensics using hands‑on labs. Learn to analyze Thumbs.db and thumbcache_xxx.db, uncover hidden file previews, and reconstruct user activity. Ideal for DFIR analysts and forensic investigators.
$50