Your Path to DFIR Mastery
Navigate from security fundamentals to enterprise-scale incident response. Each track builds on the last — learn the concepts, practice with real scenarios, and validate your skills.
Training Tracks
— structured learning paths from fundamentals to advancedSOC ANALYST CORE
Enterprise Security
Build your security foundation — understand enterprise environments, attacker tradecraft, and core defensive concepts that every security professional needs.
ANALYST I
Practical Windows Forensics
Develop hands-on forensic investigation skills — disk & memory analysis, timeline reconstruction, and evidence handling in realistic enterprise scenarios.
Analyze a compromised system, reconstruct the attack timeline, and deliver a professional DFIR report. Score 85%+ for distinction.
Learn about the examANALYST II
Advanced DFIR
Master enterprise-scale incident response — multi-host investigations, advanced memory analysis, and full IR reporting for real-world APT and ransomware cases.
The Analyst II certification exam is currently in development. Stay tuned for the ultimate enterprise DFIR validation.
Ongoing Practice
— continuous skill-building, independent of tracksAnalyst Defense Labs
Monthly investigation scenarios for working analysts
Sharpen your skills with fresh, real-world investigation scenarios released monthly. Each lab drops you into a realistic case with logs, artifacts, and a guided in-browser environment. No track required — built from feedback by SOC analysts to senior DFIR engineers.

