Analyst I: Practical Windows Forensics Track
Support & FAQs
Please use our Support & FAQ page to find more information and reach out to us and join our Discord community for general conversation topics and networking.
200FOR Investigation Scenario Bundle
This bundle includes four browser-based scenarios, each modeled after real-world enterprise incidents:
- FOR001: Disgruntled Manager’s Exodus – Intermediate
- FOR002: Suspicious Network Connection – Intermediate
- FOR003: Unauthorized Access to Confidential Share Drive – Advanced
- FOR004: Suspicious Logons to CTO Workstation – Beginner
Each scenario is fully self-contained and delivered in a cloud-based forensic lab—no downloads or setup required.
Learn, Practice, and Validate Your Skills
These scenarios are part of the “Practice” phase of our Learn → Practice → Validate framework. You’ll get to:
- Apply investigative techniques in realistic settings
- Analyze memory, disk, log, and network artifacts
- Build confidence with guided objectives and forensic tools
- Practice storytelling through reporting and evidence correlation
Certificate of Completion
Once you finish the course you will earn:
- A Certificate of Completion for finishing the full course
- Individual certificates for each scenario upon completing the end-of-scenario quiz
- An Achievement Badge after completing each investigation scenario
- A Forensic Excellence Badge for any scenario where you score 80% or higher on the quiz
🏆 Both badges qualify you for future leaderboard features and special recognition opportunities.

You must log in and have started this course to submit a review.


I have already taken the Practical Windows Forensics course, which contains many valuable tips on how to use Kape and the Zimmermann tools. With the four scenarios here from 200, I was able to apply what I had learned in four realistic scenarios. I can say that the scenarios are realistic because I have been working in the DFIR area and have had to deal with more or less similar incidents there. A valuable addition to the scenarios is the analysis of memory images, which is often neglected. The scenarios are feasible for everyone, whether beginner (with knowledge of FOR201) or advanced.