Analyst II: Advanced DFIR Track
> View Course SyllabusÂ
Support & FAQs
Please use our Support & FAQ page to find more information and reach out to us and join our Discord community for general conversation topics and networking.
Important: Virtual Labs
- Your lab VM is a Windows virtual machine in the cloud. This means it may take a few minutes until they are started up and available.
- Whenever you have less than 15 minutes remaining, you will have the option to extend your lab by 1 hour.
- VMs are persistent. When a lab VM is stopped, it will be stored and you can resume the VM at a later point.
- Terminating a VM will destroy the VM and data will be lost.
- For the best experience, it’s recommended to use Google Chrome where you will have copy and paste functionality.
Tools Used
Splunk, Velociraptor, Plaso, Timesketch, Yara, Sigma, Wireshark, Zeek, Volatility3, CyberChef, EricZimmerman Tools, bulk_extractor, Hayabusa, PEStudio, BrowsingHistoryView
Certificate of Completion
Once you finish the course you will receive your Certificate of Completion!
You must log in and have started this course to submit a review.



I just finished the 301 Advanced Enterprise DFIR course and honestly loved it.
The content was clear, well-structured, and surprisingly engaging. The explanations were easy to follow without oversimplifying anything, and the hands-on parts really helped tie everything together. It’s definitely one of the most solid and interesting DFIR courses I’ve taken so far.
Highly recommend.