← All labs
Cyber Defense Forensics Analyst Training Series
Blue Team · 70 labs · Unlimited attempts — included in StationX Unlimited
🔒 Sign in with StationX to get access.
- Analyze Malicious Network Traffic (Scored)
- Auditing Service Accounts - Scored
- Auditing Service Accounts and Setting Up Automated Log Collection - Scored
- Baseline Systems in Accordance with Policy Documentation - Scored
- Conduct Root Cause Analysis for System Crashes (Scored)
- Conduct Supplemental Monitoring
- Control Assessment and Evaluation (Scored)
- Creating a Baseline Using Autopsy (v.2023) - Scored
- Creating a Case in FTK (v.2025) - Scored
- Creating a Forensic Image (v.2023) - Scored
- Creating a List of Installed Programs, Services and User Accounts from a WIN2K12 Server (Scored)
- Cryptography: Steganography (Scored)
- Cryptography: Using GPG for Encryption and Key Management (Scored)
- Data Backup to Prep for Recovery (Scored)
- Data Recovery with Autopsy (Scored)
- Denial of Service PCAP Analysis - Scored
- Dynamic Malware Analysis (Scored)
- Event Log Collection with Splunk (Scored)
- Hash Verification (v.2024) - Scored
- Host Identification Scanning via Windows
- Host Identification Scanning with Linux (Scored)
- Identify Access to a LINUX Firewall Through SYSLOG Service (Scored)
- Implement Single System Changes in Firewall (v.2026)
- Import Nexpose Vulnerability Data into QRadar
- Intro to Linux - Routing and SSH Tunnels (Scored)
- Introduction to Squert
- LNX101 - OpenSSH Installation, Configuration, and Hardening - Scored
- LNX101 - Setting Up a Firewall With UFW and Firewalld
- LNX101 - Telnet vs. SSH
- Lab Environment Orientation - *** (Start Here!) ***
- Live Imaging with FTK Imager Lite
- Log Event Reports (v.2026)
- Manual Vulnerability Assessment - Scored
- Manually Analyze Malicious PDF Documents (Scored)
- Manually Analyze Malicious PDF Documents 2 (Scored)
- Manually Creating a Baseline with MD5Deep - Scored
- Memory Extraction and Analysis (Scored)
- Nessus Scanning and Reporting (v.2026)
- Nexpose: Blue Team Remediation
- Overview of Kibana
- PAM Lab
- Parse Files Out of Network Traffic (Scored)
- Participate in Attack Analysis Using Trusted Tool Set (Scored)
- Patching With WSUS (Scored)
- Pentesting & Network Exploitation - Linux Target Analysis Labs (Scored)
- Preliminary Scanning (v.2024) - Scored
- Protect Against Beaconing (Scored)
- Recover from Incident (Scored)
- Recovery From Inadequate Patching
- Registry Analysis (v.2025) - Scored
- Rogue Device Identification and Blocking - Scored
- Scanning From Windows (Scored)
- Scanning with Nmap
- Securing Linux - Firewalls
- Securing Linux for System Administrators (Scored)
- Setting up Filters and Queries in Kibana
- Snap Exploit
- Snort Signatures, IDS Tuning, and Blocking (Scored)
- Specialized Linux Port Scans
- Threat Designation - Scored
- Tweaking Firewall Rules for Detection (Scored)
- Use pfTop to Analyze Network Traffic - Scored
- Using Snort and Wireshark to Analyze Traffic (v.2026) - Scored
- Validate Indications of Compromise: Analysis of PE File
- WebApp Attack PCAP Analysis - Scored
- Whitelist IP Address from IDS Alerts
- Windows Event Log Manipulation via Windows Event Viewer (v.2026)
- Windows System Hardening with Group Policy & Active Directory (v.2026)
- Windows System Hardening with PowerShell (v.2026) - Scored
- Wireshark (v.2026) - Scored