
Digital Forensics Analyst — career path
StationX Advanced
Recover, preserve and explain what happened on a machine or a network. Security+ first, then disk, network, malware and document forensics, with the deepest lab series on the platform.
The path
Step 1 — Security foundation
The baseline every forensics role lists.
follows a certification path
Learn
- PathFollow the CompTIA Security+ (SY0-701) path — the entry certification for every defensive role
Step 2 — Forensics foundations
Acquire and handle evidence so it survives scrutiny.
1 course · 28 labs
Learn
- CourseDigital Forensics for Pentesters - Hands-on Learning 🔒 StationX Unlimited
18 sections · 67 lectures
- Training Overview 2
- Course Overview 1
- Building Your Forensics Lab Environment Using VirtualBox 6
- New Course Content 6
- Troubleshooting VirtualBox 2
- Introduction to Autopsy 4
- Kali forensic Mode 4
- CSI Linux Investigator 3
- Digital Forensics Case Management 1
- Open-source intelligence (OSINT) 3
- Using Shodan to Search for Vulnerable devices 3
- Computer Forensics 9
- Reverse Engineering and Malware Analysis 5
- Malware Hunting with Sysinternal Tools 3
- Stenography 2
- Network forensics Using Wireshark 7
- Practice What You learned 5
- Audio Version of Training 1
Practise
- LabsForensic Investigations and Evidence Handling — 13 labs 🔒 StationX Unlimited
- Analyze Packed Executable to Identify Attack Vector and Payload
- Analyze and Update a Company BCP/BIA/DRP/CIRP
- BCP DRP and Test Planning
- Creating a Case in Autopsy
- Creating a Case in OSF
- Creation of BCP and DRP
- FTK Analysis & Reporting
- FTK Enterprise Fundamentals and Mobile Investigation
- Metadata Extraction Lab
- Open Source Password Cracking
- Password Cracking with PRTK
- Registry Analysis
- Virtualization
- LabsDigital Media Forensics — 15 labs 🔒 StationX Unlimited
- Analyze Malicious Network Traffic
- Compromise Assessment with Crowd Response
- Conduct Log Analysis and Cross Examination for False Positives
- Creating a Forensic Image
- Data Recovery with Autopsy
- Detect the Introduction of a Malicious Application
- Identify Access to a LINUX Firewall Through SYSLOG Service
- Identify Suspicious Information in VM Snapshots
- Identify Whether High-Risk Systems Were Affected
- Identify and Remove Trojan Using Various Tools
- Live Imaging with FTK Imager and Data Recovery with Autopsy
- Manually Analyze Malicious PDF Documents
- Manually Analyze Malicious PDF Documents 2
- Memory Extraction and Analysis
- Participate in Attack Analysis Using Trusted Tool Set
Step 3 — Network forensics
Reconstruct what crossed the wire.
1 course · 15 labs
Learn
- CourseMaster Wireshark 3 in 5 Days 🔒 StationX Unlimited
6 sections · 34 lectures
- Training Overview 2
- Day One 3
- Day Two 8
- Day Three 7
- Day Four 7
- Day Five 7
Practise
- LabsNetwork Forensics — 15 labs 🔒 StationX Unlimited
- Analyze Browser-based Heap Spray Attack
- Automated in-Depth Packet Decoding
- Clonezilla_Network
- Identifying Intrusion and Mitigating Attacks with RHEL Server
- Identifying Malicious Callbacks
- Identifying Malicious Network Connections
- Incident Detection and Identification
- Nexpose: Analysis & Reporting (Executive, High Risk and Recommendation Reporting)
- Parse Files Out of Network Traffic
- Searching for Indicators of Compromise
- Setting up Filters and Queries in Kibana
- Use pfTop to Analyze Network Traffic
- Verify Attributes of Identified SilentBanker Intrusion
- Verify Attributes of Intrusion Through Additional Analysis
- Windows Event Log Manipulation via Windows Event Viewer
Step 4 — Malware and document analysis
Take apart the binary or the booby-trapped document at the centre of the case.
3 courses · 18 labs
Learn
- CourseReverse Engineering and Malware Analysis Fundamentals 🔒 StationX Unlimited
1 section · 0 lectures
- First Section 0
- CourseReverse Engineering & Malware Analysis - Intermediate Level 🔒 StationX Unlimited
14 sections · 39 lectures
- Introduction 1
- Types of Malware and Malware Analysis Terminologies 2
- Lab: Analysis of .NET Trojan Spyware (Info-Stealers) 4
- Assembly Language Refresher and Malicious APIs 2
- API Hooking, Process Hijacking and Dumping Memory 3
- Lab: Unpacking Emotet Trojan 3
- Lab: Unpacking Hancitor Trojan 3
- Lab: Unpacking Vmprotect Trojan 3
- Lab: Unpacking Trickbot Trojan 3
- Lab: Unpacking Dridex Trojan 4
- Lab: Unpacking Ramnit Trojan 3
- Lab: Unpacking Remcos Trojan with xdbg and dnSpy 4
- Lab: Unpacking Zloader Trojan 3
- Resources For Further Study 1
- CourseMalware Analysis Of Malicious Documents 🔒 StationX Unlimited
12 sections · 35 lectures
- Section 1 : Introduction 2
- Section 2 : Installing the Tools 6
- Section 3 : Malware Analysis Process 1
- Section 4 : Intro to Static Analysis 2
- Section 5 :Analyzing PDF Documents 8
- Section 6 : Performing Javascript Analysis 2
- Section 7 : Lab: Pdf Analysis 2
- Section 8 : Analyzing Office Documents 2
- Section 9 : Performing VBA Script Analysis 2
- Section 10 : Using Debuggers in Document Analysis 3
- Section 11 : Lab: Analyzing An Office Document 3
- Section 12 : Resources For Further Study 2
Practise
- LabsMalware Analysis & Reverse Engineering — 18 labs 🔒 StationX Unlimited
- Advanced Techniques for Malware Recovery
- Analysis and Recommendation Report
- Analyze DoomJuice Infection to Identify Attack Vector and Payload
- Analyze Malicious Activity in Memory Using Volatility
- Analyze and Classify Malware
- Conduct Root Cause Analysis for System Crashes
- Detect Embedded Shellcode in a Microsoft Office Document
- Dynamic Malware Analysis
- Fundamentals of Malware Analysis
- Linux Analysis
- Log Analysis
- MAC Analysis
- Practical Malware Analysis Labs
- Recover from Incident
- Remove Trojan
- Reverse Engineering Malware
- RootKit
- Validate Indications of Compromise: Analysis of PE File
Step 5 — Casework, end to end
Run full investigations at series scale, then hand over to response.
104 labs
Learn
- CourseCovered in Digital Forensics for Pentesters - Hands-on Learning — the investigation workflow, applied case after case 🔒 StationX Unlimited
Practise
- LabsCyber Defense Forensics Analyst Training Series — 70 labs 🔒 StationX Unlimited
- Analyze Malicious Network Traffic
- Auditing Service Accounts
- Auditing Service Accounts and Setting Up Automated Log Collection
- Baseline Systems in Accordance with Policy Documentation
- Conduct Root Cause Analysis for System Crashes
- Conduct Supplemental Monitoring
- Control Assessment and Evaluation
- Creating a Baseline Using Autopsy
- Creating a Case in FTK
- Creating a Forensic Image
- Creating a List of Installed Programs, Services and User Accounts from a WIN2K12 Server
- Cryptography: Steganography
- Cryptography: Using GPG for Encryption and Key Management
- Data Backup to Prep for Recovery
- Data Recovery with Autopsy
- Denial of Service PCAP Analysis
- Dynamic Malware Analysis
- Event Log Collection with Splunk
- Hash Verification
- Host Identification Scanning via Windows
- Host Identification Scanning with Linux
- Identify Access to a LINUX Firewall Through SYSLOG Service
- Implement Single System Changes in Firewall
- Import Nexpose Vulnerability Data into QRadar
- Intro to Linux - Routing and SSH Tunnels
- Introduction to Squert
- LNX101 - OpenSSH Installation, Configuration, and Hardening
- LNX101 - Setting Up a Firewall With UFW and Firewalld
- LNX101 - Telnet vs. SSH
- Lab Environment Orientation - *** (Start Here!) ***
- Live Imaging with FTK Imager Lite
- Log Event Reports
- Manual Vulnerability Assessment
- Manually Analyze Malicious PDF Documents
- Manually Analyze Malicious PDF Documents 2
- Manually Creating a Baseline with MD5Deep
- Memory Extraction and Analysis
- Nessus Scanning and Reporting
- Nexpose: Blue Team Remediation
- Overview of Kibana
- PAM Lab
- Parse Files Out of Network Traffic
- Participate in Attack Analysis Using Trusted Tool Set
- Patching With WSUS
- Pentesting & Network Exploitation - Linux Target Analysis Labs
- Preliminary Scanning
- Protect Against Beaconing
- Recover from Incident
- Recovery From Inadequate Patching
- Registry Analysis
- Rogue Device Identification and Blocking
- Scanning From Windows
- Scanning with Nmap
- Securing Linux - Firewalls
- Securing Linux for System Administrators
- Setting up Filters and Queries in Kibana
- Snap Exploit
- Snort Signatures, IDS Tuning, and Blocking
- Specialized Linux Port Scans
- Threat Designation
- Tweaking Firewall Rules for Detection
- Use pfTop to Analyze Network Traffic
- Using Snort and Wireshark to Analyze Traffic
- Validate Indications of Compromise: Analysis of PE File
- WebApp Attack PCAP Analysis
- Whitelist IP Address from IDS Alerts
- Windows Event Log Manipulation via Windows Event Viewer
- Windows System Hardening with Group Policy & Active Directory
- Windows System Hardening with PowerShell
- Wireshark
- LabsCyber Defense Incident Responder — 34 labs 🔒 StationX Unlimited
- Analyze SQL Injection Attack
- Analyze and Update a Company BCP/BIA/DRP/CIRP
- Applying Filters to TCPDump and Wireshark
- Block Incoming Traffic on Known Port
- Comprehensive Threat Response
- Cryptography: Steganography
- Cryptography: Using GPG for Encryption and Key Management
- Data Backup to Prep for Recovery
- Data Recovery with Autopsy
- Dynamic Malware Analysis
- Firewall Setup and Configuration
- Hash Verification
- Identify Whether High-Risk Systems Were Affected
- Implement Single System Changes in Firewall
- Installing Patches and Testing Software
- Introduction to Squert
- Log Event Reports
- Microsoft Baseline Security Analyzer
- Monitoring Network Traffic
- Network Discovery
- Network Segmentation (FW/DMZ/WAN/LAN)
- Network Topology Generation
- Overview of Kibana
- Recover from Incident
- Report Writing for Presentation to Management
- Setting Up Zones in a Firewall
- Setting up Filters and Queries in Kibana
- Threat Designation
- Validate Indications of Compromise: Analysis of PE File
- Vulnerability Analysis/Protection
- WebApp Attack PCAP Analysis
- Windows Event Log Manipulation via Windows Event Viewer
- Windows System Hardening with Group Policy & Active Directory
- Windows System Hardening with PowerShell
Practice tests
- CourseComputer Hacking Forensic Investigator (CHFI) Practice Exams 🔒 StationX Unlimited
1 section · 6 lectures
- Practice exams 6
Where this leads
Advanced · after the job
The AI-Driven Digital Forensics Analyst
Senior roles are going to the people who can direct AI to build security solutions. When you're working in the role and ready for that step, the AI Master's Program is where it's taught — an advanced, application-only programme.
See the AI Master's Program →Application-only. A separate programme for when you're ready.