DFIR accelerator

Build practical skills in Digital Forensics, Incident Response, and Threat Hunting.

Perform forensic analysis on live systems, hunt threats at scale with Velociraptor, and respond to incidents in Active Directory environments - all through hands-on lab exercises.

Write your awesome label here.

50% OFF

Build or refresh a solid foundation in DFIR and Threat Hunting - from triage on a single host to hunting across enterprise environments.

Three Disciplines, One Course

Module 1 — Digital Forensics

Forensic Analysis on Live Systems & Images

Perform efficient forensic analysis on live systems or forensic images. Triage hosts rapidly without centrally managed security tools. Interpret artifacts at a lower level than commercial tooling allows.

Module 2 — Threat Hunting

Hunt Threats at Scale Across Enterprises

Develop and execute tactical and strategic threat hunting hypotheses. Find evidence of malicious activity in large datasets across multiple systems. Customize existing detection logic and deploy it at scale.

Module 3 — Incident Response

Respond to Incidents in Active Directory Environments

Respond to incidents creatively without relying on pre-installed security controls, alerts, or a SIEM. Build a triage methodology that scales from a handful of systems to thousands.

Learners

Assignments

Hours

Videos

Learn from Two Decades of Experience

Andreas van Leeuwen Flamino

Incident Response and Digital Forensics Lead & Trainer
Andreas is a cybersecurity professional with over two decades of experience across red and blue teams. Andreas started in the late 1990s as a Linux and UNIX systems administrator, moved into red teaming in the early 2000s. Over the last decade, he has focused on Threat Hunting, Incident Response, and Digital Forensics - standing up multiple practices in each discipline. He is passionate about teaching and open-source tools, bringing real-world operational experience to every lesson in this course.

Course Lessons