Browse CTFs New CTF Sign in
Back to Learning Paths
Digital Forensics Analyst
Practitioner Wave 1

Digital Forensics Analyst

35.0h estimated 4 Courses

Practitioner-level certification for digital forensics. Covers file artifacts, network forensics, and memory analysis.

Sign in to enroll

File Forensics, Metadata, Carving and Steganography

24 cards

EXIF metadata

forensic_file_artifacts Difficulty 1–5 31 min

Hidden ZIP in image

forensic_file_artifacts Difficulty 1–5 30 min

Steganography

forensic_file_artifacts Difficulty 1–5 30 min

Corrupted archive

forensic_file_artifacts Difficulty 1–5 30 min

Cloud Instance Metadata Credential Theft: IMDS Exploitation for IAM Role Token Extraction

forensic_file_artifacts Difficulty 1–5 30 min

Employee OSINT Profiling: Corporate Web Presence Analysis and Identity Correlation

forensic_file_artifacts Difficulty 1–5 30 min

Email-to-Pastebin OSINT Pivot: Address-Based Identity Tracing to Exposed Secret Discovery

forensic_file_artifacts Difficulty 1–5 30 min

Type Confusion Exploitation: C++ Vtable Misdirection and Union-Based Memory Reinterpretation for Code Execution

forensic_file_artifacts Difficulty 1–5 30 min

IMDS SSRF to IAM Credential Theft: Metadata Endpoint Exploitation for Role Hijacking

network_forensics_pcap Difficulty 1–5 30 min

Lambda-to-Secrets-Manager Privilege Chain: Function Role Exploitation for Secret Retrieval

network_forensics_pcap Difficulty 1–5 30 min

Terraform State-to-AWS Pivot: Credential Extraction Chain from Leaked State to Live Resources

network_forensics_pcap Difficulty 1–5 30 min

Git Commit-to-Pastebin OSINT Pivot: Repository Secret Discovery Chained to Paste Platform Intelligence

forensic_file_artifacts Difficulty 1–5 30 min

E-Commerce Order-to-Email OSINT: Purchase Record Pivoting for Customer Identity Attribution

forensic_file_artifacts Difficulty 1–5 30 min

Corporate OSINT Chain: WHOIS, Website and SMTP Enumeration for Targeted Intelligence Gathering

forensic_file_artifacts Difficulty 1–5 30 min

Point-of-Interest to Social Media Pivot: Geographic OSINT Chained to Instagram Profile Identification

forensic_file_artifacts Difficulty 1–5 30 min

Git-to-S3 Infrastructure OSINT: Repository Credential Pivoting to Cloud Storage Data Extraction

forensic_file_artifacts Difficulty 1–5 30 min

Corporate OSINT Chain: Website, LDAP and SMTP Enumeration for Employee and Infrastructure Discovery

forensic_file_artifacts Difficulty 1–5 30 min

Four-Service Social OSINT Trail: Sequential Platform Pivoting for Target Activity Reconstruction

forensic_file_artifacts Difficulty 1–5 30 min

AWS S3 Bucket OSINT Enumeration: Public Bucket Discovery and Sensitive Data Identification

forensic_file_artifacts Difficulty 1–5 30 min

Social Media Identity Operations OSINT: Detecting Coordinated Inauthentic Behavior and Sockpuppet Networks

forensic_file_artifacts Difficulty 1–5 30 min

Cloud Asset Leak Investigation: Exposed Object Storage and Misconfigured Public Resource OSINT

forensic_file_artifacts Difficulty 1–5 30 min

Corporate Digital Footprint OSINT: Passive Reconnaissance and External Attack Surface Mapping

forensic_file_artifacts Difficulty 1–5 30 min

Multi-Service Infrastructure OSINT Chain: LDAP, OAuth, Kubernetes and Git Pivot Sequence

forensic_file_artifacts Difficulty 1–5 30 min

Multi-Platform OSINT Chain: Shop, Git, IMDS and Chat Pivot Across Five Distinct Data Sources

forensic_file_artifacts Difficulty 1–5 30 min

Network Forensics and Session Reconstruction

33 cards

Detecting Advanced DNS Tunneling Evasion via Slow-Rate Exfiltration and Multi-Domain Correlation

network_forensics_pcap Difficulty 1–5 30 min

Reconstructing HTTP Sessions via Multi-Request Correlation, Credential and Object Recovery

network_forensics_pcap Difficulty 1–5 30 min

Detecting TLS Fingerprint Anomalies via JA3/JA3S Computation and Malware Client Identification

network_forensics_pcap Difficulty 1–5 30 min

Detecting ICMP Covert Channels via Payload Anomaly Identification and Hidden Data Extraction

network_forensics_pcap Difficulty 1–5 30 min

Reconstructing FTP Data Exfiltration via Passive Mode Analysis and TCP Stream Extraction

network_forensics_pcap Difficulty 1–5 30 min

Analyzing Advanced SMTP Exfiltration via MIME Multipart Parsing and Encoded Attachment Recovery

network_forensics_pcap Difficulty 1–5 30 min

Identifying IRC Botnet C2 via PRIVMSG Command Pattern Analysis and Bot Fingerprinting

network_forensics_pcap Difficulty 1–5 30 min

Detecting Kerberoasting and AS-REP Roasting via TGS-REQ Analysis and Ticket Extraction

network_forensics_pcap Difficulty 1–5 30 min

Analyzing WebSocket Data Exfiltration via Frame Demasking, Payload Extraction and Protocol Reconstruction

network_forensics_pcap Difficulty 1–5 30 min

Extracting Modbus Register Data via ICS/OT Protocol Forensics and Unauthorized Read Detection

network_forensics_pcap Difficulty 1–5 30 min

Recovering Corrupted PCAP Files via Magic Byte Forensics and Partial Capture Reconstruction

network_forensics_pcap Difficulty 1–5 30 min

Volatility 3 Advanced Analysis: Symbol Tables, Namespaced Plugins and Cross-Layer Memory Correlation

network_forensics_pcap Difficulty 1–5 30 min

DOCX core metadata forensics

network_forensics_pcap Difficulty 1–5 30 min

DOCX hidden text forensics

network_forensics_pcap Difficulty 1–5 30 min

DOCX revision comment forensics

network_forensics_pcap Difficulty 1–5 30 min

DOCX acrostic steganography

network_forensics_pcap Difficulty 1–5 30 min

DOCX revision history (track changes)

network_forensics_pcap Difficulty 1–5 30 min

DOCX extended app properties forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX core metadata forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX hidden cell forensics (white-on-white)

network_forensics_pcap Difficulty 1–5 30 min

XLSX named range forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX cell comment forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX hidden worksheet forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX very-hidden worksheet forensics

network_forensics_pcap Difficulty 1–5 30 min

Shellcode Injection and Execution: NX-Free Environment Exploitation and NOP Sled Delivery

network_forensics_pcap Difficulty 1–5 30 min

Kubernetes RBAC to S3 Pivot: Pod Service Account Lateral Movement to Cloud Storage

network_forensics_pcap Difficulty 1–5 30 min

IAM Privilege Escalation Chain: AssumeRole, PassRole and CreatePolicyVersion Abuse Paths

network_forensics_pcap Difficulty 1–5 30 min

Reconstructing Ransomware Infection Vectors from Multi-Source Log Evidence

network_forensics_pcap Difficulty 1–5 30 min

C2 Beaconing Detection via Log Interval Analysis and Temporal Correlation

network_forensics_pcap Difficulty 1–5 30 min

Correlating SQLi, XSS, LFI and RCE Attack Patterns Across Web Server Access Logs

network_forensics_pcap Difficulty 1–5 30 min

Detecting Malicious Service Persistence via Windows Event 7045 and Systemd Unit Forensics

network_forensics_pcap Difficulty 1–5 30 min

Detecting DNS Exfiltration Through Entropy-Based Subdomain Anomaly Analysis

network_forensics_pcap Difficulty 1–5 30 min

Instagram-to-Twitter Persona Pivot: Cross-Platform Handle Correlation and Profile Reconstruction

network_forensics_pcap Difficulty 1–5 30 min

Chain of Custody and Forensic Report Writing [Non-CTF]

0 cards

No cards in this course yet.

🏅

CTFFactory Digital Forensics Analyst — Practitioner

Practitioner credential — awarded upon completion