Student DFIR Lab Suite

Windows + macOS Digital Forensics

Two self-contained, browser-based forensic investigation environments designed for students who do not have access to a prepared Windows or Mac forensic image.

Interactive evidenceGuided labsForensic consolesReport export
Windows

Windows Digital Forensics Simulator

Investigate EVTX, Registry, Prefetch, USBSTOR, LNK/Jump Lists, browser history, Recycle Bin, SRUM, $MFT and USN evidence.

PowerShellEVTXRegistryNTFS
Launch Windows Lab →
macOS

macOS Digital Forensics Simulator

Investigate Safari, quarantine, TCC, Unified Logs, LaunchAgents, FSEvents, Spotlight, recent items, zsh history, APFS and FileVault context.

APFSUnified LogsTCCFSEvents
Launch macOS Lab →

Suggested course use

Before class

Students review artifact concepts and complete the knowledge check.

In class

Students work the case, query the simulated console, correlate artifacts and build a timeline.

Assessment

Students export the examiner report and defend which conclusions are facts, inferences, or unsupported.