Forendi DFIR Lab

Attack it, then detect it.

A hands-on DFIR range where the same environment teaches both sides. Break into a target, then hunt what the break-in left behind.

Offensive track

Web exploitation, cryptography, recon and privilege escalation across staged targets that behave like real ones.

Defensive track

Write detection rules against a labelled corpus. Graded on what the rule catches and what it wrongly flags — not on wording.

Measured progress

Every attempt returns true and false positives, so you can see whether a rule is too narrow, too broad, or both.

What you work through

Six tracks, from shell basics to detection engineering.

01

General Skills

File operations, shell fundamentals

02

Cryptography

Encodings, classical ciphers, hashing

03

Web Exploitation

Headers, hidden paths, injection

04

Forensics

Metadata, carving, steganography

05

Network & OS

Scanning, remote services, capture analysis

06

Detection Engineering

YARA rules scored on a labelled corpus