Forendi DFIR Lab
Attack it, then detect it.
A hands-on DFIR range where the same environment teaches both sides. Break into a target, then hunt what the break-in left behind.
Offensive track
Web exploitation, cryptography, recon and privilege escalation across staged targets that behave like real ones.
Defensive track
Write detection rules against a labelled corpus. Graded on what the rule catches and what it wrongly flags — not on wording.
Measured progress
Every attempt returns true and false positives, so you can see whether a rule is too narrow, too broad, or both.
What you work through
Six tracks, from shell basics to detection engineering.
General Skills
File operations, shell fundamentals
Cryptography
Encodings, classical ciphers, hashing
Web Exploitation
Headers, hidden paths, injection
Forensics
Metadata, carving, steganography
Network & OS
Scanning, remote services, capture analysis
Detection Engineering
YARA rules scored on a labelled corpus