HomeForensic Lab
Northgate Engineering / Digital Forensics Windows · Linux · cross-platform

Forensic Lab

Every case hands you the parsed artifacts an examiner actually works from: MFT records, event logs, prefetch, registry hives, auth logs, process snapshots and network connections. You read the evidence, correlate it across sources, and commit to findings with a confidence grade, then a guided walkthrough shows what each artifact meant and how the pieces connected. For hands-on work with real tools, build your own forensic workstation and examine actual disk images and memory captures.

16Cases
15hOf work
3Platforms
7Courses covered
Examine Correlate Conclude Graded

🪟 Windows Intermediate

INC-NE-2026-0915: Insider Data Exfiltration

A departing engineer is suspected of exfiltrating proprietary data through a personal cloud storage account. Forensic image acquired from the workstation. Determine what data left, through which channels, over what time period.

⏱ 60 min FOR501, FOR401
🪟 Windows Advanced

INC-NE-2026-1022: Ransomware Attack Reconstruction

A phishing email led to credential compromise, lateral movement, and ransomware deployment. Forensic image from the initial compromise workstation. Reconstruct the complete attack chain from initial access through encryption.

⏱ 75 min FOR501, FOR401
🐧 Linux Intermediate

INC-NE-2026-0310: Linux Web Server Compromise

Unusual outbound connections detected from an internal web server. Live acquisition performed before isolation. Determine initial access, attacker actions, and lateral movement scope.

⏱ 50 min FOR402, FOR401
🐧 Linux Advanced

INC-NE-2026-0422: Container Escape Investigation

A Kubernetes web application pod executed unexpected host commands. Container runtime monitor detected escape from the webapp namespace. Determine the escape method, host compromise scope, and persistence mechanisms.

⏱ 65 min FOR402, FOR401
🪟 Windows Foundational

INC-NE-2026-0847: USB Data Theft

A departing project manager is suspected of copying sensitive bid documents to a personal USB drive. Forensic image acquired. Determine what removable storage was used, what data was copied, and whether the activity was deliberate.

⏱ 40 min FOR501, FOR401
🐧 Linux Foundational

INC-NE-2026-0563: SSH Brute Force & Cryptominer

Monitoring flagged sustained 98% CPU on a RHEL application server. A suspicious hidden process is consuming all resources with an active external network connection. Determine how access was gained and what the attacker installed.

⏱ 35 min FOR402, FOR401
🪟 Windows Intermediate

INC-NE-2026-1134: Credential Theft & Lateral Movement

SOC alert on anomalous PsExec activity on a file server. A service account executed commands it never runs. Trace the attack from initial phishing through credential theft and lateral movement to data staging.

⏱ 60 min FOR501, FOR401, SEC403
🪟 Windows Foundational

INC-NE-2026-0729: Business Email Compromise

A supplier is complaining about unpaid invoices, but Finance sent updated bank details last week, except the analyst says they never sent that email. Investigate the account compromise, inbox manipulation, and financial impact.

⏱ 35 min FOR401, SEC301
🪟 Windows Intermediate

INC-NE-2026-0958: Malware Persistence & C2 Beacon

EDR flagged an anomalous scheduled task running a suspicious executable from AppData with periodic HTTPS beacons to an unrecognised domain. Determine the delivery method, persistence mechanisms, and C2 infrastructure.

⏱ 55 min FOR501, FOR401, SEC401
🐧 Linux Intermediate

INC-NE-2026-0612: Privilege Escalation & Rootkit

Monitoring detected an unknown systemd service and a UID-0 user account on a database server. Trace the attack from contractor account compromise through SUID exploitation to rootkit installation.

⏱ 55 min FOR402, FOR401
🪟 Windows Advanced

INC-NE-2026-1247: Living-off-the-Land Attack

SOC flagged anomalous DNS TXT queries from an HR workstation. No malware detected, the entire attack used only native Windows binaries. Trace the LOLBin chain from HTA phishing to DNS exfiltration.

⏱ 65 min FOR501, FOR401, SEC401, SEC402
🪟 Windows Advanced

INC-NE-2026-1389: Anti-Forensics & Shadow Copy Tampering

Defender updates are failing on a file server. The HOSTS file has been tampered with, shadow copies are gone, and the Security log is empty. Work around six anti-forensic techniques to reconstruct the attack.

⏱ 65 min FOR501, FOR401, SEC403
🐧 Linux Intermediate

INC-NE-2026-0834: Insider Database Exfiltration

A disgruntled DBA on notice period dumped the production database and SCPed it to a personal VPS. Bash history was edited, but journald and auth logs tell the full story.

⏱ 50 min FOR402, FOR401
🐧 Linux Advanced

INC-NE-2026-0491: Supply Chain Package Compromise

An unknown systemd timer appeared on a dev server after a routine npm install. A typosquatted package dropped a reverse shell payload via its postinstall hook. Trace the supply chain from package to persistence.

⏱ 60 min FOR402, SEC401
🔀 Cross-Platform Advanced

INC-NE-2026-1501: Cross-Platform Pivot & Database Breach

Two alerts fired minutes apart: anomalous RDP from an HR workstation to an admin jump box, then password SSH to a production database. Trace the three-host attack chain from phishing to credential theft to database exfiltration.

⏱ 70 min FOR501, FOR402, FOR401
🔀 Cross-Platform Advanced

INC-NE-2026-1602: Compromised Admin, Multi-System Lateral Movement

A CPU alert on a web server reveals a cryptominer, but the real threat is far worse. An admin VPN account was compromised, and the attacker spent 40 minutes across 6 systems: WMI, DCSync, golden ticket, SSH backdoors.

⏱ 70 min FOR501, FOR402, FOR401, SEC403
Forensic Lab v1.0 This lab is actively developed. Hit a bug or something that doesn't look right?