529 words
3 minutes
eCDFP Lab

Overview#

This roadmap supports the eCDFP course (Digital Forensics & Incident Response) with hands-on TryHackMe labs, organized into 6 sections that follow the flow of a real DFIR workflow: fundamentals, system forensics, investigation tools, full case scenarios, endpoint detection, and monitoring. A section with an additional learning resource is included at the end.

The roadmap was put together by Netriders Academy, with the labs curated by Ahmed Sultan. Every link opens the lab directly.

Total labs17
PlatformTryHackMe
Sections6 (plus 1 extra resource)

Note: TryHackMe occasionally moves rooms between free and paid. If you find a lab that is locked, let me know and I will update the list.

Section Map#

#SectionFocusLabs
01DFIR FundamentalsCore DFIR concepts, process, and legal considerations4
02Windows & Linux ForensicsArtifacts and evidence on Windows and Linux systems4
03DFIR Investigation ToolsAutopsy, KAPE, Velociraptor, and TheHive4
04Incident Investigation & CasesFull investigation scenarios2
05Endpoint Detection & Response (EDR)Endpoint security and EDR2
06Detection & MonitoringNetwork intrusion detection with Snort1
07Extra Learning ResourceDFIR Science YouTube channelResource

Suggested Learning Path#

  1. DFIR Fundamentals: understand the process and the legal side first
  2. Windows & Linux Forensics: learn what evidence looks like on each system
  3. DFIR Investigation Tools: get hands-on with Autopsy, KAPE, Velociraptor, and TheHive
  4. Incident Investigation & Cases: apply everything on full scenarios
  5. Endpoint Detection & Response (EDR): see the same activity from the defender’s tooling
  6. Detection & Monitoring: finish with network-level detection

01. DFIR Fundamentals#

Focus: Core DFIR concepts, process, and legal considerations
Labs: 4

The starting point: what digital forensics and incident response are, how an investigation is structured, the legal considerations that apply to evidence handling, and how DFIR fits into security operations.

#LabPlatform
1DFIR: An IntroductionTryHackMe
2Intro to Digital ForensicsTryHackMe
3DFIR Process and Legal ConsiderationsTryHackMe
4Security OperationsTryHackMe

02. Windows & Linux Forensics#

Focus: Artifacts and evidence on Windows and Linux systems
Labs: 4

Hands-on forensic analysis of the two most common operating systems: Windows artifacts and the registry, and Linux forensics.

#LabPlatform
1Windows Forensics 1TryHackMe
2Windows Forensics 2TryHackMe
3Linux ForensicsTryHackMe
4Registry ForensicsTryHackMe

03. DFIR Investigation Tools#

Focus: Autopsy, KAPE, Velociraptor, and TheHive
Labs: 4

The tools of the trade: disk analysis with Autopsy, fast artifact collection with KAPE, endpoint visibility and hunting with Velociraptor, and case management with TheHive.

#LabPlatform
1AutopsyTryHackMe
2KAPETryHackMe
3VelociraptorTryHackMe
4TheHive ProjectTryHackMe

04. Incident Investigation & Cases#

Focus: Full investigation scenarios
Labs: 2

Put the tools and techniques together in complete case scenarios, working from the evidence to a conclusion the way a real investigation would.

#LabPlatform
1DisgruntledTryHackMe
2CriticalTryHackMe

05. Endpoint Detection & Response (EDR)#

Focus: Endpoint security and EDR
Labs: 2

How endpoint security works and how EDR tooling detects and records malicious activity on a host.

#LabPlatform
1Intro to Endpoint SecurityTryHackMe
2Aurora EDRTryHackMe

06. Detection & Monitoring#

Focus: Network intrusion detection with Snort
Labs: 1

A practical detection exercise: applying Snort to network traffic in a guided challenge.

#LabPlatform
1Snort Challenge 2TryHackMe

07. Extra Learning Resource#

Type: Video content

A YouTube channel dedicated to digital forensics and incident response, useful for extra explanations and walkthroughs alongside the labs.

#ResourceType
1DFIR ScienceYouTube

Tips for Getting the Most Out of These Labs#

  • Document your process the way a real investigator would: what you found, where you found it, and why it matters. Good notes are part of the skill.
  • Keep a timeline for each case scenario. Ordering events is at the heart of every investigation.
  • Avoid walkthroughs until you have genuinely tried on your own.
  • Repeat labs a few days later without looking at the solution. This is what makes the knowledge stick.

These labs are for learning and practice in the provided lab environments only. Only analyze evidence and systems you are authorized to investigate.

eCDFP Lab
https://bad-glitch.github.io/posts/labs/ecdfp---labs/ecdfp/
Author
Amr Abdel Hamide
Published at
2026-09-19