Training & Certification
Structured labs and guided paths built on real tools
Learn by doing. Every course runs directly in the Cal Security & Forensics LLC toolkit — no VMs, no setup, no fluff.
Learning paths
Structured sequences from zero to job-ready
Each path bundles related courses into a guided sequence with clear prerequisites, learning outcomes, and a step-by-step syllabus. Expand any path to see the full curriculum.
Forensics Fundamentals
Master the core forensic workflow. Learn to analyze files, verify integrity, parse logs, and document findings using the Forensics and Hash modules.
What you'll learn
- Perform structured file analysis and metadata extraction
- Verify file integrity using MD5, SHA-1, SHA-256, and SHA-512
- Parse and correlate system and application log files
- Maintain a defensible chain of custody for digital evidence
- Produce a professional forensic findings report
Offensive Security Practitioner
Build offensive skills across recon, exploitation, and lateral movement. Covers OSINT gathering, network packet analysis, and cipher attacks.
What you'll learn
- Conduct structured OSINT reconnaissance against a target organization
- Analyze network traffic to identify attack vectors and lateral movement
- Identify and exploit classical and modern cipher weaknesses
- Document a red team engagement from scoping through reporting
- Map findings to MITRE ATT&CK techniques
Blue Team Defender
Detect, analyze, and respond. Learn threat hunting, IOC analysis, network traffic inspection, and incident documentation.
What you'll learn
- Build and execute structured threat hunting playbooks
- Identify and analyze indicators of compromise (IOCs) across log sources
- Correlate network traffic with endpoint telemetry to detect intrusions
- Respond to and contain a simulated security incident
- Produce an incident report with timeline, impact assessment, and remediation steps
Course catalog
Six courses covering the full toolkit
Two free courses to get started, three paid deep-dives, and the CSFA certification exam. Expand any card to view the full module-by-module syllabus.
Free — included with any account
Digital Forensics Essentials
A hands-on introduction to digital forensics. Learn to analyze files, verify integrity with cryptographic hashes, extract metadata, and document your findings — all inside the toolkit, no setup required.
Included with any account
Network Traffic Analysis
Learn to read and analyze network packet captures. Understand TCP/IP, dissect common protocols, reconstruct sessions, and identify anomalies — using the Network module directly in your browser.
Included with any account
Paid courses — one-time purchase
OSINT Fundamentals
A structured, methodology-first OSINT course. Learn passive reconnaissance, IP and domain intelligence, threat actor profiling, and how to produce a professional intelligence report — all using the OSINT module.
One-time purchase · Lifetime access
Red Team Operations
A comprehensive red team course covering the full engagement lifecycle. From scoping and recon through exploitation, lateral movement, and reporting — with every technique mapped to MITRE ATT&CK.
One-time purchase · Lifetime access
Incident Response & Threat Hunting
A practitioner-level course in incident response and proactive threat hunting. Learn to detect, contain, and eradicate threats using structured playbooks, log correlation, and MITRE ATT&CK-driven hunting hypotheses.
One-time purchase · Lifetime access
Cyber Security & Forensics Analyst (CSFA) Certification
Demonstrate mastery across the full toolkit. Pass the proctored exam to earn the CSFA credential — a verifiable digital certificate you can share on LinkedIn.
Certification exam + digital certificate
Courses are launching Q4 2026.
Join the waitlist to get early access and a 20% launch discount.
Certification
The CSFA Credential
The Cyber Security & Forensics Analyst (CSFA) credential is a verifiable proof of hands-on security and forensics proficiency. Earn it by passing the proctored online exam.
Exam domains
Domain 1
Digital Forensics (20%)
- File system structures, magic bytes, and artifact locations
- Hash algorithm selection, collision resistance, and integrity validation
- Metadata extraction from images, documents, and executables
- Log analysis, event ID interpretation, and timeline reconstruction
- Chain of custody principles, evidence documentation, and report writing
Domain 2
Network Analysis (15%)
- TCP/IP stack, protocol identification, and packet structure
- Protocol dissection: HTTP, DNS, FTP, SMB, and ICMP
- TCP stream reconstruction and file extraction from packet captures
- Anomaly detection: port scans, beaconing, and C2 communication patterns
- DNS tunneling, covert channels, and exfiltration identification
Domain 3
OSINT & Threat Intelligence (20%)
- Passive reconnaissance methodology, OPSEC, and legal boundaries
- IP, domain, ASN, and certificate intelligence gathering
- IOC enrichment using AbuseIPDB, OTX, VirusTotal, Shodan, and Censys
- Threat actor profiling, TTP clustering, and infrastructure pivoting
- Intelligence report structure, confidence levels, and source attribution
Domain 4
Offensive Security (20%)
- Red team engagement lifecycle: scoping, RoE, execution, and debrief
- Cipher identification, frequency analysis, and cryptanalysis techniques
- Encoding, obfuscation, and multi-layer payload decoding
- Lateral movement, persistence mechanisms, and LOLBin abuse
- ATT&CK technique mapping and engagement documentation standards
Domain 5
Defensive Operations (25%)
- Incident response lifecycle (PICERL): phases, roles, and evidence handling
- IOC analysis, diamond model, kill chain, and threat actor attribution
- Multi-source log correlation, Windows Event IDs, and timeline construction
- Threat hunting playbook execution: persistence, lateral movement, and exfiltration hunts
- Containment, eradication, recovery, and post-incident reporting
Proctored online exam
Complete the 3-hour proctored exam from any browser — no test center required.
Instant digital certificate
Receive your PDF certificate and digital badge immediately upon passing.
Verifiable public registry
Every certificate has a unique URL — employers and clients can verify authenticity instantly.
FAQ
Frequently asked questions
When do courses launch?
Q4 2026. Join the waitlist to be notified and receive a 20% early-bird discount.
Do I need a Pro account?
Free courses are available to all registered users. Paid courses require purchase but do not require a Pro subscription.
How does the CSFA certification work?
You purchase the exam, complete it online within a 3-hour window, and receive your digital certificate immediately upon passing. The certificate is verifiable via a public URL.
Are labs browser-based?
Yes. Every lab runs directly in the Cal Security & Forensics LLC toolkit — no VM downloads, no external tools required.
Can I take courses in any order?
Free courses have no prerequisites. Paid courses list recommended prerequisites on their cards. The CSFA exam is designed for learners who have completed at least the Forensics Fundamentals and one intermediate course.
What score do I need to pass the CSFA exam?
A passing score is 75% or higher across all five domains. You must score at least 60% in each individual domain. You may retake the exam after a 14-day waiting period.
Ready to level up?
Start with a free course today — no credit card, no setup, just the tools.
