Training & Certification

Structured labs and guided paths built on real tools

Learn by doing. Every course runs directly in the Cal Security & Forensics LLC toolkit — no VMs, no setup, no fluff.

6 coursesHands-on labsCompletion certificates

Learning paths

Structured sequences from zero to job-ready

Each path bundles related courses into a guided sequence with clear prerequisites, learning outcomes, and a step-by-step syllabus. Expand any path to see the full curriculum.

Beginner

Forensics Fundamentals

~8 hours

Master the core forensic workflow. Learn to analyze files, verify integrity, parse logs, and document findings using the Forensics and Hash modules.

File AnalysisLog ForensicsHash VerificationEvidence Chain
Prerequisites: No prior experience required. Basic familiarity with file systems is helpful.

What you'll learn

  • Perform structured file analysis and metadata extraction
  • Verify file integrity using MD5, SHA-1, SHA-256, and SHA-512
  • Parse and correlate system and application log files
  • Maintain a defensible chain of custody for digital evidence
  • Produce a professional forensic findings report
Intermediate

Offensive Security Practitioner

~12 hours

Build offensive skills across recon, exploitation, and lateral movement. Covers OSINT gathering, network packet analysis, and cipher attacks.

Red TeamOSINTNetwork AnalysisCipher
Prerequisites: Comfortable with Linux command line. Basic networking knowledge (TCP/IP, DNS, HTTP). Completion of Forensics Fundamentals recommended.

What you'll learn

  • Conduct structured OSINT reconnaissance against a target organization
  • Analyze network traffic to identify attack vectors and lateral movement
  • Identify and exploit classical and modern cipher weaknesses
  • Document a red team engagement from scoping through reporting
  • Map findings to MITRE ATT&CK techniques
Intermediate

Blue Team Defender

~10 hours

Detect, analyze, and respond. Learn threat hunting, IOC analysis, network traffic inspection, and incident documentation.

Blue TeamNetworkShared Utilities
Prerequisites: Basic understanding of networking and operating systems. Familiarity with log files. Forensics Fundamentals recommended.

What you'll learn

  • Build and execute structured threat hunting playbooks
  • Identify and analyze indicators of compromise (IOCs) across log sources
  • Correlate network traffic with endpoint telemetry to detect intrusions
  • Respond to and contain a simulated security incident
  • Produce an incident report with timeline, impact assessment, and remediation steps

Course catalog

Six courses covering the full toolkit

Two free courses to get started, three paid deep-dives, and the CSFA certification exam. Expand any card to view the full module-by-module syllabus.

Free — included with any account

FREE
Free

Digital Forensics Essentials

4 hours18 labsBeginner

A hands-on introduction to digital forensics. Learn to analyze files, verify integrity with cryptographic hashes, extract metadata, and document your findings — all inside the toolkit, no setup required.

File carvingMetadata extractionHash verificationChain of custody

Included with any account

FREE
Free

Network Traffic Analysis

3.5 hours16 labsBeginner

Learn to read and analyze network packet captures. Understand TCP/IP, dissect common protocols, reconstruct sessions, and identify anomalies — using the Network module directly in your browser.

PCAP analysisProtocol dissectionTCP stream reconstructionDNS forensics

Included with any account

Paid courses — one-time purchase

$29

OSINT Fundamentals

6 hours22 labsIntermediate

A structured, methodology-first OSINT course. Learn passive reconnaissance, IP and domain intelligence, threat actor profiling, and how to produce a professional intelligence report — all using the OSINT module.

IP/domain reconThreat intel correlationPassive fingerprintingReport writing

One-time purchase · Lifetime access

PRO PICK
$39

Red Team Operations

8 hours26 labsIntermediate

A comprehensive red team course covering the full engagement lifecycle. From scoping and recon through exploitation, lateral movement, and reporting — with every technique mapped to MITRE ATT&CK.

Recon methodologyCipher attacksPayload encodingEngagement documentation

One-time purchase · Lifetime access

$39

Incident Response & Threat Hunting

7 hours24 labsAdvanced

A practitioner-level course in incident response and proactive threat hunting. Learn to detect, contain, and eradicate threats using structured playbooks, log correlation, and MITRE ATT&CK-driven hunting hypotheses.

IOC analysisLog correlationThreat hunting playbooksMITRE ATT&CK mapping

One-time purchase · Lifetime access

CERTIFICATION
$99

Cyber Security & Forensics Analyst (CSFA) Certification

3-hour exam75 questionsAll levels

Demonstrate mastery across the full toolkit. Pass the proctored exam to earn the CSFA credential — a verifiable digital certificate you can share on LinkedIn.

ForensicsNetworkOSINTRed teamBlue teamCipherHash

Certification exam + digital certificate

Courses are launching Q4 2026.

Join the waitlist to get early access and a 20% launch discount.

Certification

The CSFA Credential

The Cyber Security & Forensics Analyst (CSFA) credential is a verifiable proof of hands-on security and forensics proficiency. Earn it by passing the proctored online exam.

Exam domains

Domain 1

Digital Forensics (20%)

  • File system structures, magic bytes, and artifact locations
  • Hash algorithm selection, collision resistance, and integrity validation
  • Metadata extraction from images, documents, and executables
  • Log analysis, event ID interpretation, and timeline reconstruction
  • Chain of custody principles, evidence documentation, and report writing

Domain 2

Network Analysis (15%)

  • TCP/IP stack, protocol identification, and packet structure
  • Protocol dissection: HTTP, DNS, FTP, SMB, and ICMP
  • TCP stream reconstruction and file extraction from packet captures
  • Anomaly detection: port scans, beaconing, and C2 communication patterns
  • DNS tunneling, covert channels, and exfiltration identification

Domain 3

OSINT & Threat Intelligence (20%)

  • Passive reconnaissance methodology, OPSEC, and legal boundaries
  • IP, domain, ASN, and certificate intelligence gathering
  • IOC enrichment using AbuseIPDB, OTX, VirusTotal, Shodan, and Censys
  • Threat actor profiling, TTP clustering, and infrastructure pivoting
  • Intelligence report structure, confidence levels, and source attribution

Domain 4

Offensive Security (20%)

  • Red team engagement lifecycle: scoping, RoE, execution, and debrief
  • Cipher identification, frequency analysis, and cryptanalysis techniques
  • Encoding, obfuscation, and multi-layer payload decoding
  • Lateral movement, persistence mechanisms, and LOLBin abuse
  • ATT&CK technique mapping and engagement documentation standards

Domain 5

Defensive Operations (25%)

  • Incident response lifecycle (PICERL): phases, roles, and evidence handling
  • IOC analysis, diamond model, kill chain, and threat actor attribution
  • Multi-source log correlation, Windows Event IDs, and timeline construction
  • Threat hunting playbook execution: persistence, lateral movement, and exfiltration hunts
  • Containment, eradication, recovery, and post-incident reporting

Proctored online exam

Complete the 3-hour proctored exam from any browser — no test center required.

Instant digital certificate

Receive your PDF certificate and digital badge immediately upon passing.

Verifiable public registry

Every certificate has a unique URL — employers and clients can verify authenticity instantly.

FAQ

Frequently asked questions

When do courses launch?

Q4 2026. Join the waitlist to be notified and receive a 20% early-bird discount.

Do I need a Pro account?

Free courses are available to all registered users. Paid courses require purchase but do not require a Pro subscription.

How does the CSFA certification work?

You purchase the exam, complete it online within a 3-hour window, and receive your digital certificate immediately upon passing. The certificate is verifiable via a public URL.

Are labs browser-based?

Yes. Every lab runs directly in the Cal Security & Forensics LLC toolkit — no VM downloads, no external tools required.

Can I take courses in any order?

Free courses have no prerequisites. Paid courses list recommended prerequisites on their cards. The CSFA exam is designed for learners who have completed at least the Forensics Fundamentals and one intermediate course.

What score do I need to pass the CSFA exam?

A passing score is 75% or higher across all five domains. You must score at least 60% in each individual domain. You may retake the exam after a 14-day waiting period.

Ready to level up?

Start with a free course today — no credit card, no setup, just the tools.