Training & Certification

Structured labs and guided paths built on real tools

Learn by doing. Every course runs directly in the Cal Security & Forensics LLC toolkit — no VMs, no setup, no fluff.

6 coursesHands-on labsCompletion certificates

Learning paths

Structured sequences from zero to job-ready

Each path bundles related courses into a guided sequence with clear prerequisites, learning outcomes, and a step-by-step syllabus. Expand any path to see the full curriculum.

Beginner

Forensics Fundamentals

~8 hours

Master the core forensic workflow. Learn to analyze files, verify integrity, parse logs, and document findings using the Forensics and Hash modules.

File AnalysisLog ForensicsHash VerificationEvidence Chain
Prerequisites: No prior experience required. Basic familiarity with file systems is helpful.

What you'll learn

  • Perform structured file analysis and metadata extraction
  • Verify file integrity using MD5, SHA-1, SHA-256, and SHA-512
  • Parse and correlate system and application log files
  • Maintain a defensible chain of custody for digital evidence
  • Produce a professional forensic findings report
Intermediate

Offensive Security Practitioner

~12 hours

Build offensive skills across recon, exploitation, and lateral movement. Covers OSINT gathering, network packet analysis, and cipher attacks.

Red TeamOSINTNetwork AnalysisCipher
Prerequisites: Comfortable with Linux command line. Basic networking knowledge (TCP/IP, DNS, HTTP). Completion of Forensics Fundamentals recommended.

What you'll learn

  • Conduct structured OSINT reconnaissance against a target organization
  • Analyze network traffic to identify attack vectors and lateral movement
  • Identify and exploit classical and modern cipher weaknesses
  • Document a red team engagement from scoping through reporting
  • Map findings to MITRE ATT&CK techniques
Intermediate

Blue Team Defender

~10 hours

Detect, analyze, and respond. Learn threat hunting, IOC analysis, network traffic inspection, and incident documentation.

Blue TeamNetworkShared Utilities
Prerequisites: Basic understanding of networking and operating systems. Familiarity with log files. Forensics Fundamentals recommended.

What you'll learn

  • Build and execute structured threat hunting playbooks
  • Identify and analyze indicators of compromise (IOCs) across log sources
  • Correlate network traffic with endpoint telemetry to detect intrusions
  • Respond to and contain a simulated security incident
  • Produce an incident report with timeline, impact assessment, and remediation steps

Course catalog

Six courses covering the full toolkit

Two free courses to get started, three paid deep-dives, and the CSFA certification exam. Expand any card to view the full module-by-module syllabus.

Free — included with any account

FREE
Free

Digital Forensics Essentials

4 hours18 labsBeginner

A hands-on introduction to digital forensics. Learn to analyze files, verify integrity with cryptographic hashes, extract metadata, and document your findings — all inside the toolkit, no setup required.

File carvingMetadata extractionHash verificationChain of custody

Included with any account

FREE
Free

Network Traffic Analysis

3.5 hours16 labsBeginner

Learn to read and analyze network packet captures. Understand TCP/IP, dissect common protocols, reconstruct sessions, and identify anomalies — using the Network module directly in your browser.

PCAP analysisProtocol dissectionTCP stream reconstructionDNS forensics

Included with any account

Paid courses — one-time purchase

$29

OSINT Fundamentals

6 hours22 labsIntermediate

A structured, methodology-first OSINT course. Learn passive reconnaissance, IP and domain intelligence, threat actor profiling, and how to produce a professional intelligence report — all using the OSINT module.

IP/domain reconThreat intel correlationPassive fingerprintingReport writing

One-time purchase · Lifetime access

PRO PICK
$39

Red Team Operations

8 hours26 labsIntermediate

A comprehensive red team course covering the full engagement lifecycle. From scoping and recon through exploitation, lateral movement, and reporting — with every technique mapped to MITRE ATT&CK.

Recon methodologyCipher attacksPayload encodingEngagement documentation

One-time purchase · Lifetime access

$39

Incident Response & Threat Hunting

7 hours24 labsAdvanced

A practitioner-level course in incident response and proactive threat hunting. Learn to detect, contain, and eradicate threats using structured playbooks, log correlation, and MITRE ATT&CK-driven hunting hypotheses.

IOC analysisLog correlationThreat hunting playbooksMITRE ATT&CK mapping

One-time purchase · Lifetime access

CERTIFICATION
$199

Calsec Certified Security & Forensics Analyst (CSFA) Certification

3-hour exam75 questionsAll levels

Demonstrate mastery across the full toolkit. Pass the proctored exam to earn the CSFA credential — a verifiable digital certificate you can share on LinkedIn.

ForensicsNetworkOSINTRed teamBlue teamCipherHash

Certification exam + digital certificate

Certification

The CSFA Credential

The Calsec Certified Security & Forensics Analyst (CSFA) credential is a verifiable proof of hands-on security and forensics proficiency. Earn it by passing the proctored online exam.

Exam domains

Domain 1

Digital Forensics (20%)

  • File system structures, magic bytes, and artifact locations
  • Hash algorithm selection, collision resistance, and integrity validation
  • Metadata extraction from images, documents, and executables
  • Log analysis, event ID interpretation, and timeline reconstruction
  • Chain of custody principles, evidence documentation, and report writing
  • Lab: Identify disguised files from magic bytes
  • Lab: Resolve a hash verification failure
  • Lab: Extract and cross-check file metadata
  • Lab: Interpret Windows Event IDs and build a timeline
  • Lab: Document evidence handling and custody

Domain 2

Network Analysis (15%)

  • TCP/IP stack, protocol identification, and packet structure
  • Protocol dissection: HTTP, DNS, FTP, SMB, and ICMP
  • TCP stream reconstruction and file extraction from packet captures
  • Anomaly detection: port scans, beaconing, and C2 communication patterns
  • DNS tunneling, covert channels, and exfiltration identification
  • Lab: Fingerprint a scan from TTL and TCP flags
  • Lab: Repair an evadable Suricata rule
  • Lab: Reconstruct a TCP stream and extract a file
  • Lab: Detect beaconing in flow data
  • Lab: Identify DNS tunnelling exfiltration

Domain 3

Offensive Security Concepts (20%)

  • Exploitation fundamentals, vulnerability classification, and memory corruption
  • Social engineering, phishing forensics, and email authentication
  • Exploitation frameworks, post-exploitation artifacts, and living-off-the-land
  • Lateral movement, persistence mechanisms, and LOLBin abuse
  • ATT&CK technique mapping and engagement documentation standards
  • Lab: Classify web attacks and find the successful one
  • Lab: Determine spoofing versus account takeover
  • Lab: Triage a suspicious PE from static indicators
  • Lab: Find LOLBin abuse by process lineage
  • Lab: Map observed activity to ATT&CK techniques

Domain 4

Incident Response & Threat Intelligence (20%)

  • IR lifecycle, playbooks, and response readiness
  • Threat intelligence frameworks, IOC analysis, and actor attribution
  • Multi-source log correlation, Windows Event IDs, and timeline construction
  • Threat hunting playbook execution: persistence, lateral movement, and exfiltration hunts
  • Containment, eradication, recovery, and post-incident reporting
  • Lab: Correct a ransomware playbook sequence
  • Lab: Map an intrusion across three frameworks
  • Lab: Correlate multi-source logs into a timeline
  • Lab: Execute a persistence hunt playbook
  • Lab: Assemble an eradication checklist

Domain 5

Reporting, Ethics & Legal (25%)

  • Forensic report writing, chain of custody, and evidence handling
  • Ethics, legal frameworks, and expert testimony
  • Professional ethics, scope limitations, and examiner independence
  • Legal frameworks: search and seizure, privacy law, and international jurisdiction
  • OSINT methodology, passive reconnaissance, and intelligence operationalization
  • Lab: Find the fatal chain of custody gap
  • Lab: Respond to pressure and cross-examination
  • Lab: Rewrite findings with correct confidence language
  • Lab: Determine notification obligations and deadlines
  • Lab: Assess an OSINT collection for legal constraints

Proctored online exam

Complete the 3-hour proctored exam from any browser — no test center required.

Instant digital certificate

Receive your PDF certificate and digital badge immediately upon passing.

Verifiable public registry

Every certificate has a unique URL — employers and clients can verify authenticity instantly.

FAQ

Frequently asked questions

Are courses available now?

Yes — free courses are available immediately upon registration. Paid courses can be purchased individually and accessed right away.

Do I need a Pro account?

Free courses are available to all registered users. Paid courses require purchase but do not require a Pro subscription.

How does the CSFA certification work?

You purchase the exam, complete it online within a 3-hour window, and receive your digital certificate immediately upon passing. The certificate is verifiable via a public URL.

Are labs browser-based?

Yes. Every lab runs directly in the Cal Security & Forensics LLC toolkit — no VM downloads, no external tools required.

Can I take courses in any order?

Free courses have no prerequisites. Paid courses list recommended prerequisites on their cards. The CSFA exam is designed for learners who have completed at least the Forensics Fundamentals and one intermediate course.

What score do I need to pass the CSFA exam?

A passing score is 75% or higher across all five domains. You must score at least 60% in each individual domain. You may retake the exam after a 14-day waiting period.

Ready to level up?

Start with a free course today — no credit card, no setup, just the tools.