Skip to content
🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
Free lab

Forensics Lab

An investigation is not about having a theory — it is about proving one from the artifacts. Work a business-email-compromise case from a day of logs across mail, identity, endpoint and network, separate the real evidence from the everyday noise, and answer the board's questions. You are scored on your conclusions and on whether you can cite the evidence behind them. A review board is watching.

Case brief

Finance paid a fraudulent $240k wire. You are handed a day of artifacts from mail, identity, endpoint and network. Reconstruct what happened, separate the evidence from the noise, and answer the board’s questions.

Evidence (check the artifacts relevant to this case)

Investigative questions

What was the initial access vector?

How did the attacker hide their activity in the mailbox?

What was the attacker’s objective?

Was malware involved?

Where did the malicious session originate?

Answer all 5 questions to submit.

Case score

Work the evidence and answer the questions.

Investigation room

co-investigators + review board
dfir-noa2/5
analyst-ren1/5
review-board-ai0/3

opening the evidence locker…

Investigator's rule

A conclusion is only as good as the artifact that backs it. Picking a red herring costs you — so does a theory you can't cite. Find the evidence, then answer.

TL;DR

What this lab is

  • A free digital-forensics lab: work a real-looking case from a pile of artifacts across mail, identity, endpoint and network.
  • You separate the evidence from the red herrings and answer five investigative questions — initial access, persistence, objective, malware, session origin — from the artifacts.
  • It is scored on both axes a real investigation is judged on: did you reach the right conclusions, and can you cite the evidence that backs them.
  • Picking a red herring or stating a theory you cannot support costs you, exactly as it would in front of a review board.
  • A live investigation room shows co-investigators and an AI review board probing your theory as you build it.

Frequently asked questions

What is the Forensics Lab?

A free, in-browser digital-forensics and incident-investigation exercise. You are given a case brief and a timeline of artifacts from multiple sources — some are the evidence of the attack, some are everyday noise. You mark the relevant artifacts and answer five investigative questions, and the lab scores both your conclusions and whether the evidence you selected supports them.

Why does it score evidence selection and not just answers?

Because in a real investigation, being right is not enough — you have to be able to prove it. An analyst who guesses the right answer but cites a red herring, or cannot point to the artifact, loses in court and in the incident review. The lab rewards recall (finding the relevant artifacts) and penalises picking the noise, so it trains the habit of reasoning from evidence.

What kind of case is it?

The first scenario is a business-email-compromise wire fraud: a phishing credential-harvest, a foreign sign-in, a malicious inbox rule, a fraudulent wire request, and a clean endpoint that tells you this was identity, not malware — surrounded by plausible but irrelevant everyday events you must rule out.

Is the case real?

No. The case, the artifacts and the live participants are a self-contained simulation inside the page, built to teach evidence-based investigation. Nothing here connects to real systems, mailboxes or people.

Forensics Lab — Free Digital-Forensics Investigation Trainer · PlayCISO