Legal Cyber Academy
Blog or channelPartly freeCurrent

13Cubed

Richard Davis

Access and status

Cost

Partly free

Part of it is free and part is not. The entry says which part; read that before you plan around it.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A YouTube channel and companion training site covering Windows, Linux and macOS endpoint forensics, memory analysis and threat hunting. The YouTube videos are free; the on-demand courses on training.13cubed.com are paid.

Who it is for, and when

Use the free videos when you need to see a single artifact worked end to end — what writes it, how to parse it, what the output means. The pacing suits someone learning an artifact for the first time, and the demonstrations are done on real images rather than slides. The paid courses bundle the same teaching style into structured lab-based tracks with 365-day access.

What it does not cover

It is endpoint-centric: there is essentially nothing on mobile, cloud or network forensics, and nothing on report writing, disclosure or testimony.

Go to the source

Open at youtube.com (opens in a new tab)

https://www.youtube.com/@13Cubed

Details

Type
Blog or channel
Written for
New to the fieldWorking examinerNew to the field, Working examiner
Author
Richard Davis
Topics
training, windows, memory-forensics, linux, macos, threat-hunting
Checked at source
  • A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.

  • Memory acquisition and analysis across Windows, Linux and macOS, written by the people who built Volatility: process and kernel structures, code injection, rootkit detection, registry and event logs recovered from RAM, the GUI subsystem, network state, and case studies.

  • A gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.

  • A DFIR training company that publishes a substantial block of genuinely free self-paced courses alongside its paid catalogue. Confirmed free titles include C5W-100 Introduction to Digital Forensics, Linux Forensics Distributions, Intro to Linux from a Forensics Perspective (Ubuntu and Tsurugi), Writing Forensics Reports, Computer Data Representation, Working with Files, Prepare Your Forensic Environment, Working with Virtual Hard Disk, several Spanish-language courses on evidence acquisition and Windows forensics, and a set of case-study workshops.

  • A community-maintained, machine-readable knowledge base of digital forensic artefact definitions — where an artefact lives and how to collect it — expressed in YAML and licensed Apache-2.0. It is documented at artifacts.readthedocs.io and coordinated through the forensicartifacts Google Group and the Open Source DFIR Slack.