Ali Hadi's DFIR Challenges
Ali Hadi
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.
Who it is for, and when
These are the standard teaching images for specific Windows and NTFS techniques — if you want to practise finding data hidden in alternate data streams or in NTFS structures, this is where the evidence is. Several were built for university courses and conference workshops (Challenge 5 came out of a BSides Amman 2021 workshop), so the scenarios are tight and the artefact you are meant to find is deliberately placed.
What it does not cover
Downloads are spread across Archive.org, Mega and GitHub rather than one maintained host, and Challenge 11 is listed as only partly available — expect to hunt for links. The cases are single-host and mostly Windows; there is no mobile, cloud or enterprise-scale material.
Go to the source
Open at ashemery.com (opens in a new tab)https://www.ashemery.com/dfir.html
Details
- Type
- Dataset
- Written for
- Working examinerWorking examiner
- Author
- Ali Hadi
- Topics
- datasets, ctf, windows, file-systems, memory-forensics, linux, training
- Checked at source
Related entries
13Cubed
Partly freeA YouTube channel and companion training site covering Windows, Linux and macOS endpoint forensics, memory analysis and threat hunting. The YouTube videos are free; the on-demand courses on training.13cubed.com are paid.
A scripted corporate scenario covering the first four weeks of a fictional patent-search company, from 13 November 2009 to 12 December 2009. It ships daily hard drive images and daily RAM captures for each computer, USB drive images, inbound and outbound packet captures, final-day images of every system, and simulated case paperwork including detective reports, warrants and affidavits.
Cyber5W Free DFIR Courses
Partly freeA DFIR training company that publishes a substantial block of genuinely free self-paced courses alongside its paid catalogue. Confirmed free titles include C5W-100 Introduction to Digital Forensics, Linux Forensics Distributions, Intro to Linux from a Forensics Perspective (Ubuntu and Tsurugi), Writing Forensics Reports, Computer Data Representation, Working with Files, Prepare Your Forensic Environment, Working with Virtual Hard Disk, several Spanish-language courses on evidence acquisition and Windows forensics, and a set of case-study workshops.
IACIS runs "an annual training event in Orlando, Florida the last week of April and the first week of May each year", with the next Orlando conference scheduled for 19-30 April 2027 and roughly 800-900 students attending across the two weeks. The flagship course is Basic Computer Forensic Examiner (BCFE), with advanced offerings in mobile device forensics, Windows, Linux and scripting; a 2026 Budapest event is also listed at €4,800.
Memory acquisition and analysis across Windows, Linux and macOS, written by the people who built Volatility: process and kernel structures, code injection, rootkit detection, registry and event logs recovered from RAM, the GUI subsystem, network state, and case studies.