Legal Cyber Academy
Free trainingPartly freeCurrent

Cyber5W Free DFIR Courses

Access and status

Cost

Partly free

Part of it is free and part is not. The entry says which part; read that before you plan around it.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A DFIR training company that publishes a substantial block of genuinely free self-paced courses alongside its paid catalogue. Confirmed free titles include C5W-100 Introduction to Digital Forensics, Linux Forensics Distributions, Intro to Linux from a Forensics Perspective (Ubuntu and Tsurugi), Writing Forensics Reports, Computer Data Representation, Working with Files, Prepare Your Forensic Environment, Working with Virtual Hard Disk, several Spanish-language courses on evidence acquisition and Windows forensics, and a set of case-study workshops.

Who it is for, and when

The free tier is the best structured free starting point that is actually about forensics rather than general security. Writing Forensics Reports is the unusual one — very little free training addresses how to document findings — and the Linux and environment-setup courses solve the practical problem of getting a working analysis machine. The paid courses and certifications are priced only on the academy platform.

What it does not cover

The free courses are foundational: no mobile forensics, no cloud, no memory analysis of any depth, and the paid catalogue is where the advanced material sits. It is a commercial training vendor, so the free tier functions as a funnel.

Go to the source

Open at cyber5w.com (opens in a new tab)

https://www.cyber5w.com/

Details

Type
Free training
Written for
New to the fieldWorking examinerNew to the field, Working examiner
Topics
free-training, training, linux, imaging, windows
Checked at source
  • 13Cubed

    Partly free

    A YouTube channel and companion training site covering Windows, Linux and macOS endpoint forensics, memory analysis and threat hunting. The YouTube videos are free; the on-demand courses on training.13cubed.com are paid.

  • A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.

  • IACIS runs "an annual training event in Orlando, Florida the last week of April and the first week of May each year", with the next Orlando conference scheduled for 19-30 April 2027 and roughly 800-900 students attending across the two weeks. The flagship course is Basic Computer Forensic Examiner (BCFE), with advanced offerings in mobile device forensics, Windows, Linux and scripting; a 2026 Budapest event is also listed at €4,800.

  • A scripted corporate scenario covering the first four weeks of a fictional patent-search company, from 13 November 2009 to 12 December 2009. It ships daily hard drive images and daily RAM captures for each computer, USB drive images, inbound and outbound packet captures, final-day images of every system, and simulated case paperwork including detective reports, warrants and affidavits.

  • A free eight-hour online unit from The Open University on its OpenLearn platform, classified as Level 3 (advanced undergraduate entry), with a free statement of participation on completion.