DFIR Practice & CTF Directory

Sharpen your skills hands-on: evidence images and datasets to examine, browser labs and platforms to train in, and CTFs to compete in, from free community classics to full commercial ranges. The companion to our Training Finder: learn there, practise here.

What the directory lists

36 free and paid resources for practising digital forensics and incident response: 16 evidence datasets and images, 3 hands-on labs, 5 practice platforms, 4 recurring ctf competitions, 3 ctf archives, 5 directories of further resources. Each entry records provider, topics, difficulty, cost and format. Data as of 2026-07-25.

Evidence datasets and images (16)

Ali Hadi DFIR Challenges (Dr. Ali Hadi (ashemery.com)), free; CIRCL Digital Forensic Training Materials (CIRCL (Computer Incident Response Center Luxembourg)), free; DFRWS Forensic Challenge Datasets (DFRWS), free; Digital Corpora (Digital Corpora / Simson Garfinkel), free; Digital Forensics Lab (frankwxu) (University of Baltimore / Frank Xu), free; Digital Forensics Tool Testing Images (DFTT) (Brian Carrier / DFTT project), free; EVTX-ATTACK-SAMPLES (Samir Bousseaden (sbousseaden)), free; flaws.cloud CloudTrail Log Dataset (Scott Piper (Summit Route)), free; Honeynet Project Forensic Challenges (The Honeynet Project), free; Malware-Traffic-Analysis.net Exercises (Brad Duncan (malware-traffic-analysis.net)), free; MemLabs (stuxnet999 (Abhiram Kumar)), free; NIST CFReDS (NIST), free; Security Datasets (OTRF) (Open Threat Research Forge), free; The Binary Hick Public Test Images (Josh Hickman (The Binary Hick)), free; The Stolen Szechuan Sauce (Case 001) (DFIR Madness (James Smith)), free; Wireshark Sample Captures (Wireshark Foundation), free.

Hands-on labs (3)

DFIR Labs (The DFIR Report), paid; HTB Academy — SOC Analyst path (Hack The Box), freemium; XINTRA Labs (XINTRA), paid.

Practice platforms (5)

Blue Team Labs Online (Security Blue Team), freemium; CyberDefenders (CyberDefenders), freemium; Hack The Box Sherlocks (Hack The Box), freemium; LetsDefend (LetsDefend (Hack The Box)), freemium; TryHackMe — DFIR module (TryHackMe), freemium.

Recurring CTF competitions (4)

BelkaCTF (Belkasoft), free; Blue Team Village CTF (DEF CON) (Blue Team Village), free; Cellebrite CTF (Cellebrite), free; Magnet Virtual Summit CTF (Magnet Forensics / Hexordia), free.

CTF archives (3)

13Cubed Mini Memory CTF (13Cubed), free; DFIR Madness (DFIR Madness (James Smith)), free; Magnet Weekly CTF archive (Magnet Forensics), free.

Directories of further resources (5)

AboutDFIR Challenges & CTFs List (AboutDFIR / Devon Ackerman), free; CTFtime (CTFtime.org), free; Netresec Public PCAP Repository List (Netresec), free; Stark 4N6 Forensics StartMe (Kevin Pagano (Stark 4N6)), free; Volatility Foundation Memory Samples (Volatility Foundation), free.

More DFIR career tools