Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/azr43lkn1ght/dfir-labs
Disk ForensicsMemory ForensicsNetwork ForensicsMalware AnalysisDigital ForensicsCTFLearning & EducationIncident ResponseLabs & Practice
GitHubazr43lkn1ght/dfir-labs

DFIR-LABS

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world scenarios.

5577279 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

DFIR LABS

About

DFIR LABS is a compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital Forensics, Incident Response, Malware Analysis and Threat Hunting.

This is aimed at Professionals, Security Researchers, Students, CTF Players as well as DFIR & Malware Analysis Enthusiasts in the field of Cyber Security who want to practice or have an interest in the aforementioned topics.

Though the final goal of the challenges is CTF-styled flags, most of the challenges are in the traditional and effective learning method of answering an incident response scenario.

The first release of DFIR LABS is focused primarily on Windows-based challenges. Future and upcoming editions will broaden the scope to include Linux, MacOS, and Android, offering a comprehensive range of DFIR challenges across diverse platforms.

Our vision is to create a comprehensive resource that grows with the community, incorporating modern threats and techniques, and fostering collaboration across diverse cybersecurity domains. Whether you're a beginner or an expert, DFIR LABS offers a unique opportunity to sharpen your skills and stay ahead in this ever-evolving field.

Important Notice

Individuals are strongly advised against executing any executables or binaries provided in the challenge files, as they may contain potentially malicious software. Authors of DFIR LABS holds no responsibility for any consequences resulting from the use of these files, including but not limited to system compromise, data loss, or operational disruptions. To mitigate risks, all activities should be conducted within a secure, isolated environment such as a virtual machine or sandboxed setup. Ensure your testing infrastructure is robust and appropriately configured to handle potential threats.

Warning
The challenges in DFIR LABS are designed to simulate real-world scenarios and may contain potentially harmful softwares like ransomware, trojan, stealers, c2, etc., Always exercise caution and use a secure, isolated environment when working with these challenges.

Challenges

Note
The difficulty level of each challenge is subjective and may vary based on individual experience and skill level. The challenges are designed to be completed in a specific order, with each challenge building upon the previous one. However, participants are free to attempt the challenges in any order they prefer.

Environment Setup

To ensure a secure and efficient analysis environment, follow these steps:

  • Isolated Virtual Machine: Use a dedicated virtual machine (VM) for DFIR LABS challenges. Recommended platforms include VMware, VirtualBox, or Hyper-V. Ensure the VM is configured with sufficient resources (CPU, memory, and disk space) for smooth operation.

  • Operating System: Install a clean version of Windows or any favourable OS. Apply all security patches and updates.

  • Network Configuration: Disable internet access on the VM to prevent unintended data exfiltration or malware communication. Use a host-only or internal network configuration.

  • Forensic Tools: Install industry-standard forensic tools, such as Autopsy, Volatility, or FTK Imager, depending on the nature of the challenge. Ensure all tools are updated to their latest stable versions.

  • Snapshot Management: Take an initial snapshot of the VM after setup and before beginning any analysis. This allows for easy rollback in case of system compromise or misconfiguration.

  • Secure Storage: Store challenge files and findings in an isolated container.

Feedback/ Suggestions

Any and all feedbacks, suggestions or improvements are welcome! We would appreciate any feedbacks from the community.

Send your feedback on X: Azr43lKn1ght

How to Contribute

If you are interested in contributing to DFIR LABS, please refer to the CONTRIBUTING.md file for more information.

Usage

DFIR Labs is absolutely free for anyone to use. If you wish/want to use DFIR Labs in your workshops, Sessions or anywhere else, Please always use the original links to the labs and also mention the author's name and the labs as well. For any other queries, please contact me via email or twitter/X : Azr43lKn1ght

Circle of Gratitude

We extend our deepest gratitude to everyone who has played a part in the success of DFIR LABS. This project thrives on the passion, expertise, and unwavering dedication of our core contributors and supporters. A special acknowledgment goes to the incredible teams that have supported and enriched this initiative:

  • bi0s
  • Traboda CyberLabs
  • r3kapig
  • idek
  • l3ak
  • m53
  • ws1004

We are profoundly grateful for the continued encouragement, insightful feedback, and inspiration from the global DFIR and cybersecurity community. Your support fuels the growth and evolution of DFIR LABS, and we are honored to have you alongside us on this journey!

Tools and Resources

Here are some of the most used open-source tools that will help you in solving the challenges:

Network Analysis

  • Wireshark
  • NetworkMiner

Memory Forensics

  • Volatility
  • MemProcFS

Disk, File System and Windows Forensics

  • autopsy
  • EZ Tools
  • FTK Imager
  • The Sleuth Kit
  • Active@ Disk Editor

Debugging and Reverse Engineering

  • WinDbg
  • IDA
  • Ghidra
  • x64dbg

Process Analysis

  • Process Hacker
  • Sysinternals Suite

Binary and PE Analysis

  • 010editor
  • PEStudio
  • CFF Explorer
  • PE Bear

Here are some of the most used resources that will help you in solving the challenges:

Blogs:

  • Azr43lKn1ght's Blog
  • ws1004's Blog
  • crazymaan's Blog
  • warlocksmurf's Blog
  • Abdelrhman Shaban's Blog
  • cyber5w
  • Ashemery
  • Stuxn3t's Blog
  • G4rud4's Blog
  • This Week in 4n6
  • frsecure
  • Sans Blog
  • DFIR training

CTF Writeups

  • bquanman's CTF writeups
  • bi0s Blog

YouTube Channels

  • Ali Haadi
  • 13cubed
  • MyDFIR
  • All Things IDA

Guides and References

  • MemLabs
  • Volatility Labs
  • Volatility Command Reference
  • MAS Series
  • aboutdfir

Books

  • The art of memory forensics
  • Practical Malware Analysis
  • Malware Analyst's Cookbook

Discord

Join our Discord server to connect with the DFIR community, share insights, and collaborate on cybersecurity challenges. The server is open to all cybersecurity enthusiasts, students, professionals, and researchers. We welcome diverse perspectives and encourage active participation in discussions, workshops, and CTF events.

DFIR LABS Community Discord

Also join the Digital Forensics Discord server for more discussions and resources on DFIR topics.

Digital Forensics Discord

Chief Author and Maintainer

Azr43lKn1ght - Twitter | Linkedin | Github

Download Tool
Chall-NameDifficultyAuthor(s)
Gotham HustleEasyAzr43lKn1ght
Trinity Of SecretsEasyrudraagh, kr4z31n, __ m1m1 __
2-layer securityEasybquanman
WinserpartEasyAzr43lKn1ght,jl_24, gh0stkn1ght, sp3p3x
Kn1ghtfl4r3Mediumkr4z31n, __ m1m1 __, rudraagh
VerbotenMediumsp3p3x, jl_24, gh0stkn1ght, hrippi.x_
Covid Crime ScenarioMediumws1004
pf-ingMediumk.eii
The Malware CrusadeMediumAzr43lKn1ght, sp3p3x, jl_24 , gh0stkn1ght, 5h4rrk
CompromisedMediumAbdelrhman
DFIR 2025 Ⅰ - Lost In RouterMediumSuyun
Shiunji-oukaMediumk.eii
Famous AMOSMediumwarlocksmurf
The Saint BatMediumAzr43lKn1ght
StealthHardbquanman
InterestingHardk.eii
Thugs on a boatHardbquanman
Batman Investigation IHardAzr43lKn1ght
Master of DFIR - PhishingHardcrazyman, F0rest, yuro
Master of DFIR - CoffeeHardcrazyman, F0rest
ReAL File SystemHard5h4rrk
Hidden Gem MixtapeHardbquanman
Kn1ghtF4LLHardAzr43lKn1ght, sp3p3x, jl_24, gh0stkn1ght
BreadcrumbsInsaneAbdelrhman
DFIR 2025 Ⅱ - fake newsInsanecrazyman, bquanman, F0rest, yuro
DFIR 2025 III - who is spyderInsanecrazyman, F0rest
Batman Investigation IIInsaneAzr43lKn1ght
Batman Investigation IIIInsaneAzr43lKn1ght
Kn1ghtw4r3InsaneAzr43lKn1ght, gh0stkn1ght, jl_24, sp3p3x, hrippi.x_
S4nct1m0nyInsanegh0stkn1ght
Kn1ghtm4r3InsaneAzr43lKn1ght
Batman Investigation IVInsaneAzr43lKn1ght, jl_24, sp3p3x, gh0stkn1ght
Kage No NazoInsanejl_24
Batman Investigation VInsaneAzr43lKn1ght, Kr4z31n
Batman Investigation VIInsaneAzr43lKn1ght