EFFORT
210h
with instructor
FORMAT
Self-paced
or instructor-led
CERTIFIES
City & Guilds
Assured
PROGRAMS
5
across Levels 1–4
OUTCOME
Digital Forensics
Job-ready
For teams & organizations — volume pricing, instructor-led delivery, custom scenarios.
2,499
Digital Forensics Bundle
Valid for 12 months
// ALL-IN-ONE FORENSICS BUNDLE · LEVELS 1·2·3·4
Get full multi-platform investigation with the
Digital Forensics Bundle
Five hands-on programs spanning Levels 1 to 4 — a fast ramp through the fundamentals, then deep forensic investigation across Windows, Linux and the network. Real tools on real systems, real artifacts, and the cross-platform investigative skill set that modern breaches actually demand.
Overview
This Bundle takes you from fundamentals to full-spectrum forensic capability across four levels. You'll build a footing in networks, then investigate three platforms the way real incidents cross them — carving Windows disks and memory, working Linux file systems and logs, and reconstructing attacks from the network itself. Every step runs on live systems inside Cyberium Arena, against real evidence, not slides.
One investigation, every platform — Windows, Linux and the wire.
Where it leads
This Bundle is your move into multi-platform investigation, not your ceiling.
Forensics / IR Consultant
Digital Forensics Specialist
→
Senior Forensics Investigator
→
DFIR Team Lead
→
Why this gets you hired
-
City & Guilds Assured credentials on XE101, NX201 and NX212 — internationally recognized
-
Hands-on proof across three platforms — Windows, Linux and network — not one
-
Real artifacts on live systems, not theory-only certificates
-
Built by Israeli intelligence veterans, used by organizations worldwide
Who's hiring
-
Incident response and DFIR teams, and the MSSPs that staff them
-
Enterprise security and threat-hunting teams running mixed Windows/Linux estates
-
Government, defense and national CERT/CSIRT units
-
Consultancies running breach investigations and IR retainers
-
Cyber-insurance-driven response practices
What you'll actually do
-
Acquire and preserve evidence on live systems — capture volatile memory, image and clone drives, and mount partitions without contaminating the source.
-
Reconstruct Windows activity — carve the MFT, parse the registry (NTUSER.DAT), event logs and timelines, and pull artifacts from memory with Volatility.
-
Investigate Linux — read ext4/XFS file systems and inodes, parse logs with grep, sed and awk, and trace user activity through shell history, cron and persistence.
-
Work the network — capture and dissect traffic with Wireshark, TShark and tcpdump, decrypt HTTPS, trace phishing through email headers, run Suricata IDS, and investigate Wi-Fi, routers and cloud.
-
Analyze malware — static and dynamic analysis to establish what ran and what it touched.
The market
Projected size of the digital forensics & incident response solutions market by 2030, up from $10.46B in 2025 — a 20.37% CAGR.
$26.4B
Source · Mordor Intelligence — 2025
Where it's heading
Cloud forensics is the fastest-growing investigative type through 2030 — the work is moving off Windows endpoints and onto Linux, network and cloud, exactly the breadth this Bundle covers.
28.2%
Source · Mordor Intelligence — 2025
The pay
Average for a digital forensics analyst in the US; top earners clear $244K. The more platforms you can investigate, the higher you sit.
$133K
Source · Glassdoor — 2026
The role you're training for
Real breaches don't stay on one operating system. An attacker lands on a Windows host, pivots through Linux servers, and moves across the network and into the cloud — and the investigator who can follow that trail across all of it is the one organizations fight to hire. Demand climbs as breaches multiply, regulators compress investigation windows, and workloads scatter across platforms that single-OS tooling can't read. This is the discipline that turns "we think we were breached" into a reconstructed, evidenced timeline.
Digital Forensics Specialist — one of the most in-demand investigative roles in cybersecurity worldwide.
→ Each link opens the full, up-to-date syllabus on its own program page.
XE101
NX201
NX212
LEVEL 3 · 48h
Windows Forensics
Disk and memory forensics, registry, event logs, malware analysis
NX215
LEVEL 4 · 40h
Linux Forensics
File systems, log and user-activity analysis, live acquisition
NX216
What's Included
This Bundle is built for capable profiles. If you already have a footing in cyber or networking, XE101 and NX201 are a fast on-ramp, not a starting line — but take them anyway: even seasoned investigators pick up something in the fundamentals that sharpens how they approach the Windows, Linux and network depth of NX212, NX215 and NX216. Each program is a complete course in its own right, with hands-on labs, scenarios and its own path to certification. Open any one for the full syllabus.
Five programs.
One investigation.
€2,499
You save €4,701 (65%)
✓ 12 months access
✓ Among most demanded job roles
✓ Pure hands-on experience
XE101
Intro-to-Cyber
€800
NX201
Network Research
€1,600
NX212
Windows Forensics
€1,600
NX215
Linux Forensics
€1,600
NX216
Network Forensics
€1,600
Total purchased separately
€7,200
THE NUMBERS
Cheaper than the three forensics courses on their own.
Bought one by one, NX212, NX215 and NX216 come to €4,800 — nearly double the whole five-program Bundle, before you've even added the XE101 and NX201 fundamentals.
Certifications
XE101, NX201 and NX212 are each individually City & Guilds Assured — internationally recognized credentials earned by passing a practical, scenario-based exam, verifiable by employers via a unique code. NX215 and NX216 each carry a ThinkCyber Certificate of Completion. You earn every credential separately — proof of real capability, not attendance.
Individually certifiable via City & Guilds:
XE101 and/or NX201 and/or NX212
Delivery & Assessment
Conceptual teaching paired with hands-on labs on real forensic tools — Volatility, FTK, Wireshark, TShark, Suricata and Scapy — all inside Cyberium Arena.
You'll run live investigation scenarios across Windows, Linux and network evidence, and prove your skills through hands-on assessments at each level.
// Where you'll do all of this
You won't watch this.
You'll run it live.
Every module above is executed inside Cyberium Arena — real tools on real nodes, deployed on the live internet, with live threat intelligence running from your first login. Not a sandbox. Not a VM. Not a video.
Live Internet
Real Tools
Sand Box
VM




WHAT OUR CLIENTS SAY
“The training was crucial... SOC analysts from across the nation participate in CERT-IL Advanced Cyber Training using the Cyberium simulator”
— Homeland Security
WHAT OUR CLIENTS SAY
“Over 1000 students trained... hands-on experience invaluable for career progression. Instrumental in nationwide SOC training”
— Centre for Cybersecurity Institute, Singapore
WHAT OUR CLIENTS SAY
“Students secure excellent positions as SOC Analysts, Network Security Engineers & Penetration Testers thanks to applicable hands-on skills”
— John Bryce Training Center, Israel
WHAT OUR CLIENTS SAY
“Exceptional course that outshines them all in every conceivable way: comprehensive content, expert guidance, practical exercises”
— Defense Forces
2,499
Digital Forensics Bundle
Valid for 12 months
Investigate the whole breach.
Get hired to lead it.
Trusted since 2016 — national police, military cyber units & Fortune 500 teams · City & Guilds Assured
