top of page

EFFORT

210h

with instructor

FORMAT

Self-paced

or instructor-led

CERTIFIES

City & Guilds

Assured

PROGRAMS

5

across Levels 1–4

OUTCOME

Digital Forensics

Job-ready

For teams & organizations — volume pricing, instructor-led delivery, custom scenarios.

2,499

Digital Forensics Bundle

Valid for 12 months

// ALL-IN-ONE FORENSICS BUNDLE · LEVELS 1·2·3·4

Get full multi-platform investigation with the

Digital Forensics Bundle

Five hands-on programs spanning Levels 1 to 4 — a fast ramp through the fundamentals, then deep forensic investigation across Windows, Linux and the network. Real tools on real systems, real artifacts, and the cross-platform investigative skill set that modern breaches actually demand.

Overview

This Bundle takes you from fundamentals to full-spectrum forensic capability across four levels. You'll build a footing in networks, then investigate three platforms the way real incidents cross them — carving Windows disks and memory, working Linux file systems and logs, and reconstructing attacks from the network itself. Every step runs on live systems inside Cyberium Arena, against real evidence, not slides.

One investigation, every platform — Windows, Linux and the wire.

Where it leads

This Bundle is your move into multi-platform investigation, not your ceiling.

Forensics / IR Consultant

Digital Forensics Specialist

Senior Forensics Investigator

DFIR Team Lead

Why this gets you hired

  • City & Guilds Assured credentials on XE101, NX201 and NX212 — internationally recognized

  • Hands-on proof across three platforms — Windows, Linux and network — not one

  • Real artifacts on live systems, not theory-only certificates

  • Built by Israeli intelligence veterans, used by organizations worldwide

Who's hiring

  • Incident response and DFIR teams, and the MSSPs that staff them

  • Enterprise security and threat-hunting teams running mixed Windows/Linux estates

  • Government, defense and national CERT/CSIRT units

  • Consultancies running breach investigations and IR retainers

  • Cyber-insurance-driven response practices

What you'll actually do

  • Acquire and preserve evidence on live systems — capture volatile memory, image and clone drives, and mount partitions without contaminating the source.

  • Reconstruct Windows activity — carve the MFT, parse the registry (NTUSER.DAT), event logs and timelines, and pull artifacts from memory with Volatility.

  • Investigate Linux — read ext4/XFS file systems and inodes, parse logs with grep, sed and awk, and trace user activity through shell history, cron and persistence.

  • Work the network — capture and dissect traffic with Wireshark, TShark and tcpdump, decrypt HTTPS, trace phishing through email headers, run Suricata IDS, and investigate Wi-Fi, routers and cloud.

  • Analyze malware — static and dynamic analysis to establish what ran and what it touched.

The market

Projected size of the digital forensics & incident response solutions market by 2030, up from $10.46B in 2025 — a 20.37% CAGR.

$26.4B

Source · Mordor Intelligence — 2025

Where it's heading

Cloud forensics is the fastest-growing investigative type through 2030 — the work is moving off Windows endpoints and onto Linux, network and cloud, exactly the breadth this Bundle covers.

28.2%

Source · Mordor Intelligence — 2025

The pay

Average for a digital forensics analyst in the US; top earners clear $244K. The more platforms you can investigate, the higher you sit.

$133K

Source · Glassdoor — 2026

The role you're training for

Real breaches don't stay on one operating system. An attacker lands on a Windows host, pivots through Linux servers, and moves across the network and into the cloud — and the investigator who can follow that trail across all of it is the one organizations fight to hire. Demand climbs as breaches multiply, regulators compress investigation windows, and workloads scatter across platforms that single-OS tooling can't read. This is the discipline that turns "we think we were breached" into a reconstructed, evidenced timeline.

Digital Forensics Specialist — one of the most in-demand investigative roles in cybersecurity worldwide.

→ Each link opens the full, up-to-date syllabus on its own program page.

XE101

LEVEL 1 · 32h

Intro-to-Cyber          

Networking, protocols, OSINT, packet analysis   

 

NX201

LEVEL 2 · 40h

Network Research  

Scanning, MiTM, Metasploit, firewalls 

NX212

LEVEL 3 · 48h

Windows Forensics

Disk and memory forensics, registry, event logs, malware analysis

NX215

LEVEL 4 · 40h

Linux Forensics

File systems, log and user-activity analysis, live acquisition 

NX216

LEVEL 4 · 50h

Network Forensics

Packet analysis, HTTPS, Wi-Fi, IDS, cloud and DarkNet 

What's Included

This Bundle is built for capable profiles. If you already have a footing in cyber or networking, XE101 and NX201 are a fast on-ramp, not a starting line — but take them anyway: even seasoned investigators pick up something in the fundamentals that sharpens how they approach the Windows, Linux and network depth of NX212, NX215 and NX216. Each program is a complete course in its own right, with hands-on labs, scenarios and its own path to certification. Open any one for the full syllabus.

Five programs.
One investigation.

€2,499

You save €4,701   (65%)

✓  12 months access

✓  Among most demanded job roles

✓  Pure hands-on experience

XE101

Intro-to-Cyber

€800

NX201

Network Research

€1,600

NX212

Windows Forensics

€1,600

NX215

Linux Forensics

€1,600

NX216

Network Forensics

€1,600

Total purchased separately

€7,200

THE NUMBERS

Cheaper than the three forensics courses on their own.

Bought one by one, NX212, NX215 and NX216 come to €4,800 — nearly double the whole five-program Bundle, before you've even added the XE101 and NX201 fundamentals.

Certifications

XE101, NX201 and NX212 are each individually City & Guilds Assured — internationally recognized credentials earned by passing a practical, scenario-based exam, verifiable by employers via a unique code. NX215 and NX216 each carry a ThinkCyber Certificate of Completion. You earn every credential separately — proof of real capability, not attendance.

Individually certifiable via City & Guilds:

XE101 and/or NX201 and/or NX212

Delivery & Assessment

Conceptual teaching paired with hands-on labs on real forensic tools — Volatility, FTK, Wireshark, TShark, Suricata and Scapy — all inside Cyberium Arena.

 

You'll run live investigation scenarios across Windows, Linux and network evidence, and prove your skills through hands-on assessments at each level.

// Where you'll do all of this

You won't watch this.

You'll run it live.

Every module above is executed inside Cyberium Arena — real tools on real nodes, deployed on the live internet, with live threat intelligence running from your first login. Not a sandbox. Not a VM. Not a video.

Live Internet

Real Tools

Sand Box

VM

Cyberium2_Login.png
Cyberium2_Student_1.png
Cyberium2_Training_Stats.png
Cyberium2_Specto_Cases.png

WHAT OUR CLIENTS SAY

“The training was crucial... SOC analysts from across the nation participate in CERT-IL Advanced Cyber Training using the Cyberium simulator”

— Homeland Security

WHAT OUR CLIENTS SAY

“Over 1000 students trained... hands-on experience invaluable for career progression. Instrumental in nationwide SOC training”

— Centre for Cybersecurity Institute, Singapore

WHAT OUR CLIENTS SAY

“Students secure excellent positions as SOC Analysts, Network Security Engineers & Penetration Testers thanks to applicable hands-on skills”

— John Bryce Training Center, Israel

WHAT OUR CLIENTS SAY

“Exceptional course that outshines them all in every conceivable way: comprehensive content, expert guidance, practical exercises”

— Defense Forces

2,499

Digital Forensics Bundle

Valid for 12 months

Investigate the whole breach.
Get hired to lead it.

Trusted since 2016 — national police, military cyber units & Fortune 500 teams · City & Guilds Assured

bottom of page