HBNF · Network forensics and incident response training

Host-Based Network Forensics (HBNF)

Investigate network intrusions and ransomware using host-based evidence: traffic artefacts, live triage, memory analysis, Windows event logs and Registry persistence, and attack timelines.

Dates
22–26 Feb 2027
Duration
5 days, 08:00–17:00
Level
Advanced
Seats
Limited number of seats
Network forensics and incident response training – Host-Based Network Forensics (HBNF)

Course overview

The Host-Based Network Forensics (HBNF) course offered by Spyder Forensics is an intensive 5-day training program designed for experienced examiners in digital forensics. Geared towards individuals familiar with digital forensic principles, this course aims to expand their expertise in advanced network exploitation forensics using host-based artifacts from systems victimized by attacks, including ransomware incidents.

Throughout the training, participants will gain unbiased knowledge and essential skills for analyzing artifacts resulting from network intrusion activities, with a strong emphasis on ransomware detection and response. The curriculum involves the use of standard techniques and open-source approaches to delve deeper into data exploration. By understanding how applications function and store data during network intrusions, attendees will acquire the expertise needed to navigate forensic challenges.

The course covers the identification, processing, understanding, and documentation of crucial forensic artifacts related to network intrusion investigations, including ransomware attack lifecycles. Participants will learn to apply various methodologies and utilities effectively. This includes investigating network intrusions through host-based evidence, capturing and analyzing network traffic artifacts on hosts, triaging live systems, and examining memory captures to pinpoint potential malware and threat artifacts linked to network activity. The curriculum also encompasses the analysis of Windows network-related artifacts to uncover additional information relevant to network intrusion investigations, such as persistence mechanisms.

Emphasizing hands-on learning, students will engage in extensive labs and exercises, including ransomware-focused scenarios and a capstone investigation. By the end of the course, attendees will have acquired comprehensive skills and knowledge to conduct advanced host-based network forensic analyses, reconstruct attack timelines, and effectively document findings for real-world applications.

Who should attend

Experienced digital forensic examiners who investigate network intrusions and ransomware incidents.

Course objectives

  • Develop incident response plans and methodologies for investigating network intrusions using host-based network evidence.
  • Recognize and analyze ransomware attack patterns and lifecycles within host-based artifacts.
  • Construct intrusion timelines by correlating host-based network data and logs.
  • Understand network components and concepts that impact host-based forensics, including malicious activity identification.
  • Capture and analyze host-based network traffic artifacts to detect data exfiltration and command-and-control activity.
  • Reconstruct network sessions and recover ransomware-related files using host-based evidence.
  • Capture volatile memory from hosts and identify network and ransomware artifacts through memory analysis.
  • Analyze Windows host-based network artifacts, including event logs and registry entries, for ransomware persistence and indicators.

Prerequisites

This course is designed for experienced examiners who are familiar with digital forensic principles.

Tools and techniques

  • Standard forensic techniques and open-source tools

Certificate

Official e-DiFTA certificate

Every participant who passes the course receives an official e-DiFTA certificate confirming successful completion of the class and recognising the training hours completed.

Instructor

Anna Truss

Anna Truss

Senior Trainer / Developer, Spyder Forensics

Anna Truss is a highly skilled and respected professional in the field of digital forensics. With extensive experience as a forensic practitioner and trainer, Anna has made significant contributions to the examination and analysis of digital data.…

Full profile →

Frequently asked questions

Who can attend this course?

Attendance is intended exclusively for law enforcement personnel, military personnel engaged in digital forensic activities and private-sector investigators.

What is included in the €2,500 fee?

Five days of hands-on training (08:00–17:00), an official certificate of successful completion recognising the training hours, a buffet lunch and morning and afternoon coffee breaks every day.

How are seats allocated?

Seats are limited and allocated on a “first paid – first confirmed” basis. Your registration is confirmed once payment is received; the payment deadline is 25 December 2026.

Do I receive a certificate?

Yes. Every participant who passes the course receives an official e-DiFTA certificate confirming successful completion of the class and recognising the training hours completed.

Is VAT charged?

Invoices are issued from France. Private individuals and organisations in France pay French VAT (20%). Organisations outside France are invoiced without French VAT when they provide a valid VAT number, TIN or EIN. Full VAT rules.

Related courses

All 8 courses →
€2,500HBNF · 22–26 Feb 2027
Register →