Every time I’ve asked someone actually working in DFIR what to do next, the first answer is Richard Davis’s 13Cubed. That’s not a coincidence — it’s the community rating his course as one of the best options out there. I’ve now finished both Investigating Windows Endpoints and Investigating Windows Memory, and after going through them myself, I get it.
Who this is actually for
If you struggle with wall-of-text material, this is the course. I’ve always found that kind of learning demoralizing, and Richard breaks everything down on camera in a way that just clicks. If you learn better watching than reading, this is built for you specifically — not as a general “video courses are nice” pitch, but because the entire course is structured around that.
Try before you buy
There’s a genuine wealth of free content on the 13Cubed YouTube channel, and it’s the easiest way to know before you spend the money. Watch one video and see if his style clicks for you — I’d be amazed if it didn’t.
It’s also not just the paid content that’s accessible. I’ve emailed Richard directly more than once, probably more than I should have, and he actually replies. This is Richard Davis himself, not a support inbox, taking the time to answer questions from randoms like me.
365 days, not 4 months
Most platforms cut you off a few months in. Here you keep access for a full year — even after you’re already certified — so you can go back and re-watch lessons whenever you need a refresher. That alone is worth factoring into the price, and it’s part of why I’d call this SANS-level training at a fraction of the cost.
Lab setup
One thing that doesn’t get talked about enough — Richard walks you through setting up your own DFIR lab, and it’s the same environment you use for the exam. He covers WSL, Windows Sandbox, and the specific applications he recommends. By the end you’ve got a proper reusable DFIR image you can snapshot and reuse for malware labs down the line, not just exam notes.
The Endpoints exam
Endpoints goes deep on the lesson content, but the exam itself stuck to testing the more common, high-value material — fair, once you’d put the work in. The standout moment for me was learning to properly map artefacts with the Eric Zimmerman tool suite, and the Shellbags module — somehow in all my hands-on time I hadn’t run into that yet, and having it laid out step by step was one of those “how did I not know this” moments.
The Memory exam
Memory felt more in-depth than Endpoints — though I’ll be honest, that’s partly on me, since I hadn’t run a memory lab in a while and I’m just more confident on the endpoints side already. The practical exam wouldn’t let a lazy strings search carry you to the right answer; you actually have to understand what you’re looking at.
The standout module here was reflective code injection — how it differs from basic code injection, and how you identify it with malfind. Small bit of trivia for anyone following along: Volatility 3 renamed the plugin to windows.malware.malfind at some point. Same behavior, same output, just a heads-up if the lesson still references the old name.
Coverage
Richard covers everything the cert needs, and the additional modules go further — into things like browser artefacts that a lot of courses skip entirely. There were no gaps I had to go outside the course to fill.
Verdict
Out of every cert I’ve done, this is the one I’d pick. I’m probably a little biased since I learn so well from video, but the way Richard structures and explains this material just makes it click. If you haven’t done Investigating Windows Endpoints yet, do that first — it sets you up properly for Memory.
Course → training.13cubed.com