Personal Learning Roadmap — Jenny

OSINT & Behavioral Forensics
Learning Path

A phased journey from free exploration to credentialed analyst combining digital forensics, behavioral profiling, and OSINT investigation. Built around your hands-on learning style and Boston location.

Phases →
Phase 1 — Foundation
Phase 2 — Behavioral Layer
Phase 3 — OSINT + Volunteer
Phase 4 — Certifications
01
Phase 01 Foundation — Dip Your Toes Months 1–3
⭐ Start Here
Great Learning — Digital Forensics Essentials
Evidence handling, forensic imaging, file system analysis, artifact identification. No prior tech knowledge needed.
Free 5–8 hrs Self-paced
mygreatlearning.com
Hands-On
Blue Team Labs Online — Intro to Digital Forensics
Gamified labs including investigating a mock employee's hard drive. Learn evidence chain-of-custody through doing.
Free 4–6 hrs Gamified
securityblue.team
⭐ Local Boston
Boston Citizens Police Academy
Behind-the-scenes law enforcement access — forensics lab, investigations unit, dispatch. Best free immersion available locally.
Free 10 weeks In-Person
boston.gov/police
Deep Dive
Alison — Diploma in Digital Forensic Investigation
Data acquisition, malware analysis, network forensics. Free diploma-level depth. Certificate ~$20 if wanted.
Free 10–15 hrs Self-paced
alison.com
Watchable
DFIR.Science YouTube Series
Free intro forensics course from a practicing analyst. Watch on the couch. Great practitioner perspective.
Free ~6 hrs Video
dfir.training
02
Phase 02 Behavioral Layer — Profiling & Psychology Months 3–6
⭐ Top Pick
John Jay College — Investigative Psychology Certificate
Closest civilian access to FBI-style profiling. Offender profiling, crime scene psychology, behavioral analysis frameworks.
$150–500 Self-paced Online
jjay.cuny.edu
In-Person Event
AAFS Behavioral Assessment Workshop
Crime scene profiling through behavioral lens. Real case exercises. Annual event — book early. Closest to FBI BAU training available to civilians.
$100–250 Half-day Conference
aafs.org
Free Framework
ATAP Threat Assessment Framework
Core language of threat assessment professionals. Distinguishes transient vs substantive threats — foundational behavioral vocabulary.
Free ~5 hrs Self-directed
atapworldwide.org
Industry Standard
MITRE ATT&CK Framework
The common language for adversary behavior. Shows up in every job posting. Learn to speak the vocabulary of the industry.
Free ~4 hrs Self-directed
attack.mitre.org
03
Phase 03 OSINT Skills + Real Volunteer Work Months 4–9
Labs
TryHackMe — Cyber Defense Path
Beginner cybersecurity labs covering Wireshark, log analysis, network investigation. Gamified and beginner-friendly.
Free–$14/mo 20–40 hrs Guided labs
tryhackme.com
⭐ Best Entry Point
Trace Labs — Missing Persons CTF Events
Real OSINT investigations on real missing persons cases. Gamified, team-based, law enforcement referred. Every case = a portfolio entry.
Free 4–8 hrs/event Online events
tracelabs.org
Volunteer — Remote
Night Owl Reconnaissance (NOR)
501(c)3 nonprofit: missing persons OSINT alongside law enforcement. Remote, flexible, training provided. Min 1 hr/week. Age 55+ welcome.
Free 1+ hr/week Remote
idealist.org — NOR listing
Volunteer — High Impact
Innocent Lives Foundation (ILF)
OSINT to unmask online predators and traffickers — provide to law enforcement. Rigorous vetting process. Deeply meaningful work.
Free Flexible Remote
innocentlivesfoundation.org
Tools Practice
Core OSINT Tool Proficiency
Maltego, Shodan, SpiderFoot, Google dorking, Recon-ng. Build a personal practice lab. Document findings as case studies for your portfolio.
Free–$50 Ongoing Self-directed
osintframework.com
04
Phase 04 Certifications — If You're Hooked Month 6–12+
⭐ First Cert
EC-Council — Digital Forensics Essentials (DFE)
Industry-recognized cert. 11 video modules + 11 hands-on labs + proctored exam. Dark web, Linux, web app forensics. No prior IT experience needed.
$199 11 hrs + exam Online
eccouncil.org
Portfolio — Critical
Document 3–5 Investigation Cases
Structured case studies from Trace Labs CTFs + NOR volunteer work. In OSINT hiring, portfolio is often more important than formal credentials.
Free Ongoing LinkedIn + site
linkedin.com
Gold Standard
SANS SEC497 — OSINT Gathering & Analysis
The gold standard for serious OSINT roles. Advanced tradecraft, tools, ethics. Only pursue if targeting paid employment.
$5,000–7,000 5 days Online/In-person
sans.org
Boston — Hybrid
BU MET — Crime Analysis Graduate Certificate
Cybercrime, digital forensics, behavioral threat assessment. Local to Boston. Only pursue if fully committed to a formal role.
$4,000–8,000 4–6 courses Hybrid
bu.edu/met
Target Roles — Where This Path Takes You
⭐ OSINT Investigative Researcher
$0 volunteer → $30–60/hr consulting
Investigate missing persons, predators, or persons of interest using publicly available digital data. Reconstruct timelines, map digital footprints, build subject profiles from open sources.
Social media forensics Geospatial analysis Timeline reconstruction Maltego
Trace Labs CTFs → NOR volunteer → portfolio → consulting
Threat Assessment Investigator
$50–100/hr contract
Evaluate individuals displaying concerning behavior. Combine digital footprint analysis with behavioral red flag assessment to determine if someone poses a genuine risk of violence.
ATAP framework Behavioral psychology Risk assessment OSINT research
Universities, hospitals, corporate security, K-12 districts
OSINT Analyst
$40–80/hr contract
Gather, analyze, and report intelligence from open sources. Build subject profiles, track digital behavior patterns, identify threats or risks for corporate or nonprofit clients.
Maltego Shodan Dark web research Intelligence reports
Corporate security, law firms, private investigation, civic tech
Cyber Behavioral Analyst
$60–120/hr contract
Analyze digital artifacts — files, metadata, logs, browsing patterns — and interpret the human behavior and intent behind them. Why was this hidden? Why deleted? What does this pattern mean?
Autopsy / FTK Metadata analysis Behavioral interpretation Log analysis
Tech companies, financial institutions, defense contractors
Digital Forensic Examiner
$50–90/hr contract
Collect and analyze digital evidence from computers, phones, and storage media. Maintain chain of custody. Write expert reports and potentially testify in legal proceedings.
Autopsy EnCase Forensic imaging Legal report writing
Law enforcement support, law firms, insurance, corporate legal
Insider Threat Analyst
$55–95/hr contract
Monitor and investigate employees who may be stealing data or planning harm. Combine technical monitoring — who accessed what, when — with behavioral analysis of motivation and risk indicators.
SIEM tools DLP platforms Behavioral indicators MITRE ATT&CK
Banks, tech companies, defense contractors, government agencies
Total Timeline
9–18 mo
At a retirement pace
Phase 1–2 Cost
~$0–770
Free to explore deeply
Phase 3 Entry Role
Month 5+
Volunteer → portfolio → paid
First Target Role
OSINT Researcher
Most accessible entry point
What Employers Want

Synthesized from real 2026 job postings across USAJOBS, Glassdoor, LinkedIn, and ZipRecruiter — covering Digital Forensics Analyst, OSINT Analyst, Threat Assessment Analyst, and Cyber Defense Forensics Analyst roles.

Sources → USAJOBS (NCTC, SDNY, CISA) NYC DA Cybercrime Bureau Glassdoor OSINT Analyst ZipRecruiter OSINT / Forensics SANS Job Role Guides O*NET Digital Forensics 15-1299.06
Digital Forensics Analyst
Law enforcement, DA offices, federal agencies, corporate security
$75K–$133K staff · $50–90/hr contract
Core Responsibilities
  • Collect and preserve digital evidence from computers, phones, storage media
  • Conduct forensic imaging and maintain strict chain of custody
  • Analyze file systems, Windows artifacts, registry, and metadata
  • Recover deleted or encrypted data using forensic tools
  • Write detailed forensic reports admissible in legal proceedings
  • Testify in grand jury and trial proceedings as an expert witness
  • Perform mobile device exploitation (Cellebrite, physical extraction)
Top Qualifications Requested
EnCase / FTK / Autopsy Cellebrite Chain of custody CFCE (preferred) GCFA EnCE Windows file systems Report writing Bachelor's degree
Soft Skills Emphasized
Attention to detail Works independently Communicates to non-technical audiences
OSINT Analyst / Investigator
Corporate security, law firms, nonprofits, intelligence, insurance
$51K–$119K remote · $40–80/hr contract · $22/hr entry
Core Responsibilities
  • Gather and analyze publicly available data from social media, forums, public records, dark web
  • Build subject profiles and reconstruct digital footprints and timelines
  • Produce timely, actionable intelligence reports for leadership or legal teams
  • Conduct due diligence and background investigations on individuals and companies
  • Monitor threats, geopolitical risk, and emerging cyber trends
  • Verify information credibility and handle conflicting sources
  • Collaborate with legal, HR, security, and compliance teams
Top Qualifications Requested
Maltego Shodan Social media forensics Dataminr / Recorded Future CompTIA Security+ SANS SEC487/497 3+ yrs investigative experience SQL (a plus) Dark web monitoring
Soft Skills Emphasized
Analytical thinking Written communication Ethical & legal compliance Self-motivated / remote-capable
Threat Assessment Analyst
Universities, hospitals, corporations, K-12 districts, government
$60K–$110K staff · $50–100/hr contract
Core Responsibilities
  • Conduct OSINT research on individuals displaying concerning behavior
  • Assess risk level using structured behavioral frameworks (transient vs substantive)
  • Review digital footprints: social media, emails, forum activity, communication patterns
  • Produce threat assessment reports and briefings for leadership
  • Collaborate with HR, legal, law enforcement, and mental health teams
  • Monitor individuals of concern over time and document behavioral changes
  • Support crisis response and incident management
Top Qualifications Requested
ATAP framework Behavioral psychology knowledge OSINT techniques Security clearance (some roles) Intelligence analysis background Criminal justice or psychology background Report writing
Soft Skills Emphasized
Interpersonal communication Judgment under pressure Discretion & confidentiality
Cyber Defense Forensics Analyst
CISA, DOD, tech companies, financial institutions, defense contractors
$80K–$143K staff · clearance often required for federal
Core Responsibilities
  • Analyze log files, network traffic, and intrusion artifacts to identify perpetrators
  • Perform file signature analysis and file system forensic investigation
  • Analyze malicious code and identify obfuscation techniques
  • Support incident response teams — rapidly extract intelligence from devices
  • Preserve volatile and non-volatile digital evidence per legal standards
  • Write technical summaries and cyber defense recommendations
  • Script automation tasks (Python) for large data parsing
Top Qualifications Requested
EnCase / Sleuthkit / FTK Linux / Windows environments Python scripting MITRE ATT&CK GCFA / GCFE CompTIA Security+ Network traffic analysis Malware analysis basics TS/SCI clearance (federal)
Soft Skills Emphasized
Critical thinking Rapid analysis under pressure Team collaboration
Your UX Skills → Forensics

25 years as a UX Director gives you a formidable and underrated foundation for forensics work. Here's exactly how your skills map — and where employers will see immediate value vs. where you'll need to build.

Your UX Skill How It Transfers to Forensics Employer Skill It Matches Transfer Strength Status
Human Behavior AnalysisUX research, user psychology, behavioral flows Reading digital artifacts for behavioral intent — why files were hidden, deleted, or created in a specific pattern. This IS behavioral forensics. Cyber Behavioral Analyst, Threat Assessment, OSINT profiling
Strong
Direct Transfer
Pattern RecognitionSpotting anomalies in user flows, usage data Identifying anomalous patterns in access logs, browsing history, file timestamps, and communication sequences — the same cognitive skill, different data. OSINT Analyst, Digital Forensics Analyst, Insider Threat
Strong
Direct Transfer
Research MethodologyStructured user research, synthesis, insight generation Investigative research follows the same methodology: define question → gather data → verify sources → synthesize findings → report. Your process already maps to intelligence workflows. OSINT Analyst, Threat Assessment, all forensics roles
Strong
Direct Transfer
Communicating Complex FindingsPresenting research to executives, non-technical stakeholders Forensic analysts must translate technical findings into clear reports for legal teams, executives, and juries. This is one of the most cited soft skills employers struggle to find. All roles — report writing and testimony explicitly listed in postings
Strong
Direct Transfer
Structured DocumentationUX specs, research reports, design rationale Forensic reports must be methodical, complete, legally defensible, and reproducible — the same standard as a well-written UX research report. Chain of custody is essentially documentation discipline. Digital Forensics Analyst, CFCE certification requirement
Strong
Direct Transfer
Systems ThinkingUnderstanding how complex product ecosystems interact Forensic investigators must understand how operating systems, networks, applications, and user behavior all intersect. Your product-ecosystem thinking is directly applicable. Cyber Defense Forensics, Digital Forensics Analyst
Strong
Direct Transfer
Ethical FrameworkPrivacy, consent, responsible design, data ethics Forensics and OSINT require strict legal and ethical compliance — evidence admissibility, privacy laws, GDPR, FCPA. Your ethics-first UX approach maps directly to this mindset. OSINT Analyst (ethics explicitly listed), all forensics roles
Strong
Direct Transfer
Attention to DetailUX micro-interactions, edge cases, QA Every job posting lists this. Forensic work is detail-intensive — a mislabeled evidence file or missed timestamp can invalidate an entire case. UX directors live this already. All roles — explicitly listed in every posting reviewed
Strong
Direct Transfer
Digital Tool ProficiencyFigma, analytics platforms, prototyping tools You know how to learn complex software quickly and deeply. Forensic tools (Autopsy, Maltego, EnCase) have steep learning curves — but tool fluency itself is a transferable meta-skill. All roles requiring EnCase, FTK, Autopsy, Cellebrite, Maltego
Adjacent
Adjacent — Learn Tools
OS & Technical LiteracyGeneral computer proficiency, some dev collaboration Forensics requires deep Windows/Linux internals knowledge — file systems, registries, shell commands. You have general literacy but will need to go deeper, especially in the command line. All forensics roles — Windows artifacts, Linux environments
Partial
Adjacent — Build Depth
Scripting / AutomationLimited — not a core UX skill Multiple postings request Python for parsing large data files and automating analysis tasks. This is a gap but not a blocker for entry-level or volunteer roles — and it's learnable. Cyber Defense Forensics Analyst, senior OSINT roles
Gap
Gap — Build Over Time
Forensic Tool ExpertiseNone yet — purpose-built forensics software EnCase, FTK, Autopsy, Cellebrite — these are purpose-built forensic tools with no UX equivalent. The good news: EC-Council DFE and Blue Team Labs give you hands-on access quickly. Digital Forensics Analyst, Cyber Defense Forensics — required in most postings
Gap
Gap — Top Priority
Knowledge Gaps & How to Close Them

Based on what employers actually ask for vs. your current background. Prioritized by how quickly each gap blocks your entry into the field.

🔴 Forensic Tool Hands-On Experience
Priority 1 — Blocks entry without this
EnCase, FTK, Autopsy, and Cellebrite appear in nearly every digital forensics job posting. No equivalent in UX. Must build from scratch.
Close it with: Blue Team Labs Online (free, immediate), EC-Council DFE cert ($199, 11 labs), Trace Labs CTF events (real casework). Timeline: 3–6 months.
🔴 Windows & Linux OS Internals
Priority 1 — Core to every forensics role
File systems (NTFS, FAT32), Windows Registry, artifacts (prefetch, shellbags, event logs), Linux command line — all appear across CISA, NCTC, and NYC DA postings.
Close it with: TryHackMe Cyber Defense Path (free–$14/mo), Alison forensics diploma (free), DFIR.Science YouTube. Timeline: 2–4 months.
🟡 Chain of Custody & Evidence Law
Priority 2 — Required for formal roles, less so for OSINT
Legal evidentiary standards, admissibility, proper evidence handling procedures. Explicitly tested in the CFCE. Critical for law enforcement or legal-adjacent roles.
Close it with: EC-Council DFE certification covers this directly. John Jay Investigative Psychology also touches legal frameworks. Timeline: alongside cert work.
🟡 Behavioral Assessment Frameworks
Priority 2 — Your strongest gap-to-strength opportunity
ATAP framework, transient vs substantive threat language, structured professional judgment — the formal vocabulary of threat assessment employers use.
Close it with: ATAP free resources (atapworldwide.org), John Jay cert. This builds on your existing behavior intuition — fastest gap to close. Timeline: 1–2 months.
🟡 OSINT Tool Proficiency
Priority 2 — Required for OSINT Analyst roles
Maltego, Shodan, SpiderFoot, Google dorking, ShadowDragon — specific tools listed in OSINT job postings that have no direct UX equivalent.
Close it with: osintframework.com (free), Trace Labs CTFs (tools in context), Maltego free tier. Timeline: 2–3 months of regular practice.
🟢 Report Writing for Legal Audiences
Priority 3 — Closest to skills you already have
Forensic reports must follow specific legal standards — structured differently from UX research reports but built on the same documentation discipline you already have.
Close it with: EC-Council DFE teaches forensic report format. Review sample forensic reports from SANS whitepapers. This is your fastest win. Timeline: weeks, not months.
🟢 Python / Basic Scripting
Priority 3 — Not required at entry level, valuable later
Senior OSINT and cyber defense roles ask for Python to automate parsing of large datasets. Not a blocker for volunteer or entry-level work but worth learning over time.
Close it with: Python for Everybody (Coursera, free audit), automate simple OSINT tasks as practice. Timeline: 6–12 months, low urgency.
🟢 Professional Forensics Network
Priority 3 — Builds naturally through volunteering
Most postings emphasize collaboration with law enforcement, legal teams, and intelligence partners. OSINT hiring is heavily network-driven — referrals matter more than cold applications.
Close it with: Trace Labs events (community), AAFS conference (in-person), IACIS membership, OSINT-jobs.com. Timeline: builds through volunteer work naturally.
Bottom Line

You walk in with 8 of 12 employer-demanded skills already solid. The gaps are real but learnable — and your 25 years of behavioral thinking, structured documentation, and communicating complexity to non-technical stakeholders are genuinely rare in this field. Most forensics candidates have the tools; few have your behavioral intuition and communication depth. That's your competitive edge.

Programming Languages for Forensics

You don't need to become a developer. Forensics is investigator-first, not engineer-first. But targeted scripting literacy makes you dramatically more capable — and shows up in job postings. Here's what matters, why it matters, and the fastest path to get there. Good news: the workarounds are real and widely used by working investigators.

Recommended Learning Order
Learn First
🔴 SQL
Fastest to learn, immediately applicable. Browser history, chat logs, and mobile evidence all live in SQLite.
~2–4 weeks
Learn Second
🔴 Python
The de facto language of digital forensics. Focus only on file handling, loops, and basic automation — not full software dev.
~6–10 weeks
Learn Third
🟡 Bash
Linux is where forensic tools live. Learn 30 essential commands first — full scripting comes later if needed.
~3–5 weeks
Learn If Needed
🟢 PowerShell
Windows-specific. Only necessary if you pursue corporate incident response. Python covers most of the same ground cross-platform.
Optional
Py
Python
The de facto language of digital forensics — automates everything
Must Learn
Why It Matters in Forensics
  • Automates processing of thousands of files instead of doing it manually one by one
  • Extracts metadata from images, documents, PDFs — dates, authors, GPS coordinates embedded in files
  • Parses large log files to surface patterns and anomalies automatically
  • Powers the Volatility memory forensics framework — the gold standard for RAM analysis
  • Interacts with forensic tool APIs (Shodan, Maltego, VirusTotal) for automated OSINT collection
  • Writes custom decoders for unusual file formats encountered in cases
  • Automates timeline reconstruction from fragmented digital artifacts
Real Forensics Use Cases
  • Evidence triage: scan 50,000 files and flag only those matching known patterns
  • Browser forensics: extract Chrome history, cookies, downloads from SQLite databases
  • Image metadata: pull GPS, device info, timestamps from photos in bulk
  • OSINT automation: query public APIs and compile subject profiles automatically
  • Memory analysis: run Volatility plugins to find running processes and injected code
  • Report generation: auto-build structured forensic reports from raw data output
  • Network forensics: parse packet captures with Scapy to identify anomalies
Free
Python for Everybody — Specialization
University of Michigan via Coursera
The most beginner-friendly Python course available. File handling, data structures, and databases. Audit free — pay only for certificate.
coursera.org/specializations/python →
Free
Python Digital Forensics Tutorial
TutorialsPoint
Forensics-specific Python from day one — evidence integrity, metadata extraction, smartphone forensics. No detour through general programming.
tutorialspoint.com →
Free
The Python Code — Forensics Tutorials
thepythoncode.com
Practical recipes: extract browser data, recover deleted files, analyze document metadata, discover saved Wi-Fi networks. Hands-on from the first lesson.
thepythoncode.com →
~$15–20
Python Digital Forensics
Udemy (Packt)
Network forensics, host analysis, memory analysis. Windows and Linux environments. No prior experience required. Watch for Udemy sales — often under $20.
udemy.com →
SQL
SQL
Unlocks the databases hidden inside every device and application
Must Learn — Fastest Win
Why It Matters in Forensics
  • Virtually every major app stores its data in SQLite databases — including deleted records that tools miss
  • Browser history (Chrome, Firefox, Safari) is a SQLite file — queryable directly
  • WhatsApp, Signal, and most messaging apps store messages in SQLite
  • Cellebrite mobile extractions output data in SQL-queryable format
  • Explicitly requested in OSINT analyst job postings alongside Maltego and Shodan
  • Lets you ask precise questions of evidence: "Show me all messages sent after 11pm between these two contacts"
Real Forensics Use Cases
  • Browser forensics: query Chrome's History.db for visited URLs, search terms, timestamps
  • Chat app analysis: extract WhatsApp or Signal message history directly from the database
  • Mobile forensics: query Cellebrite extraction databases for call logs, contacts, location data
  • Deleted record recovery: SQL can surface records that GUI tools mark as "deleted" but remain in the DB
  • Timeline building: JOIN tables across multiple app databases to reconstruct a subject's full day
  • OSINT data management: store and query large collected datasets during investigations
Free
SQL for Data Science
UC Davis via Coursera
Highly rated beginner SQL course. Covers SELECT, JOIN, WHERE, subqueries. Audit free. Takes 4–5 weeks at a relaxed pace.
coursera.org →
Free
Tools of the Trade: Linux and SQL
Google Cybersecurity Certificate, Coursera
SQL taught directly in a cybersecurity context — exactly the framing you need. Covers Linux basics simultaneously. Free to audit.
coursera.org/learn/linux-and-sql →
Free
SQLiteOnline.com
SQLiteOnline.com — browser-based practice
Run SQL queries directly in your browser against real SQLite databases — zero setup. Perfect for practicing forensics queries on sample browser history files.
sqliteonline.com →
Free tool
DB Browser for SQLite
sqlitebrowser.org — free GUI tool
A free GUI that lets you open and explore SQLite databases visually — like Excel for databases. Used by forensic investigators who prefer not to write raw SQL.
sqlitebrowser.org →
$_
Bash / Linux Command Line
The environment where forensic tools actually live — learn to navigate it
Learn Commands First, Scripting Later
Why It Matters in Forensics
  • Linux is the OS of professional forensic analysis environments — SIFT Workstation, Kali, REMnux all run on Linux
  • Forensic tools like Volatility, Autopsy, log2timeline, and The Sleuth Kit are command-line first
  • Lets you chain forensic tools together in automated pipelines without writing full scripts
  • Process large disk images, extract specific files, and filter evidence at the command line
  • Essential for navigating the SIFT Workstation — the free forensic lab environment you'll use for practice
  • grep, find, and awk let you search massive evidence sets in seconds
Real Forensics Use Cases
  • SIFT Workstation navigation: mount disk images, run tools, export results — all via command line
  • Log analysis: use grep to search 100,000 log lines for a specific IP, username, or timestamp
  • File system exploration: navigate and map directory structures of seized device images
  • Volatility memory forensics: run plugins to list running processes, network connections, injected code
  • Bulk hash verification: verify integrity of an entire evidence set with a single command
  • TryHackMe labs: nearly every hands-on forensics lab runs in a Linux terminal
Free
OverTheWire: Bandit
overthewire.org
The best gamified Linux command line learning available. Solve puzzles by navigating a real Linux system via SSH. Addictive, hands-on, and completely free. Start here.
overthewire.org/wargames/bandit →
Free (audit)
Tools of the Trade: Linux and SQL
Google Cybersecurity Certificate, Coursera
Covers Bash in a security context — file navigation, user management, grep, and more. Part of Google's well-structured cybersecurity certificate. Free to audit.
coursera.org/learn/linux-and-sql →
Free
The Linux Command Line (book)
William Shotts — free online
The definitive beginner Linux book, available free online. Read chapters 1–10 for everything a forensic investigator needs at the command line.
linuxcommand.org →
Free
SIFT Workstation — Free Forensic Lab
SANS Institute
Free Ubuntu-based virtual machine pre-loaded with Autopsy, Volatility, log2timeline, and 40+ forensic tools. Your practice lab — and the environment the GCFA exam uses.
sans.org/tools/sift-workstation →
PS
PowerShell
Windows-specific scripting — situationally useful, not a priority for your path
Optional — Learn If You Pursue Corporate IR
Why It Matters in Forensics
  • Windows is the dominant OS in corporate forensics investigations — and PowerShell is Windows' native scripting tool
  • Extract and query Windows Event Logs, Registry keys, and prefetch files programmatically
  • Automate Windows-based incident response tasks across multiple machines simultaneously
  • Relevant specifically for insider threat and enterprise incident response roles
  • Many corporate security teams use PowerShell playbooks for standardized investigation workflows
Real Forensics Use Cases
  • Windows artifact extraction: pull prefetch files, event logs, and scheduled tasks via script
  • Registry analysis: query Registry hives to find persistence mechanisms or user activity
  • Incident response automation: collect volatile data from live Windows systems quickly
  • Log correlation: pull and filter Windows Security Event Logs across an enterprise
  • NTFS analysis: enumerate file system metadata including timestamps and alternate data streams
Free
Microsoft Learn — PowerShell
Microsoft (learn.microsoft.com)
Microsoft's own free learning path for PowerShell. Structured modules from absolute beginner to automation. Official, well-maintained, and completely free.
learn.microsoft.com →
Free
TryHackMe — Windows Forensics Rooms
TryHackMe
Hands-on labs combining PowerShell and Windows forensics. Learn by investigating real scenarios — Registry analysis, event logs, prefetch artifacts.
tryhackme.com →
~$49
PowerShell for IT Security Professionals
Coursera / various
Security-focused PowerShell covering automation, event log analysis, and incident response scripting. Only pursue this if you've committed to a corporate IR path.
coursera.org →
Your Realistic Starting Point

Start with SQL in week one — open a Chrome browser history file in DB Browser for SQLite and query it. You'll immediately see why it matters. Then layer in Python basics alongside your forensics course work, using the forensics-specific tutorials so every script you write is directly useful. Bash comes naturally once you're running SIFT Workstation labs. None of this requires becoming a programmer — it requires becoming an investigator who isn't afraid of a terminal window.

Forensics Apps    Side-by-Side

Primary use, individual cost model, and platform-specific download links. Mac and PC kept in separate columns — you are Mac-only now but PC info is here for future reference. Pricing reflects 2026 practitioner data.

App Primary Use Cases Cost — Individual   macOS (Your Setup Now) ▩  Windows (Future Reference)
Autopsy
Basis Technology
Completely Free
macOS Windows Linux
⭐ Primary practice tool. Free, court-accepted worldwide.
What It Does
  • Disk image analysis — examine hard drives, SSDs, USB drives from forensic images
  • Deleted file recovery — surface files removed from the file system
  • Web artifact extraction — browser history, cookies, downloads
  • Keyword search across entire disk images
  • Timeline analysis — visualize file activity over time
  • Windows Registry analysis — user activity, persistence, artifacts
  • Hash filtering — flag known bad files using NIST hash sets
  • Used by tens of thousands of law enforcement investigators worldwide
Cost Model
  • 100% free — open source, Apache 2.0 license
  • No trial, no feature limits, no subscription
  • No registration required
  • Community-supported via GitHub and Sleuth Kit forums
  • Accepted in court proceedings globally
  • Enterprise multi-user version is paid — the solo version is complete
 Mac Download & Notes
  • Mac version exists but needs manual setup via Homebrew
  • Requires Homebrew + Liberica JDK 8 + The Sleuth Kit compiled from source
  • Some features (Timeline tool) have limited Mac support
  • Easiest Mac path: install free UTM VM app and run Autopsy inside Ubuntu — more stable and how many Mac forensic practitioners work
▩ Windows Download & Notes
  • Windows is the primary and best-supported platform
  • One-click .msi installer — no manual setup required
  • All features fully functional including the Timeline tool
  • Recommended: 64-bit Windows 10/11, 16 GB+ RAM
FTK
Exterro (formerly AccessData)
Paid — Enterprise
Windows
Know what it is. Use Autopsy instead. Get FTK Imager free for imaging.
What It Does
  • Enterprise disk forensics — commercial alternative to Autopsy for large agencies
  • Pre-indexing — indexes all data upfront so searches run instantly
  • E-discovery — legal document review and evidence management
  • Multi-core processing — fully leverages modern hardware for speed
  • Mobile + disk integration — unified case files across sources
  • FTK Imager (free, separate) — creates forensic disk images only, no analysis
  • Used by FBI, DoD, major law firms, and corporate security teams
Cost Model
  • Perpetual license: ~$3,995 + $1,119/year support
  • Subscription: ~$2,227/year or ~$65/month per user
  • No meaningful free version — limited trial only
  • FTK Imager: free (imaging only, no analysis)
  • Designed for agencies and firms — not individual purchase
 Mac Notes
  • FTK Imager: Windows only — no Mac version exists
  • Full FTK is also Windows-only
  • Mac alternative: Magnet ACQUIRE — free, Mac-native forensic imaging with SHA-256 hash verification
  • Skills built in Autopsy transfer directly to FTK workflows
▩ Windows Download & Notes
  • Full FTK: contact Exterro for enterprise quote
  • FTK Imager: free Windows download — the most useful free component
  • Creates forensically sound E01/raw images with hash verification
  • Standard imaging tool used across most forensic labs
Cellebrite
Cellebrite DI Ltd.
$6K–$20K+/year
Windows + Hardware Unit
Understand conceptually. Not a personal purchase. Not Mac-native.
What It Does
  • Mobile device extraction — dominant platform for iOS and Android data
  • Physical extraction — bit-for-bit copy including deleted files and encrypted partitions
  • Locked device bypass — proprietary exploit research for encrypted phones
  • Cloud acquisition — iCloud, Google Drive, app cloud backups
  • Cellebrite Reader (free) — view UFED extraction reports, no extraction capability
  • Used by law enforcement, immigration, border security, and national security agencies globally
Cost Model
  • UFED full suite: $6,000–$20,000+/year
  • Annual renewal required — no perpetual option
  • Training: additional $2,000–$5,000 per analyst
  • 3-year single-license cost: ~$45,000
  • Pricing not published — requires a sales quote
  • Cellebrite Reader: free (view reports only)
 Mac Notes
  • UFED: Windows + hardware unit — not Mac-native
  • Cellebrite Reader is primarily Windows-focused — no stable Mac version
  • Best Mac alternative for mobile database analysis: DB Browser for SQLite — directly query WhatsApp, Chrome, and Signal databases
  • For your OSINT and behavioral forensics path, DB Browser covers what you realistically need
▩ Windows Download & Notes
  • UFED software runs on Windows — contact Cellebrite for quote
  • Cellebrite Reader: free Windows download — see extraction report formats
  • Worth downloading on a Windows machine for format familiarization
DB Browser for SQLite
sqlitebrowser.org — Open Source
Completely Free
macOS Windows Linux
⭐ Download today — open Chrome history in 5 minutes.
What It Does
  • Browse SQLite databases visually — like Excel for database files
  • Browser forensics — open Chrome, Firefox, Safari history files directly
  • Chat app analysis — view WhatsApp, Signal, iMessage databases
  • Mobile evidence — query app databases extracted from devices
  • SQL queries without the command line — visual or code
  • Surface deleted records — SQLite retains deleted rows until overwritten
  • Works with any SQLite output from Autopsy or Cellebrite extractions
Cost Model
  • 100% free — open source, no licensing
  • No premium tier, no paid features, no registration
  • Available for Windows, macOS, and Linux
  • Actively maintained — regular updates for latest OS versions
  • Fully standalone — no other software required
 Mac Download & Notes
  • Native macOS .dmg — drag to Applications, done
  • Works on Intel and Apple Silicon Macs with no compatibility issues
  • Also via Homebrew: brew install db-browser-for-sqlite
  • Try now — open your Chrome history at:~/Library/Application Support/Google/Chrome/Default/History
▩ Windows Download & Notes
  • Windows .exe installer available — same site, same features
  • Also via winget or Chocolatey package managers
  • Identical functionality to Mac version
  • Try with Chrome history at:C:\Users\[user]\AppData\Local\Google\Chrome\User Data\Default\History
 Download Today (Mac)
DB Browser
Native .dmg. Free. Open Chrome history in 5 minutes.
 Set Up This Week (Mac)
Autopsy
Free. Homebrew setup or easier: UTM + Ubuntu VM.
 Mac Imaging Alternative
Magnet ACQUIRE
Free. Mac-native replacement for FTK Imager.
Understand Conceptually
FTK + Cellebrite
Enterprise only. Windows-only. Know what they do — don't buy them.
Certifications    Worth Pursuing

Two tracks worth building toward — OSINT-specific credentials for investigative work, and the broader digital forensics pathway already anchoring your CFCE plan. Treat this as a menu, not a checklist — practical experience still outweighs holding certificates, per Dr. Lee.

OSINT‑Focused Open Source Intelligence Certifications
Foundational · Most Recognized
GIAC GOSI — Open Source Intelligence
The most industry-recognized dedicated OSINT credential. Covers OSINT methodology, privacy/OPSEC fundamentals, and searching, collecting, and processing data at scale. Tied to the SANS SEC497 course (36 hrs, 29 hands-on labs).
~$7,020 w/ course GIAC · SANS
giac.org/certifications/gosi
Advanced
GIAC GSOA — Strategic OSINT Analyst
Advanced skills: automating investigations with Python, analyzing data at scale, dark web and cryptocurrency tracing, and social platform investigations. A natural next step after GOSI or real field experience.
Premium tier GIAC · SANS
giac.org/certifications/gsoa
Affordable Starting Point
TCM Security — Practical OSINT / OSINT Python
Hands-on, methodology-first training at a fraction of GIAC's cost. Practical OSINT covers the foundations; the OSINT Python certification layers in automation for scaling investigations.
~$30 entry course TCM Security
academy.tcm-sec.com
Board Certification
C|OSINT — Certified in Open Source Intelligence
Billed as the first globally recognized, accredited board certification specifically in OSINT — a different model from GIAC's SANS-course-tied approach. Worth a closer look before committing.
Verify current cost & provider
Your Existing Pathway Digital Forensics Certifications
Entry Point
EC-Council DFE — Digital Forensics Essentials
Your planned first step. Free training modules with an affordable certification exam — the standard low-cost entry credential into digital forensics.
$199
Target Credential
IACIS CFCE — Certified Forensic Computer Examiner
The practitioner "gold standard" you've been building toward, via IACIS's BCFE training pathway. Widely respected across both law enforcement and private consulting.
$2,500–$4,000 IACIS
Alternative / Complement
GIAC GCFE — Certified Forensic Examiner
SANS-affiliated forensic examiner credential. Well-respected, but priced and structured like GOSI — worth comparing against the CFCE pathway rather than assuming you need both.
Premium tier GIAC · SANS
Resources    Books, Podcasts & Newsletters

A reading and listening list to build fluency alongside the coursework — books and the podcast recommended directly by Dr. Hannarae Lee (BSU), plus a few well-regarded additions from the wider OSINT community.

Recommended by Dr. Lee Books & Podcast
Book
Deep Dive
Rae Baker — a practitioner-written, hands-on guide to OSINT investigation from one of the field's well-known voices.
Book
OSINT Techniques: Resources for Uncovering Online Information
Michael Bazzell & Jason Edison — the field's most comprehensive practical reference, updated regularly as tools and platforms change.
Book
Extreme Privacy
Michael Bazzell — the flip side of investigation: how people disappear from the same data you'd be searching. Useful for understanding both sides of the same coin.
Podcast
DFIRL — Digital Forensics in Real Life
Practitioner conversations grounded in real casework, not just theory.
Additional Finds Widely-Followed Community Resources
Podcast
The OSINT Curious Project
Community-run hub of the OSINT world — interviews veteran practitioners on tactics, techniques, and how they broke into the field. Companion blog and instructional videos too.
osintcurio.us
Podcast
The Privacy, Security & OSINT Show
Michael Bazzell's weekly podcast — pairs naturally with his two books already on your list.
Podcast
Breadcrumbs, by Trace Labs
Techniques and tools discussion straight from the organization behind the CTF events already on your volunteer entry-point plan.
Newsletter
Sector035 — Week in OSINT
A curated weekly roundup of OSINT talks, tips, tools, and techniques, published every Monday. Widely considered the field's benchmark newsletter.
sector035.nl
Blog / Toolkit
Bellingcat's Online Investigation Toolkit
Free, continuously updated, and cited constantly across the field — deep dives into specific verification and geolocation techniques.
bellingcat.com/resources