
New Forensics Certification from Blue Cape Security? I Got It — Here Is My Review.
Hello everyone, it's me Chicken0248 with a review of the first-ever forensics certification exam from Blue Cape Security: the Practical Windows Forensic Analyst (PWFA). This exam was announced in August 2025 and has a very unique format: one that requires you to apply your Windows forensics methodology to the fullest to pass.

Blue Cape Security is a well-known blue team training and consulting company. It offers several packages:
- Analyst I ($697): includes the 201 Practical Windows Forensics (PWF) course, 4 forensic investigation scenarios (FOR200), and 2 PWFA exam attempts
- Analyst II ($997): includes the 301 Advanced DFIR course and 3 Advanced DFIR investigation scenarios (IR300). This package does not include the PWFA exam, though it's possible Blue Cape Security will release an advanced certification down the road, but that's just my guess ¯\_(ツ)_/¯
- Hero Bundle ($1,297): includes everything in Analyst I and Analyst II, plus the 101 Enterprise Security Fundamentals course
I only purchased the Analyst I package during a discount, so I'll be reviewing the PWF course, the FOR200 labs, and the exam. Let's see what this package has to offer.

Analyst I is also known as the Core Forensic Track. It comes with 12 months of on-demand access to the course and 150 hours of lab access. Once you purchase it, the 12-month access timer starts immediately.

Here is the pathway Blue Cape Security lays out for you: start with the PWF course to learn the fundamentals, then apply your knowledge through the FOR200 investigation scenarios, and finally validate your skills in the PWFA exam. It's a clean, logical progression, and I'll cover each step in that order.
R U READY? LET'S GO.


The PWF course is designed to teach the fundamentals of Windows forensics. It starts with the data collection process (how to acquire and triage disk images with KAPE) then walks through key Windows forensics artifacts, timeline construction, and a brief introduction to report writing. You can read the full syllabus here: course syllabus (Google Sheets).
The majority of the course is video-based, recorded by Markus Schober, the CEO of Blue Cape Security, and likely the face you'll be most familiar with from this company.
The course is excellent for absolute beginners who want to learn Windows forensics. It covers what each key Windows artifact does without going too deep, and teaches you how to parse them with free, industry-recognized tools and interpret the results. That said, it does move quickly through certain areas.

Many topics include extra resources at the bottom of each video under a "Further Reading" section for those who want to go deeper into each artifact's background. I highly recommend taking the time to read them. They're great.

The course also includes labs you can follow along with for each topic, accessible entirely in your browser: no extra tools or VM required. One thing I don't love is the time limit: you have to extend your session every hour, and if you don't finish in time you'll need to relaunch the instance. (I haven't tested whether in-progress work is fully lost on relaunch.)
What I do like is the Stop feature, which lets you pause your running lab and have all parsed artifacts preserved when you resume it later.
One more thing worth mentioning: the course includes a Windows Forensics cheat sheet covering all the key artifacts taught throughout. It's a handy reference, and it'll also come in useful during the PWFA exam itself. 😄
Honestly, I did pick up a few fundamentals I'd been glossing over for years. But the course got a bit repetitive for me since I was already familiar with most of the artifacts and tools. The report writing module was also quite vague: I was expecting something closer to an industry-standard forensics report, but it's only briefly touched on.
The evidence acquisition section is similarly surface-level, covering FTK Imager for full disk and memory images, and VM acquisition. Alternative tools and methods aren't discussed, so you'll need to research those on your own.
If I had to score it: 4.5 ⭐ / 5 ⭐ for complete beginners, and 2 ⭐ / 5 ⭐ for seasoned analysts. In my opinion, experienced analysts should skip straight to a more advanced course.
Now let's talk about the FOR200 investigation scenarios.

The FOR200 Investigation Scenarios are lab-based forensic cases designed to let you practice Windows forensics skills and methodology. There are four scenarios in total.

The difficulty varies across scenarios (from Beginner to Advanced) and all labs are browser-accessible, just like the PWF course.

All artifacts from all four scenarios are accessible from the same shared directory, so you can effectively work through every scenario from a single VM instance. You just need to keep extending your session each hour.
The lab instances run very smoothly: no lag or freezing in my experience. A stable internet connection is all you need to work comfortably and practice your timelining.
One important note on difficulty order: despite the numbering, FOR001–FOR004 don't scale in difficulty sequentially. If you want to go from easier to harder, I recommend: FOR004 → FOR001 → FOR002 → FOR003.
Since the PWF course covers disk and memory image analysis, each scenario provides a full disk image, a full memory dump, or both, depending on the case. Some scenarios have multiple systems. Getting comfortable with all of these is essential preparation for the PWFA exam.

Each scenario is structured as its own course. You'll receive a case brief, conduct your analysis, then complete a quiz to confirm your findings. (Blue Cape Security uses their course platform for everything, the exam included.)
Blue Cape Security also encourages you to build your own timeline and perform independent analysis. They provide a reference timeline and summary report for comparison afterward, which is a genuinely valuable learning tool. That said, don't treat their version as the absolute ground truth: some artifacts are intentionally omitted to keep the timeline readable.

I recommend downloading the timeline provided in FOR004, keeping only the header row, and using it as your template for building your own timelines. Once you're done, compare your version with theirs to see what you may have missed: it's a great way to reinforce your learning.
For real-world incidents involving multiple analysts, the CrowdStrike DFIR tracker is a solid option: CrowdStrike DFIR Tracker.

At the end of each scenario, Blue Cape Security provides walkthrough videos recorded by Markus himself, a great resource to validate your findings and methodology before sitting the exam.
I made a significant mistake here that you should avoid: I only completed one lab and never practiced building a proper timeline. That meant I had to figure out Blue Cape Security's preferred timeline format during the actual exam, which made my experience considerably harder than it needed to be. Learn from my mistake.

Before moving on to the exam, note that you'll earn a badge and certificate for passing the quiz in each scenario. Collect them all and post them on LinkedIn to show what you can do!

After purchasing the Analyst I package, three courses are added to your account: the PWF course, FOR200, and the Analyst I Training Track, which acts as a pre-exam checklist and the gateway to the exam itself. You can review the exam overview, requirements, and grading and retake policy in Section 3 of this course before starting.
Originally, I planned to take the exam in the same month I purchased it: I assumed, incorrectly, that the deliverable would be a report similar to the HTB CDSA exam. Once I realized the submission is a timeline in XLSX format (DOCX is technically accepted but XLSX is preferred), I postponed until late September and started the exam then.

At launch, you had to book an exam slot in advance, but that requirement has since been removed. You can now start the exam at any time. Once started, you're enrolled in a dedicated exam course where you'll find the core logistics, the tools list, submission requirements, technical requirements, the grading breakdown, a lab VM, the case scenario, and your exam objectives.

A confirmation email is also sent to remind you of everything you need to deliver. As you can see, I started the exam during my lunch break on Monday, 30th September. I read through everything carefully to understand the deliverables and all exam objectives, then launched the lab VM and started parsing artifacts while building my initial hypothesis. I then wrapped up for the rest of the workday.
In the evening, I worked through each artifact methodically. But as I mentioned earlier: I hadn't practiced building a timeline before the exam, and that caught up with me. I spent most of the night struggling with the format until I settled on an approach: add every relevant entry, keep only what's tied to the incident, group supporting artifacts together, sort chronologically to see the full picture, and repeat until it's coherent.

I spent the whole night completing my timeline, then submitted a first draft through the assignment section of the exam course. (Blue Cape Security uses their platform's assignment feature as the submission form.) After submitting, you'll receive another email confirming receipt. Importantly, grading only begins after the 7-day exam window closes, and you can retract and resubmit a revised timeline at any point before then.
I took a vacation day to recover from the sleepless night, but when I woke up I realized the exhaustion had caused me to miss several important pieces of evidence. I retracted my submission, filled in the gaps, and rested. The following day I planned to do a thorough final review, but work completely overwhelmed me, and I couldn't focus at all. At that point I just wanted it to be over, and submitted my timeline with barely enough technical analysis to pass.

On grading: you need at least 70% to pass. Your score comes from two parts: technical analysis (66%) and timeline quality (33%). The analysis carries significantly more weight, so you need to show your reasoning clearly, not just list events. Score above 85% and you'll receive the exclusive PWFA challenge coin + swag, plus an additional line on your certificate.

I expected to receive results the week after my exam window closed, but I actually got the email on Friday: they may have noticed I had already submitted and graded it early. Either way, I was fine with that.
As you can see, I performed well on the timeline portion but scored poorly on technical analysis, which was expected given how I'd rushed it. That gap cost me the challenge coin, but honestly, if I were in the same situation again, I'd still submit the same report. At least it was over. 😄

The result email included a link to my digital certificate, along with the option to order a printed version directly from the same service.

After I posted my result on LinkedIn, Markus congratulated me in the Blue Cape Security Discord and encouraged others to try the exam as well. I genuinely appreciate this kind of community culture: it's the same vibe as CyberDefenders, where the community rallies around certified members and encourages others to give it a go.
- Familiarize yourself with timeline building. Use the FOR200 scenarios to practice your timelining before exam day: this is the single most important thing you can do.
- Don't be lazy like me 😄: explain in detail what the threat actor did, based on your timeline, and present it as fact. No guessing.
- Try sketching a quick flowchart by hand to understand what happened. It helps you see the big picture instead of keeping everything in your head, which will overwhelm you fast.
- Read the exam objectives carefully. Your analysis and timeline need to address them directly.
- Don't rush to write your summary first. Build out the relevant timeline entries first, then analyze what happened: this keeps you from tunnel-visioning on incomplete parts of the picture and losing the big picture.
- You have 7 days. Don't hurry to submit. Submit when your timeline is complete (or near-complete), and plan your week so you balance your day job and exam time effectively.
- Treat the exam like another FOR200 scenario, just another Monday. The exam is not hard and is beginner-friendly, but you need to see the whole picture to reach the right conclusion.
That's it for today, I hope you enjoyed it. Peace out~ ✌️