Notepad++ Hands-on Labs¶
Choose a lab¶
Choose the Interactive Lab for a short, guided browser exercise. Try the Full Lab after reviewing the tool guide and preparing an isolated, authorised environment.
- Recommended first
- No installation
- Short guided scenario
- Isolated lab required
- Independent decisions
- Evidence or analyst outcome
How to use these labs
Start with the browser-based route to practise the workflow and evidence decisions without touching a real system. Use the Full Lab only in an isolated, authorised environment, and compare its outcome with the corresponding tool guide.
Interactive Lab¶
Notepad++ Interactive Lab
Practise a guided Notepad++ workflow in a safe browser simulation with immediate feedback.
- 1Source
- 2Configure
- 3Review
- 4Explain
Choose the authorised, traceable source
The case question is bounded. Select the item that preserves scope and provenance.
Select a source to continue.
Task or value
Do this nowEnter the requested value, then select Run task. Open the guided hint if you need an exact example.
Guided hintUse the labelled working-output name from the brief.
Enter the acquisition command, then run the simulation.
Identify the result that answers the case question
Inspect the host, output, expected size and integrity fields. A completed tool run is not automatically a finding.
| Input | Operation | Output | Integrity |
|---|---|---|---|
| Working copy | Focused task | case-014-output.csv | Source retained |
| Background activity outside the case window | |||
Select the row that should be preserved for analysis.
Choose the conclusion supported by the result
Separate the acquired evidence from interpretation and state the next analytical step.
Full Lab¶
Notepad++ Full Lab
Hands-on DFIR proof of concept
Prepare it. Examine it. Explain it.
Use Notepad++ to search structured text output and save a clearly labelled working note, retain the evidence trail and write a bounded finding another analyst can review.
Safety boundary
Keep original, working, and derived material separate. Treat links, archives, and files as untrusted when appropriate.
clearly labelled working copies and a separate controlled output directory
a reproducible supporting result with input, transformation, output, and integrity context
Recommended first
Beginner Core Lab¶
Complete one bounded Notepad++ workflow using the documented source, settings and expected result.
Optional extension
Add a comparison¶
After the core succeeds, repeat the same focused task with one controlled change and explain the difference without widening the authorised scope.
Full Lab scenario¶
You are the first analyst reviewing a bounded training case. Your task is to search structured text output and save a clearly labelled working note. The result must be understandable to a second analyst who did not watch you perform the work.
01
Activity 1: Prepare the environment¶
- Record the case question, authority and the identity of the isolated training system or evidence source.
- Record the Notepad++ version, provenance, system time and time zone.
- Identify the original material, working location and separate output destination. Confirm that there is enough free space.
- Take or verify a recoverable baseline before changing the training system.
02
Activity 2: Complete the focused task¶
- Restate the investigation question and select only the settings or commands required to search structured text output and save a clearly labelled working note.
- Follow the preserved Notepad++ guide and record any necessary difference in paths, labels or version-specific behaviour.
- Record start and finish times, relevant settings, completion status, warnings and errors.
- Preserve the returned output and keep it attributable to its source and collection context.
03
Activity 3: Review and report¶
- Work from an identified copy and confirm a reproducible supporting result with input, transformation, output, and integrity context.
- Separate direct tool observations from analyst interpretation. Record missing fields, unavailable material and alternative explanations.
- Preserve relevant integrity information, settings or commands and the evidence needed for another analyst to reproduce the result.
- Write a bounded conclusion with observation, interpretation, confidence and limitations, then clean up the disposable environment.
Full Lab evidence checklist¶
This checklist applies to the self-hosted Full Lab. If you completed the Interactive Lab, retain its browser evidence summary instead.
-
Core completion¶
Required to demonstrate a safe, attributable workflow.
-
Good analyst practice¶
Supplementary records that improve reproducibility and review quality.
Clean up¶
Protect retained output and case notes, remove harmless training material, clear temporary credentials or access and restore disposable systems to their recorded baseline. Confirm that no test collection remains active.