Red Herrings builds realistic, randomized forensics labs from one scenario: unique evidence, a worksheet, an answer key computed from that evidence, and a rubric, for every single student. Labs cannot be copied between students or reused across semesters.

Realistic artifacts that open in the tools your students already use, and a verification pass that proves every answer is really there.
Disk images, registry hives, EVTX logs, Prefetch, LNK and jump lists, Chrome and Firefox history, email, memory exports and mobile databases, in the real on-disk formats.
After generation, every artifact is re-opened with an independent parser and every answer is confirmed present. No hand-waving: if it is on the key, it is in the evidence.
Names, timestamps, hashes, IPs and answers differ per student from a single seed. Same seed and roster reproduce the exact same labs on any machine.
Import a student's answers and score against their variant with sensible tolerances: hashes case-insensitive, timestamps within seconds, text fuzzy-matched with a review flag.
See, per question, how many distinct answers were handed out, and which student pairs look most alike. Copied answers stand out.
One Settings screen rebrands every screen and every document: your name, logo, colors and footer. Or strip the branding entirely.
Local software. No hosting, and no runtime network call. Double-click to launch; it opens in your browser.
Five are included; build your own in the visual editor or install a pack.
A number of students or a roster CSV, a difficulty, and a seed.
Per-student evidence, worksheet, answer key and rubric, verified as it goes.
One zip per student, an instructor package, and a built-in grader.
Each has 8 to 15 questions across easy, medium and hard, with points and per-tool answer walkthroughs.
USBSTOR device history, shortcuts to a removable drive, an archiving tool, and a staged archive on disk.
A spoofed email with a real Received path, a downloaded payload, persistence, and a remote-controlled process in memory.
Tool staging, a new admin account, a persistence service, and a cleared Security log to work around.
A web shell in the web root, the worker process spawning commands, and a second-stage agent reaching out.
Browser history, searches and a data export, plus a phone extraction with incriminating messages.
The visual editor validates live and previews a resolved answer key. Export a pack to share or sell.
Buy per instructor for teaching, per seat for business. A 14-day free trial, no card required.
Prices are placeholders for launch planning and are subject to change. Scenario packs are available as add-ons.
No. Generation and grading run entirely on your machine with no network call. The only time the software contacts a server is to activate, refresh or deactivate a license, when it sends just the license key, a derived machine id, the hostname and the app version. Air-gapped labs activate offline.
After generating each lab, Red Herrings re-opens every artifact with an independent parser (The Sleuth Kit, python-registry, python-evtx and others) and confirms each answer is present in the evidence. The result is the green "Fresh Catch" checklist. Answers are computed from the generated evidence, never hard-coded.
The evidence is written in real on-disk formats, so it opens in Autopsy, FTK Imager, Registry Explorer, EvtxECmd, PECmd, JLECmd, Volatility-style workflows, and standard SQLite and email tools.
Yes. The visual editor validates live and previews a resolved answer key, so you can see exactly what a student will get. Export a pack to share or sell it.
Yes, with a white-label license. One setting rebrands every screen and document with your institution or company identity.