AX280 Enterprise Remote Endpoint Investigations

Remote collection isn't a lecture topic — it's a skill you develop. This course is engineered from the ground up around live, hands-on acquisition. Rather than working from static disk images, students target real, running endpoints across Windows, macOS, and Linux — the same way as in the field. Every module pairs concept with practice, providing the ability to perform remote collections and not just describe them.

Description

Remote collection isn't a lecture topic — it's a skill you develop.

This course is engineered from the ground up around live, hands-on acquisition. Rather than working from static disk images, students target real, running endpoints across Windows, macOS, and Linux — the same way as in the field. Every module pairs concept with practice, providing the ability to perform remote collections and not just describe them.

A realistic, evolving investigation

The course is built around a unified investigative scenario that grows with you. Each module introduces a new employee of interest, layering in fresh background and evidence, then puts you to work investigating them using the remote collection techniques you've just learned. Purpose-built user accounts and curated artifacts are staged on the target systems, giving you authentic "subjects" to acquire and analyze at every stage. The modular design means the scenario stays fresh and current — and consistently relevant to real-world enterprise investigations.

Built for true hands-on learning

To make live, in-classroom remote acquisition possible, each mobile lab is equipped with a dedicated wireless access point — enabling students to create, deploy, and run collection agents against one another's machines across realistic network configurations. The course supports in-person, classroom, and virtual delivery, including cloud-based lab environments where each student works in their own isolated VM.

What to expect

The ability to plan and execute remote collections across Windows, macOS, and Linux; confidence navigating segmented enterprise networks; fluency with Axiom Cyber, Magnet Nexus, Hybrid agents, and Magnet Response; and the troubleshooting instincts that separate practitioners who understand remote acquisition from those who can actually do it.

Course modules

Module 1: Course Introduction & Lab Environment

  • Orientation to the course, the investigative scenario, and the hands-on lab setup.

 Module 2: DFIR Concepts for Remote Acquisition

  • The core principles and decision-making behind modern remote collection.

Module 3: Axiom Cyber Architecture & Workflow

  • A fully hands-on tour of creating, managing, and deploying remote collection agents across Windows, macOS, and Linux using Axiom Cyber.

Module 4: Windows Endpoint Collection

  • Students deploy an agent and run a targeted collection against their own machine, then process and review the artifacts in Axiom Cyber — building core skills with no network complexity to distract.

Module 5: Remote Collection Fundamentals

  • Working in teams across a shared private network, students deploy agents and collect from one another's endpoints, putting the full remote workflow into practice.

Module 6: Network Collection: Windows Endpoint via Axiom Cyber Agent.

  • Grounded in the realities of network segmentation, DNS, IP addressing, firewall rules, and authentication, students perform cross-VLAN collections by hostname and develop the connectivity troubleshooting skills that define real-world remote acquisition work.

Module 7: Magnet Nexus & Hybrid Agents

  • A closer look at Nexus, including creating cases, generating agents, and watching collections come to life as agents call home.

Module 8: Network Collection: macOS via Nexus Agent

  • Extending remote collection to macOS endpoints using the Nexus agent.

Module 9: Network Collection: Linux Endpoint via Hybrid Agent

  • Acquiring from a Linux target populated with scenario data, including coverage of MCAG/UCAG collection approaches.

Module 10: Magnet Response & Triage Lab.

  • Where Response fits in the toolkit, when to use it, and how it complements Axiom Cyber and Nexus — with a hands-on lab running Response, reviewing artifacts in Examine, and validating the collection.

Module 11: Automation & Wrap-Up

  • Automating remote agent deployment through EDR/SOAR workflows and base-image integration, leveraging Magnet Response within EDR alert response, and best practices for collection decision-making and avoiding over-collection.

Module 12: Capstone Exercise.

  • A segmented, hands-on challenge that reinforces every skill from the week — and serves as a take-home practice resource to keep building after class.

Additional information

Who should attend: Participants who are unfamiliar with the principles of digital forensics
Advanced preparation: None
Program level: Intermediate 
Field of study: Computer software & applications
Delivery method: Group live & Group internet based

Refunds and cancellations: Training Course(s) can be rescheduled to a later date or cancelled by either Magnet Forensics or you without charge or penalty if written notice is received twenty-one (21) days or more prior to the date of the Training Course. No rescheduling shall be permitted on less than twenty-one (21) days written notice, which shall constitute a cancellation without a refund. Your written rescheduling or cancellation notice must be emailed to training@magnetforensics.com or contact 202.984.3417. If Magnet Forensics cancels a Training Course due to insufficient attendance, you will have the option to register in a different scheduled Training Course or receive a full refund. Please do not book travel until you have confirmed that the Training Course will be running.

Magnet Forensics is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website:www.nasbaregistry.org.

Similar courses

GK200 is an intermediate-level, four-day training course designed for participants who are familiar with the principles of digital forensics and are looking to extend their capability into iOS, Android, and vehicle examinations using Magnet Graykey. Students must be part of a law enforcement agency and must be cleared in advance to attend this course.

More Information

AX250 is an advanced level course designed for students who are familiar with the principles of digital forensics and use Magnet Axiom in Windows investigations. You can purchase training classes directly online using a credit card or if payment by purchase order is required, please request a quotation from sales@magnetforensics.com.

More Information

This course is an expert-level four-day training course, designed for participants who are familiar with the principles of digital forensics and who are seeking to improve their mobile device investigations. You can purchase training classes directly online using a credit card or if payment by purchase order is required, please request a quotation from sales@magnetforensics.com.

More Information

Magnet Axiom Examinations (AX200) is ideal for those who require intermediate-level training with a digital investigation platform that covers cases involving smartphones, tablets, computers, and cloud data in a single collaborative interface. This course is the perfect entry point for examiners who are new to Axiom. You can purchase training classes directly online using a credit card or if payment by purchase order is required, please request a quotation from sales@magnetforensics.com.

More Information

This course is an intermediate-level four-day training course, designed for participants who are somewhat familiar with the principles of digital forensics and who are seeking to expand their knowledge base into cloud-based and social media forensics. You can purchase training classes directly online using a credit card or if payment by purchase order is required, please request a quotation from sales@magnetforensics.com.

More Information

AX350 is an expert-level four-day training course, designed for participants who understand digital forensics fundamentals, basic Axiom usage, and are seeking to expand their forensic investigative skills targeting Mac computers. You can purchase training classes directly online using a credit card or if payment by purchase order is required, please request a quotation from sales@magnetforensics.com.

More Information

Forensic Fundamentals (AX100) is a beginner-level course, designed for participants who are unfamiliar with the principles of digital forensics. You can purchase training classes directly online using a credit card or if payment by purchase order is required, please request a quotation from sales@magnetforensics.com.

More Information

Digital Video Investigations with Magnet Witness (DV200) is a beginner-level course, designed for participants who are not yet familiar with the concepts of the recovery and analysis of digital video files from commercially available digital video recorders.

More Information

Magnet Axiom to Cyber Transitions is ideal for those who are looking to continue their education and transition into the unique features of Axiom Cyber after taking the Axiom Examinations (AX200) course.

More Information

Magnet Axiom Examination (AX200 Microlearning) is ideal for those who require intermediate-level training with a digital investigation platform that covers cases involving smartphones, tablets, computers, and cloud data in a single collaborative interface. This course is the perfect entry point for examiners who are new to Axiom. You can purchase training classes directly online using a credit card or if payment by purchase order is required, please request a quotation from sales@magnetforensics.com.

More Information

Core Mobile Acquisition and Analysis (AX150) is a beginner level course, designed for participants who are unfamiliar with the principles of mobile forensics. The course focuses on iOS and Android devices from the point of collection to the point of analysis whilst exploring Magnet Axiom and Magnet tools such as Magnet Acquire, the Magnet Custom Artifact Generator (MCAG) and Magnet Axiom Dynamic App Finder.

More Information

Core Mobile Acquisition and Analysis (AX150 Microlearning) is a beginner level course, designed for participants who are unfamiliar with the principles of mobile forensics. The course focuses on iOS and Android devices from the point of collection to the point of analysis whilst exploring Magnet Axiom and Magnet tools such as Magnet Acquire, the Magnet Custom Artifact Generator (MCAG) and Magnet Axiom Dynamic App Finder.

More Information

Magnet Axiom Advanced Mobile Forensics (AX300 Microlearning) details the use of Magnet Axiom’s advanced mobile analysis capabilities. Students will learn advanced analysis techniques and leverage Magnet Axiom Examine to become proficient in investigating advanced aspects of full file system extractions of both iOS and Android devices.

More Information

The Magnet Griffeye Examinations Course is a 3-day training course designed for students who have attended the Magnet Griffeye Lite online course or have already attained proficiency in Magnet Griffeye Advanced. The course is designed to equip you with the necessary skills and tools to handle media files effectively during a criminal investigation, thereby maximizing the productivity of the tool.

More Information

Magnet Verakey Examinations (VK200) is an intermediate-level four-day training course, designed for participants who are familiar with the principles of digital forensics and who are seeking to improve their mobile device investigations.

More Information

Magnet Griffeye Lite is a limited, free version of Griffeye offered to law enforcement officials to navigate digital media more efficiently. In this free tutorial, available in numerous 20-minute-or-less modules, attendees will see how they can make the most out of their use of Griffeye Lite, including how to use the software, applying searching and filtering techniques, as well as creating reports and exporting.

More Information

This two-day instructor-led course provides students with the knowledge and skills necessary to perform structural comparative analysis on digital image and video files and to articulate expert results in both a report and court of law. Students will learn how to manually decode multimedia files at the binary level, performing authentication examinations using file metadata and structure. We will be working within Magnet Verify.

More Information

DV300 is an advanced course designed for investigators, examiners, and analysts who are already operating at a moderate level of audio/video complexity. This course focuses heavily on what practitioners should know instead of step-by-step training on how to conduct an investigation.

More Information

This course is a two-day, expert-level training program designed to equip digital forensic examiners with advanced skills for navigating complex mobile data. Emphasizing unsupported third-party applications, advanced data structures, and custom artifact creation, this course will provide essential tools for analyzing mobile device data with confidence.

More Information

This course is designed for individuals who have completed the Magnet Griffeye Lite course. It will provide the skills and tools needed to process cases, manage media files, and utilize the collaborative features of the tool, allowing multiple examiners to work together on a single case and enhancing the overall productivity of the tool.

More Information

Magnet Axiom Digital Evidence Reporting: A Prosecutor’s Toolkit (AP100) is an introductory-level, three-day training course designed for criminal prosecutors. It provides a strengthened understanding of digital forensics and how it applies to prosecutorial duties.

More Information

The AX250 Axiom Advanced Computer Forensics microlearning course offers a comprehensive exploration of Windows operating system artifacts and their forensic relevance.

More Information