Digital Forensics Basics: A Step-by-Step Guide for Beginners
September 8, 2026 · View on GitHub
|
This companion site supports Digital Forensics Basics: A Step-by-Step Guide for Beginners with chapter-aligned presentations and practical guidance for using the book's laboratory activities. The presentations reinforce the concepts in the corresponding chapters; they do not replace the explanations, evidence notes, or exercises in the textbook. Preview: first 100 out of 529 pages (PDF, 2.52 MB; includes front matter). |
Start Here
- Read the book's Preface and How to Use This Book.
- Work through the chapters in order, especially Chapters 1–5 before beginning acquisition or file-system analysis.
- Download the presentation for the chapter you are studying and use it to review vocabulary, diagrams, and lab workflow.
- Perform hands-on activities only with the provided training materials, a virtual machine, or media you are explicitly authorized to examine.
- Keep an evidence note for every exercise: the source, tool and version, command or action, time, result, and any limitation in the result.
Chapter Presentations
| Book chapter | Topic | Companion presentation |
|---|---|---|
| Chapter 1 | Introduction to Digital Forensics | Download PPTX |
| Chapter 2 | Number Systems for Digital Forensics | Download PPTX |
| Chapter 3 | Computer Systems and Digital Evidence | Download PPTX |
| Chapter 4 | Linux for Digital Forensics | Download PPTX |
| Chapter 5 | Advanced Linux for Digital Forensics | Download PPTX |
| Chapter 6 | USB Image Analysis with Autopsy | No separate presentation at this time |
| Chapter 7 | The Sleuth Kit Tutorial | Download PPTX |
| Chapter 8 | USB Image Acquisition | Download PPTX |
| Chapter 9 | Digital Evidence Search | Part 1: Pattern Matching · Part 2: File Metadata · Part 3: Advanced Search |
| Chapter 10 | Data Carving and Recovery | Download PPTX |
| Chapter 11 | Wireshark Text Extraction | Download PPTX |
| Chapter 12 | Wireshark Image Extraction | Download PPTX |
| Chapter 13 | Steganography | Download PPTX |
| Chapter 14 | Conclusion and Next Steps | No separate presentation at this time |
Lab Files and Downloads
Use this index to locate files that the hands-on chapters ask you to download. The book remains the authoritative source for the procedure, context, and interpretation of each file. Download only the item required for the activity you are completing, save it in the location specified by the chapter, and record its source and any verification result in your evidence notes.
| Book chapter | Required or practice material | Download |
|---|---|---|
| Chapter 4 | Practice JPEG image for the Linux download and viewing exercise | Download DulILzQXcAAkFMV.jpg |
| Chapters 6 and 7 | USB forensic-image archive used for Autopsy and The Sleuth Kit activities | Download 120M.7z |
| Chapter 9 | Regular-expression exercise files | Download regex.zip |
| Chapter 9 | Packet-capture sample for evidence-search practice | Download vm_to_ub_traffic.log |
| Chapter 9 | NTFS image used in the chapter's later exercise | Download NTFS.zip, then extract NTFS.001. |
| Chapter 10 | JPEG used in the introductory download and hashing example | Download J_ub_law.jpg |
| Chapter 10 | Document used for manual file-carving practice | Download File_carving.docx |
| Chapter 10 | USB forensic-image archive used for carving exercises | Download 120M.7z |
| Chapter 11 | HTTP/TCP packet-capture sample | Download basic.log |
| Chapter 12 | Packet-capture sample containing an image transfer | Download image2.log |
| Chapter 13 | BMP carrier image for the steganography exercise | Download _tower_original_image_for_lab.bmp |
Chapters 1--3, 5, 8, and 14 do not currently specify a separate downloadable lab artifact in the textbook. Chapter 8 instead uses a USB device and acquisition workflow; use only media you are authorized to handle.
Supplemental Presentation
The following presentation supports learners who want additional Windows command-line practice. It is supplementary and is not assigned to a single chapter.
Study and Lab Practices
- Use copies, not original evidence. Never experiment on original media or a device that may contain evidence.
- Make observations before conclusions. Record what a tool reports, then explain what that observation may and may not support.
- Preserve reproducibility. Save commands, screenshots, hashes, and tool versions so another reader can repeat the activity.
- Respect authorization and privacy. Examine only training data, your own data, or media you are authorized to inspect.
- Treat tools as aids. A result from Autopsy, The Sleuth Kit, Wireshark, a hex editor, or a search utility requires context and corroboration.
Suggested Tools
The book introduces open or freely available tools and utilities. Use the official project documentation when installing or updating them:
Tool interfaces and versions change. Follow the book's forensic principles—preservation, documentation, verification, and careful interpretation—even when a current version looks different from a screenshot.
Using and Contributing Materials
Presentations and lab instructions are educational resources. Before redistributing, adapting, or adding third-party screenshots, images, scripts, or datasets, confirm that you have the necessary permission and provide appropriate attribution. Contributions should preserve the chapter numbering and use descriptive filenames so students can easily locate the matching material.