Digital Forensics Basics: A Step-by-Step Guide for Beginners

September 8, 2026 · View on GitHub

Cover of Digital Forensics Basics: A Step-by-Step Guide for Beginners

This companion site supports Digital Forensics Basics: A Step-by-Step Guide for Beginners with chapter-aligned presentations and practical guidance for using the book's laboratory activities. The presentations reinforce the concepts in the corresponding chapters; they do not replace the explanations, evidence notes, or exercises in the textbook.

Get the book on Amazon.

Preview: first 100 out of 529 pages (PDF, 2.52 MB; includes front matter).

Start Here

  1. Read the book's Preface and How to Use This Book.
  2. Work through the chapters in order, especially Chapters 1–5 before beginning acquisition or file-system analysis.
  3. Download the presentation for the chapter you are studying and use it to review vocabulary, diagrams, and lab workflow.
  4. Perform hands-on activities only with the provided training materials, a virtual machine, or media you are explicitly authorized to examine.
  5. Keep an evidence note for every exercise: the source, tool and version, command or action, time, result, and any limitation in the result.

Chapter Presentations

Book chapterTopicCompanion presentation
Chapter 1Introduction to Digital ForensicsDownload PPTX
Chapter 2Number Systems for Digital ForensicsDownload PPTX
Chapter 3Computer Systems and Digital EvidenceDownload PPTX
Chapter 4Linux for Digital ForensicsDownload PPTX
Chapter 5Advanced Linux for Digital ForensicsDownload PPTX
Chapter 6USB Image Analysis with AutopsyNo separate presentation at this time
Chapter 7The Sleuth Kit TutorialDownload PPTX
Chapter 8USB Image AcquisitionDownload PPTX
Chapter 9Digital Evidence SearchPart 1: Pattern Matching · Part 2: File Metadata · Part 3: Advanced Search
Chapter 10Data Carving and RecoveryDownload PPTX
Chapter 11Wireshark Text ExtractionDownload PPTX
Chapter 12Wireshark Image ExtractionDownload PPTX
Chapter 13SteganographyDownload PPTX
Chapter 14Conclusion and Next StepsNo separate presentation at this time

Lab Files and Downloads

Use this index to locate files that the hands-on chapters ask you to download. The book remains the authoritative source for the procedure, context, and interpretation of each file. Download only the item required for the activity you are completing, save it in the location specified by the chapter, and record its source and any verification result in your evidence notes.

Book chapterRequired or practice materialDownload
Chapter 4Practice JPEG image for the Linux download and viewing exerciseDownload DulILzQXcAAkFMV.jpg
Chapters 6 and 7USB forensic-image archive used for Autopsy and The Sleuth Kit activitiesDownload 120M.7z
Chapter 9Regular-expression exercise filesDownload regex.zip
Chapter 9Packet-capture sample for evidence-search practiceDownload vm_to_ub_traffic.log
Chapter 9NTFS image used in the chapter's later exerciseDownload NTFS.zip, then extract NTFS.001.
Chapter 10JPEG used in the introductory download and hashing exampleDownload J_ub_law.jpg
Chapter 10Document used for manual file-carving practiceDownload File_carving.docx
Chapter 10USB forensic-image archive used for carving exercisesDownload 120M.7z
Chapter 11HTTP/TCP packet-capture sampleDownload basic.log
Chapter 12Packet-capture sample containing an image transferDownload image2.log
Chapter 13BMP carrier image for the steganography exerciseDownload _tower_original_image_for_lab.bmp

Chapters 1--3, 5, 8, and 14 do not currently specify a separate downloadable lab artifact in the textbook. Chapter 8 instead uses a USB device and acquisition workflow; use only media you are authorized to handle.

Supplemental Presentation

The following presentation supports learners who want additional Windows command-line practice. It is supplementary and is not assigned to a single chapter.

Study and Lab Practices

  • Use copies, not original evidence. Never experiment on original media or a device that may contain evidence.
  • Make observations before conclusions. Record what a tool reports, then explain what that observation may and may not support.
  • Preserve reproducibility. Save commands, screenshots, hashes, and tool versions so another reader can repeat the activity.
  • Respect authorization and privacy. Examine only training data, your own data, or media you are authorized to inspect.
  • Treat tools as aids. A result from Autopsy, The Sleuth Kit, Wireshark, a hex editor, or a search utility requires context and corroboration.

Suggested Tools

The book introduces open or freely available tools and utilities. Use the official project documentation when installing or updating them:

Tool interfaces and versions change. Follow the book's forensic principles—preservation, documentation, verification, and careful interpretation—even when a current version looks different from a screenshot.

Using and Contributing Materials

Presentations and lab instructions are educational resources. Before redistributing, adapting, or adding third-party screenshots, images, scripts, or datasets, confirm that you have the necessary permission and provide appropriate attribution. Contributions should preserve the chapter numbering and use descriptive filenames so students can easily locate the matching material.