diff --git a/Email_Harassment/1_tshark_forensics.pptx b/Email_Harassment/1_tshark_forensics.pptx new file mode 100644 index 0000000..908a933 Binary files /dev/null and b/Email_Harassment/1_tshark_forensics.pptx differ diff --git a/Email_Harassment/2_Investigate_Harassment_Email.pptx b/Email_Harassment/2_Investigate_Harassment_Email.pptx new file mode 100644 index 0000000..d3d1612 Binary files /dev/null and b/Email_Harassment/2_Investigate_Harassment_Email.pptx differ diff --git a/Email_Harassment/3_Investigate_Harassment_Email_TShark.pptx b/Email_Harassment/3_Investigate_Harassment_Email_TShark.pptx new file mode 100644 index 0000000..b90c553 Binary files /dev/null and b/Email_Harassment/3_Investigate_Harassment_Email_TShark.pptx differ diff --git a/Illegel_Possesion_Images/HTTP_Wireshark_Forensics_1_text.pptx b/Illegel_Possesion_Images/HTTP_Wireshark_Forensics_1_text.pptx new file mode 100644 index 0000000..8abd5c6 Binary files /dev/null and b/Illegel_Possesion_Images/HTTP_Wireshark_Forensics_1_text.pptx differ diff --git a/Illegel_Possesion_Images/HTTP_Wireshark_Forensics_2_image.pptx b/Illegel_Possesion_Images/HTTP_Wireshark_Forensics_2_image.pptx new file mode 100644 index 0000000..e25085e Binary files /dev/null and b/Illegel_Possesion_Images/HTTP_Wireshark_Forensics_2_image.pptx differ diff --git a/Illegel_Possesion_Images/Rhion_Possesion_1_File_Recovering.pptx b/Illegel_Possesion_Images/Rhion_Possesion_1_File_Recovering.pptx new file mode 100644 index 0000000..821a242 Binary files /dev/null and b/Illegel_Possesion_Images/Rhion_Possesion_1_File_Recovering.pptx differ diff --git a/Illegel_Possesion_Images/Rhion_Possesion_2_Steganography.pptx b/Illegel_Possesion_Images/Rhion_Possesion_2_Steganography.pptx new file mode 100644 index 0000000..5271a6f Binary files /dev/null and b/Illegel_Possesion_Images/Rhion_Possesion_2_Steganography.pptx differ diff --git a/Illegel_Possesion_Images/Rhion_Possesion_3_FTP_Traffic_crackzip.pptx b/Illegel_Possesion_Images/Rhion_Possesion_3_FTP_Traffic_crackzip.pptx new file mode 100644 index 0000000..77653f0 Binary files /dev/null and b/Illegel_Possesion_Images/Rhion_Possesion_3_FTP_Traffic_crackzip.pptx differ diff --git a/Illegel_Possesion_Images/Rhion_Possesion_4_HTTP_Traffic.pptx b/Illegel_Possesion_Images/Rhion_Possesion_4_HTTP_Traffic.pptx new file mode 100644 index 0000000..d5aca87 Binary files /dev/null and b/Illegel_Possesion_Images/Rhion_Possesion_4_HTTP_Traffic.pptx differ diff --git a/Illegel_Possesion_Images/The_Sleuth_Kit_Tutorial.pptx b/Illegel_Possesion_Images/The_Sleuth_Kit_Tutorial.pptx new file mode 100644 index 0000000..96bacd1 Binary files /dev/null and b/Illegel_Possesion_Images/The_Sleuth_Kit_Tutorial.pptx differ diff --git a/README.md b/README.md index caaaf74..6d15d86 100644 --- a/README.md +++ b/README.md @@ -27,7 +27,7 @@ The case study is to investigate an image involving intellectual property theft * A large and complex image created by [NIST](https://www.cfreds.nist.gov/data_leakage_case/data-leakage-case.html) * 13 hands-on labs/topics in digital forensics -* Each lab has an PPT with lab screenshots +* Each lab has a PPT with lab screenshots Topics Covered @@ -41,7 +41,7 @@ Topics Covered | Lab 5 | File Change History and USN Journal |2M | | Lab 6 | Network Evidence and shellbag |2M | | Lab 7 | Network Drive and Windows shellbag |5M | -| Lab 8 | $MFT (Master File Table) Analysis |4M | +| Lab 8 | Master File Table ($MFT) Analysis |4M | | Lab 9 | Windows Search History | 4M| | Lab 10 | Windows Volume Shadow Copy Analysis |6M | | Lab 11 | Data Carving |3M |