Cybercop 201 - Digital Evidence Examination and Processing
The "Cybercop (CC) 201 - Digital Evidence Examination and Processing" (DEEP) course builds on the concepts introduced in "CC 101: Basic Digital Forensic Imaging" (BDFI). This course covers the architecture and functionality of the Windows NT File System (NTFS), the FAT File System, and related directory entry information for locating files on electronic devices. Topical areas include file headers and file hashing, recovery of deleted files and long file names, and techniques for discovering potential evidence that might otherwise be overlooked.