A round-up of this week’s digital forensics news and views:
Research & Techniques
NIST Launches Digital Forensics Artifact Catalog ArtCat
NIST has publicly released the Digital Forensics Artifact Catalog (ArtCat), a curated, community-driven resource designed to standardize how digital forensic artifacts are identified and interpreted. Originally led by CKE founder Eoghan Casey, ArtCat turns practitioner knowledge into structured, shareable scientific infrastructure.
Case Studies
Heather Barnhart Details Kohberger Digital Forensics Methodology
Heather Barnhart, working pro bono with FBI support backed by SANS and Cellebrite, has published a detailed account of the digital forensic investigation into the Idaho student murders. Key findings include a CTF device that matched Bryan Kohberger's carrier exactly and recoverable errors in his digital cleanup attempts. Barnhart also addresses how the absence of plain-text motive can itself constitute meaningful forensic evidence.
Industry News
Trauma or Misconduct? Policing Must Decide
Forensic Mental Health & Well-being Lead Paul Gullon-Scott examines how cumulative trauma and organisational stress in policing and digital forensics can manifest as conduct breaches before being recognised as psychological injury. Drawing on peer-reviewed research, he argues that neurobiological dysregulation from chronic exposure impairs judgement and impulse control in ways organisations routinely misread as attitude or performance problems. He calls for trauma-informed early intervention systems that address misconduct risk before formal proceedings compound existing harm.
Research & Techniques
VW MIB2 Infotainment Forensics Paper Published
A new peer-reviewed paper in Forensic Science International: Digital Investigation details an alternative, tool-free acquisition method for the Volkswagen MIB2 infotainment system, alongside a structured walkthrough of data artefacts, volatile memory, and crash logging. Parsing support via the open-source VLEAPP project extends access for investigators without commercial tooling. Practitioners handling criminal casework are advised to review the authors' limitations section before applying the methodology across different MIB2 software revisions.
Industry News
Running Offline AI On Evidence With BelkaGPT
Belkasoft X's BelkaGPT feature enables investigators to run forensics-specific AI entirely offline, keeping sensitive case data off external servers. It supports analysis across images, audio, video, and chat data, aiming to accelerate examinations without compromising security.
Tools & Software
ALEAPP Now Parses Android Intrusion Logs
Android's new intrusion logging feature, part of Advanced Protection Mode, captures security events, DNS queries, and connection data that examiners can run IOC checks against. ALEAPP now includes parser support for these JSON-format logs, with acquisition possible via manual export, MVT, or the newly updated ALEX tool from Christian Peter.
Research & Techniques
Pass-ta-key Attacks Leave Concrete Forensic Artifacts
Unit 42 research describes three passkey attack variants targeting Google-synced credentials in Chrome on Windows, none of which break WebAuthn cryptography but instead exploit trust assumptions in device onboarding and UV-flag validation. Forensic artifacts include LevelDB reads from Chrome's Sync Data store, unexpected modification or deletion of passkey_enclave_state, and a transiently plaintext security domain secret in Chrome's process memory. Detection centers on process-access telemetry, file-integrity monitoring on passkey state files, and memory acquisition timed to re-enrollment events.
Research & Techniques
Decrypting BitLocker Clear-Key Images With Dislocker
When a BitLocker partition uses a Clear Key, the key material is embedded within the image itself, eliminating the need for an external password or recovery key. Practitioner Pieces0310 walks through identifying the "-FVE-FS-" signature, converting an E01 to raw format, and using dislocker and bdeinfo/bdemount to produce a mountable, decrypted NTFS image on Linux.
Tools & Software
Seven Tools DFIR Investigators Find in Data Exfil Cases
Attackers routinely abuse legitimate utilities — SCP, curl, Rclone, RMMs, and cloud storage clients — to quietly move stolen data, and each leaves distinct forensic artifacts. This roundup maps seven common exfiltration tool categories to investigation resources, covering WinSCP, AnyDesk, WinRAR, Restic, and Dropbox with linked case examples and methodology. Examiners responding to data theft incidents can use the references to target artifact collection and analysis for each tool class.
Industry News
AI Redefines DFIR Expertise Standards
As AI tools lower the barrier to building functional forensic software, the question of what separates a genuine expert from a capable hobbyist becomes urgent. LEAPPs argues that access to AI is not the differentiator — five distinct professional qualities are, framing a timely debate about competence and credibility in the field.
Case Studies
Private APN Pivot Shuts Polish CHP Turbine
Attackers reached a Polish combined heat and power plant's Siemens PLCs through a private cellular APN by pivoting from a compromised wind-farm FortiGate, using SSH tunneling and default WAGO credentials — no malware required. CERT Polska, disclosing the December 2025 incident in August, identifies this as the first confirmed real-world attack through a private APN. Every destructive step used legitimate device functions over native OT protocols.
Tools & Software
Velociraptor 0.76.7 Backports Security Fixes
Velociraptor has released version 0.76.7, a backported patch for the 0.76 branch addressing CVEs identified during the 0.77.2 release cycle. Practitioners running the stable 0.76 branch should update to remediate the disclosed vulnerabilities.
Industry News
Eight Years of Atola TaskForce Innovation
Atola TaskForce has evolved over eight years into a comprehensive forensic acquisition platform, adding record-breaking imaging speeds, automated RAID reconstruction, and 50 Gbit/s networking. The piece traces how each development was designed to eliminate emerging investigator bottlenecks.
Training & Events
Crypto Forensics Webinar Covers Blockchain Tracing Workflow
A free webinar led by former HSI Supervisory Special Agent Robert Whitaker offers a forensically defensible workflow for multi-hop cryptocurrency tracing, mixer recognition, and court-ready taint methodologies. Attendees will also learn off-chain deconfliction strategies to prevent multi-agency operations from compromising active leads.





