Digital Forensics Round-Up, August 26 2026

A round-up of this week’s digital forensics news and views:


Research & Techniques

Forensic Artifact Guide PDF for OpenAI Platforms Released

Frontier Forensics has published a platform-by-platform breakdown of evidence left by AI systems, starting with ChatGPT Workspace and the OpenAI API. Coverage maps what gets logged, where artifacts reside, what logging must be enabled before an incident, and how quickly data expires. Claude, Gemini, and Copilot coverage follows in subsequent releases.

Read more (go.invictus-ir.com)


Industry News


Get The Latest DFIR News

The monthly Forensic Focus newsletter, plus webinar invitations and occasional research surveys.

Unsubscribe or change what you receive at any time. We respect your privacy: read our privacy policy.


DFIR Well-Being Study Results Explored

Repeated exposure to traumatic digital evidence carries measurable psychological consequences for forensic investigators. Phil Anderson returns to the Forensic Focus Podcast to unpack further findings from the international well-being study, exploring impact, coping mechanisms, and support structures across the DFIR community.

Read more (forensicfocus.com)


Research & Techniques

Apple Screen Time Artifacts Mapped for iOS Forensics

Apple Screen Time artifacts stored in RMAdminStore-Local.sqlite can yield hourly usage summaries, category totals, pickup counts, notification counts, and timed app activity linked to specific bundle identifiers and Apple account profiles. These records support timeline reconstruction and user behavior analysis when correlated with location data, browser history, and system logs.

Read more (forensafe.com)


Tools & Software

Simson Garfinkel’s bulk_extractor 2.2.0 Beta Released on GitHub

bulk_extractor beta 2.2.0 is now available on GitHub, closing more than 100 open issues while improving reliability and performance. The open-source forensic carving tool is widely used by DFIR practitioners for extracting artifacts from disk images and memory dumps without full parsing.

Read more (github.com)


Training & Events

RAM Artefacts Reveal Phone Location Without GPS

Smartphones passively log nearby Wi-Fi, Bluetooth, and cellular signals, leaving transient memory artefacts that can reconstruct device movements even when traditional location data is absent. An upcoming SANS DFIR Europe Summit 2026 session will demonstrate how wireless signal data recovered from RAM can be converted into actionable investigative evidence.

Read more (linkedin.com)


Case Studies

Cellebrite Explores Ten Best Practices for AI-Assisted Investigations

Legal and compliance teams using AI for investigations must prioritize governance, traceability, and documented human oversight to ensure findings hold up in court or regulatory review. Cellebrite’s Head of AI Innovation Center outlines ten practices — from piloting narrow use cases to involving stakeholders before deployment — that define defensible AI-assisted investigations. Strong documentation, data security controls, and a culture of governed experimentation separate organizations that succeed with AI from those that struggle with adoption.

Read more (forensicfocus.com)


Training & Events

ICMDE Mobile Forensics Certification Explained

The ICMDE (Infosec Certified Mobile Device Examiner) certification targets digital forensics professionals specialising in mobile investigation across iOS and Android platforms. Key exam requirements, scope, and preparation considerations are covered for practitioners weighing mobile forensics credentials.

Read more (youtube.com)


Industry News

Atola Technology Explores How to Fix the Forensic Imaging Backlog Bottleneck

Over 25,000 devices are awaiting examination in UK policing labs, and imaging speed determines how fast any case can progress. Drive type, cable quality, network configuration, and imaging settings all act as potential bottlenecks — and any one of them can cap throughput regardless of how fast other components are. Practical fixes include diagnosing drives before imaging, testing cables with real transfers, enabling Jumbo Frames on lab networks, and choosing output formats and hash algorithms based on drive condition.

Read more (forensicfocus.com)


Research & Techniques

DOJ-Funded Research Explores IoT Forensic Evidence

A George Mason University researcher discusses DOJ-funded work on extracting digital evidence from IoT devices, including smartwatches and other connected consumer hardware. As IoT devices proliferate, they are emerging as significant sources of forensic artifacts capable of supporting event reconstruction and courtroom testimony.

Read more (tdonnel.podbean.com)


Tools & Software

Chainsaw v2.16.5 Fixes Output Regression

WithSecureLabs has released Chainsaw v2.16.5, patching a regression that caused incorrect output flushing behaviour. Chainsaw is a widely used open-source tool for rapidly searching and hunting through Windows event logs during DFIR investigations.

Read more (github.com)

Leave a Comment