DFIR News, 21 Sep 2026

A round-up of today’s digital forensics news and views:

 


Research & Techniques

iOS Unified Log Retention Varies Dramatically by Device Activity

Controlled testing on two iPhones running iOS 26.6.2 shows that kernel-level unlock artefacts vanish from the Unified Log within 13 hours on a busy device but persist beyond 87 hours on an idle one. Only ChronoServices lines, which carry an explicit time-to-live value, survived on the active phone, yet even that TTL proved unreliable as a retention predictor on the idle reference device. Examiners cannot assume a fixed retention window when reconstructing unlock timelines from log archives.

Read more (thesisfriday.com)


Get The Latest DFIR News

The monthly Forensic Focus newsletter, plus webinar invitations and occasional research surveys.

Unsubscribe or change what you receive at any time. We respect your privacy: read our privacy policy.



Mac Forensics Best Practices Guide Updated for macOS 27

A fully updated Mac Forensics Best Practices Guide for 2026, authored by Steve Whalen, covers material changes in macOS 27 relevant to examiners, including revised Full Disk Access and TCC restrictions, image file formats, and upcoming feature deprecations. Guidance is aligned with SWGDE published standards, making it applicable across experience levels.

Read more (sumuri.com)


Tools & Software

Strata: Open-Source macOS DFIR Triage Tool

Strata is a native macOS triage tool that ingests disk images (E01, VMDK, VHD, raw dd) and loose KAPE/UAC folders, parses artifacts across Windows, Linux, and macOS, and builds a MACB super-timeline from over 30 sources. Sixty-one ATT&CK-tagged detection analyzers feed a Cyber Kill Chain view, lateral-movement graph, and IOC matching engine, all statically linked with no runtime dependencies. An on-device AI case summary validates every claim against real findings before output.

Read more (github.com)


RLEAPP Adds Instagram Artifact Support

RLEAPP now parses Meta’s current Instagram data return format, extracting 25 artifact types including messages displayed as conversations with inline photos, videos, and voice notes. The update is merged and available immediately via the GitHub codebase, ahead of a formal release. The developer notes potential compatibility with other Meta products, pending community testing.

Read more (leapps.org)


crush-forensics v0.20.0 Adds EWF and Raw Image Support

crush-forensics v0.20.0 can now open raw disk images and EWF acquisitions (.img/.dd, split .001, .E01) directly, covering NTFS, APFS, and QNX filesystems without separate mounting tools. iOS investigators gain a beta Get Installed Apps analyzer ported from LEAPPs, aiding app install path resolution. The release also adds C2PA/XMP AI-provenance detection in the Image Viewer.

Read more (github.com)


Case Studies

Multi-Stage Malware Loader Unpacked Step by Step

A TrustedSec researcher walked through unpacking a six-stage malware loader that chains obfuscated Python bytecode, Donut shellcode, and laZzzy PE injection into encrypted .NET payloads. Each layer required separate tooling, including a modified brute-force deobfuscator and Volexity’s donut_decryptor, with custom scripts written to fill gaps in public tooling. AES-CBC with an XOR layer protects the laZzzy stage, and static analysis in Ghidra guided extraction at each step.

Read more (trustedsec.com)


Industry News

dfir.blog Relaunches as Hindsight Foundry

The browser forensics research site dfir.blog has relaunched as Hindsight Foundry, a dedicated hub for browser artifact analysis, open-source tooling, and related investigative resources. Practitioners who rely on browser history and artifact examination will find a consolidated home for ongoing research and tool development in this space.

Read more (hindsig.ht)


Training & Events

SANS Webcast Covers Attacker Persistence on Network Devices

Network infrastructure devices such as routers, switches, and firewalls run Linux but typically lack EDR coverage and consistent logging, making them attractive targets for persistent attackers. Jim Clausing will present a free SANS webcast on 12 October 2026 examining how attackers establish footholds on these devices and what recent incidents reveal about the techniques involved.

Read more (sans.org)

Leave a Comment