A round-up of today’s digital forensics news and views:
Forensic Focus News
Magnet Forensics Expands Collaboration With NCMEC To Strengthen Victim Identification
Coming soon to Magnet Griffeye: new capabilities will enable investigators to securely share CSAM-related files, hashes and investigative information directly with NCMEC, helping streamline workflows and support faster child victim identification.
Radim Motycka, Founder, Proofsnap
Why screenshots alone may not be enough: ProofSnap founder Radim Motycka explains how hashes, timestamps, WARC, network artefacts and independent verification can strengthen the preservation of web evidence.
Evidence Locker Adds CTF and Memory Images
The Evidence Locker has added new practice datasets including Josh Brunty CTF images, Hackropole memory and iOS images, EC Cybersecurity Operations Centre sysdiagnose files, OSForensics sample memory images for Volatility Workbench, and sanitized Slack files. File search improvements include hash-based cross-correlation, evidence source filtering, tooltip OS indicators, and pagination upgrades allowing direct page navigation.
Read more (theevidencelocker.github.io)
Threat Intelligence
CERT Polska Dissects MikroTik Auth Bypass Chain
CERT Polska researchers identified a two-CVE chain, dubbed MikroTrick, allowing full administrative access to MikroTik RouterOS devices without credentials. CVE-2026-67279 exploits incorrect SSH rekey handling during authentication, while CVE-2026-86060 abuses argument injection in the login binary. Patches were released across multiple RouterOS branches in September 2026, and specific IoCs including a rogue ops account and failed login for user -2 aid post-compromise detection.
Research & Techniques
SEM Recovers Crash Data from Destroyed EDR Modules
Researchers Sergei Skorobogatov and Peter Vertal recovered EDR crash data from a severely damaged SRS/airbag control module using Scanning Electron Microscopy to examine physically destroyed EEPROM memory cells. Recovered data was then processed with CrashScan, demonstrating that visible hardware damage does not necessarily render vehicle crash data unrecoverable. Vehicle forensics examiners are reminded that OBD, bench, ISP, chip-off, and SEM approaches each unlock different data recovery possibilities.
Automating Edge Device Memory Forensics with Volatility
Edge devices remain among the hardest forensic targets despite their growing role in intrusions. A session at Volexity Cyber Sessions in Amsterdam on October 29 will cover an agentic framework that fingerprints unknown networked devices, selects architecture-appropriate acquisition paths, and extends Volatility 3 to support MIPS-based routers natively unsupported by the tool.
Training & Events
DFIR Summit Showcases Real Case Digital Evidence
Investigators Heather Barnhart and Jason Higley, whose cases featured in Netflix documentaries, will present the actual digital evidence from those investigations at the SANS DFIR Summit on October 15, 16 in Arlington. Attendees will see firsthand what the digital artifacts looked like in real casework, making it a rare methodology-focused session for working investigators.
In-Depth Review: 13Cubed Windows Memory Course
An independent reviewer has published a detailed assessment of 13Cubed’s Investigating Windows Memory course, covering its content and value for DFIR practitioners. A prior review of the Investigating Windows Endpoints course is also available for those evaluating training options.





