DFIR News, 25 Sep 2026

A round-up of today’s digital forensics news and views:


Forensic Focus News

Corrobora – Cross-Artifact Consistency Analysis For Windows Digital Forensics

Dielle De Noon explores the development and validation of two key components of her open-source Windows digital forensics framework and how they lay the foundation for future cross-artifact correlation.

Read more (forensicfocus.com)


Research & Techniques


Get The Latest DFIR News

The monthly Forensic Focus newsletter, plus webinar invitations and occasional research surveys.

Unsubscribe or change what you receive at any time. We respect your privacy: read our privacy policy.


New iOS AFU Location Artifact Parses in iLEAPP

A newly identified data source provides location data within Apple File System (AFU) extractions when cache.sqlite files are inaccessible, offering examiners an alternative when full filesystem access is unavailable. Locations can be corroborated with app usage artifacts, such as pairing a visit to a specific venue with corresponding application activity. Support has been added to iLEAPP, enabling automated parsing of this artifact.

Read more (linkedin.com)


Investigating Suspicious TeamViewer Use in DFIR

Suspicious TeamViewer activity is a common foothold in intrusions, and practitioners need to know exactly which artifacts to hunt. This guide walks through forensic next steps for identifying unauthorized or malicious TeamViewer sessions, covering key artifacts and investigative methodology a working examiner can apply directly.

Read more (cybertriage.com)


Case Studies

JFrog Artifactory Exploit Chain Leaves Hidden Persistence

A two-step unauthenticated token escalation in JFrog Artifactory attributes attacker actions to a built-in anonymous principal, creating a SIEM blind spot that trained analysts are conditioned to ignore. Patching closes the entry point but leaves malicious Groovy plugins in the plugins directory and stolen signing keys capable of minting valid tokens indefinitely. Incident responders should hunt anonymous-as-admin token activity, inventory known malicious plugins, and rotate Access signing material before treating a patched instance as remediated.

Read more (linkedin.com)


Industry News

Seven Pitfalls Threatening Digital Forensics Programs

Examiner burnout, growing case backlogs, and inadequate training are among seven systemic risks threatening digital forensics programs, according to Chad Gish, drawing on decades of investigative experience. Agencies are offered practical strategies to build more resilient forensic units capable of keeping pace with evolving technology.

Read more (magnetforensics.com)

Leave a Comment