A round-up of today’s digital forensics news and views:
Forensic Focus News
ADF Solutions Named A Major Player In IDC MarketScape For Worldwide Digital Forensics Platforms 2026 Vendor Assessment
ADF Solutions has been named a Major Player in the IDC MarketScape: Worldwide Digital Forensics Platforms 2026 Vendor Assessment, recognizing the company’s continued focus on intelligent triage, automation, and AI-driven digital investigations.
Tools & Software
qnxprobe v1.50 Adds APFS Decryption, Broad Format Support
qnxprobe v1.50 is a free, open-source Python tool that reads QNX, Linux, Windows, and Apple file systems across forensic image formats including E01, AFF4, VMDK, and raw flash dumps. Version 1.50 adds software-encrypted APFS volume decryption alongside existing BitLocker and FTK Imager AD-encryption support, requiring no admin rights and never writing to the image. Deleted file recovery, NTFS alternate data streams, free space reporting, and integration with LEAPPs, GLEAPP, and Arc2Lite make it a versatile addition to any examiner’s workflow.
Volatility Workbench v3.0.1017 Released
Volatility Workbench v3.0.1017, a free open-source graphical interface for the Volatility 3 Framework, is now available for download. Built on Volatility 3 Framework v2.28.2 with source pulled from GitHub in September 2026, it offers point-and-click memory analysis requiring no command-line experience.
GLEAPP Map Downloader Brings Offline Maps to Examiners
GLEAPP Map Downloader lets examiners pull regional map tiles from the Protomaps planet basemap on an internet-connected machine, then import a single .pmtiles file into GLEAPP on an air-gapped forensic workstation. Geotagged photo evidence can then be plotted against street-level maps without any online connection during examination. The tool is free, open-source under MIT license, and ships as a single Python file with executables for Windows, macOS, and Linux.
Chipset Search Unlocks Devices Without Matching Profiles
When a device profile is absent from the extraction library, searching by chipset rather than device name can surface compatible alternate profiles. A locked device running an MT6739 chipset yielded a successful physical extraction after a chipset search revealed two candidates, only one supporting physical acquisition of a locked unit.
Legal & Policy
Paper Examines Evidence-Grade OSINT Standards
A new paper from the Coalition of Cyber Investigators sets out what a globally credible OSINT standard must deliver to be trusted across courts, investigations, businesses and national borders. Credibility, practicability and cross-jurisdictional consistency are identified as core requirements for any standard that aims to elevate OSINT to evidence-grade status.





