DFIR News, 05 Oct 2026

A round-up of today’s digital forensics news and views:


Forensic Focus News

Block Hash Scan: Illegal File Triage Completed On Site

Block Hash Scan in MD-LIVE divides files into fixed-size blocks and hashes only the blocks needed for matching, so identifying a 40GB video requires reading roughly the same data as a 4GB one. Full-file hash comparison and manual review both scale poorly with modern smartphone storage exceeding 512GB, driving unnecessary seizures and lab backlogs. The approach applies to CSAM investigations, IP theft, malware, and fraud cases, with defined guidance on interpreting zero-detection results.

Read more (forensicfocus.com)


MISP 2.5.47 Fixes RCE, Adds PostgreSQL Support

MISP 2.5.47 patches 27 confirmed vulnerabilities including a remote code execution reachable by any authenticated user, multiple XSS flaws, access-control bypasses, and an MFA brute-force bypass. A new ledger-based database migration system replaces the historic db_version counter and introduces early PostgreSQL 16 support for fresh installs. AI-assisted analysis enables event summarisation, tag recommendation, and indicator extraction via the ai_connector misp-module.


Get The Latest DFIR News

The monthly Forensic Focus newsletter, plus webinar invitations and occasional research surveys.

Unsubscribe or change what you receive at any time. We respect your privacy: read our privacy policy.


Read more (misp-project.org)


Tools & Software

GrayKey Claims iOS Inactivity Reboot Bypass

Magnet Forensics has claimed its GrayKey Preserve device and Evidence Preservation Mode can keep seized iPhones in the After First Unlock state, preventing Apple’s 72-hour inactivity reboot from pushing devices back to the harder Before First Unlock encryption state. A leaked law enforcement training video also claims the tools can block iOS from deleting time-limited data including cached locations and recently deleted messages. The mechanism has not been disclosed or independently verified, and Apple has not commented.

Read more (technology.org)


PowerShell Tool Automates NetScaler Forensic Timelines

Get-NetScalerTimeline v0.1.0 is a PowerShell script that builds a file system timeline from NetScaler ADC/Gateway VMDK disk images and loads results into DuckDB for SQL-based threat hunting. It auto-detects FreeBSD slices and UFS partitions, extracts web and error logs including rotated archives, and flags log poisoning via CVE-2026-88771. Over 20 built-in queries cover web shells, persistence mechanisms, crash dumps, and CVE IOCs.

Read more (github.com)


AI Skills Toolkit Released for Velociraptor DFIR

A new open-source project, velociraptor-skills, provides reusable AI-guided workflows for artifact selection, collection, hunting, and host analysis using Velociraptor. A Python harness called vraptor standardises token use and analysis output across providers including OpenAI, Azure OpenAI, and Anthropic. The release includes practical security guidance on prompt injection risks from attacker-controlled forensic data and data residency considerations for cloud AI providers.

Read more (labs.infoguard.ch)


WEBCQUISITION Automates Forensic Web Acquisition

WEBCQUISITION is an open-source tool that automates web acquisition inside a VMware Workstation Pro Windows VM, handling Wireshark capture, TLS key logging, and screenshot hashing so examiners focus on navigation rather than repetitive setup. Each case produces a PCAPNG, TLS key log, screenshots with metadata, an acquisition JSON, an HTML report, and a hash-chain log verifiable with sha256sum on any machine. SHA-256 verification runs on every file transferred from VM to host, and interrupted sessions are recovered and flagged as INCOMPLETE rather than lost.

Read more (strangerforensics.wordpress.com)


Velociraptor 0.77.3 Fixes Forensic Artifact Bugs

Velociraptor 0.77.3 corrects a long-standing error in Windows.Forensics.Prefetch, which now reads VolumeSerialNumber at offset 16 rather than 12, and fixes registry MULTI_SZ value parsing. New Azure Monitor upload support and corrected NTUser path handling in the registry mail-rules artifact round out the forensic-facing changes.

Read more (github.com)


Incident Response

NetScaler CVE Demands Active Forensic Investigation

A second Citrix emergency patch for CVE-2026-88779 followed exploitation on already-patched NetScaler appliances, with login fields carrying shell commands pulling payloads from a known exfil IP. Responders should collect ns.log, httpaccess logs, support bundles, and crash history before touching affected boxes. Key artifact checks include setuid /bin/sh, unauthorized httpd.conf handlers, unknown ns.conf users, crontab modifications, and outbound connections to 213.209.159[.]55.

Read more (linkedin.com)


Research & Techniques

Safari History Database Reveals Hidden Tag Artifacts

Safari’s History.db contains two underexamined tables, history_tags and history_items_to_tags, that link visited pages to Wikidata-referenced keyword tags, surfacing browsing themes even after history deletion. Tags use a Cocoa timestamp epoch and persist with zero item counts when associated history entries are removed. mac_apt has been updated to parse these tags, giving macOS examiners a new artifact for reconstructing user activity.

Read more (swiftforensics.com)


iOS Unified Log Forensics Workflow for Beginners

Apple’s Unified Log retains unlock traces for roughly one day on active devices, making same-day acquisition critical. A repeatable workflow covers log collection via Mac or UFADE, cryptographic hashing of the logarchive folder, and filtering with iLEAPP and Consolation3 to surface both known and unknown artifacts. When automated tools return nothing, querying the raw log with –info and –debug flags may still reveal hidden entries.

Read more (thesisfriday.com)


Windows Memory Forensics Acquisition and Analysis Guide

Windows memory forensics requires acquiring a RAM image before shutdown, since volatile data including running processes, network connections, and cached registry keys vanishes when power is cut. Analysts can supplement raw memory with pagefile.sys, swapfile.sys, and hiberfil.sys to recover paged-out or hibernated state. Tools such as Volatility, MemProcFS, bulk_extractor, and YARA-X cover everything from OS structure traversal to pattern-based IOC hunting across binary images.

Read more (sumeshi.github.io)


Open-Source ICAC Cross-Case Analysis Tool Launches

CaseLinker, an open-source knowledge representation system for ICAC investigations, now supports MCP, a SPARQL endpoint, and programmatic access across 10,362 public case records and 700+ federal court cases. A companion Exploitation State Machine models offender phase progression using affordance-based action transitions and Markov decision processes, offering investigators a structured framework for pattern analysis.

Read more (linkedin.com)


Forensic Timelines Need Smarter Clustering

Modern forensic and EDR tools have commoditized timeline analysis, but massive file-copy migrations and multi-iteration web directories create distortions that flat chronological views miss. Clustering atomic events by attributed intent, detecting web shells across backup directories, and distinguishing red-team activity from threat actor behavior are areas where current tooling still falls short.

Read more (hexacorn.com)

Latest from Forensic Focus

Leave a Comment