<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									Forensic Focus Forums - Recent Topics				            </title>
            <link>https://www.forensicfocus.com/forums/</link>
            <description>Digital Forensics Discussion Forums</description>
            <language>en-US</language>
            <lastBuildDate>Tue, 22 Sep 2026 02:37:05 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>Webinar: Finding Answers Faster: Genesis For Private Sector Investigations</title>
                        <link>https://www.forensicfocus.com/forums/general/webinar-finding-answers-faster-genesis-for-private-sector-investigations-2/</link>
                        <pubDate>Mon, 21 Sep 2026 16:00:00 +0000</pubDate>
                        <description><![CDATA[Cellebrite&#039;s Matt Goeckel demos Genesis on a real enterprise case - UFDRs, CDRs, documents, audio and video - showing how agentic AI surfaces leads and timelines while linking every finding ...]]></description>
                        <content:encoded><![CDATA[<p><span>Cellebrite's Matt Goeckel demos Genesis on a real enterprise case - UFDRs, CDRs, documents, audio and video - showing how agentic AI surfaces leads and timelines while linking every finding back to its source. </span></p>
<p><span>Watch the full webinar here: https://www.forensicfocus.com/webinars/finding-answers-faster-genesis-for-private-sector-investigations/ </span></p>]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/"></category>                        <dc:creator>Zoe</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/general/webinar-finding-answers-faster-genesis-for-private-sector-investigations-2/</guid>
                    </item>
				                    <item>
                        <title>Webinar: Finding Answers Faster: Genesis For Private Sector Investigations</title>
                        <link>https://www.forensicfocus.com/forums/general/webinar-finding-answers-faster-genesis-for-private-sector-investigations/</link>
                        <pubDate>Mon, 21 Sep 2026 15:59:18 +0000</pubDate>
                        <description><![CDATA[Cellebrite&#039;s Matt Goeckel demos Genesis on a real enterprise case - UFDRs, CDRs, documents, audio and video - showing how agentic AI surfaces leads and timelines while linking every finding ...]]></description>
                        <content:encoded><![CDATA[<p><span>Cellebrite's Matt Goeckel demos Genesis on a real enterprise case - UFDRs, CDRs, documents, audio and video - showing how agentic AI surfaces leads and timelines while linking every finding back to its source. </span></p>
<p><span>Watch the full webinar here: https://www.forensicfocus.com/webinars/finding-answers-faster-genesis-for-private-sector-investigations/ </span></p>]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/"></category>                        <dc:creator>Zoe</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/general/webinar-finding-answers-faster-genesis-for-private-sector-investigations/</guid>
                    </item>
				                    <item>
                        <title>A Stab Vest Is Protection. DFIR Resilience Is Not.</title>
                        <link>https://www.forensicfocus.com/forums/general/a-stab-vest-is-protection-dfir-resilience-is-not/</link>
                        <pubDate>Thu, 17 Sep 2026 14:59:32 +0000</pubDate>
                        <description><![CDATA[We would never tell a police officer to face a blade with “resilience” instead of body armour, so why do we expect digital forensic investigators to face repeated trauma with little more tha...]]></description>
                        <content:encoded><![CDATA[<p><span>We would never tell a police officer to face a blade with “resilience” instead of body armour, so why do we expect digital forensic investigators to face repeated trauma with little more than resilience to protect them? </span></p>
<p><span>Read the full article here: https://www.forensicfocus.com/articles/a-stab-vest-is-protection-dfir-resilience-is-not/ </span></p>]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/"></category>                        <dc:creator>Zoe</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/general/a-stab-vest-is-protection-dfir-resilience-is-not/</guid>
                    </item>
				                    <item>
                        <title>Forensic Imaging Is A Workflow Problem, Not Just A Speed Problem</title>
                        <link>https://www.forensicfocus.com/forums/general/forensic-imaging-is-a-workflow-problem-not-just-a-speed-problem/</link>
                        <pubDate>Tue, 15 Sep 2026 10:50:42 +0000</pubDate>
                        <description><![CDATA[Atola TaskForce 2 helps forensic labs reduce imaging backlogs by combining fast parallel acquisition, automation, smarter workflows, and high-speed connectivity to keep evidence moving.
Rea...]]></description>
                        <content:encoded><![CDATA[<p><span>Atola TaskForce 2 helps forensic labs reduce imaging backlogs by combining fast parallel acquisition, automation, smarter workflows, and high-speed connectivity to keep evidence moving.</span></p>
<p><span></span>Read the full article here: <a class="_ymio1r31 _ypr0glyw _zcxs1o36 _mizu194a _1ah3dkaa _ra3xnqa1 _128mdkaa _1cvmnqa1 _4davt94y _4bfu1r31 _1hms8stv _ajmmnqa1 _vchhusvi _kqswh2mm _2rkolb4i _ect4ttxp _syaz13af _1a3b1r31 _4fpr8stv _5goinqa1 _f8pj13af _9oik1r31 _1bnxglyw _jf4cnqa1 _30l313af _1nrm1r31 _c2waglyw _1iohnqa1 _9h8h12zz _10531ra0 _1ien1ra0 _n0fx1ra0 _1vhv17z1" title="https://www.forensicfocus.com/articles/forensic-imaging-is-a-workflow-problem-not-just-a-speed-problem/" href="https://www.forensicfocus.com/articles/forensic-imaging-is-a-workflow-problem-not-just-a-speed-problem/" data-renderer-mark="true" data-is-router-link="false" data-testid="link-with-safety">https://www.forensicfocus.com/articles/forensic-imaging-is-a-workflow-problem-not-just-a-speed-problem/</a><span> </span></p>]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/"></category>                        <dc:creator>Zoe</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/general/forensic-imaging-is-a-workflow-problem-not-just-a-speed-problem/</guid>
                    </item>
				                    <item>
                        <title>Before acquisition: should first response be driven by the observed state?</title>
                        <link>https://www.forensicfocus.com/forums/general/before-acquisition-should-first-response-be-driven-by-the-observed-state/</link>
                        <pubDate>Sun, 13 Sep 2026 06:32:28 +0000</pubDate>
                        <description><![CDATA[When approaching a powered-on computer, one of the first decisions may come before choosing an acquisition method: should the current state be maintained, or deliberately changed?
A running...]]></description>
                        <content:encoded><![CDATA[<p class="PDq2pG_selectionAnchorContainer" data-start="130" data-end="313">When approaching a powered-on computer, one of the first decisions may come before choosing an acquisition method: <strong data-start="245" data-end="313">should the current state be maintained, or deliberately changed?</strong><span class="PDq2pG_selectionAnchor" aria-hidden="true"></span></p>
<p data-start="315" data-end="543">A running system may be unlocked, have encrypted volumes already mounted, contain useful volatile data, maintain authenticated sessions, or depend on network resources that may no longer be available after isolation or shutdown.</p>
<p data-start="545" data-end="754">But maintaining that state is not neutral either. Processes continue to run, logs change, applications write data, synchronization may continue, and remote access or destructive activity may still be possible.</p>
<p data-start="756" data-end="825">This makes the usual options difficult to reduce to a fixed sequence.</p>
<p data-start="827" data-end="943">Network isolation may reduce the risk of remote interference, but it can also break active sessions or dependencies.</p>
<p data-start="945" data-end="1082">Live collection may preserve memory, encryption material and other volatile information, while necessarily introducing its own footprint.</p>
<p data-start="1084" data-end="1266">Shutdown may stop ongoing activity, but it can also destroy volatile state or turn an accessible encrypted system into one that is much harder — or impossible — to access afterwards.</p>
<p data-start="1268" data-end="1420">This makes me wonder whether first-response guidance should begin less with a predefined procedure and more with the <strong data-start="1385" data-end="1419">observable state of the system</strong>.</p>
<p data-start="1422" data-end="1434">For example:</p>
<ul data-start="1436" data-end="1667">
<li data-section-id="1ygu4vv" data-start="1436" data-end="1459">power and lock state;</li>
<li data-section-id="7w119g" data-start="1460" data-end="1490">encryption and access state;</li>
<li data-section-id="1mz8toy" data-start="1491" data-end="1525">mounted local or remote storage;</li>
<li data-section-id="42a9n6" data-start="1526" data-end="1544">active sessions;</li>
<li data-section-id="18tbr7o" data-start="1545" data-end="1568">network dependencies;</li>
<li data-section-id="1geiljt" data-start="1569" data-end="1610">volatile information likely to be lost;</li>
<li data-section-id="1n2rw1l" data-start="1611" data-end="1667">indications of ongoing remote or destructive activity.</li>
</ul>
<p data-start="1669" data-end="1837">The available options could then be compared in terms of what they preserve, what may be lost, what footprint they introduce, and how reversible the decision really is.</p>
<p data-start="1839" data-end="2020">By <em data-start="1842" data-end="1854">reversible</em>, I do not simply mean whether an action can technically be undone. I mean whether the evidential state that existed before the action can realistically be recovered.</p>
<p data-start="2022" data-end="2165"><strong data-start="2022" data-end="2165">For those who regularly deal with powered-on systems: which observable states actually make you change your normal first-response approach?</strong></p>
<p data-start="2167" data-end="2317">And are there situations where you deliberately maintain the current state rather than immediately isolating, collecting, or shutting the system down?</p>
<h3 data-section-id="wo0cxl" data-start="2319" data-end="2344">Interested to hear how others approach this in practice.</h3>]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/"></category>                        <dc:creator>lmolinario</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/general/before-acquisition-should-first-response-be-driven-by-the-observed-state/</guid>
                    </item>
				                    <item>
                        <title>Forensic help needed: locating Tuya/ThingClips IPC Privacy Zone configuration and history</title>
                        <link>https://www.forensicfocus.com/forums/general/forensic-help-needed-locating-tuya-thingclips-ipc-privacy-zone-configuration-and-history/</link>
                        <pubDate>Sat, 12 Sep 2026 08:22:28 +0000</pubDate>
                        <description><![CDATA[I am examining an Android IP camera application with package name:com.fnk.fnkThe APK contains Tuya/ThingClips-related IPC components.Relevant strings/resources found in the APK include:ENABL...]]></description>
                        <content:encoded><![CDATA[<p>I am examining an Android IP camera application with package name:<br /><br />com.fnk.fnk<br /><br />The APK contains Tuya/ThingClips-related IPC components.<br /><br />Relevant strings/resources found in the APK include:<br /><br />ENABLE_PRIVACY_MODE_BUTTON_ATTRIBUTE_ID<br />ipc_set_privacy_mode_switch<br />ipc_set_privacy_zone_settings<br />ipc_private_area_tips<br />privacy_zone_set_point<br /><br />The app data directory is:<br /><br />/data/user/0/com.fnk.fnk/<br /><br />I have confirmed that these functions/resources exist, but I now need help identifying the actual forensic artifacts that store the configuration and history.<br /><br />I am specifically trying to determine:<br /><br />1. Which database, SharedPreferences file, XML/JSON file, device property or DP ID stores Privacy Mode / Privacy Zone / Private Area settings?<br /><br />2. Where are the coordinates or geometry of privacy zones stored?<br />For example x/y values, width/height, rectangle coordinates or polygon points.<br /><br />3. Is there any local Android artifact or cloud/device log showing when a privacy zone was enabled, changed or deleted?<br /><br />4. Can the account or device that changed the privacy setting be identified?<br /><br />5. Is ENABLE_PRIVACY_MODE_BUTTON_ATTRIBUTE_ID likely only a UI feature flag, or could it map to a Tuya/ThingClips device property?<br /><br />6. Does privacy_zone_set_point look like a persisted zone-coordinate function, and where would you expect those values to be stored?<br /><br />I have access to the APK and an extraction of the application files from the phone.<br /><br />Any suggestions for specific databases, SharedPreferences files, SDK classes, DP IDs, log files or forensic artifacts to examine would be greatly appreciated.<br /><br />This concerns forensic examination of an owned camera system.</p>]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/"></category>                        <dc:creator>mixen</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/general/forensic-help-needed-locating-tuya-thingclips-ipc-privacy-zone-configuration-and-history/</guid>
                    </item>
				                    <item>
                        <title>The Sound Of Silence – What Institutional Silence On DFI Well-Being Actually Tells Us</title>
                        <link>https://www.forensicfocus.com/forums/general/the-sound-of-silence-what-institutional-silence-on-dfi-well-being-actually-tells-us/</link>
                        <pubDate>Thu, 10 Sep 2026 15:46:24 +0000</pubDate>
                        <description><![CDATA[When six organisations receive evidence that one in five digital forensic investigators meet the clinical threshold for suicidal or self-harm ideation, and only one responds, what does that ...]]></description>
                        <content:encoded><![CDATA[<p><span>When six organisations receive evidence that one in five digital forensic investigators meet the clinical threshold for suicidal or self-harm ideation, and only one responds, what does that silence say about who is looking out for the profession? </span></p>
<p><span>Read the full article here: https://www.forensicfocus.com/articles/the-sound-of-silence-what-institutional-silence-on-dfi-well-being-actually-tells-us/ </span></p>]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/"></category>                        <dc:creator>Zoe</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/general/the-sound-of-silence-what-institutional-silence-on-dfi-well-being-actually-tells-us/</guid>
                    </item>
				                    <item>
                        <title>Digital vs Computer Forensics</title>
                        <link>https://www.forensicfocus.com/forums/employment-and-career-issues/digital-vs-computer-forensics/</link>
                        <pubDate>Thu, 10 Sep 2026 01:38:13 +0000</pubDate>
                        <description><![CDATA[Hello everyone, I&#039;m current a college freshman getting a AS in Networking/Cybersecurity. I want to be a Computer Forensic Specialist (dealing with criminal&#039;s hard drives using hashing, write...]]></description>
                        <content:encoded><![CDATA[<p>Hello everyone, I'm current a college freshman getting a AS in Networking/Cybersecurity. I want to be a Computer Forensic Specialist (dealing with criminal's hard drives using hashing, write blockers, autopsy, documentation etc.), probably/hopefully working for my state's bureau of investigation. However when researching for what I need educationally (Degrees and Certs) I have found that my field is also often used with the term Digital Forensics, which (if I understand it correctly) leans more towards investigating cyberattacks. While this does sound fun, I would not want to do this for my job, I have a natural incline towards hardware and find it more interesting, no offense to anyone doing this as a job, y'all are awesome for that!</p>
<p>So it begs the question: What is the proper term for the forensics I want to do? And if anyone happens to know it, what degree/certs would I need to do this/that would help me? I appreciate any help I could get, thank you all!</p>]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/"></category>                        <dc:creator>wlygon7</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/employment-and-career-issues/digital-vs-computer-forensics/</guid>
                    </item>
				                    <item>
                        <title>After the decrypt: how do you actually triage a network-scale message set?</title>
                        <link>https://www.forensicfocus.com/forums/general/after-the-decrypt-how-do-you-actually-triage-a-network-scale-message-set/</link>
                        <pubDate>Thu, 03 Sep 2026 17:43:58 +0000</pubDate>
                        <description><![CDATA[Working on triage methods for large communication sets, I keep coming back to a handoff problem that doesn&#039;t get much airtime: the moment cryptographic recovery succeeds and the linguistic p...]]></description>
                        <content:encoded><![CDATA[<p dir="ltr">Working on triage methods for large communication sets, I keep coming back to a handoff problem that doesn't get much airtime: the moment cryptographic recovery succeeds and the linguistic problem begins.</p>
<p dir="ltr">A takedown-scale corpus (think EncroChat or Sky ECC proportions) lands as plaintext: hundreds of thousands of messages, a dozen languages, thousands of participants, no single device owner to anchor the analysis. The technical recovery disciplines have done their job. Now someone has to answer the only question the case team actually has: <em>which conversations do we read first?</em></p>
<p dir="ltr">The reflexive move is keyword search built from the case brief. In my experience it fails in both directions at this scale, too broad and you're handed a hundred thousand hits; too narrow and you miss the case material entirely, because participants have often already adapted their language (codewords drifting into slang, operational-security instructions, deliberate obfuscation — especially post-takedown, when they know the platform is burned).</p>
<p dir="ltr">I've been working on a layered alternative: a source-cited lexicon pass for the first cut, then behavioural/co-occurrence signals to catch the adapted exchanges keywords miss, producing a ranked reading order rather than a binary hit list, with each flag traceable to why it was raised.</p>
<p dir="ltr">But I'm genuinely curious how teams handle this in practice today:</p>
<ol dir="ltr">
<li>When a decrypted network-scale set lands on your desk, what's your actual first move? Case-brief keyword lists? Sampling? Participant-first prioritisation? Something more structured?</li>
<li><span>The question that </span><span>interests me most: if </span><span>a defence team later </span><span>asks </span><em><span>"why wasn't this thread reviewed earlier?"</span><span></span></em><span> What does your </span><span>answer look like? Is </span><span>there a documented </span><span>rationale behind your </span><span>triage order, or does </span><span>it live in the </span><span>examiner's head?</span></li>
</ol>
<p dir="ltr">Happy to compare notes with anyone working the same problem.</p>
<p dir="ltr">/Andreas</p>]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/"></category>                        <dc:creator>antonsen</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/general/after-the-decrypt-how-do-you-actually-triage-a-network-scale-message-set/</guid>
                    </item>
				                    <item>
                        <title>“The Skills And Resilience To Do One Of The Hardest Jobs In Policing” — Why This DFIR Recruitment Language Gets The Evidence Wrong</title>
                        <link>https://www.forensicfocus.com/forums/general/the-skills-and-resilience-to-do-one-of-the-hardest-jobs-in-policing-why-this-dfir-recruitment-language-gets-the-evidence-wrong-2/</link>
                        <pubDate>Thu, 03 Sep 2026 13:28:42 +0000</pubDate>
                        <description><![CDATA[Does recruiting for “resilience” risk putting responsibility in the wrong place? Paul Gullon-Scott looks at what the evidence says about digital forensic well-being, workload and organisatio...]]></description>
                        <content:encoded><![CDATA[<p><span>Does recruiting for “resilience” risk putting responsibility in the wrong place? Paul Gullon-Scott looks at what the evidence says about digital forensic well-being, workload and organisational support, and why the language we use matters. </span></p>
<p><span>Read the full article here: https://www.forensicfocus.com/articles/the-skills-and-resilience-to-do-one-of-the-hardest-jobs-in-policing-why-this-dfir-recruitment-language-gets-the-evidence-wrong/ </span></p>]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/"></category>                        <dc:creator>Zoe</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/general/the-skills-and-resilience-to-do-one-of-the-hardest-jobs-in-policing-why-this-dfir-recruitment-language-gets-the-evidence-wrong-2/</guid>
                    </item>
							        </channel>
        </rss>
		