Digital Forensics Round-Up, August 05 2026

A round-up of this week’s digital forensics news and views:


Research & Techniques

Android 16 Intrusion Logging: What Examiners Get

Android 16’s Intrusion Logging, tested on live Pixel hardware, produces encrypted, cloud-backed security bundles retained for 12 months — surviving device wipes. Bundles contain per-app DNS lookups, connection events with destination IPs and ports, and security events including process launches with SHA-256 hashes and full ADB command histories. Encrypted DNS-over-HTTPS traffic from apps like Chrome remains a blind spot, as those resolvers bypass the system logger entirely.

Read more (iverify.io)


Training & Events


Get The Latest DFIR News

The monthly Forensic Focus newsletter, plus webinar invitations and occasional research surveys.

Unsubscribe or change what you receive at any time. We respect your privacy: read our privacy policy.


Webinar: Mastering the First 60 Minutes On Scene

ADF Solutions’ Director of Training Richard Frawley leads a webinar on maximising the first hour of a digital evidence scene, covering pre-planning, evidence preservation, and on-scene triage decisions. Drawing on 23 years in law enforcement, Frawley addresses pitfalls such as tipping off suspects and walks through mobile and computer triage workflows aimed at producing actionable intelligence.

Read more (forensicfocus.com)


Industry News

NCSC Pushes Forensic Observability for Network Devices

The UK’s NCSC is calling on network device vendors to build reliable forensic capabilities — including logging, memory acquisition, and configuration state collection — directly into products like firewalls and VPN gateways. Too many edge devices still force incident responders to rely on reverse engineering or unsupported techniques, leaving defenders with fewer investigative tools than attackers. NCSC has published a reference architecture for forensic observability and is encouraging buyers to include forensic capability as an evaluation criterion.

Read more (ncsc.gov.uk)


Industry News

DFI Mental Health Support Falls Short

Paul Gullon-Scott, Forensic Mental Health & Well-being Lead at Spectrum Specialist Consultancy, attended Forensics Europe Expo 2026 to gauge real-world psychological support for digital forensic investigators — and found consistent, systemic failures. Across multiple conversations, investigators described psychometric assessments completed alone via email, binary fit/unfit verdicts with no clinical dialogue, and therapy capped at six sessions regardless of career-long cumulative trauma exposure. Drawing on findings from the Forensic Focus Well-Being Study 2026, Gullon-Scott argues the current model functions as gatekeeping rather than genuine care, and calls for commissioning-level reform.

Read more (forensicfocus.com)


Industry News

GrapheneOS Duress Password Poses Examiner Challenges

A forensic analysis of the Samuel Tunick case examines whether a GrapheneOS duress password was used and what artifacts that leaves for examiners. GrapheneOS’s duress PIN feature wipes the device on entry, creating significant challenges for acquisition and evidence interpretation in criminal proceedings.

Read more (blog.siliconprairiecyber.com)


Research & Techniques

P.E.T. Guide Reveals Forensic Artifacts in Privacy Apps

A practitioner-oriented analysis of the P.E.T. Guide examines how privacy-focused messaging platforms — Signal, Telegram, Briar, and Cwtch — differ in metadata exposure, server-side logging, and artifact recoverability. Briar and Cwtch’s Tor-routed, serverless architectures shift investigative strategy entirely to endpoint acquisition, while Signal and Telegram leave more recoverable traces than their reputations suggest. Understanding the threat models that privacy-aware subjects use maps directly onto designing realistic acquisition and attribution strategies.

Read more (andreafortuna.org)


Legal & Policy

Jessica Hyde on Daubert, AI, and Peer Review

Jessica Hyde concludes a two-part podcast discussion on the Daubert standard, AI use in digital forensics casework, and peer review practices. These topics directly affect how examiners present and defend findings in court.

Read more (open.spotify.com)


Industry News

Vendor Capability Gaps Undermine Mobile Forensic Standards

A mobile forensics expert flagged a case where a local vendor performed only an advanced logical extraction despite full file system extraction being supported by available tooling. The gap between what a vendor can do and what the technology actually supports has direct implications for evidence completeness and expert testimony. For DFIR practitioners, the distinction matters: device support is defined by the broader tool ecosystem, not a single examiner’s toolkit.

Read more (linkedin.com)


Research & Techniques

Forensic Analysis of Skout and MeetMe Databases

A new blog post examines database artifacts from Skout and MeetMe, two chat and social-discovery apps that appear underserved by major forensic tools. Examiners working cases involving these platforms may find the SQL query guidance and artifact locations directly applicable to their investigations.

Read more (northloopconsulting.com)

Leave a Comment