Digital Forensics Round-Up, August 12 2026

A round-up of this week’s digital forensics news and views:


Research & Techniques

NIST Launches Digital Forensics Artifact Catalog ArtCat

NIST has publicly released the Digital Forensics Artifact Catalog (ArtCat), a curated, community-driven resource designed to standardize how digital forensic artifacts are identified and interpreted. Originally led by CKE founder Eoghan Casey, ArtCat turns practitioner knowledge into structured, shareable scientific infrastructure.

Read more (cke-ltd.com)


Case Studies


Get The Latest DFIR News

The monthly Forensic Focus newsletter, plus webinar invitations and occasional research surveys.

Unsubscribe or change what you receive at any time. We respect your privacy: read our privacy policy.


Heather Barnhart Details Kohberger Digital Forensics Methodology

Heather Barnhart, working pro bono with FBI support backed by SANS and Cellebrite, has published a detailed account of the digital forensic investigation into the Idaho student murders. Key findings include a CTF device that matched Bryan Kohberger's carrier exactly and recoverable errors in his digital cleanup attempts. Barnhart also addresses how the absence of plain-text motive can itself constitute meaningful forensic evidence.

Read more (linkedin.com)


Industry News

Trauma or Misconduct? Policing Must Decide

Forensic Mental Health & Well-being Lead Paul Gullon-Scott examines how cumulative trauma and organisational stress in policing and digital forensics can manifest as conduct breaches before being recognised as psychological injury. Drawing on peer-reviewed research, he argues that neurobiological dysregulation from chronic exposure impairs judgement and impulse control in ways organisations routinely misread as attitude or performance problems. He calls for trauma-informed early intervention systems that address misconduct risk before formal proceedings compound existing harm.

Read more (forensicfocus.com)


Research & Techniques

VW MIB2 Infotainment Forensics Paper Published

A new peer-reviewed paper in Forensic Science International: Digital Investigation details an alternative, tool-free acquisition method for the Volkswagen MIB2 infotainment system, alongside a structured walkthrough of data artefacts, volatile memory, and crash logging. Parsing support via the open-source VLEAPP project extends access for investigators without commercial tooling. Practitioners handling criminal casework are advised to review the authors' limitations section before applying the methodology across different MIB2 software revisions.

Read more (sciencedirect.com)


Industry News

Running Offline AI On Evidence With BelkaGPT

Belkasoft X's BelkaGPT feature enables investigators to run forensics-specific AI entirely offline, keeping sensitive case data off external servers. It supports analysis across images, audio, video, and chat data, aiming to accelerate examinations without compromising security.

Read more (forensicfocus.com)


Tools & Software

ALEAPP Now Parses Android Intrusion Logs

Android's new intrusion logging feature, part of Advanced Protection Mode, captures security events, DNS queries, and connection data that examiners can run IOC checks against. ALEAPP now includes parser support for these JSON-format logs, with acquisition possible via manual export, MVT, or the newly updated ALEX tool from Christian Peter.

Read more (stark4n6.com)


Research & Techniques

Pass-ta-key Attacks Leave Concrete Forensic Artifacts

Unit 42 research describes three passkey attack variants targeting Google-synced credentials in Chrome on Windows, none of which break WebAuthn cryptography but instead exploit trust assumptions in device onboarding and UV-flag validation. Forensic artifacts include LevelDB reads from Chrome's Sync Data store, unexpected modification or deletion of passkey_enclave_state, and a transiently plaintext security domain secret in Chrome's process memory. Detection centers on process-access telemetry, file-integrity monitoring on passkey state files, and memory acquisition timed to re-enrollment events.

Read more (andreafortuna.org)


Research & Techniques

Decrypting BitLocker Clear-Key Images With Dislocker

When a BitLocker partition uses a Clear Key, the key material is embedded within the image itself, eliminating the need for an external password or recovery key. Practitioner Pieces0310 walks through identifying the "-FVE-FS-" signature, converting an E01 to raw format, and using dislocker and bdeinfo/bdemount to produce a mountable, decrypted NTFS image on Linux.

Read more (forensicfocus.com)


Tools & Software

Seven Tools DFIR Investigators Find in Data Exfil Cases

Attackers routinely abuse legitimate utilities — SCP, curl, Rclone, RMMs, and cloud storage clients — to quietly move stolen data, and each leaves distinct forensic artifacts. This roundup maps seven common exfiltration tool categories to investigation resources, covering WinSCP, AnyDesk, WinRAR, Restic, and Dropbox with linked case examples and methodology. Examiners responding to data theft incidents can use the references to target artifact collection and analysis for each tool class.

Read more (elastic.co)


Industry News

AI Redefines DFIR Expertise Standards

As AI tools lower the barrier to building functional forensic software, the question of what separates a genuine expert from a capable hobbyist becomes urgent. LEAPPs argues that access to AI is not the differentiator — five distinct professional qualities are, framing a timely debate about competence and credibility in the field.

Read more (leapps.org)


Case Studies

Private APN Pivot Shuts Polish CHP Turbine

Attackers reached a Polish combined heat and power plant's Siemens PLCs through a private cellular APN by pivoting from a compromised wind-farm FortiGate, using SSH tunneling and default WAGO credentials — no malware required. CERT Polska, disclosing the December 2025 incident in August, identifies this as the first confirmed real-world attack through a private APN. Every destructive step used legitimate device functions over native OT protocols.

Read more (thehackernews.com)


Tools & Software

Velociraptor 0.76.7 Backports Security Fixes

Velociraptor has released version 0.76.7, a backported patch for the 0.76 branch addressing CVEs identified during the 0.77.2 release cycle. Practitioners running the stable 0.76 branch should update to remediate the disclosed vulnerabilities.

Read more (github.com)


Industry News

Eight Years of Atola TaskForce Innovation

Atola TaskForce has evolved over eight years into a comprehensive forensic acquisition platform, adding record-breaking imaging speeds, automated RAID reconstruction, and 50 Gbit/s networking. The piece traces how each development was designed to eliminate emerging investigator bottlenecks.

Read more (forensicfocus.com)


Training & Events

Crypto Forensics Webinar Covers Blockchain Tracing Workflow

A free webinar led by former HSI Supervisory Special Agent Robert Whitaker offers a forensically defensible workflow for multi-hop cryptocurrency tracing, mixer recognition, and court-ready taint methodologies. Attendees will also learn off-chain deconfliction strategies to prevent multi-agency operations from compromising active leads.

Read more (live.avairy.events)

Leave a Comment