A round-up of this week’s digital forensics news and views:
Research & Techniques
Forensic Artifact Guide PDF for OpenAI Platforms Released
Frontier Forensics has published a platform-by-platform breakdown of evidence left by AI systems, starting with ChatGPT Workspace and the OpenAI API. Coverage maps what gets logged, where artifacts reside, what logging must be enabled before an incident, and how quickly data expires. Claude, Gemini, and Copilot coverage follows in subsequent releases.
Read more (go.invictus-ir.com)
Industry News
DFIR Well-Being Study Results Explored
Repeated exposure to traumatic digital evidence carries measurable psychological consequences for forensic investigators. Phil Anderson returns to the Forensic Focus Podcast to unpack further findings from the international well-being study, exploring impact, coping mechanisms, and support structures across the DFIR community.
Research & Techniques
Apple Screen Time Artifacts Mapped for iOS Forensics
Apple Screen Time artifacts stored in RMAdminStore-Local.sqlite can yield hourly usage summaries, category totals, pickup counts, notification counts, and timed app activity linked to specific bundle identifiers and Apple account profiles. These records support timeline reconstruction and user behavior analysis when correlated with location data, browser history, and system logs.
Tools & Software
Simson Garfinkel’s bulk_extractor 2.2.0 Beta Released on GitHub
bulk_extractor beta 2.2.0 is now available on GitHub, closing more than 100 open issues while improving reliability and performance. The open-source forensic carving tool is widely used by DFIR practitioners for extracting artifacts from disk images and memory dumps without full parsing.
Training & Events
RAM Artefacts Reveal Phone Location Without GPS
Smartphones passively log nearby Wi-Fi, Bluetooth, and cellular signals, leaving transient memory artefacts that can reconstruct device movements even when traditional location data is absent. An upcoming SANS DFIR Europe Summit 2026 session will demonstrate how wireless signal data recovered from RAM can be converted into actionable investigative evidence.
Case Studies
Cellebrite Explores Ten Best Practices for AI-Assisted Investigations
Legal and compliance teams using AI for investigations must prioritize governance, traceability, and documented human oversight to ensure findings hold up in court or regulatory review. Cellebrite’s Head of AI Innovation Center outlines ten practices — from piloting narrow use cases to involving stakeholders before deployment — that define defensible AI-assisted investigations. Strong documentation, data security controls, and a culture of governed experimentation separate organizations that succeed with AI from those that struggle with adoption.
Training & Events
ICMDE Mobile Forensics Certification Explained
The ICMDE (Infosec Certified Mobile Device Examiner) certification targets digital forensics professionals specialising in mobile investigation across iOS and Android platforms. Key exam requirements, scope, and preparation considerations are covered for practitioners weighing mobile forensics credentials.
Industry News
Atola Technology Explores How to Fix the Forensic Imaging Backlog Bottleneck
Over 25,000 devices are awaiting examination in UK policing labs, and imaging speed determines how fast any case can progress. Drive type, cable quality, network configuration, and imaging settings all act as potential bottlenecks — and any one of them can cap throughput regardless of how fast other components are. Practical fixes include diagnosing drives before imaging, testing cables with real transfers, enabling Jumbo Frames on lab networks, and choosing output formats and hash algorithms based on drive condition.
Research & Techniques
DOJ-Funded Research Explores IoT Forensic Evidence
A George Mason University researcher discusses DOJ-funded work on extracting digital evidence from IoT devices, including smartwatches and other connected consumer hardware. As IoT devices proliferate, they are emerging as significant sources of forensic artifacts capable of supporting event reconstruction and courtroom testimony.
Read more (tdonnel.podbean.com)
Tools & Software
Chainsaw v2.16.5 Fixes Output Regression
WithSecureLabs has released Chainsaw v2.16.5, patching a regression that caused incorrect output flushing behaviour. Chainsaw is a widely used open-source tool for rapidly searching and hunting through Windows event logs during DFIR investigations.





