Digital Forensics Round-Up, September 02 2026

A round-up of this week’s digital forensics news and views:


Industry News

SANS Releases AI Frameworks for DFIR Practice

SANS Institute has backed two new frameworks — DF+AI and IR+AI — mapping AI usage to established digital forensics and incident response phases, with associated risks for each. Designed for trained examiners and analysts, the frameworks treat AI as an augmentation tool requiring human oversight, not a replacement for qualified personnel. A second phase covering case types and scenarios is already in development.

Read more (smarterforensics.com)


Tools & Software


Get The Latest DFIR News

The monthly Forensic Focus newsletter, plus webinar invitations and occasional research surveys.

Unsubscribe or change what you receive at any time. We respect your privacy: read our privacy policy.


AI DFIR Hackathon Winners Released on GitHub

Three open-source AI investigation harnesses took top honours in the Find Evil! Hackathon, drawn from 291 submissions and evaluated by 90 expert judges. Winner Mulder uses a five-phase adversarial self-contradiction pass before committing findings to a report, while TRUDI reasons across eight-host APT scenarios in causal chains and Camel enforces full command-level reproducibility. Mulder is slated for integration into the SIFT Workstation.

Read more (linkedin.com)


Industry News

Toll of Cumulative Trauma on Digital Forensic Investigators Explored

Digital forensic investigators routinely examine thousands of CSAM files per case, endure cumulative trauma exposure that is the working day itself — not an interruption to it. Findings from the Forensic Focus International Well-Being Study show clinically significant rates of PTSD, anxiety, and depression among practitioners across multiple countries. Organisational pressures — chronic understaffing, crushing backlogs, and stigma around disclosing distress — compound the harm, leaving those most exposed least likely to seek help.

Read more (forensicfocus.com)


Research & Techniques

Untappd Android App Forensic Artifacts Revealed

Android forensic analysis of the Untappd beer check-in app uncovers user profile data, device analytics, and cached location coordinates stored across several SQLite databases and a gzip-compressed HTTP cache. Cached check-in records expose timestamps, venue details, and photo URLs, while device_attributes entries reveal approximate IP-based geolocation and network type at time of use. Parsers for all identified artifacts have been added to ALEAPP.

Read more (stark4n6.com)


Tools & Software

Peach Tool Brings Unified Log Analysis Across Platforms

Peach is a new open-source log analysis tool built for digital forensic practitioners, supporting Apple Unified Logs, EVTX, journald, and text-based log formats within a single session-based workbench. Developed as an extension of the crush forensics ecosystem, it offers persistent sessions, tagging rules in TOML format, and direct integration with iOS full filesystem extractions. Version 0.4.0 introduces versioned rule packages via a dedicated peach-rules repo, with manual download support for air-gapped environments.

Read more (bebinary4n6.blogspot.com)


Research & Techniques

macOS Unified Log Reveals Unlock Method Artifacts

The macOS Unified Log records distinct keybag state transitions — locked→inBioUnlock for Touch ID and locked→unlocked for password — that reliably identify how a Mac was authenticated without requiring inference. On Apple Silicon running macOS 26.6.2, biometrickitd logs match results including a template UUID potentially identifying which enrolled finger was used, while secure event input prevents keystroke content from being recovered. Cross-subsystem millisecond ordering is unreliable for event sequencing, a critical caution for examiners building authentication timelines.

Read more (thesisfriday.com)


Tools & Software

crush Forensics Workbench Reaches v0.17.0

crush, an open-source desktop workbench for digital forensic analysis, has released v0.17.0 after four months of community-driven development. The tool supports inspection of ZIP, TAR, 7z archives, iTunes and Android backups, and parses formats including SQLite, ABX, SEGB, PLIST, REALM, Protobuf, and more within a single GUI.

Read more (github.com)


Tools & Software

macos-collector v1.7.0 Adds UAC and Biome Collection

LETHAL-FORENSICS has released macos-collector v1.7.0, adding forensic artifact collection via UAC (Unix-like Artifacts Collector) by Thiago Lahr and Biome data collection including Biome Timeline support by Mahmoud Swelam. Users can now specify custom output paths, improving workflow flexibility for macOS investigations.

Read more (github.com)


Tools & Software

HEART Tool Adds ECG and Apple Health Artifacts

HEART by Metadata Forensics v2.1.0.2 expands Apple Health artifact support with four new data types: Medical ID, handwashing, toothbrushing, and ECG recordings. ECG data is processed and rendered as visual waveforms, giving mobile forensic examiners a clearer path to reviewing cardiac data from iPhone extractions.

Read more (github.com)


Tools & Software

Open-Source Tool Pseudonymizes Logs Before External Sharing

SOC Prime's LogTotal Phase I sanitizes sensitive log fields — hostnames, IPs, usernames, tokens — before logs leave an environment, using consistent pseudonymization so attack chains and timelines remain intact. Released under Apache 2.0, it runs online without login, locally, or fully air-gapped for strict privacy requirements.

Read more (logtotal.com)


Industry News

4n6 App Finder Adds iTunes Backup Blind Spots

A new 'Blind Spots' feature added to the 4n6 App Finder tool parses iTunes backup info.plist files entirely client-side in the browser, helping mobile examiners identify gaps in their extractions. The tool includes a sample plist from Josh Hickman's public iOS 15 image for immediate testing, with additional file sources planned.

Read more (4n6appfinder.habben.net)


Research & Techniques

Hibernation Recon Tool Analyzes Windows Artifacts Free

Arsenal Recon's Hibernation Recon offers free core functionality for analyzing Windows hibernation files, demonstrated against the publicly accessible TechHive Windows on Arm disk image scenario. Hibernation analysis is a valuable forensic technique for recovering memory-resident artifacts and user activity from hiberfil.sys.

Read more (arsenalrecon.com)

Leave a Comment