This Week on Forensic Focus
Belkasoft X For Mobile Forensics: Acquisition, Analysis, And Reporting
Explore Belkasoft X as a mobile forensics tool for iOS and Android acquisitions, full-file-system extraction, data recovery, application analysis, and reporting.
MSAB Technology Helps Uncover International Fraud Network And Provides Answers To A Grieving Family
Discover how MSAB’s XRY Pro and BruteStorm Surge helped unlock crucial digital evidence, expose an international fraud operation and bring long-awaited answers…
Elsewhere in DFIR
- 1
LSU Releases Scalpel3 for Fragmented File Recovery
LSU researchers have released Scalpel3, the first open-source tool capable of automatically reconstructing fragmented files from damaged or wiped storage media at scale. Built on a massively parallel architecture with an integrated ML model trained on 619 file types, it solved the DFRWS 2006 and 2007 grand challenges, reconstructing every fragmented file. The NSA has awarded the team $750,000 for continued development. Read more (lsu.edu)
- 2
SQLite GUI Analyzer Adds Timestamp Conversion, Relationship Graph
SQLite GUI Analyzer has released a new version with dark mode, a table relationship graph, and right-click timestamp conversion supporting Unix, Chrome, FILETIME, and Mac time formats. It recovers deleted records from WAL files and freed pages, decodes BLOBs, and searches all tables simultaneously without modifying the source database. A Windows installer removes the Python setup requirement. Read more (github.com)
- 3
Mobile Forensics Cross-Examination Lessons from Gatlin Case
A forensic analysis of the Ahmed Gatlin case examines how mobile phone evidence, cloud storage, and app-specific location permissions were challenged during cross-examination. Gaps in phone activity data do not independently confirm whether a device was off, idle, or simply not logging, a distinction courts increasingly scrutinize. Expert witnesses should bring reports to court and understand the legal basis for device access before testifying. Read more (open.spotify.com)
- 4
Android Advanced Protection Adds Forensic Logging Feature
Google has introduced Intrusion Logging to Android's Advanced Protection suite, a mobile-industry first that stores end-to-end encrypted security and network events in the cloud for up to 12 months, enabling forensic investigation of suspected device compromises. Additional features include USB Protection against juice-jacking and hardware attacks, Accessibility Protection restricting API abuse, and Failed Authentication Lock to counter brute-force attempts on seized devices. Read more (blog.google)
- 5
AI Skills Toolkit Released for Velociraptor DFIR
A new open-source project, velociraptor-skills, provides reusable AI-guided workflows for artifact selection, collection, hunting, and host analysis using Velociraptor. A Python harness called vraptor standardises token use and analysis output across providers including OpenAI, Azure OpenAI, and Anthropic. The release includes practical security guidance on prompt injection risks from attacker-controlled forensic data and data residency considerations for cloud AI providers. Read more (labs.infoguard.ch)





