Forensic Focus Forum Round-Up

Welcome to this month’s round-up of recent posts to the Forensic Focus forums.

How would you recover a $J file from a UsnJrnl file in a shadow copy?

Forum members discuss containing and recovering a malware infected server.

Share your tips for carving an .H264 video format on the forum.

Can you help Pachuco to find a blank PDF file?


Get The Latest DFIR News

The monthly Forensic Focus newsletter, plus webinar invitations and occasional research surveys.

Unsubscribe or change what you receive at any time. We respect your privacy: read our privacy policy.


How would you find out whether the ‘reset this PC‘ option has been used on a Windows machine?Forum members discuss how to decrypt Android dumps with Oxygen Forensic Detective.

What tools would you recommend for browser forensics?

Forum members discuss ACPO / NPCC guidelines.

How would you work out when a system last hibernated?

Forum members suggest free video enhancement software.

Leave a Comment