A round-up of today’s digital forensics news and views:
Forensic Focus News
Block Hash Scan: Illegal File Triage Completed On Site
Block Hash Scan in MD-LIVE divides files into fixed-size blocks and hashes only the blocks needed for matching, so identifying a 40GB video requires reading roughly the same data as a 4GB one. Full-file hash comparison and manual review both scale poorly with modern smartphone storage exceeding 512GB, driving unnecessary seizures and lab backlogs. The approach applies to CSAM investigations, IP theft, malware, and fraud cases, with defined guidance on interpreting zero-detection results.
MISP 2.5.47 Fixes RCE, Adds PostgreSQL Support
MISP 2.5.47 patches 27 confirmed vulnerabilities including a remote code execution reachable by any authenticated user, multiple XSS flaws, access-control bypasses, and an MFA brute-force bypass. A new ledger-based database migration system replaces the historic db_version counter and introduces early PostgreSQL 16 support for fresh installs. AI-assisted analysis enables event summarisation, tag recommendation, and indicator extraction via the ai_connector misp-module.
Tools & Software
GrayKey Claims iOS Inactivity Reboot Bypass
Magnet Forensics has claimed its GrayKey Preserve device and Evidence Preservation Mode can keep seized iPhones in the After First Unlock state, preventing Apple’s 72-hour inactivity reboot from pushing devices back to the harder Before First Unlock encryption state. A leaked law enforcement training video also claims the tools can block iOS from deleting time-limited data including cached locations and recently deleted messages. The mechanism has not been disclosed or independently verified, and Apple has not commented.
PowerShell Tool Automates NetScaler Forensic Timelines
Get-NetScalerTimeline v0.1.0 is a PowerShell script that builds a file system timeline from NetScaler ADC/Gateway VMDK disk images and loads results into DuckDB for SQL-based threat hunting. It auto-detects FreeBSD slices and UFS partitions, extracts web and error logs including rotated archives, and flags log poisoning via CVE-2026-88771. Over 20 built-in queries cover web shells, persistence mechanisms, crash dumps, and CVE IOCs.
AI Skills Toolkit Released for Velociraptor DFIR
A new open-source project, velociraptor-skills, provides reusable AI-guided workflows for artifact selection, collection, hunting, and host analysis using Velociraptor. A Python harness called vraptor standardises token use and analysis output across providers including OpenAI, Azure OpenAI, and Anthropic. The release includes practical security guidance on prompt injection risks from attacker-controlled forensic data and data residency considerations for cloud AI providers.
WEBCQUISITION Automates Forensic Web Acquisition
WEBCQUISITION is an open-source tool that automates web acquisition inside a VMware Workstation Pro Windows VM, handling Wireshark capture, TLS key logging, and screenshot hashing so examiners focus on navigation rather than repetitive setup. Each case produces a PCAPNG, TLS key log, screenshots with metadata, an acquisition JSON, an HTML report, and a hash-chain log verifiable with sha256sum on any machine. SHA-256 verification runs on every file transferred from VM to host, and interrupted sessions are recovered and flagged as INCOMPLETE rather than lost.
Read more (strangerforensics.wordpress.com)
Velociraptor 0.77.3 Fixes Forensic Artifact Bugs
Velociraptor 0.77.3 corrects a long-standing error in Windows.Forensics.Prefetch, which now reads VolumeSerialNumber at offset 16 rather than 12, and fixes registry MULTI_SZ value parsing. New Azure Monitor upload support and corrected NTUser path handling in the registry mail-rules artifact round out the forensic-facing changes.
Incident Response
NetScaler CVE Demands Active Forensic Investigation
A second Citrix emergency patch for CVE-2026-88779 followed exploitation on already-patched NetScaler appliances, with login fields carrying shell commands pulling payloads from a known exfil IP. Responders should collect ns.log, httpaccess logs, support bundles, and crash history before touching affected boxes. Key artifact checks include setuid /bin/sh, unauthorized httpd.conf handlers, unknown ns.conf users, crontab modifications, and outbound connections to 213.209.159[.]55.
Research & Techniques
Safari History Database Reveals Hidden Tag Artifacts
Safari’s History.db contains two underexamined tables, history_tags and history_items_to_tags, that link visited pages to Wikidata-referenced keyword tags, surfacing browsing themes even after history deletion. Tags use a Cocoa timestamp epoch and persist with zero item counts when associated history entries are removed. mac_apt has been updated to parse these tags, giving macOS examiners a new artifact for reconstructing user activity.
Read more (swiftforensics.com)
iOS Unified Log Forensics Workflow for Beginners
Apple’s Unified Log retains unlock traces for roughly one day on active devices, making same-day acquisition critical. A repeatable workflow covers log collection via Mac or UFADE, cryptographic hashing of the logarchive folder, and filtering with iLEAPP and Consolation3 to surface both known and unknown artifacts. When automated tools return nothing, querying the raw log with –info and –debug flags may still reveal hidden entries.
Windows Memory Forensics Acquisition and Analysis Guide
Windows memory forensics requires acquiring a RAM image before shutdown, since volatile data including running processes, network connections, and cached registry keys vanishes when power is cut. Analysts can supplement raw memory with pagefile.sys, swapfile.sys, and hiberfil.sys to recover paged-out or hibernated state. Tools such as Volatility, MemProcFS, bulk_extractor, and YARA-X cover everything from OS structure traversal to pattern-based IOC hunting across binary images.
Open-Source ICAC Cross-Case Analysis Tool Launches
CaseLinker, an open-source knowledge representation system for ICAC investigations, now supports MCP, a SPARQL endpoint, and programmatic access across 10,362 public case records and 700+ federal court cases. A companion Exploitation State Machine models offender phase progression using affordance-based action transitions and Markov decision processes, offering investigators a structured framework for pattern analysis.
Forensic Timelines Need Smarter Clustering
Modern forensic and EDR tools have commoditized timeline analysis, but massive file-copy migrations and multi-iteration web directories create distortions that flat chronological views miss. Clustering atomic events by attributed intent, detecting web shells across backup directories, and distinguishing red-team activity from threat actor behavior are areas where current tooling still falls short.





