A round-up of today’s digital forensics news and views:
Forensic Focus News
S21 Transcriber: Turn Spoken Evidence Into Searchable Intelligence
S21 Transcriber, from Semantics 21, converts audio and video recordings into searchable, reviewable text entirely offline, removing the need for manual listen-and-type workflows. Investigators can search key phrases across recorded material, compare passages and extract content for reporting without replaying entire recordings from start to finish.
Tools & Software
Scalpel3 Reconstructs Fragmented Files from Wiped Devices
Louisiana State University researchers have released Scalpel3, an open-source tool that automatically reconstructs fragmented files from damaged or deliberately wiped storage media. Backed by NSA, NSF, Oak Ridge National Laboratory, and NIST, the tool addresses a longstanding challenge in file carving that has direct implications for criminal investigations and national security cases.
Raml KQL Queries Multiple Sentinel Tenants Simultaneously
Raml KQL is a free, open-source desktop app for macOS, Windows, and Linux that lets analysts run a single KQL query across multiple Azure Log Analytics and Microsoft Sentinel workspaces spanning different Entra tenants and accounts. Results are merged into one view, with each row attributed to its source tenant and workspace, making cross-customer log review faster for IR analysts without a Defender multi-tenant organization. A built-in audit log, sandboxed extensions, and Monaco editor with schema-aware IntelliSense round out the feature set.
Forensic OSINT Extension Adds Keyword Alerts
Version 3.7.0 of the Forensic OSINT browser extension introduces Keyword Alerts, letting investigators add names, usernames, and aliases to a case profile and receive real-time matches as they browse. Hits appear in a side panel with jump-to navigation and peek previews, without altering the underlying page. A dark theme for the popup, side panel, and Case Management System also ships in this release.
Research & Techniques
Project Zero Explains Emergency Patch Delivery Systems
Google Project Zero has published guidance on how large software vendors can remediate critical vulnerabilities faster than standard update cycles, covering feature flags, filtering, and dual-stack library approaches. Bottlenecks in testing and delivery, not triage or development, are identified as the primary limiting factors in emergency patch timelines. Vendors are encouraged to design rapid-response patching capability before an urgent zero-day forces the issue.
Read more (projectzero.google)
Training & Events
Live Deepfake Detection Demo for DFIR Labs
AI-generated media and GAN deepfakes pose growing challenges for digital investigators handling potential evidence. Security researcher Mike Raggo will demonstrate over a dozen detection techniques for exposing altered media and forged artifacts at the PFIC Fall Session on November 19th.
Read more (pfic-conference.com)
IACIS Opens Mark Baker Memorial Scholarship
IACIS has opened applications for the inaugural Mark Baker Memorial Scholarship, honoring a figure known for mentorship and service to the DFIR community. The recipient receives fully funded IACIS training and lodging, with access to BCFE or specialized digital forensics courses. Applications close November 30.





