A round-up of today’s digital forensics news and views:
Research & Techniques
iOS Unified Log Retention Varies Dramatically by Device Activity
Controlled testing on two iPhones running iOS 26.6.2 shows that kernel-level unlock artefacts vanish from the Unified Log within 13 hours on a busy device but persist beyond 87 hours on an idle one. Only ChronoServices lines, which carry an explicit time-to-live value, survived on the active phone, yet even that TTL proved unreliable as a retention predictor on the idle reference device. Examiners cannot assume a fixed retention window when reconstructing unlock timelines from log archives.
Mac Forensics Best Practices Guide Updated for macOS 27
A fully updated Mac Forensics Best Practices Guide for 2026, authored by Steve Whalen, covers material changes in macOS 27 relevant to examiners, including revised Full Disk Access and TCC restrictions, image file formats, and upcoming feature deprecations. Guidance is aligned with SWGDE published standards, making it applicable across experience levels.
Tools & Software
Strata: Open-Source macOS DFIR Triage Tool
Strata is a native macOS triage tool that ingests disk images (E01, VMDK, VHD, raw dd) and loose KAPE/UAC folders, parses artifacts across Windows, Linux, and macOS, and builds a MACB super-timeline from over 30 sources. Sixty-one ATT&CK-tagged detection analyzers feed a Cyber Kill Chain view, lateral-movement graph, and IOC matching engine, all statically linked with no runtime dependencies. An on-device AI case summary validates every claim against real findings before output.
RLEAPP Adds Instagram Artifact Support
RLEAPP now parses Meta’s current Instagram data return format, extracting 25 artifact types including messages displayed as conversations with inline photos, videos, and voice notes. The update is merged and available immediately via the GitHub codebase, ahead of a formal release. The developer notes potential compatibility with other Meta products, pending community testing.
crush-forensics v0.20.0 Adds EWF and Raw Image Support
crush-forensics v0.20.0 can now open raw disk images and EWF acquisitions (.img/.dd, split .001, .E01) directly, covering NTFS, APFS, and QNX filesystems without separate mounting tools. iOS investigators gain a beta Get Installed Apps analyzer ported from LEAPPs, aiding app install path resolution. The release also adds C2PA/XMP AI-provenance detection in the Image Viewer.
Case Studies
Multi-Stage Malware Loader Unpacked Step by Step
A TrustedSec researcher walked through unpacking a six-stage malware loader that chains obfuscated Python bytecode, Donut shellcode, and laZzzy PE injection into encrypted .NET payloads. Each layer required separate tooling, including a modified brute-force deobfuscator and Volexity’s donut_decryptor, with custom scripts written to fill gaps in public tooling. AES-CBC with an XOR layer protects the laZzzy stage, and static analysis in Ghidra guided extraction at each step.
Industry News
dfir.blog Relaunches as Hindsight Foundry
The browser forensics research site dfir.blog has relaunched as Hindsight Foundry, a dedicated hub for browser artifact analysis, open-source tooling, and related investigative resources. Practitioners who rely on browser history and artifact examination will find a consolidated home for ongoing research and tool development in this space.
Training & Events
SANS Webcast Covers Attacker Persistence on Network Devices
Network infrastructure devices such as routers, switches, and firewalls run Linux but typically lack EDR coverage and consistent logging, making them attractive targets for persistent attackers. Jim Clausing will present a free SANS webcast on 12 October 2026 examining how attackers establish footholds on these devices and what recent incidents reveal about the techniques involved.





