A round-up of today’s digital forensics news and views:
Forensic Focus News
Finding Answers Faster: Genesis For Private Sector Investigations
Cellebrite’s Matt Goeckel demos Genesis on a real enterprise case – UFDRs, CDRs, documents, audio and video – showing how agentic AI surfaces leads and timelines while linking every finding back to its source.
Research & Techniques
AFF4-L Standard Gains Container Hash Support
The Advanced Forensic Format (AFF4-L) standard has been updated to support logical file container hashes, strengthening evidence integrity verification for digital forensic acquisitions. Container-level hashing allows examiners to verify the authenticity of an entire logical container rather than relying solely on individual file hashes, closing a gap in the existing standard.
Field Video Acquisition Protocol for CCTV Evidence
Crime scene investigators increasingly encounter digital video evidence requiring disciplined acquisition protocols, yet field personnel often rely on informal exports or smartphone recordings of monitors. Three acquisition tiers cover closed-box DVR export, direct network access, and write-blocked disk imaging, with cryptographic hashing at each stage to protect chain of custody. Cloud-sourced footage from Ring or Nest systems carries transcoding risks that can silently degrade evidential quality.
XRY Tutorial Covers Limited Extraction Methods
Mobile forensic examiners working under warrant restrictions or time pressure can use XRY’s limited extraction modes to narrow scope without sacrificing precision. Two approaches are available: logical extraction with time frame and category filters, and targeted file selection by navigating device storage paths such as DCIM/Camera.
Threat intelligence via tools
LOLRMM Adds Lavawall RMM Artifact Entry
A new pull request to the LOLRMM project documents Lavawall, ThreeShield’s RMM platform, with Windows forensic artifacts covering services, registry keys, extracted assemblies, network endpoints, and Authenticode hashes. Four Sigma detection rules accompany the entry, and signed agent samples are noted to appear under Zoom and Adobe installer names, a masquerading tactic relevant to investigations. Renamed agents can evade filename matching, so registry, network, and signing context are provided as alternative detection anchors.
Training & Events
DC3 Trains Investigators in Drone Forensics
Military investigators are increasingly treating drones as digital evidence sources, recovering SD cards, internal storage, flight logs, and imagery to reconstruct criminal activity. DC3’s Cyber Training Academy runs a five-day course covering drone platforms, including homemade builds, hands-on flight data capture, and forensic analysis of that data. The Defense Cyber Crime Center warns that technical expertise and partnerships must be built now, before drone-related casework becomes routine.





