Corrobora – Cross-Artifact Consistency Analysis For Windows Digital Forensics

Hero Image

Dielle De Noon explores the development and validation of two key components of her open-source Windows digital forensics framework and how they lay the foundation for future cross-artifact correlation....

Today's headlines 25 Sep 2026

Go Beyond The Basics With XRY Kiosk From MSAB

Go Beyond The Basics With XRY Kiosk From MSAB

Go beyond the basics with XRY Kiosk - extract logical, full file system, physical and RAM data through controlled, compliant workflows built for fast frontline forensics....read more

How Semantics 21 Is Calling Time On Add-On Culture In Digital Forensics

How Semantics 21 Is Calling Time On Add-On Culture In Digital Forensics

Investigative capability shouldn’t be split across licences, modules and bolt-ons - S21 VisionX brings visual review, prioritisation and victim identification into one intelligence-led platform....read more

Magnet Forensics Expands Collaboration With NCMEC To Strengthen Victim Identification

Magnet Forensics Expands Collaboration With NCMEC To Strengthen Victim Identification

Coming soon to Magnet Griffeye: new capabilities will enable investigators to securely share CSAM-related files, hashes and investigative information directly with NCMEC, helping streamline workflows and support faster child victim identification....read more

Book Review: Mastering Windows Network Forensics and Investigations

Mastering Windows Network Forensics and Investigations fills an interesting niche not well addressed in the pantheon of digital forensics resources. The material is well suited for beginning and intermediate forensic examiners looking to better understand network artifacts and go beyond

X1 Discovery and the National White Collar Crime Center Fight Cybercrime

X1 Discovery, the leader in software solutions for social media and website evidence search and collection, along with the National White Collar Crime Center (NW3C), an internationally recognized leader in education and support in the prevention and prosecution of high

Guidance Software Ranked #1 in E-Discovery Software Buyer’s Guide

Guidance Software Inc. has announced that its EnCase(R) eDiscovery software was ranked #1 out of more than 20 vendors in the inaugural DCIG E-Discovery Early Case Assessment (ECA) Buyer’s Guide. For the Buyer’s Guide, DCIG looked at more than 60

Book Review: Mastering Windows Network Forensics & Investigations

Mastering Windows Network Forensics and Investigations fills an interesting niche not well addressed in the pantheon of digital forensics resources.  The material is well suited for beginning and intermediate forensic examiners looking to better understand network artifacts and go beyond

Authenticating Internet Web Pages as Evidence: a New Approach

Previously, in Forensic Focus, we addressed the issue of evidentiary authentication of social media data. General Internet site data available through standard web browsing, instead of social media data provided by APIs or user credentials, presents slightly different but just

Interview with Jess Garcia, founder of One eSecurity

Let's say we're looking at a cyber-crime scene comprised of several still powered on computers as well as confiscated smartphones. When the forensic investigator arrives, what does his workflow look like? Mobile devices are typically the most volatile of all

Forensic Examination of FrostWire version 5

Introduction As digital forensic practitioners, we are faced regularly  with users utilizing the internet to swop and download copyrighted and contraband material. Peer to peer (P2P) applications are commonly used for this purpose, and like any software application, they is

Firefox Forensics

I was showing someone a trick to export Firefox SQLite tables to a spread sheet, and while she is a forensics person, she had never ever heard of this trick. It is neat enough to know when working off an

Retrieving Digital Evidence: Methods, Techniques and Issues

This article describes the various types of digital forensic evidence available on users’ PC and laptop computers, and discusses methods of retrieving such evidence. A recent research conducted by Berkeley scientists concluded that up to 93% of all information never

Authenticating Internet Web Pages as Evidence: a New Approach

By John Patzakis [1] and Brent Botta [2] Previously, in Forensic Focus, we addressed the issue of evidentiary authentication of social media data (see previous entries here and here). General Internet site data available through standard web browsing, instead of

Parallels hard drive image converting for analysis

The other day, talking to one of the analysts in Dallas, a question emerged about analyzing Parallels’ virtual machine hard drives. To my surprise, I did not find many help on this issue on-line and did not find tools that