“The Skills And Resilience To Do One Of The Hardest Jobs In Policing” — Why This DFIR Recruitment Language Gets The Evidence Wrong

Hero Image

Does recruiting for “resilience” risk putting responsibility in the wrong place? Paul Gullon-Scott looks at what the evidence says about digital forensic well-being, workload and organisational support, and why the language we use matters....

Belkasoft Named A Major Player In The IDC MarketScape: Worldwide Digital Forensics Platforms 2026 Vendor Assessment

Belkasoft Named A Major Player In The IDC MarketScape: Worldwide Digital Forensics Platforms 2026 Vendor Assessment

Belkasoft has been named a Major Player in the IDC MarketScape: Worldwide Digital Forensics Platforms 2026 Vendor Assessment - a milestone that reflects the maturity of Belkasoft X and the company's continued innovation in AI-powered digital forensics....read more

Cellebrite Genesis: Turn Digital Evidence Into Actionable Leads In Minutes

Cellebrite Genesis: Turn Digital Evidence Into Actionable Leads In Minutes

See how Cellebrite Genesis uses agentic AI to help enterprise investigative teams cut through complex digital evidence, uncover connections, and move from data to actionable leads in minutes....read more

Digital Forensics Round-Up, September 02 2026

Digital Forensics Round-Up, September 02 2026

Read the latest DFIR news - SANS AI frameworks for DFIR, AI hackathon tools, investigator well-being, macOS unlock artifacts, cross-platform log analysis, Apple Health forensics, and more....read more

Anonymous, what does it mean?

Posted by forens245 "Anonymous, a word which Merriam-Webster describes as: of unknown authorship or origin, not named or identified, or lacking individuality, distinction, or recognizability. There are some in this world that wish to remain anonymous, not named or identified.

CCL-Forensics offers “dunk!” for cookie files

CCL-Forensics has developed “dunk!”, a software utility which parses cookie files, and presents the investigator with the data they contain. A free trial version of dunk! is available at www.ccl-forensics.com/dunk which gives complete functionality for a limited time. Thereafter licences

GCHQ to offer British firms expertise in cybercrime

Some of the secret technologies created at the government’s giant eavesdropping centre GCHQ are to be offered to private industry as part of new cyber security strategy being unveiled by ministers on Friday. The idea is likely to be one

French Gendarmerie Nationale chooses Cellebrite’s UFED

The French Gendarmerie Nationale has equipped its national N-TECH force with Cellebrite’s Universal Forensic Extraction Device (UFED) for its mobile forensic investigations. The Gendarmerie Nationale, in charge of public safety in France, is using the UFED to extract information from

Paraben Releases P2 Commander v2.0

Paraben is pleased to announce the release of P2 Commander v2.0. Here are some feature highlights: * New memory dump parser* Added support for Exchange 2010 (.EDB)* Added support for Chrome history, cookies, auto fill items, keywords, and login analysis*

Forensic Toolkit v3 Tips and Tricks ― Not on a Budget

A couple of weeks ago, Brian Glass posted a very helpful comment, Forensic Toolkit v3 Tips and Tricks — on a Budget.  His comment focused on how to “get close to SSD performance on the cheap” and he discussed the

iPhone Tracking – from a forensic point of view

– Introduction – iPhoneTracking is sexy!!! Every mobile forensic suite, at least the ones dealing with iPhones, are providing it proudly. iPhoneTracking also has been a hot topic in the media all around the globe. People stated, that there is

Android Forensics Study of Password and Pattern Lock Protection

Let’s see what Pattern Lock is, how to access, determine or even get rid of it? We’ll also speak about Password Lock Protection and find out what it has in common with Pattern Lock. And finally we’ll try to understand 

Mike’s Forensic Tools – Cookie Cutter

A simple app to decode the data held within Google Analytics Cookies. The data can be identified by “__UTM” starting each section. The data holds: records, the number of visits to a website, the first, last and current visit dates;

Publishing articles at Forensic Focus

Forensic Focus is always keen to publish articles, papers or blog posts of interest to the digital forensics community. Articles are published not only online but also included in the monthly newsletter (sent to over 12,00 subscribers) and promoted via

SC Suite v4.4 Released.

A new version of SC Suite is available, version 4.4 now includes more tools to analyse and extract information from a variety of file types and utilities to assist in every day tasks. Continuing user feedback has resulted in the

DFCB Announces Q4 Deadline for Applications

The Digital Forensics Certification Board (DFCB) has announced that its next application deadline for its Digital Forensics Certified Practitioner (DFCP) designation is December 2, 2011. The DFCB currently accepts applications four times a year. To obtain detailed certification information and

SQLite Forensic Reporter v1.2 Released.

A new version of SQLite Forensic Reporter, Universal SQLite database examination tool is now available, Version 1.2 includes more features to analyse, extract and report on information from any SQLite database (not corrupted or encrypted). Useful for Computer & Phone