Corrobora – Cross-Artifact Consistency Analysis For Windows Digital Forensics

Hero Image

Dielle De Noon explores the development and validation of two key components of her open-source Windows digital forensics framework and how they lay the foundation for future cross-artifact correlation....

Today's headlines 25 Sep 2026

Go Beyond The Basics With XRY Kiosk From MSAB

Go Beyond The Basics With XRY Kiosk From MSAB

Go beyond the basics with XRY Kiosk - extract logical, full file system, physical and RAM data through controlled, compliant workflows built for fast frontline forensics....read more

How Semantics 21 Is Calling Time On Add-On Culture In Digital Forensics

How Semantics 21 Is Calling Time On Add-On Culture In Digital Forensics

Investigative capability shouldn’t be split across licences, modules and bolt-ons - S21 VisionX brings visual review, prioritisation and victim identification into one intelligence-led platform....read more

Magnet Forensics Expands Collaboration With NCMEC To Strengthen Victim Identification

Magnet Forensics Expands Collaboration With NCMEC To Strengthen Victim Identification

Coming soon to Magnet Griffeye: new capabilities will enable investigators to securely share CSAM-related files, hashes and investigative information directly with NCMEC, helping streamline workflows and support faster child victim identification....read more

iPhone Tracking – from a forensic point of view

– Introduction – iPhoneTracking is sexy!!! Every mobile forensic suite, at least the ones dealing with iPhones, are providing it proudly. iPhoneTracking also has been a hot topic in the media all around the globe. People stated, that there is

Android Forensics Study of Password and Pattern Lock Protection

Let’s see what Pattern Lock is, how to access, determine or even get rid of it? We’ll also speak about Password Lock Protection and find out what it has in common with Pattern Lock. And finally we’ll try to understand 

Mike’s Forensic Tools – Cookie Cutter

A simple app to decode the data held within Google Analytics Cookies. The data can be identified by “__UTM” starting each section. The data holds: records, the number of visits to a website, the first, last and current visit dates;

Publishing articles at Forensic Focus

Forensic Focus is always keen to publish articles, papers or blog posts of interest to the digital forensics community. Articles are published not only online but also included in the monthly newsletter (sent to over 12,00 subscribers) and promoted via

SC Suite v4.4 Released.

A new version of SC Suite is available, version 4.4 now includes more tools to analyse and extract information from a variety of file types and utilities to assist in every day tasks. Continuing user feedback has resulted in the

DFCB Announces Q4 Deadline for Applications

The Digital Forensics Certification Board (DFCB) has announced that its next application deadline for its Digital Forensics Certified Practitioner (DFCP) designation is December 2, 2011. The DFCB currently accepts applications four times a year. To obtain detailed certification information and

SQLite Forensic Reporter v1.2 Released.

A new version of SQLite Forensic Reporter, Universal SQLite database examination tool is now available, Version 1.2 includes more features to analyse, extract and report on information from any SQLite database (not corrupted or encrypted). Useful for Computer & Phone

Backbone’s Steganography Application Fingerprint Database v3.11 released

Backbone Security has announced the release of Version 3.11 of the Steganography Application Fingerprint Database (SAFDB) which now contains 1,000 steganography applications…Developed in Backbone’s Steganography Analysis and Research Center (SARC), SAFDB is the world’s largest commercially available hash set exclusive

Skype in eDiscovery

Author: Stuart Clarke, 7Safe The EDRM (Electronic Discovery Reference Model) is a widely accepted workflow, which guides those involved in eDiscovery. Typically, the identification and collection phases see email and common office documents harvested, but as technology moves forward is

Forensic Toolkit v3 Tips and Tricks – On a budget

While researching FTK 3X and Oracle, you just recently discovered that the best configuration of your Oracle database would be on a solid state drive (SSD). Solid state drives give the maximum level of performance to Oracle databases and in

Anonymous, what does it mean?

Anonymous, a word which Merriam-Webster describes as: of unknown authorship or origin, not named or identified, or lacking individuality, distinction, or recognizability. There are some in this world that wish to remain anonymous, not named or identified. Sure I am

NJIT to host digital forensics, watermarking, steganography conference

The 10th International Workshop on Digital-Forensics and Watermarking will be held Oct. 23-26, 2011 at the ACH Casino Resort, Atlantic City. The event, organized by NJIT Professor of Electrical and Computer Engineering Yun-Qing Shi, is a forum for researchers and

Guidance forensics tool now working with SIEM

Guidance Software says its computer forensics tool is now capable of automated collection of data on endpoint devices, including computers and smartphones, based on a security information and event management (SIEM) alert. The Guidance product, EnCase Cybersecurity version 4.3, can

Publishing articles at Forensic Focus

Forensic Focus is always keen to publish articles, papers or blog posts of interest to the digital forensics community. Articles are published not only online but also included in the monthly newsletter (sent to over 12,00 subscribers) and promoted via