Corrobora – Cross-Artifact Consistency Analysis For Windows Digital Forensics

Hero Image

Dielle De Noon explores the development and validation of two key components of her open-source Windows digital forensics framework and how they lay the foundation for future cross-artifact correlation....

Today's headlines 25 Sep 2026

Go Beyond The Basics With XRY Kiosk From MSAB

Go Beyond The Basics With XRY Kiosk From MSAB

Go beyond the basics with XRY Kiosk - extract logical, full file system, physical and RAM data through controlled, compliant workflows built for fast frontline forensics....read more

How Semantics 21 Is Calling Time On Add-On Culture In Digital Forensics

How Semantics 21 Is Calling Time On Add-On Culture In Digital Forensics

Investigative capability shouldn’t be split across licences, modules and bolt-ons - S21 VisionX brings visual review, prioritisation and victim identification into one intelligence-led platform....read more

Magnet Forensics Expands Collaboration With NCMEC To Strengthen Victim Identification

Magnet Forensics Expands Collaboration With NCMEC To Strengthen Victim Identification

Coming soon to Magnet Griffeye: new capabilities will enable investigators to securely share CSAM-related files, hashes and investigative information directly with NCMEC, helping streamline workflows and support faster child victim identification....read more

Geotags: Friend or Foe?

by David Benford Director, Blackstage Forensics I recently wrote a research paper, “Geotag Data: The Modification of Evidence on the Apple iPhone”, based around the possibility of modifying geotag evidence on the Apple iPhone. A test was performed as part

Is the NTSB a model for incident response?

by Sean McLinden Recently, the events surrounding the defacement of the HBGary Web site and publication of sensitive data were being bantered about on a number of forensic, security and incident response sites. As is typical for these kind of

I’m here! Now what?

by Ken Pryor Working for a small police department in a rural area, my opportunities to do digital forensic work on real cases are much fewer and farther between than those who work in large departments or in the private

Challenges of Smart Phone Forensics

by Rob Adams ACE, CDIA+ SALIX Mobile devices have become an essential component of our daily lives. These devices keep us connected and act as so much more than the cell phones and portable music players of the 1990’s. It

2010 report of digital forensic standards, processes and accuracy measurement

Joshua Isaac James, Pavel Gladyshev {Joshua.James, Pavel.Gladyshev}@UCD.ie Centre for Cybercrime Investigation University College Dublin Belfield, Dublin 4 Ireland 1. Introduction From December 7th 2010 to December 12th 2010 a survey on Digital Investigation Process and Accuracy was conducted in an

Four arrested in the Netherlands in FBI cyber attack probe

Four people have been arrested in the Netherlands as part of an FBI-led investigation into computer hacking, according to US media reports. Sixteen people have been picked up in the US and one, aged 16, in Britain, the reports say.

My cat did it – honest, Guv!

and he did it via remote access… by Sam Raincock, IT and telecommunications expert witness When evaluating computer forensics cases the tricky part is often not just evaluating what is found but determining how it came to reside there. “It

Side channel attacks

by Simon Biles Founder of Thinking Security Ltd., an Information Security and Risk Management consultancy firm based near Oxford in the UK Forensics is all about evidence, but the trick is knowing where to find it! Locard’s exchange principle effectively

Digital Forensics and ‘self-tracking’

by Dr Chris Hargreaves, lecturer at the Centre for Forensic Computing at Cranfield University in Shrivenham, UK This month’s article is based very loosely around a recent 5-minute talk from Gary Wolf (link here) which explores the concept of ‘self-tracking’

It’s not always what you find…

by Sam Raincock, IT and telecommunications expert witness In digital forensics we are often asked to determine the presence of evidence. However, what happens when we do not find anything? How do we prove something wasn’t there? Proving something is

A cloud by any other name…

by Simon Biles Founder of Thinking Security Ltd., an Information Security and Risk Management consultancy firm based near Oxford in the UK. “You have to know the past to understand the present” – Dr. Carl SaganIf you have been kind

How to seduce your (potential) computer forensics employer

by David Sullivan We all over-complicate things and this is certainly true when seeking a new job. Essentially, to be successful at a Computer Forensics interview you just need to demonstrate two things:1. You have the technical skills needed to

Windows Search forensics

Analyzing the Windows (Desktop) Search Extensible Storage Engine database by Joachim Metz [email protected] Summary While some may curse Windows Vista for all its changes, for us forensic investigators it also introduced new interesting ‘features’. One is the integration of Windows

Sometimes it’s all about timing

First published June 2010 by Sam Raincock, IT and telecommunications expert witness When a crime happens, the time of the events may be critical to the legal case. However, how are these times established? Is it the time alleged by