Cellebrite Genesis: Turn Digital Evidence Into Actionable Leads In Minutes

Hero Image

See how Cellebrite Genesis uses agentic AI to help enterprise investigative teams cut through complex digital evidence, uncover connections, and move from data to actionable leads in minutes....

Digital Forensics Round-Up, September 02 2026

Digital Forensics Round-Up, September 02 2026

Read the latest DFIR news - SANS AI frameworks for DFIR, AI hackathon tools, investigator well-being, macOS unlock artifacts, cross-platform log analysis, Apple Health forensics, and more....read more

Semantics 21 Asks The Uncomfortable Question Every Review Team Should Be Asking

Semantics 21 Asks The Uncomfortable Question Every Review Team Should Be Asking

If your forensic tool isn’t showing you every file in a case, how can you be sure you’re investigating the full picture? See how S21 VisionX keeps difficult, damaged and excluded material visible to investigators....read more

Techno Security & Digital Forensics Conference Returns To San Diego October 20–22, 2026

Techno Security & Digital Forensics Conference Returns To San Diego October 20–22, 2026

Join the DFIR community in San Diego, October 20–22, 2026, for the Techno Security & Digital Forensics Conference - three days of expert-led education, emerging technologies, hands-on insights, and valuable industry networking....read more

It’s not always what you find…

by Sam Raincock, IT and telecommunications expert witness In digital forensics we are often asked to determine the presence of evidence. However, what happens when we do not find anything? How do we prove something wasn’t there? Proving something is

A cloud by any other name…

by Simon Biles Founder of Thinking Security Ltd., an Information Security and Risk Management consultancy firm based near Oxford in the UK. “You have to know the past to understand the present” – Dr. Carl SaganIf you have been kind

How to seduce your (potential) computer forensics employer

by David Sullivan We all over-complicate things and this is certainly true when seeking a new job. Essentially, to be successful at a Computer Forensics interview you just need to demonstrate two things:1. You have the technical skills needed to

Windows Search forensics

Analyzing the Windows (Desktop) Search Extensible Storage Engine database by Joachim Metz [email protected] Summary While some may curse Windows Vista for all its changes, for us forensic investigators it also introduced new interesting ‘features’. One is the integration of Windows

Sometimes it’s all about timing

First published June 2010 by Sam Raincock, IT and telecommunications expert witness When a crime happens, the time of the events may be critical to the legal case. However, how are these times established? Is it the time alleged by

Publication: an ethical dilemma for digital forensics research?

First published June 2010 by Dr Chris Hargreaves, lecturer at the Centre for Forensic Computing at Cranfield University in Shrivenham, UK Ethical issues in science are commonplace; examples such as cloning, climate change and genetic engineering are all subject to

Flash drives and acquisition

First published June 2010 by Dominik Weber, Senior Software Architect for Guidance Software, Inc. “Take a look at this”. It started simply with that.A co-worker was looking into some strange issue with an acquisition of a flash drive. It seemed

Unusual devices

First published June 2010 by Sean McLinden In 2007, New Jersey Governor Jon Corzine made the news twice for a single event. The first time was the report of a car accident on the Garden State Parkway in which he

Digital forensic sampling

The application of statistical sampling in digital forensics Authors: Robert-Jan Mora and Bas Kloet Company: Hoffmann Investigations, Almere, The Netherlands URL: http://en.hoffmannbv.nl Date: 27th March 2010 Version:1.0 Table of contents 1 Introduction 2 Sampling basics 2.1 The necessity for sampling

EnCase file copying and Windows Short File Names

First published May 2010 By Lee Hui Jing, EnCe Edited by Sarah Khadijah Taylor ABSTRACT A couple of months ago, one of my clients, an Investigating Officer from a Law Enforcement Agency, had requested me to extract some of the

The (Nearly) Perfect Forensic Boot CD – Windows Forensic Environment

by Brett Shavers   Introduction Figure 1: WWW.FORENSICS-INTL.COM As a quick introduction to the Windows Forensics Environment (WinFE); it is a bootable CD, based on the Windows Pre-Installed Environment (PE), with a few changes to create a forensically sound boot

Are users getting smarter?

First published February 2010 by Darren Ilston of MelBek Technology www.melbek.co.uk There is no doubt in my mind that computer users in general think they are becoming smarter when it comes to covering their tracks.The usual suspects of deleting browser

Timeline Analysis – A One Page Guide

First published February 2010 by Darren Quick Comments and suggestions may be sent to [email protected] Prepare The scope of the request determines the data to be collected, such as within a specific timeframe, and data of relevance such as specific

Casey Anthony Trial – Valid conclusions?

"Recently, the Casey Anthony trial in the USA has been a source of discussion in many fora, but most recently a bit of a “spat” seems to be in danger of breaking out between the developers of two of the

The darker side of computer forensics

First published January 2010 by John Irvine http://johnjustinirvine.com http://twitter.com/John_Irvine For the better part of the past thirteen (thirteen?!) years, I have been a computer forensic examiner. Sure, the title varies by job and location — digital forensic analyst, media exploiter,

Serving search warrants in Spain

First published January 2010 The expert witness perspective by Joaquim Anguas Abstract This article describes the most common schema and basic procedure in which search warrants related to computer evidence are served in Spain from the expert witness perspective, and