Corrobora – Cross-Artifact Consistency Analysis For Windows Digital Forensics

Hero Image

Dielle De Noon explores the development and validation of two key components of her open-source Windows digital forensics framework and how they lay the foundation for future cross-artifact correlation....

Today's headlines 25 Sep 2026

Go Beyond The Basics With XRY Kiosk From MSAB

Go Beyond The Basics With XRY Kiosk From MSAB

Go beyond the basics with XRY Kiosk - extract logical, full file system, physical and RAM data through controlled, compliant workflows built for fast frontline forensics....read more

How Semantics 21 Is Calling Time On Add-On Culture In Digital Forensics

How Semantics 21 Is Calling Time On Add-On Culture In Digital Forensics

Investigative capability shouldn’t be split across licences, modules and bolt-ons - S21 VisionX brings visual review, prioritisation and victim identification into one intelligence-led platform....read more

Magnet Forensics Expands Collaboration With NCMEC To Strengthen Victim Identification

Magnet Forensics Expands Collaboration With NCMEC To Strengthen Victim Identification

Coming soon to Magnet Griffeye: new capabilities will enable investigators to securely share CSAM-related files, hashes and investigative information directly with NCMEC, helping streamline workflows and support faster child victim identification....read more

Forensic Analysis of the Windows Registry

First published April 2006 Lih Wern Wong School of Computer and Information Science, Edith Cowan University [email protected] Abstract Windows registry contains lots of information that are of potential evidential value or helpful in aiding forensic examiners on other aspects of

Evidentiary Value of Link Files

First published March 2006 by Nathan Weilbacher I have been reading the posts in Forensic Focus for about a year now and on many occasions I have followed with great interest the threads of discussion on many topics. There are

Are non technical juries keeping criminals at large?

First published February 2006 by Carrie Moss, Marketing Assistant, CY4OR www.CY4OR.co.uk In England and Wales the only qualifications required of a jury member to be eligible to appear in a court of law are that they are registered on the

Analysis of hidden data in the NTFS file system

First published January 2006 Cheong Kai Wee Edith Cowan University [email protected] Abstract Criminals with sensitive information such as crime records tend to hide/encrypt this information so that even if their computers are collected by police department, there is no evidence

Real-Time Steganalysis

First published October 2005 A Key Component of a Comprehensive Insider Threat Solution James E. Wingate, CISSP-ISSEP, CISM, IAM Director, Steganography Analysis & Research Center (SARC) and Vice President for West Virginia Operations Backbone Security.Com and Chad W. Davis, CCE

Digital forensics of the physical memory

First published September 2005 Mariusz Burdach [email protected] Warsaw, March 2005 last update: July 11, 2005 Abstract This paper presents methods by which physical memory from a compromised machine can be analyzed. Through this methods, it is possible to extract useful

An Analytical Approach to Steganalysis

First published August 2005 by James E. Wingate, CISSP-ISSEP, CISM, IAM Director, Steganography Analysis & Research Center www.sarc-wv.com Chad W. Davis Computer Security Engineer Backbone Security.Com www.backbonesecurity.com Introduction Rapidly evolving computer and networking technology coupled with a dramatic expansion in

Smart Anti-Forensics

First published June 2005 by Steven McLeod steven mcleod@ozemail com au May 2005 EXECUTIVE SUMMARY This paper highlights an oversight in the current industry best practice procedure for forensically duplicating a hard disk. A discussion is provided which demonstrates that

Phone hacking: Police probe suspected deletion of emails by NI executive

Police are investigating evidence that a News International executive may have deleted millions of emails from an internal archive, in an apparent attempt to obstruct Scotland Yard’s inquiry into the phone-hacking scandal. The archive is believed to have reached back

Data: The Basics of Computer Forensics

First published June 2005 by Edward Pscheidt www.edwardpscheidt.com Everything is created on a computer. To be more precise, almost everything that is the subject of litigation was created on a computer. Be they letters, blueprints or company books, the vast

An Investigation Into Computer Forensic Tools

First published June 2005 K.K. Arthur & H.S. Venter Information and Computer Security Architectures (ICSA) Research Group Department of Computer Science University of Pretoria Pretoria This material is based upon work supported by Telkom, IST and the NRF through THRIP.

Developing A Framework For Evaluating Computer Forensic Tools

First published May 2005 by Colin Armstrong Curtin University of Technology School of Information Systems WA Australia Abstract Forensic science is the application of science to those criminal and civil laws that are enforced by police agencies in a criminal

The Forensic Chain of Evidence Model

First published May 2005 Improving the Process of Evidence Collection in Incident Handling Procedures by Atif Ahmad Department of Information Systems, University of Melbourne, Parkville, VIC 3010, Australia Abstract This paper suggests that administrators form a new way of conceptualizing

The Essentials Of Computer Discovery

First published May 2005 by Joan E. Feldman, President Computer Forensics Inc. www.forensics.com I. INTRODUCTION Chances are good that the date you scheduled, the letter you wrote, and the inter-office message you just read have all been recorded on magnetic