Skip to content
Artwork for Digital Forensics Now

Digital Forensics Now

Heather Charpentier & Alexis "Brigs" Brignoni

A podcast by digital forensics examiners for digital forensics examiners. Hear about the latest news in digital forensics and learn from researcher interviews with field memes sprinkled in.

Play
  • 21 episodes
  • monthly
  • Avg 1 hr 9 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S3 · E7
    Monday · 1 hr 44 min

    Bite The Log Archive Cracker And You’re Hooked

    Send us Fan Mail AI is speeding up digital forensics, but speed without control is how good labs get burned. We dig into a safer way to work: use AI-assisted coding to generate a repeatable process, then test it against a real corpus of known extractions so results stay deterministic, verifiable, and defensible. If you’ve ever felt your LLM results “drift” from run to run, this mindset shift is the difference between a helpful assistant and a hidden liability. We also get practical with what’s new across the community: a free macOS timestamp utility, Android intrusion logs (and how to extract and parse them when a user has opted in), and a deep look at Apple Unified Logs and log archives as an underrated iOS forensics goldmine. The big takeaway on logs is interpretation: one scary-looking line is not a conclusion. You have to read the surrounding sequence of events to avoid false narratives, and we talk about how newer workflows can process log archives directly from extractions without requiring a Mac. From there we move into evidence sources that often decide cases: iOS Health database artifacts, LevelDB and IndexedDB for browser forensics, and a standout BitLocker improvement that can auto-unlock secondary encrypted volumes when keys are preserved in a system image. Finally, we walk through reporting at scale with LAVA, the LEAPPs viewer that adds conversation views, analytics, tagging, notes, and LAVA subset exports for massive chats that would otherwise choke HTML reports. If this helped you rethink your workflow or gave you a new artifact to chase, subscribe, share the episode with your lab, and leave a review so more examiners can find it. What tool or artifact do you want us to test next? Notes: Timestamped - https://thebinaryhick.blog/2026/08/16/timestamped/ Brett Shavers Blog Posts - http://linkedin.com/pulse/let-ai-run-your-case-make-you-stupid-brett-shavers-vproc/ Android Logical Extractor - https://github.com/prosch88/ALEX Tim Korver Blog Posts - https://www.linkedin.com/in/tim-korver/recent-activity/articles/ SANS DFIR Summit & Training - https://www.sans.org/cyber-security-training-events/digital-forensics-summit-2026 MSAB Digital Summit - https://www.msab.com/msab-mobile-forensics-digital-summit-2027/ Cellebrite 101 - https://community.cellebrite.com/s/101 HEART Metadata Forensics - https://github.com/MetadataForensics/HEART_by_Metadata_Forensics Arsenal - https://arsenalrecon.com/products LEAPPs & LAVA - leapps.org

    • Transcript
    • Chapters
  • S3 · E6
    July 11 · 1 hr 26 min

    Getting Our Tools Together

    Send us Fan Mail We come back from a busy conference stretch and go hands-on with new digital forensics tools that speed up real workflows across vehicle, iOS, and Android investigations. We also tour major updates to LEAPPs and LAVA, show how Batch LEAPP changes multi-extraction processing, and end with a hard question about validation that every examiner needs to take seriously. Show Notes: North Loop Consulting: Sedgwick and NCL Spectator https://northloopconsulting.com/ Crush Digital Forensic Analysis Workbench: https://github.com/kalink0/crush-forensics LEAPPS: leapps.org

    • Transcript
    • Chapters
  • S3 · E5
    June 3 · 52 min

    The AI Investigative Framework Interview with Heather Barnhart

    Send us Fan Mail AI is becoming more common in digital forensics, but the biggest danger is people trusting it too much. Heather Barnhart discusses a framework that helps examiners assess when AI is appropriate, where it can assist with tasks like triage, and where it should not be used, while keeping trained human experts responsible for decisions. Notes: https://www.linkedin.com/posts/heather-barnhart-cellebrite_ai-dfir-digitalforensics-ugcPost-7463670252950847488-b7s-/

    • Transcript
    • Chapters
  • May 6 · 49 min

    Truth Crime Forensics

    Send us Fan Mail “The tool said” might be the fastest way to lose a jury. Recorded live at IACIS, we sit down with Stacy Eldridge and Becky Passmore of Parsing The Truth One Bite At A Time, two former FBI senior forensic examiners who build a true crime-ish podcast around one thing most shows ignore: the digital artifacts and the courtroom testimony that prove what happened. https://parsingthetruth.com/

    • Transcript
    • Chapters
  • S3 · E3
    March 17 · 49 min

    Live From the MSAB Digital Summit 2026!

    Send us Fan Mail Tool output can look authoritative while still being dangerously easy to misread, and we’ve both seen how fast that goes sideways when a case hits court. Live from the MSAB Digital Summit 2026, we walk through a simple principle that saves careers: an artifact is a clue, not a conclusion. We talk about how “artifact worship” happens, how to build real corroboration, and why multiple records on the same phone are not automatically multiple lines of evidence. We also get honest about forensic reporting and peer review. Assuming “legal will catch it” is a trap, because attorneys and supervisors may not be able to validate the technical meaning of a timestamp, a parser decision, or an attribution statement. We share practical ways to write clearer digital forensics reports, verify tool parsing, and test your assumptions so you’re not learning hard lessons under oath. If you work mobile device forensics, this section is for you. From there we shift into training and deep technical skills that are quickly becoming baseline: Android RAM acquisition and analysis, what kinds of artifacts can show up in memory, and why RAM can hold evidence you may never find in a file system extraction. We also unpack protocol buffers (protobuf) and the uncertainty that comes with app data when the .proto schema is missing, plus why that matters when AI and automation start “helping” with interpretation. We wrap with an ALEAPP update, a reminder that a portable tool report isn’t analysis, and a quick look at how standards like Daubert and Frye raise the bar for methodology. Notes: Brett Shavers Blogs: It’s Not Artifact Worship When One Artifact Actually Changes the Case https://www.linkedin.com/pulse/its-artifact-worship-when-one-actually-changes-case-brett-shavers-nwi6c/ I Thought Legal Would Catch It. They didn’t. https://www.brettshavers.com/brett-s-blog/entry/i-thought-legal-would-catch-it-they-didnt IACIS https://www.iacis.com/events/in-person/2026-orlando-training-conference/

    • Transcript
    • Chapters
  • S3 · E2
    January 9 · 1 hr 22 min

    From Wins to Wishlists: Digital Forensics Year in Review

    Send us Fan Mail A blue jay, a busted feeder, and a brand-new camera set the tone, but only briefly. We kick off the new year with updates from the Florida ICAC conference, including firsthand courtroom experience watching frame rate and frame count testimony in action. The episode centers on Frame Counts Galore, an open-source script for extracting and hashing every video frame, calculating true variable frame rates, and producing transparent, courtroom-ready logs and reports. We cover upcoming DFIR conferences, introduce a lightweight AI Provenance Scanner for fast C2PA and metadata checks, and reflect on standout moments from the digital forensics year—especially the impact of open-source tools and honest conversations about the realities of the work. The episode closes with a 2026 wish list focused on stronger education, fair workloads, and customizable forensic reporting that analysts can actually defend in court. Happy New Year to the DFIR community. Notes: Frame Counts Galore- https://github.com/abrignoni/frame-counts-galore Upcoming Conferences- https://www.iacis.com/ https://www.msab.com/digital-summit-2026/ https://magnetvirtualsummit.com/ https://www.technosecurity.us/ https://ofta.cellebrite.com/event/cellebrite-c2c-user-summit-2026/ AI Provenance Scanner- https://github.com/abrignoni/AI_Provenance_Scanner Brett Shavers Blogs- https://www.brettshavers.com/ UFADE & ALEX- https://github.com/prosch88

    • Transcript
    • Chapters
  • S3 · E1
    Oct 30, 2025 · 1 hr 14 min

    Brett Shavers Blogging Extravaganza!

    Send us Fan Mail This episode digs into the habits that actually hold up: learning from CTF wins and post-event reviews, exploring scholarships and Reno trainings that build technical muscle, and walking through expert-witness prep that turns courtroom stress into structured, confident testimony. We’ll unpack Brett Shavers’ reminder that truth alone doesn’t win cases—procedure, documentation, and bias-aware methods do. Clear writing matters too; vague language can undermine solid work. On the tools side, RabbitHole v3 now recovers deleted SQLite records and rebuilds them into query-ready databases—speeding validation and reporting without losing traceability. We’ll also demo the new Android Logical Extractor: pull device info, logs, and scoped chat data with hashes and ready-to-file PDFs. It’s ideal when consent is limited or full file systems aren’t on the table, and integrates cleanly with downstream workflows. Throughout, we emphasize one idea: tools are abstractions. If you can’t explain how a result was produced or reproduce it, you don’t own the finding. That’s especially true with AI. Generative models are nondeterministic—useful when documented, risky when their prompts or scope stay hidden. We’ll cover prompt disclosure, reproducibility, and how to write about “deleted” data with precision: previously existing, marked deleted, not referenced—describe state, not intent. If you’re serious about improving testimony, validating results, and adopting new tools without losing forensic footing, join us. Then share your take on AI prompts and language precision—what will you change in your next report? Notes: IACIS Scholarships https://www.iacis.com/awards-and-scholarships/will-docken-scholarship/ https://www.iacis.com/awards-and-scholarships/womens-scholarship/ Training Opportunities! IACIS Reno https://www.iacis.com/events/in-person/reno-nv/ Free DFIR Test Images + Industry Tools to Analyze Them https://www.dfir.training/downloads/test-images New Blogs from Brett Shavers! https://www.linkedin.com/pulse/theres-lot-more-trial-than-you-may-know-even-have-100-brett-shavers-br4sc/ https://www.linkedin.com/pulse/case-almost-made-me-quit-dfir-shouldve-news-brett-shavers-pie1c/ https://www.linkedin.com/pulse/i-when-digital-forensics-lost-its-soul-brett-shavers-otkec/ https://www.linkedin.com/pulse/end-dfir-again-dfir-training-ab5jc/ https://www.linkedin.com/pulse/how-wreck-your-report-affidavit-testimony-one-word-brett-shavers-qkyvc/ Free Webinar https://www.suspectbehindthekeyboard.com/fighting-city-hall-dfir-lessons-from-a-pro-se-plaintiff Rabbithole Update https://www.linkedin.com/posts/rabbithole-dataviewer-sqllite-ugcPost-7384144022065274880-0d0D https://www.cclsolutionsgroup.com/forensic-products/rabbithole ALEX Release https://github.com/prosch88/ALEX https://github.com/RealityNet/android_triage

    • Transcript
    • Chapters
  • Oct 2, 2025 · 1 hr 14 min

    Blogs, blogs & blogs!

    Send us Fan Mail A baby camel, a high-speed chase, and a heartfelt tribute set the stage for a season opener that is equal parts human and hard-nosed. We pause to honor Mark Baker, mentor, officer, and friend. This episode spotlights a free Belkasoft AI course along with the much-anticipated release of Rabbit Hole v3, designed to tackle complex data structures. From there, it is all about blogs, and there are plenty of them. Mattia explores extraction nuances, showing how AFU versus BFU states and encryption classes still determine what you can recover from iOS and Android. Hexordia provides important guidance on first responder missteps, emphasizing how early handling and precise thinking safeguard the integrity of a case. We also showcase open-source and budget-friendly tools such as Autopsy and IPED, which expand analysis capacity without breaking the bank. A hands-on demo of Gallery Builder illustrates how to create courtroom-ready visuals, paired with a reminder that “vibe coding” with LLMs is no substitute for validated forensic standards. Finally, we close with the latest LEAPP and LAVA updates, which continue to push practical workflows forward for the field. Notes: BelkaGPT: Effective Artificial Intelligence in DFIR https://belkasoft.com/belkagpt-training Training First Responders in Digital Evidence Handling: How To Protect Your Department from Case-Destroying Mistakes https://www.hexordia.com/blog/training-first-responders-in-digital-evidence-handling The Packd Byte https://www.thepackdbyte.org/ Two New Blogs from Mattia http://blog.digital-forensics.it/2025/09/exploring-data-extraction-from-android.html https://blog.digital-forensics.it/2025/09/exploring-data-extraction-from-ios.html SWGDE https://www.swgde.org/documents/published-complete-listing/16-f-002-considerations-for-required-minimization-of-digital-evidence-seizure/ Gallery Builder https://github.com/charpy4n6/GalleryBuilder

    • Transcript
    • Chapters
  • Aug 29, 2025 · 1 hr 4 min

    DFN: 2nd Anniversary

    Send us Fan Mail We celebrate our two-year podcast anniversary and discuss the importance of thorough case preparation for CSAM cases, courtroom experience, and extracting evidence from iOS devices. • SANS Difference Maker Awards open for nominations through September 15th across multiple categories • AI debate webinar with Magnet Forensics scheduled for September 17th • Binary Hick's blogs reveal insights on iOS search party and Samsung's Rubin and Digital Wellbeing databases • Discussion on properly preparing CSAM cases for trial with understanding of statutes and evidence requirements • Brett Shaver's article highlights importance of attending trials to understand courtroom proceedings • iOS File Provider Storage in BFU extractions can reveal user-created images with metadata • Updates to LEAPPS tool including CashApp parser improvements and Snapchat returns parser • New Lava viewer coming soon for the LEAPPS project Notes: SANS Difference Makers Awards- https://docs.google.com/forms/d/e/1FAIpQLSeLNMZm3r4c9WSKdNW8XaPh6KRXoS3C1WI51UtnEANe2osCpQ/viewform AI Unpacked #5: The great AI debate with Digital Forensics Now- https://www.magnetforensics.com/resources/ai-unpacked-5-the-great-ai-debate-with-digital-forensics-now/ The Binary Hick New Blogs- https://thebinaryhick.blog/2025/08/19/further-observations-more-on-ios-search-party/ https://thebinaryhick.blog/2025/08/06/not-strange-bedfellows-samsungs-rubin-digital-wellbeing/ Monolith Notes- https://www.monolithforensics.com/free-tools Brett Shavers- Courtroom Trials Are the Final Exam for Your Work. Why Haven’t You Attended One?- linkedin.com/in/brettshavers/recent-activity/all/

    • Transcript
    • Chapters
  • S2 · E14
    Aug 1, 2025 · 1 hr 16 min

    From Cryptic Apps to Clickable Maps: Making Sense of Digital Evidence

    Send us Fan Mail We're back! After a short break we are back to discuss the growing crossover between real-world events and digital evidence in court cases, highlighting how device data can make or break timelines in high-stakes investigations. This episode covers: Ian Whiffin’s latest forensic work, including iOS power log timestamps, Apple Health data reliability, iPhone battery temperature readings, and IR Doppler functionality – with examples of how these artifacts were used in a recent homicide trial to validate timelines and environmental conditions. Kevin Pagano’s App Store Package Search tool, which translates obscure bundle IDs into recognizable app information for easier analysis. Concerns over the growing reliance on AI in digital forensics, emphasizing the need for human expertise and proper validation in every step of the process. A demonstration of LUMYX, a mapping tool that converts extracted location data into customizable visual timelines for courtroom presentations. Updates on LAVA (LEAPPS Artifact Viewer App) and guidance on writing LAVA-compliant artifacts to improve reporting workflows. Notes: Ian's FOUR Newest Blogs https://www.doubleblak.com/blogPost.php?k=powerlog https://www.doubleblak.com/blogPost.php?k=healthaccuracy https://www.doubleblak.com/blogPost.php?k=temperature https://www.doubleblak.com/blogPost.php?k=doppler Ian Whiffin Testimony https://www.youtube.com/watch?v=kahgl-mIUFE Kevin Pagano Stark4n6 app store package search https://www.stark4n6.com/2025/07/introducing-asp-app-store-package-search.html https://github.com/stark4n6 Elcomsoft Article- AI driven Password Recovery Myth or Reality? https://blog.elcomsoft.com/2025/07/ai-driven-password-recovery-myth-or-reality/ Beyond the Badge AI's role in Modern Investigations https://www.magnetforensics.com/blog/beyond-the-badge-ais-role-in-modern-investigations/ LUMYX https://lumyx.com/ LEAPPs leapps.org How to make LAVA Compliant LEAPP Artifacts https://www.linkedin.com/video/live/urn:li:ugcPost:7356497708628520962/ UFADE https://cp-df.com/en/blog/ufade_touch.html

    • Transcript
    • Chapters
  • S2 · E13
    Jun 27, 2025 · 1 hr 6 min

    Techno, Timeline, and Training Truths

    Send us Fan Mail We kick off this episode with highlights from the Techno Security Conference, our 80s-themed outfits, packed LEAPP labs, AI panel discussions, and great conversations with friends and colleagues across the field. We discuss Brett Shavers’ recent series on DFIR entry-level work, and share our thoughts on the need for better forensic training and clearer distinctions between forensics, cybersecurity, and incident response. We also talk about recent tool changes in the industry. Cellebrite’s acquisition of Corellium could make mobile app testing more accessible, and Magnet’s purchase of Dark Circuit Labs. We cover Harper Shaw’s Vehicle Network App, a valuable source of vehicle-related data. Alongside that, we highlight a recent blog on cached screenshots in Windows 11. Be sure to check out the excellent “Parsing the Truth” podcast. Heather walks through her Easter road trip to test Android's Timeline feature (formerly Google Location History). The location data was impressively accurate, but also showed how easily some points can mislead without the right context. Catch us at IACIS Reno in January and check out the some of the resources we mentioned. Notes: Parsing the Truth: One Byte at a Time https://parsingthetruth.com/ Cached Screenshots on Windows 11 https://thinkdfir.com/2025/06/13/cached-screenshots-on-windows-11/ The Vehicle Network App from Harper Shaw https://harpershaw.co.uk/the-vehicle-network-app-1 Beklkasoft CTF https://belkasoft.com/belkactf7/ Brett Shavers 6 part series https://www.linkedin.com/pulse/dfir-really-entry-level-brett-shavers-ewsvc/ https://www.dfir.training/new-to-dfir/dfir-career Artifact of the Week/Android Location History https://thebinaryhick.blog/2024/06/28/the-green-look-back-androids-on-device-location-history/

    • Transcript
    • Chapters
  • S2 · E12
    May 16, 2025 · 1 hr 15 min

    Every Breath You Take, Every Swipe You Make—Your iPhone’s Logging It

    Send us Fan Mail Apple devices are constantly recording user activity, yet few forensic examiners are making use of the vast amount of data these systems quietly generate. Apple's Unified Logs and Spotlight databases track nearly everything that happens on an iOS device, often without the user realizing it. Would you believe an iPhone can generate around 1.5 million log entries in just 15 minutes of regular use? These records include highly specific actions—such as the exact moment Face ID is used to unlock a device, when the phone is flipped face-up, or whether a user interacted with Siri or used the device manually. Despite their detail and reliability, these sources are often overlooked in mobile investigations. In this session, we’ll show how forensic practitioners can process and search these massive log sets using open-source tools. We’ll walk through examples of log entries that record actions like toggling airplane mode, launching specific apps like Facebook, or even detecting changes in device orientation. For investigators, this means direct, time-stamped evidence of how a device was used. One of the most valuable aspects of this data is its ability to help distinguish between user actions and automatic background processes. Was an app opened by the user, or was it a system event? These logs provide that level of clarity. We’ll demonstrate how to isolate specific events from millions of entries and construct accurate timelines that reflect exactly what happened—and when. As part of our ongoing work, we’re also focused on improving the accessibility and usability of these artifacts with incorporation into the LEAPPS. If you work with iOS devices, this is a session you won’t want to miss. Notes: 2026 IACIS in Reno NV- https://www.iacis.com/training/reno-info/ Spotlight- https://github.com/ydkhatri/mac_apt Unified Logs- https://www.ios-unifiedlogs.com/ https://github.com/abrignoni/iLEAPP

    • Transcript
    • Chapters
  • S2 · E11
    May 1, 2025 · 32 min

    Stomping Grounds: Digital Forensics at IACIS 2025

    Send us Fan Mail The Digital Forensics Now podcast brings together the core LEAPPs developer team for a candid, unscripted conversation about mobile forensics, legal challenges, and the future of their tools during the IACIS conference in Orlando. • First time bringing together most of the LEAPPs development team in person • Florida's new requirement for 10-day search warrant renewals creates significant challenges for long-running forensic processes • Timestamp parameters in warrants can limit investigators' ability to discover relevant evidence • Paladin now includes the LEAPPs integration, making powerful open-source forensic tools more accessible • Real-world success stories of the LEAPPs helping solve cases when commercial tools failed • Introduction of "The DFIR Investigative Mindset" book with technical editor Lee Harris • Multiple specialized forensic training courses available at IACIS including incident response, drone, MAC and RAM forensics Join us in two weeks for a more technical episode exploring new forensic artifacts and techniques.

    • Transcript
    • Chapters
  • S2 · E10
    Apr 11, 2025 · 1 hr 13 min

    The "Bear" Essentials of Digital Forensics 🐻

    Send us Fan Mail The digital forensics world isn’t slowing down — and neither are we. In this episode, we celebrate Heather’s well-deserved recognition as Cellebrite’s Mentor of the Year 2025. Naturally, there were a few speech mishaps and, somehow, a bear raiding Heather’s bird feeder (yes, actual wildlife). But between the chaos, we get serious about the fast-changing landscape of digital evidence collection. We dig into Amazon’s decision to remove the "do not send voice recordings" setting from Echo devices — meaning all voice requests now head straight to the cloud for AI training. It’s part of a growing industry trend, raising huge privacy red flags. We also unpack a study showing AI search engines misattribute sources at rates over 60%, and discuss how leaning too hard on generative AI risks dulling the critical thinking that digital forensics demands. On the technical front, Christian Peter reveals that some forensic tools alter or delete unified logs during extraction — a serious concern for evidence integrity that can compromise investigations before they even begin. We also walk through a deep dive into Snapchat artifacts, showing how to connect media files to user actions and locations by following database breadcrumbs that automated tools tend to overlook. Through it all, one theme stays clear: while technology keeps racing ahead, the responsibility for getting it right stays firmly with the examiner. As one guest bluntly put it, "We might be the last generation of cognitive thinkers." Tune in for a sharp, insightful, and slightly unpredictable conversation at the intersection of bears, bytes, and the future of digital evidence. Notes: Mobile Forensics Are you nerd enough? https://www.msab.com/events-webinars/webinar-are-you-nerd-enough/ New Podcasts! https://osintcocktail.com/ https://www.youtube.com/@hexordia Amazon "Do Not Send Voice Recordings" Privacy Feature https://www.usatoday.com/story/tech/2025/03/17/amazon-echo-alexa-reporting-privacy/82503576007/https://www.thesun.co.uk/tech/33907850/amazon-alexa-echo-do-not-send-voice-recordings AI search engines cite incorrect news sources at an alarming 60% rate, study says https://arstechnica.com/ai/2025/03/ai-search-engines-give-incorrect-answers-at-an-alarming-60-rate-study-says/ The Slow Collapse of Critical Thinking in OSINT due to AI https://www.dutchosintguy.com/post/the-slow-collapse-of-critical-thinking-in-osint-due-to-ai NIST https://www.nist.gov/news-events/news/2025/01/updated-guidelines-managing-misuse-risk-dual-use-foundation-models Don't lose your logbook https://www.linkedin.com/pulse/dont-lose-your-logbook-christian-peter-ebcje Not All Encryption is created equal https://www.s-rminform.com/latest-thinking/cracking-the-vault-exposing-the-weaknesses-of-encrypted-apps

    • Transcript
    • Chapters
  • S2 · E9
    Mar 7, 2025 · 1 hr 6 min

    The Iceberg of Digital Evidence: What AI Can't See

    Send us Fan Mail The boundary between tool-dependent analysis and true forensic expertise grows increasingly blurred as AI enters the digital forensics landscape. Alexis Brignoni and Heather Charpentier reunite after a month-long hiatus to sound the alarm on a concerning trend: the integration of generative AI into forensic tools without adequate safeguards for verification and validation. Drawing from Stacey Eldridge's firsthand experience, they reveal how AI outputs can be dangerously inconsistent, potentially creating false positives (or missing critical evidence) while providing no reduction in examination time if proper verification procedures are followed. This presents investigators with a troubling choice: trust AI results and save time but risk severe legal and professional consequences, or verify everything and negate the promised efficiency benefits. The hosts warn that as AI becomes ubiquitous in forensic tools, it dramatically expands the attack surface for challenging evidence in court—especially when there's no traceability of AI prompts, responses, or error rates. Beyond the AI discussion, the episode delivers practical insights for investigators, including an in-depth look at the Android gallery trash functionality. When users delete photos, these files remain in a dedicated trash directory for 30 days with their original paths and deletion timestamps fully preserved in the local DB database—a forensic goldmine for cases where suspects attempt to eliminate evidence shortly before investigators arrive. Other highlights include recent updates to the Unfurl tool for URL analysis, Parse SMS for recovering edited and unsent iOS messages, and Josh Hickman's research on Apple CarPlay forensics. Whether you're investigating distracted driving cases, analyzing group calls on iOS, or simply trying to navigate the increasingly complex digital evidence landscape, this episode offers both cautionary wisdom and practical techniques to enhance your forensic capabilities. Join the conversation as we explore what it truly means to be a digital forensic expert in an age of increasing automation. Ready to strengthen your digital investigation skills? Subscribe now for more insights from the front lines of digital forensics. Notes: Magnet Virtual Summit Presentations https://www.magnetforensics.com/magnet-virtual-summit-2025-replays/ https://www.stark4n6.com/2025/03/magnet-virtual-summit-2025-ctf-android.html parse_smsdb https://www.linkedin.com/posts/alberthui_ios-16-allows-for-imessagesmsmmsrcs-message-activity-7279586088988413952-xHWl https://github.com/h4x0r/parse_sms.db/tree/main Are you a DF/IR Expert Witness or Just a Useful Pawn? https://www.linkedin.com/posts/dfir-training_a-pawn-moves-where-its-told-a-dfir-expert-activity-7292981112463572992-c3wd/ Unfurl https://dfir.blog/unfurl-parses-obfuscated-ip-addresses/ https://github.com/obsidianforensics/unfurl AI to Summarize Chat Logs and Audio from Seized Mobile Phones https://www.404media.co/cellebrite-is-using-ai-to-summarize-chat-logs-and-audio-from-seized-mobile-phones/ Ridin' With Apple CarPlay 2 https://thebinaryhick.blog/2025/02/19/ridin-with-apple-carplay-2/ Hello Who is on the Line? https://metadataperspective.com/2025/02/05/hello-who-is-on-the-line/

    • Transcript
    • Chapters
  • S2 · E8
    Jan 24, 2025 · 1 hr 3 min

    Mind Matters: Navigating DFIR with Balance

    Send us Fan Mail Get ready for a hands-on look at digital forensics and the challenges professionals tackle every day. We share a story about forensic guessing that highlights the importance of testing assumptions and following the evidence to avoid errors. The discussion emphasizes how staying grounded in facts can prevent investigations from going off track. We also highlight advancements in forensic tools and training. Learn about tools like Belkasoft, the UFADE tool for iOS device extraction, and SQBite for SQLite database analysis. These tools are improving efficiency and accessibility in the field. But it’s not all about the tech. We address the important topic of mental health in digital forensics. We discuss the pressures of the job, strategies for managing stress, and the importance of supporting one another. Personal experiences and practical tips highlight the need to prioritize mental well-being in this demanding field. This episode provides valuable information on tools, investigative approaches, and mental health strategies for forensic professionals. Notes: Belkasoft Windows Forensics Course https://belkasoft.com/windows-forensics-training Updates to UFADE https://github.com/prosch88/UFADE/releases The Duck Hunter's Blog https://digital4n6withdamien.blogspot.com/2025/01/the-duck-hunters-guide-blog-1.html https://digital4n6withdamien.blogspot.com/2025/01/the-duck-hunters-guide-blog-2.html https://digital4n6withdamien.blogspot.com/2025/01/the-duck-hunters-guide-blog-3.html SQBite https://digital4n6withdamien.blogspot.com/2025/01/introducing-sqbite-alpha-python-tool.html https://github.com/SpyderForensics/SQLite_Forensics/tree/main/SQBite Mental Health in DFIR https://thebinaryhick.blog/2019/06/21/mental-health-in-dfir-its-kind-of-a-big-deal/ https://www.forensicfocus.com/podcast/the-impact-of-traumatic-material-on-dfir-well-being/ https://www.forensicfocus.com/news/dfir-and-mental-health-are-we-doing-enough-to-protect-investigators/ https://www.sciencedirect.com/science/article/pii/S2666281721000251 https://belkasoft.com/preventing-burnout-in-digital-forensics https://www.magnetforensics.com/resources/taking-care-of-mental-health-during-digital-forensics-investigations/ https://www.harmlessthepodcast.com/ https://www.shiftwellness.org/about-us https://www.nyleap.org/ What's New with the LEAPPS https://github.com/abrignoni

    • Transcript
    • Chapters
  • Jan 3, 2025 · 1 hr 16 min

    New Year, New Discoveries: Diving into Digital Forensics!

    Send us Fan Mail Kick off your new year with some forensic fun as we recount our holiday escapades and dive into the latest in digital forensics! Ever wondered how RAM dumps from Android devices can reveal crucial data? We spotlight MSAB's innovative RAMalyzer tool and their new blog series covering RAM from mobile devices. Discover how the digital forensics community is collaborating to propel the field forward, as we share insights from the DF Pulse 2024 Digital Forensic Practitioner Survey and the delicate dance between competition and cooperation. Standardization is the name of the game, and we're exploring how the field of digital forensics can benefit from it. Updates to Magnet Axiom's date range capabilities showcase the ceaseless evolution of digital forensics tools. Journey with us as we tackle the intricacies of Bluetooth tracker detection, all while considering the dual nature of technology and the significance of using it responsibly. From exploring Richard Davis's work with 13 Cubed to discussing Yogesh Khatri's contribution to analyzing the USN Journal, we shine a light on the vital role of principles in our field. With warm wishes for the new year, we invite you to stay tuned for more episodes brimming with insights and camaraderie. Notes: MSAB RAMalyzer series! https://msab.com/resources/blog/ Paraben Forensic Innovation Conference https://link.reachpenguin.com/widget/form/99kVMTgaA0mbpZvYLTjG Tip Tuesday: Troubleshooting in PA https://www.youtube.com/watch?v=eSNovfdwucw&list=PLwmKlEiYNUYte-pnlbw45YKpPB7K8xCgC&index=1 DFPulse: The 2024 digital forensic practitioner survey https://www.sciencedirect.com/science/article/pii/S2666281724001719 Magnet Axiom Cyber 8.7: Acquire iCloud backups from ADP-enabled accounts, and more! https://www.magnetforensics.com/blog/magnet-axiom-cyber-8-7-icloud-adp-and-more/ Android Will Let You Find Unknown Bluetooth Trackers Instead of Just Warning You About Them https://www.engadget.com/mobile/smartphones/android-will-let-you-find-unknown-bluetooth-trackers-instead-of-just-warning-you-about-them-204707655.html Be Kind, Rewind... The USN Journal https://youtu.be/GDc8TbWiQio?feature=shared Apple Photos phones home on iOS 18 and macOS 15 https://lapcatsoftware.com/articles/2024/12/3.html SWGDE Considerations for Required Minimization of Digital Evidence Seizure swgde.org/16-f-002/

    • Transcript
    • Chapters
  • S2 · E6
    Dec 13, 2024 · 1 hr 19 min

    The Gift of Expertise: Why Forensics Matter in the Courtroom

    Send us Fan Mail Join us for a holiday-themed episode of Digital Forensics Now, where we blend expert insights with personal stories from the field of digital forensics. This episode delves into cutting-edge tools and techniques for digital forensics. Explore insights from Arsenal on advanced methods for analyzing swap space and memory files. We also share experiences with the Samsung Secure Health Data Parser, highlighting the challenges of decrypting health databases and the critical role of UFED in overcoming them. Don’t miss an in-depth look at the remarkable features of ArtEX, showcasing its value to examiners. Additionally, we introduce the LEAPPS Artifact Viewer App (LAVA), a groundbreaking tool unveiled at the Cyber Social Hub conference. We discuss the vital role of forensic experts in legal proceedings, from the importance of meticulous validation to the risks of mishandling evidence. Real-world cases and a controversial court rulings that highlight why expert testimony remains essential in interpreting digital artifacts. We close with gratitude to our listeners and warm holiday wishes. Stay tuned on social media for updates on our next live session after the holidays. Notes: Working with 010 Hex-Editor https://www.youtube.com/playlist?list=PLCS2zI95IiNwheFCTaUEytA1GT0mNOOdn Arsenal Releases a New Tool! https://arsenalrecon.com/additional-products Samsung Secure Health Data Parser - A Forensic Tool for Parsing & Analyzing Samsung Secure Health Databases https://github.com/breakpointforensics/Samsung-Secure-Health-Data-Parser-/tree/main ArtEx Artifact Examiner <br>https://www.doubleblak.com/app.php?id=ArtEx2 Why the Manual Preview/Screenshots May Not Hold Up in Court https://www.forbes.com/sites/larsdaniel/2024/11/13/think-that-screenshot-is-proof-heres-why-it-might-not-hold-up-in-court/ https://www.forbes.com/sites/larsdaniel/2024/12/06/smartphone-forensics-and-fake-texts-how-are-courts-responding/ What's New with the LEAPPS!? Google Keep Notes <br>https://charpy4n6.blogspot.com/2024/12/google-keep-notes.html Signup for Updates! leapps.org

    • Transcript
    • Chapters
  • S2 · E5
    Nov 22, 2024 · 1 hr 17 min

    BFU Data, Forensic Tools, and the Future of Digital Investigations

    Send us Fan Mail The latest episode of Digital Forensics Now kicks off with lighthearted banter about Heather's newfound fame in commercials, bringing a fun and relatable start to a tech-heavy discussion. Following the laughs, the conversation shifts to an invigorating recap of Alexis' recent experience at SANS DFIRCON, featuring interactions with digital forensics luminaries like Brian Maloney and Ian Whiffin. Ian's ArtEx tool, which cleverly maps locations for forensic investigations, also takes center stage as a highlight of the conference. The episode weaves in personal reflections, including a scenic family train ride from Orlando to Miami and the implementation of a Python artifact exercise during a teaching session. The journey continues with a vibrant detour to the Tanganyika Wildlife Park in Kansas, where the usual birthday horseback riding tradition was replaced with unforgettable encounters like swimming with penguins, feeding giraffes, and snapping selfies with lemurs. These charming moments with nature set a refreshing tone before diving back into the tech world. In the realm of digital forensics, the episode explores reverse engineering iOS 18, discusses the brief availability of BitLocker support in FTK Imager, and examines the evolving landscape of BFU (Before First Unlock) data extraction in law enforcement. The hosts delve deep into the complexities of digital forensics tools, translating technical data structures into accessible insights while emphasizing the importance of a strong digital evidence strategy. Topics include advancements in the LEAPP Parsers, the innovative Lava Viewer, and the latest developments in Blue Sky data structures, offering a comprehensive look at the tools shaping the field. The episode wraps up with an open invitation for listeners to connect on social platforms, share their thoughts, and showcase innovative projects within the community, fostering a collaborative and forward-thinking space for digital forensics enthusiasts. Notes iOS Devices Rebooting Continuedhttps://naehrdine.blogspot.com/2024/11/reverse-engineering-ios-18-inactivity.html Samsung Secure Health Data Parser https://breakpointforensics.com/2024/11/06/samsung-secure-health-data-parser-a-forensic-tool-for-parsing-analyzing-samsung-secure-health-databases/ https://github.com/breakpointforensics/Samsung-Secure-Health-Data-Parser-/tree/main Mobile Forensics Data Structures: Extracting and Analyzing Data with Free Toolshttps://www.hexordia.com/blog/mobile-forensics-data-structures GAMEPLANS: A template for robust digital evidence strategy developmenthttps://onlinelibrary.wiley.com/doi/10.1111/1556-4029.15655Digital Evidence Enhancing public safety using digital investigative technologieshttps://majorcitieschiefs.com/wp-content/uploads/2024/10/MCCA-Digital-Evidence-White-Paper-_-Oct-2024.pdf Importance of BFU Partial Filesystem Extractions!https://www.linkedin.com/posts/1carl-lawrence_dfir-polcing-digitalforensics-activity-7264179600631468034-FHGh Sumuri Gives Back 2024 https://sumuri.com/sumuri-gives-back-2024/

    • Transcript
    • Chapters
  • Nov 15, 2024 · 1 hr 2 min

    iOS 18’s Inactivity Reboots Explained: AFU to BFU Transitions with Chris Vance from Magnet Forensics

    Send us Fan Mail Join us on the Digital Forensics Now podcast as we explore the details of the iOS 18 inactivity reboot issue with mobile forensics expert Christopher Vance from Magnet Forensics. Chris traces the origins of this challenge back to iOS 17 and explains how unified logs play a key role in diagnosing these system memory resets. This episode is packed with valuable insights for anyone interested in the inner workings of iOS devices and the unique considerations they present in digital forensics. We also discuss device security and data preservation, focusing on iOS devices. Examining the balance between law enforcement’s need for data access and Apple’s privacy measures, we highlight the importance of extracting the data from devices quickly to prevent data loss. Our conversation covers the legal complexities, jurisdictional nuances, and the demand for data preservation tools to address these challenges effectively. We explore recent developments in mobile technology, specifically Android 15's "Private Space" feature and how it will effect the digital forensic community workflow. With insights from industry experts, this episode is full of essential updates tailored for digital forensics professionals looking to stay current. Notes: iOS Devices Rebooting https://www.magnetforensics.com/blog/understanding-the-security-impacts-of-ios-18s-inactivity-reboot/ 5 iOS forensics evidence sources to capture before they expire https://www.magnetforensics.com/blog/ios-forensics-evidence-sources-to-capture-before-they-expire Mac and iOS Forensic Analysis and Incident Response Poster https://www.sans.org/posters/macos-ios-forensic-analysis/

    • Transcript
    • Chapters
Showing 1–20 of 21 episodes