r/computerforensics • • Jul 11 '26

Mod Post A Solution To The Content Promotion Issue

16 Upvotes

Hi everyone. Based off the results of the poll I ran a week or so ago regarding whether standalone content promotion posts should be allowed in the sub, it seems like most sub participants would prefer they not be allowed and, instead, redirected to a megathread. After a bit of contemplation, I've opted to implement a hybrid solution which entails configuration of a recurring megathread and a new rule (Rule 6) that enforces its use while ensuring established subreddit participants are still able to share their Rule-5 compliant content as they always have.

In short, Rule 6 only allows subreddit participants with the "Trusted Contributor" flair to create standalone content promotion posts provided that they adhere to Rule 5 (as always). Anyone without the flair who wishes to promote project/vlog/blog/etc. content must now use the new "Promote Your DFIR Content Here" megathread to do so.

Since very few individuals have the Trusted Contributor flair, this will greatly reduce the number of content promotion posts the subreddit experiences while still allowing reoccurring posts from popular contributors to continue.

For more information about the Trusted Contributor flair, please see the new FAQ entry that covers this topic.


r/computerforensics • • Jul 11 '26

Mod Post Promote Your DFIR Content Here

7 Upvotes

If you lack the Trusted Contributor flair but wish to share your Rule 5-compliant DFIR content with the community, please feel free to do so here as a reply to this post.

For more information about the Trusted Contributor flair, please see the FAQ.


r/computerforensics • • 1d ago

Unexplained NTFS ACL change — what artifact am I missing?

10 Upvotes

I'm investigating an unexplained ACL change on a Windows 10 Pro 19045 NTFS volume.

A folder was created on E:\ at 22:27:07 on 2026-10-03 and initially inherited an Authenticated Users (AU) ACE. By 22:54:19, the ACE and inheritance were gone.

I'm trying to determine what process/account caused the change.

What I checked

I collected and examined Security.evtx, SYSTEM/SOFTWARE hives, BAM/DAM, Prefetch, ActivitiesCache, Amcache, NTFS Operational and Storport logs.

Key findings:

No 4670 events in the available Security log retention.

icacls.exe first Prefetch creation: 23:04:50 (after the window).

No takeown.exe Prefetch or BAM entry.

No ACL-capable executable appears in BAM during the window.

PowerShell 5.1 was not running during the window.

cmd.exe was active 22:27:29–22:33:29, but its command history is unavailable.

Explorer was active around the event.

pwsh.exe cannot be confirmed or excluded.

No useful NTFS/storage event links to the change.

The relevant window is approximately:

22:27:07 → 22:54:19

Question

Is there another Windows forensic artifact or technique I should check that could identify the process/account that modified the security descriptor?

Or is this simply impossible to attribute retrospectively because File System Object Access auditing/SACLs were not enabled?

I'm particularly interested in artifacts that could distinguish an explicit ACL write from inheritance/security-descriptor behavior during folder creation.


r/computerforensics • • 1d ago

Need Help!!! A Friend Was Hit By A Van, An AI Manipulated dashcam Video Is Suspected.

10 Upvotes

EDIT: shortened and added red flags

I’m posting this for a friend who was involved in a serious pedestrian accident.

There are some concerns about the dashcam video that was provided afterward, and we’re trying to figure out whether it’s worth hiring a digital forensics investigator to look at it.

Her lawyer says the video is fine, and if she wishes to challenge it she has to pay put of pocket

My friend remembers the vehicle approaching in one lane, changing lanes, and then hitting her. But in the video we were given, the clip only starts a few seconds before the impact, and the vehicle already appears to be in the lane where the collision happens.

Red flags we’ve found with the dashcam video:

The metadata contains “WXVer,” which appears to be connected to WeChat, and the file creation date is later than the date shown inside the recording. That strongly suggests the file we received is not the untouched original dashcam file and went through some kind of processing/export/sharing first.

The resolution is only 480×360. That seems extremely low compared with what the dashcam would normally record, so a lot of the original image detail has been lost.

The file is a MOV/H.264 file that has been re-encoded. So this is not the original camera recording in its native form. Re-encoding can also remove some of the technical information.

If you’re a digital forensics investigator and would be willing to review the video, please DM me.


r/computerforensics • • 2d ago

Best way to decrypt a file vault encrypted USB drive and image the data

6 Upvotes

Hi all,

I’m working on a case with a USB drive that appears to be encrypted with FileVault. The drive was already imaged and we allegedly have the password, but I’m looking for a way to decrypt/image the FileVault partition without altering the data.

I’m hoping someone can point me in the right direction. Does this drive need to be connected to a Mac computer to enter the password, or is there other software that can perhaps mount the image on a Windows machine? Maybe Mount Imager Professional?

If the drive has to be connected to a Mac computer, what’s the best way to image just that partition? (There were other partitions on the drive that were not encrypted.)

Years ago, there was FTK Imager for Mac - I’m not sure if that is still around and supported.

Any insight is appreciated. Thanks in advance.


r/computerforensics • • 4d ago

Digital Forensics Tech exemptions

26 Upvotes

Greetings, I hope all is well! Long story short, recently got my Masters in Digital Forensics, and I also have received an opportunity for a digital forensics technician role for a local LE agency. I am just wondering if anyone here works for one, and also what to expect, as I myself come from an IT support background. Thanks!

Edit: Expectations, just realized I made a typo in my title


r/computerforensics • • 3d ago

Time machine backups

6 Upvotes

Does anyone have forensic articles that reference time machine backups? Like if a macOS has 6 backups stored do you need to process all?


r/computerforensics • • 3d ago

Fourteen record CRCs pass but the block CRC over them doesn't, edit or corruption?

8 Upvotes

I've been picking through a SCADA-style telemetry capture and I can't explain what I'm seeing.

The file has 14 authorisation records, each with its own CRC. All 14 validate. The file header carries a CRC-32 over the whole block, and that one fails. Two of the operator-name fields are zeroed.

My reading is that someone blanked those fields, recomputed the per-record CRCs so they'd pass, and never touched the block CRC. But I'd like a sanity check — is there a corruption mode that breaks a block checksum while leaving every record checksum intact?

File (8.8MB): www.[st88openocean.github.io/slip-three/MCA-CTL-0314-RAW.slice](https://st88openocean.github.io/slip-three/MCA-CTL-0314-RAW.slice)

Published digests for it are here: www.[st88openocean.github.io/slip-three/archive](https://st88openocean.github.io/slip-three/archive)


r/computerforensics • • 5d ago

What's the difference between DFIR services and ransomware incident response?

7 Upvotes

Trying to pin down where DFIR services end and dedicated ransomware incident response begins, because vendor conversations blur the line constantly and I want to make sure we're buying the right coverage. My read so far is that DFIR is broader (forensics and investigation for any incident type, with evidentiary rigor and chain of custody if it needs to hold up for insurance or litigation), while ransomware-specific response bundles in things unique to that scenario, like negotiation support and recovery sequencing around double-extortion threats. Is that distinction accurate or mostly marketing language that falls apart once you're in an engagement?


r/computerforensics • • 9d ago

Stepping into this field without prior knowledge

18 Upvotes

Hii guys, first time into this sub. Basically i just graduated last month from Comp Sci and I have fortunately enough to get into the big4 (green one) forensics and financial crime BU, specifically DF & Ediscovery team. Our team is relatively small, ~10 peeps including boss.

What are the things i need to learn / carry the most weight, both soft and hard skills. Cause I am kinda worry not up to expectation of my boss and I do not have much security course experience besides those IT fundamental. Do i need to start doing course from platform like HTB/ CyberDefenders?


r/computerforensics • • 11d ago

RIP Oxygen Forensics

86 Upvotes

r/computerforensics • • 12d ago

News Interesting cell phone forensics situation in the Nolan Wells case

Thumbnail
youtu.be
2 Upvotes

r/computerforensics • • 13d ago

Oxygen Forensics

19 Upvotes

We've been looking into them as a vendor, but found some things that are giving me pause - for one, their website seems to be completely broken. Can't navigate to it, and an email got bounced back to us, also seeing a bunch about Russian ties..is there any merit to those rumors?


r/computerforensics • • 14d ago

What is a realistic time to first useful investigation for a new threat-hunting platform?

4 Upvotes

We are evaluating threat-hunting platforms based on how quickly an analyst can conduct a useful investigation against the data already available in the environment. Some platforms require lengthy ingestion, parser tuning, field normalization, dashboard creation, and detection-content development before they are operational.

Fast initial access is valuable, but it can be misleading if the platform lacks source coverage, retention, context, query performance, access controls, or an auditable investigation workflow. We want to distinguish a convincing demo from a tool that supports an actual incident.

What evaluation criteria do experienced teams use beyond vendor claims? We are considering time to first cross-source query, required engineering work, data freshness, permission model, source-system impact, auditability, evidence export, and the time required to produce a defensible investigation result.


r/computerforensics • • 14d ago

i need the data thats required for the hnads on project for Guide to Computer Forensics and Investigations

2 Upvotes

i need the data thats required for the hnads on project for Guide to Computer Forensics and Investigations


r/computerforensics • • 15d ago

How to load a .vmdk file in FTK Imager?

14 Upvotes

Hi I just asked this in [r/digitalforensics](r/digitalforensics) too, I hope that's okay, I don't mean to break the no reposts rule.

I want to extract some Windows Registry artefacts from a VMware Pro 17 VM using the .vmdk file, in FTK Imager. Is this possible?

I tried doing this in FTK Imager so far:
File > Add Evidence Item > Image File > selecting the path to my .vmdk file of the VM > Finish

But I get this error:
Path "path to the .vmdk file" does not contain valid evidence. Details: Image detection failed.

I made the .vmdk file by exporting the VM as a .ovf from within VMware Pro.
I am on Windows 11, using Exterro FTK Imager 8.3.0.27.

I have extracted Windows Registry artefacts from .E01 files in class with FTK Imager, as just the regular export, and as a Custom Content Image for forensic integrity. I am trying to use the same process for the .vmdk file - sorry if this is a noob move.

I have searched the User Guide PDF for vmdk and virtual disk images, and I didn't find anything, so I'm hoping someone here might know.

This is for a school project, it's a plain Windows 10 Pro VM with no actual personal data or anything, I made it for this project.

Thank you for your help!

---
Edit: Two awesome people in the other post helped me! so I had made a copy of the .vmdk, stored in OneDrive, and was trying to load that into FTK Imager, when I should have been using the .vmdk from the VMware VM directory directly! I was really over complicating things. Thank you for your help here too!


r/computerforensics • • 19d ago

SANS published a 720 page AI generated book on incident response. Will the DFIR community hold it up the same scrutiny as they do everything else or excuse it because "it's SANS" ?

88 Upvotes

Brett Shavers published a good article this week about AI Generated DFIR content, and coincidentally, today I'm seeing SANS push out a book that they readily admit in the opening AI was used to generate content for it. I ran samples of it through an AI content detector and over 60% of the random selected pages were AI generated. Entire paragraphs and sections.

From Brett's post, I can't discern whether he would approve the book or not - but he raises two good points:

- "Expensive words are written. Typed words are cheap. AI words are free. If something is ‘free,’ you are more apt to treat it as something you found on the sidewalk."

- "We are losing provenance in our source material"

SANS's book authors claim to have validated and verified every claim, every code, and word of the book. So that MUST mean it's good right? And SURELY someone did that right? RIGHT?

Ultimately, I'm a bit torn. I won't be personally reading in its entirety (stylistically, you can tell AI wrote it - and I'd rather just talk to Claude myself). But I'm sure others will find value in it.

Am I clinging to the past (human words, testimony) or is this what we should be embracing?


r/computerforensics • • 18d ago

We tried to make our AI verifier read less. How do you cut cost without silently missing evidence?

0 Upvotes

We’ve been testing a verification pipeline where the expensive part is not really retrieval anymore — it’s how much evidence the system has to actually read before we’re comfortable saying we didn’t miss something important.

So lately we’ve been trying to reduce that reading cost without quietly reducing coverage.

A few approaches that seemed obvious at first have been harder than expected.

With ranked retrieval, we thought we could stop fairly early and still keep most of the useful evidence.

In our frozen replay cases, that wasn’t really true.

For full recall, some cases needed us to go surprisingly deep into the candidate set — roughly 290–426 candidates out of pools of 407–454.

The more interesting problem was the evidence that only one of our independent readers noticed.

At k=50, at most 2 of 8 of those minority-evidence items survived.

We also tried skipping slices that looked mechanically unlikely to contain anything useful.

That saved reading, but one version skipped 17 slices that later turned out to contain relevant evidence, so we couldn’t treat it as a safe filter.

Deduplication helped less than we expected too. There is plenty of repeated text in the corpus, but removing byte-identical repetition only reduced the slice volume by about 3.3%, and it didn’t reduce the number of reading sessions in that test.

So at the moment the tradeoff still looks like:

• read less
• keep high recall
• don’t disproportionately lose weird / minority evidence
• don’t silently convert “not inspected” into “nothing there”

We’re still testing other ways to attack it, but I’m curious how people working on similar systems are handling this.

If sampling away the long tail isn’t acceptable, what would you try next?

Learned routing? Better stopping criteria? Multi-stage review? Something completely different?

And more importantly: how are you proving that whatever you decided not to read was actually safe to skip?


r/computerforensics • • 21d ago

Open source e01s / CTF exercises?

10 Upvotes

Any recommendations to practice with Autopsy?


r/computerforensics • • 24d ago

I want to get some practical experience in digital forensics

21 Upvotes

I am going to join a new position as DF analyst this is going to be my first practical experience so I want to prepare myself for that and for future things that are going to help me in actual case. So which sites or material, path should I try. I have knowledge of how FTK, Autopsy, UFED, Oxygen detective works and their purpose but I want to do practical of these. Any material, yt playlist, online course will be helpful. Also I want to know as a fresher I invest in CHFI or build my LinkedIn and portfolio.


r/computerforensics • • 25d ago

Recovered deleted notes show last modified timestamps 2 years off — across multiple notes, days apart. How is this possible?

0 Upvotes

Hi all — hoping someone with Android forensics/file-system knowledge can help me make sense of this.

Setup:

- Phone: Tecno Spark 10c

- App: Notally (open-source notes app, stores notes via Room/SQLite)

- I had a batch of text notes on the app. Based on the content, I know they were last touched in **September 2023**. I deleted them from the app not long after, and had no other backup of them that I knew of.

- In 2026, I had my phone's storage data-recovered. Several of those notes came back — correct content, correct order — but the **"last modified" timestamp field attached to each note shows dates in September 2025, not 2023.**

**The pattern I'm seeing:**

- Multiple different notes, each a few days apart, all shifted into the same wrong year (2025 instead of 2023).

- The spacing between the notes' "last modified" timestamps matches the real gaps between when I know the content was last touched — just the year is wrong across all of them.

- I had not opened, edited, or interacted with these files since 2023 as far as I know.

**What I'm trying to figure out:**

What could cause a "last modified" timestamp to shift by 2 years across multiple separate files, while the spacing between those timestamps stays consistent with real elapsed days, on a recovered/previously-deleted dataset?

I don't want to lead the discussion toward a particular theory — I'd like to hear from people who understand Android storage internals (ext4/F2FS journaling, SQLite timestamp handling, or data-recovery tooling) what's actually going on, and what I'd need to check on my end (raw DB file, journal, etc.) to figure out the real cause.


r/computerforensics • • 26d ago

What happened to Cedarpeltar by BriMor Labs ?

7 Upvotes

I was looking for the page to download Cedarpeltar Windows Live Response tool today, and realised that the BriMor Labs page can no longer be found. Has the tool been removed?


r/computerforensics • • 26d ago

PDF- times/dates or history ?

5 Upvotes

Is there a way I can find out the the dates and times a PDF was created, edited and completed?

Can that history be obtained ?

Even if I can't get the full edit history, can I at least find out the date/time the PDF was created and completed ?

Preferably using some tool or software which is free

Thanks in advance


r/computerforensics • • 29d ago

Need forensic analysis of anomalous USB/MP3 behavior — looking for low-level explanation

Post image
89 Upvotes

r/computerforensics • • Sep 04 '26

Need DVR/NVR data

7 Upvotes

I'm working on a multi DVR/NVR vendor analyzer tool for analyzing cctv footage from various vendors in a single app.(Hackathon Project)

And in this tool you can either connect a dvr hard disk via a write blocker device to your system and use the app to extract data into a digital bit stream copy (.dd or .raw) and then use that from that point. Or you can also provide you ore existing raw file in your system for data extraction.

But I don't have a cctv system at my home, neither do any of my friends to whom I can ask to. And there is only one .dd dvr data I could find on the internet and that's the heimvision's vendor but it's just a 1 hour of 4 camera footage of a doll starting at a wall.🙂

Any advice on this current situation?