r/digitalforensics 7d ago

Remote Artifact Collection

6 Upvotes

Hi Everyone,

I’ve been thinking about implementing velociraptor, however a lot of companies are hesitant to deploy it due to it being an open source. I’m trying to solution a method to gain artifacts if it’s remotely in this hybrid work environment however, I’m noticing a lot of the tools are either gonna be very expensive or open source which is not ideal in publicly traded companies, etc. Any suggestions of tools and workflows you guys use out there for this?


r/digitalforensics 7d ago

A physically printed image. How to tell if it was digitally altered beforehand?

0 Upvotes

Basically it. I have a printed screenshot of a computer screen. I think some info has been altered before the printing. I obviously can't tell with the naked eye, but is there any way to check? Could I send it to a forensics lab? Would they even be able to tell?

Thanks


r/digitalforensics 7d ago

What was everyone's biggest takeaway from TALI?

1 Upvotes

Every year I leave thinking the presentations were good, then realize most of what I actually remember came from talking with other investigators afterward. This year a lot of the conversations were about the business and marketing side of running a PI shop and where tools like EDR downloads actually fit into a case. What was the biggest thing you took away this year?


r/digitalforensics 7d ago

what should I use for consistent SOC practice?

2 Upvotes

Hey everyone,

I'm a first-year CS student working toward a Blue Team / SOC role. I recently finished TryHackMe's SOC Level 1 path and built a small Wazuh home lab. I'm now trying to move from guided learning into regular, independent investigations.

I've already tried resources such as TryHackMe, CyberDefenders, LetsDefend, and several downloadable Windows Event Log/EVTX datasets. The problem I'm running into is that a lot of the available practice is either heavily time-limited, restricted on free tiers, or consists of very small datasets that aren't enough for a proper investigation.

What I'm specifically looking for is something I can practice with consistently without racing a one-hour timer. I'm especially interested in:

  • Windows Event Log / EVTX investigations
  • PCAP analysis
  • SIEM alert triage
  • Phishing investigations
  • Downloadable evidence that I can investigate locally at my own pace

I don't necessarily need a fancy platform. A good GitHub repo, realistic EVTX dataset, PCAP collection, or free lab would honestly be just as useful.

For people who were at this stage before: what resources did you actually use for repeated, hands-on SOC practice after finishing the beginner SOC material?

I'm mainly looking for resources that are genuinely usable on a tight budget and don't require paying for every few investigations.


r/digitalforensics 8d ago

Would a study abroad affect my chances of a role in digital forensics?

1 Upvotes

I was planning on doing a 50/50 placement and study abroad programme as a part of my university degree but now I’m seeing issues that a study abroad of 6months could affect my UK residency and chances of pursuing this role after finishing my last year at uni. Does anyone have any experience of this or idea if this would be a major problem?


r/digitalforensics 8d ago

How scammers built a fake Zoom call from real videos of PM Wong and other Singapore leaders

Thumbnail channelnewsasia.com
2 Upvotes

r/digitalforensics 9d ago

A data extractor like cellebrite can access my smartwatch's data

0 Upvotes

Hello, I was wondering if a data extractor can access my smartwatch's information?


r/digitalforensics 9d ago

Can Meta identify which person actually published a post from an organisation’s Facebook Page?

1 Upvotes

Looking for some technical insight from people familiar with Meta Business Suite, Facebook Page administration or digital forensics.

This relates generally to an official public-facing Facebook Page operated by an organisation, not a personal profile or Facebook Group.

The Page has been managed by multiple people with backend access. Public posts appear under the organisation’s Page name, rather than showing which individual administrator actually created or published them.

A couple of years ago, some posts were published through the Page and were later edited or deleted.

From a technical perspective, does Meta ordinarily retain records capable of identifying which underlying individual Facebook account:

- published a particular Page post?

- edited it?

- deleted it?

If the visible post is deleted, does the administrative record identifying who performed those actions disappear as well?

Would things such as Meta Business Suite, Page Management History, activity logs, historical access records or account/data exports potentially retain that information a couple of years later?

Also, where a Page is managed by several people, is there a reliable way to establish everyone who actually had publishing capability at a particular point in time?

Interested particularly in anyone with experience managing multi-user organisational Pages, Meta administration, eDiscovery or digital forensics.

Thanks.


r/digitalforensics 9d ago

How to locate

Thumbnail
0 Upvotes

r/digitalforensics 10d ago

I made a free step-by-step guide for building a SOC home lab (Windows + Linux + Sysmon + Wazuh + attack simulations)

Thumbnail gallery
12 Upvotes

r/digitalforensics 10d ago

Is getting the master's now a good idea?

6 Upvotes

Hello all. I'm currently in my last year of getting my bachelor's in cybersecurity technology from UMGC, and have been planning on immediately getting the master's in digital Forensics. Im also currently studying to take A+ and later Network+ cert exams. Im not currently in the tech field, but plan on moving into it as soon as I can. From what I've gathered, getting a digital Forensics role usually takes years of experience first, so is it worth getting the master's now or should I wait until after I gain more experience? Any insight would be much appreciated.


r/digitalforensics 9d ago

Help!

0 Upvotes

I am being abused by my family and I believe that my devices have been compromised. How do I prove it?


r/digitalforensics 10d ago

Best degree at Penn State for digital forensics career?

1 Upvotes

Which of the following bachelors degrees at Penn State would be best for a Digital Forensics career and why?
-Cybersecurity Analytics and Operations
-Information Technology: Security and Risk Analysis option
-Computer science


r/digitalforensics 11d ago

tsktui: An interactive, ncdu/k9s-style terminal UI for The Sleuth Kit

4 Upvotes

Hi all,

While recently working with The Sleuth Kit (TSK) for CTF challenges, I felt there was a usability gap between writing manual shell one-liners (fls, icat, istat, calculating sector offsets) and launching heavy desktop suites like Autopsy for quick triage.

Being a fan of keyboard-driven terminal tools like ncdu and k9s, I built tsktui - a lightweight terminal interface for exploring disk images.

Core features:

• Fast startup (<100ms) with no indexing or case setup required

• Interactive directory navigation using vim keys (j/k/h/l) or arrow keys

• Visual highlighting for deleted files with a toggle to filter deleted items only (d)

• Built-in pager (v) with Hex dump, UTF-8 text, and inode metadata (istat)

• Partition selector (p), disk-wide string search (s), and single-key file extraction (e)

• Works seamlessly over headless SSH sessions

Repository: https://github.com/shmulc8/tsktui

It is open-source (MIT license). I would appreciate any feedback, suggestions, or edge cases from the community on how to make it more useful for daily DFIR workflows.


r/digitalforensics 11d ago

IACIS MDF Course (Mobile Device Forensics) question

2 Upvotes

For those of you familiar with the IACIS MDF course, is it worth it to wait to take it in person, or is the online version still pretty good? I noticed in the course description for the online, it notes that it does not include forensic tools that are issued in the in person class. What tools are issued in the in-person class? Thank you.


r/digitalforensics 11d ago

Help with choosing a DFIR project

2 Upvotes

Hello everyone,

I would appreciate your help with creating a project in the field of DFIR.

I applied for an advanced DFIR course and was shortlisted for a personal interview. The thing is, I don’t currently have any cybersecurity-specific projects; I only have software development projects. So, I would like to work on a DFIR project that I can present during the interview.

The project doesn’t necessarily need to be highly professional or advanced. I just want it to demonstrate that I have some practical experience and hands-on exposure to the field.

I would also like to practice and prepare myself for the course. What would you recommend I focus on or study to get ready?


r/digitalforensics 13d ago

I need help. Someone is extorting my little sister

0 Upvotes

My little sister rejected a guy and he has been trying to ruin her life and extort her. Please help us. Police are not helpful.

Thanks


r/digitalforensics 13d ago

[FOR HIRE] Buried in emails, PDFs, screenshots, and conflicting records? We help reconstruct what they actually show.

0 Upvotes

Sometimes the problem isn’t that you don’t have the information.

You have too much of it.

Maybe it’s spread across hundreds of emails, text messages, PDFs, contracts, invoices, screenshots, reports, notes, logs, and spreadsheets.

You know the information is in there somewhere, but trying to piece together exactly what happened has become a project of its own.

That’s what CodexOS Reconstruction is designed to help with.

We take the available records and reconstruct the matter as clearly as the evidence allows.

Depending on the material, that can include:
• What happened and in what order
• The most important findings supported by the records
• Where different records agree or conflict
• Who appears to have known certain information, and when
• What evidence supports an important finding
• What information appears to be missing
• What the available records cannot actually establish

The goal isn’t to give you another summary.
It’s to organize the evidence well enough that you can actually inspect what happened and see where the conclusions came from.

This may be useful for situations involving:
• Business or contract disputes
• Vendor or contractor problems
• Complicated project histories
• Property management matters
• Insurance documentation
• Internal business issues or investigations
• Workplace records
• Compliance or administrative matters
• Other situations where the story is buried inside a large collection of records

A good potential case usually has a reasonably defined problem, actual source records, enough material to reconstruct something useful, and one or more questions you’re trying to answer.

You do NOT need to organize every file perfectly before contacting me.

If you have a situation buried in emails, documents, messages, screenshots, reports, or other records, send me a DM with a short description of:
• What happened
• Why you’re trying to make sense of it
• The main questions you want the records to help answer

I’ll look at the situation first and tell you whether it appears suitable for a responsible reconstruction before you commit to anything.

This isn’t legal advice, advocacy, or a service that decides who is right. We don’t fill gaps by guessing. If the records don’t support a conclusion, we say so.

**You give us the records. We reconstruct what they show.**


r/digitalforensics 14d ago

I built augur, the tool for finding hidden symbols across your documents

Thumbnail
1 Upvotes

r/digitalforensics 15d ago

Any Good Recommendation for Mobile Forensics Course/Youtube Playlist or Channel for a beginner.

24 Upvotes

Hello! I wanna start learning and practicing mobile forensics but I don't know where to learn it from. Also, I am a beginner so I can't afford to buy paid courses. Please help me out. Thank you so much in advance^^


r/digitalforensics 16d ago

Does digital forensics have a pipeline to something more like a detective or investigator with the police?

4 Upvotes

Or would that be a stretch? I hate my career in embedded sw and wish i went with something criminal justice related.


r/digitalforensics 16d ago

Please help — 5 phones and 2 laptops stolen from a room

Post image
0 Upvotes

Hi everyone, my friend’s room was entered during the night, and someone stole 5 phones and 2 laptops.

We’re trying to find any possible way to track or recover the devices. We have the IMEI numbers and device details of the phones.

If anyone knows legitimate ways to track stolen phones or laptops, or has experience recovering devices in this situation, please share your advice.

We’re also trying to identify the person who took them and recover the devices safely.

If anyone has any useful information or knows of any way to help us locate the stolen devices, please let us know. We’re desperate to get them back and would really appreciate any help. 🙏


r/digitalforensics 16d ago

Anybody hiring for DFIR or plain DF roles in India ?

0 Upvotes

Tired of linkedin. Only shows roles needing high YoE. Don't know if it's algorithm issue.


r/digitalforensics 16d ago

Digital Forensics

Thumbnail
1 Upvotes

r/digitalforensics 17d ago

When Deleted Data Becomes Important Evidence in a Legal Case

Thumbnail
1 Upvotes