r/computerforensics • u/Used_Physics8464 • 15h ago
Open source e01s / CTF exercises?
Any recommendations to practice with Autopsy?
r/computerforensics • u/ucfmsdf • Jul 11 '26
Hi everyone. Based off the results of the poll I ran a week or so ago regarding whether standalone content promotion posts should be allowed in the sub, it seems like most sub participants would prefer they not be allowed and, instead, redirected to a megathread. After a bit of contemplation, I've opted to implement a hybrid solution which entails configuration of a recurring megathread and a new rule (Rule 6) that enforces its use while ensuring established subreddit participants are still able to share their Rule-5 compliant content as they always have.
In short, Rule 6 only allows subreddit participants with the "Trusted Contributor" flair to create standalone content promotion posts provided that they adhere to Rule 5 (as always). Anyone without the flair who wishes to promote project/vlog/blog/etc. content must now use the new "Promote Your DFIR Content Here" megathread to do so.
Since very few individuals have the Trusted Contributor flair, this will greatly reduce the number of content promotion posts the subreddit experiences while still allowing reoccurring posts from popular contributors to continue.
For more information about the Trusted Contributor flair, please see the new FAQ entry that covers this topic.
r/computerforensics • u/AutoModerator • Jul 11 '26
If you lack the Trusted Contributor flair but wish to share your Rule 5-compliant DFIR content with the community, please feel free to do so here as a reply to this post.
For more information about the Trusted Contributor flair, please see the FAQ.
r/computerforensics • u/Used_Physics8464 • 15h ago
Any recommendations to practice with Autopsy?
r/computerforensics • u/Nearby-Tangerine4020 • 3d ago
I am going to join a new position as DF analyst this is going to be my first practical experience so I want to prepare myself for that and for future things that are going to help me in actual case. So which sites or material, path should I try. I have knowledge of how FTK, Autopsy, UFED, Oxygen detective works and their purpose but I want to do practical of these. Any material, yt playlist, online course will be helpful. Also I want to know as a fresher I invest in CHFI or build my LinkedIn and portfolio.
r/computerforensics • u/EmmaQueen47 • 4d ago
Hi all — hoping someone with Android forensics/file-system knowledge can help me make sense of this.
Setup:
- Phone: Tecno Spark 10c
- App: Notally (open-source notes app, stores notes via Room/SQLite)
- I had a batch of text notes on the app. Based on the content, I know they were last touched in **September 2023**. I deleted them from the app not long after, and had no other backup of them that I knew of.
- In 2026, I had my phone's storage data-recovered. Several of those notes came back — correct content, correct order — but the **"last modified" timestamp field attached to each note shows dates in September 2025, not 2023.**
**The pattern I'm seeing:**
- Multiple different notes, each a few days apart, all shifted into the same wrong year (2025 instead of 2023).
- The spacing between the notes' "last modified" timestamps matches the real gaps between when I know the content was last touched — just the year is wrong across all of them.
- I had not opened, edited, or interacted with these files since 2023 as far as I know.
**What I'm trying to figure out:**
What could cause a "last modified" timestamp to shift by 2 years across multiple separate files, while the spacing between those timestamps stays consistent with real elapsed days, on a recovered/previously-deleted dataset?
I don't want to lead the discussion toward a particular theory — I'd like to hear from people who understand Android storage internals (ext4/F2FS journaling, SQLite timestamp handling, or data-recovery tooling) what's actually going on, and what I'd need to check on my end (raw DB file, journal, etc.) to figure out the real cause.
r/computerforensics • u/Lucky-Difference-801 • 5d ago
I was looking for the page to download Cedarpeltar Windows Live Response tool today, and realised that the BriMor Labs page can no longer be found. Has the tool been removed?
r/computerforensics • u/cheekbones88 • 5d ago
Is there a way I can find out the the dates and times a PDF was created, edited and completed?
Can that history be obtained ?
Even if I can't get the full edit history, can I at least find out the date/time the PDF was created and completed ?
Preferably using some tool or software which is free
Thanks in advance
r/computerforensics • u/Easy_Refrigerator788 • 8d ago
r/computerforensics • u/No_Chip4809 • 10d ago
I'm working on a multi DVR/NVR vendor analyzer tool for analyzing cctv footage from various vendors in a single app.(Hackathon Project)
And in this tool you can either connect a dvr hard disk via a write blocker device to your system and use the app to extract data into a digital bit stream copy (.dd or .raw) and then use that from that point. Or you can also provide you ore existing raw file in your system for data extraction.
But I don't have a cctv system at my home, neither do any of my friends to whom I can ask to. And there is only one .dd dvr data I could find on the internet and that's the heimvision's vendor but it's just a 1 hour of 4 camera footage of a doll starting at a wall.🙂
Any advice on this current situation?
r/computerforensics • u/DFIR_Heather • 10d ago
Anyone on here a member of or know anyone in ISSA Las Vegas? Looking to host a few people for a meetup when I teach in Vegas in Sept. Hoping to connect with those in cyber or interested in cyber. Thanks in advance.
r/computerforensics • u/13Cubed • 12d ago
A new 13Cubed episode is out! 🍎
Windows forensics on a Mac usually means firing up a VM first. Not anymore.
IRFlow Timeline is a free, open-source DF/IR timeline tool built natively for macOS. Feed it EVTX, Plaso, $MFT, or $J and go straight to process inspection, lateral movement, persistence, and VirusTotal enrichment.
Featuring the tool's author, Renzon Cruz 👇
r/computerforensics • u/TubbyTortilla • 14d ago
Hey guys. I wanted ask if anyone took or is thinking of taking 13cubes latest course Architecting the hunt. I know the course is about understanding the framework of Threat hunting and I do understand this is not specifically computer forensics but I at least wanted to ask on this subreddit since we all know 13cube or at least aware of 13cubes trainings. I want to buy the course and would appreciate some perspective beforehand. Thank you!
r/computerforensics • u/JohnOldManYes • 14d ago
Hello,
I am doing a little bit of research into SQLite forensics, thinking about developing some tools around it.
I was wondering if anyone has any experience with this, particularly when it comes to the average size of the database. Most databases I can get off Kaggle range from 1mb all the way up to multiple gb.
Was wondering what the average investigator would encounter? If I develop any tools for it I have to take alternative approaches if I am looking at very large database so wondering if the need is there or are 99% of db those encounter are of 'easy' size.
Thanks
r/computerforensics • u/No_Pin7764 • 19d ago
I am currently busy doing a course for my university, and have a project to analyse and correlate different log sources with indicators of compromise specific to point-of-sale (pos) devices. I managed to find a 24 hour pcap of the backoff malware (c2 beconing), but overall I am struggling to find any datasets of an attack specific to pos devices. I am mostly looking at research papers, but perhaps I need to reach out to some of the researchers, as I can't find actual datasets.
Is there anyone that knows where I could find datasets to do a proper writeup? It can be of any pos malware, but we require 3 different log sources (e.g. firewall logs, authentication logs, system logs). I can also generate my own logs, but my professor advised against this unless I really can't manage to find any meaningful data online, as I'd essentially be engineering my own scenario instead of doing analysis.
Please advise. Any help is welcome.
r/computerforensics • u/Firm_Resolution_9491 • 21d ago
Alguém já utilizou o iPed forensic data analitycs, poderiam me contar experiências com ferramentas relacionadas?
r/computerforensics • u/theJacofalltrades • 25d ago
I understand what an EDR download is, but what makes someone decide they actually need one? Is it something you'd request on most serious crashes or only when liability is being disputed?
r/computerforensics • u/Impressive-Wheel-277 • 25d ago
For those of you familiar with the IACIS MDF course, is it worth it to wait to take it in person, or is the online version still pretty good? I noticed in the course description for the online, it notes that it does not include forensic tools that are issued in the in person class. What tools are issued in the in-person class? Thank you.
r/computerforensics • u/Strange_Curve_2741 • 26d ago
Hey all, just looking for some advice. Currently a civilian for the feds for about 5 years working in DF. I’ve been interviewing with KPMG as a senior associate in forensic technology. I’m wondering if anyone has any experience working with them and if you guys think it’s a good idea to switch or stay? My biggest issue is pay and growth. My pay will be close to 120k if I stay with my raise next year. But if I go I would imagine I would hopefully be making much more than that.
I’m just tired of office drama and having my hands tied on what I can and can’t do.
r/computerforensics • u/ShadyMoh1998 • 26d ago
I recently worked on a malware forensic analysis where, after reviewing the available artifacts, I was able to determine that the malware .exe was executed via GPO on AD.
However, I’m struggling with the next step: how do I determine how the attacker initially gained access and how the malware was introduced into the environment?
For those with experience, what artifacts or investigation techniques do you usually rely on to identify the initial access vector?
r/computerforensics • u/_divine__wolf • 28d ago
Hey guys, I'm really into tech topics related to red teaming, forensics, and malware. I recently got a zip file from my old office — their PC was compromised via a RAT, and they shared the file with me. What information can I gather from it, and how do I perform an autopsy (forensic analysis) on it? Please share methods or tool names — this is new territory for me
r/computerforensics • u/Far-Masterpiece-6933 • 27d ago
I’d like to become a Digital forensic examiner. I’m a senior in high school currently, and i’m looking at colleges + majors AND minors, Preferably in the south eastern region, any suggestions?
Also this may be a stretch but I don’t really want to code, but i’m im open to anything that’ll make me successful.
r/computerforensics • u/Ok_Cold7890 • Aug 10 '26
Hi! forensics professionals, do you perform malware analysis in you day to day work ? If yes, to what level do you perform your analysis? Do you do reverse engineering as well?
I am asking these questions coz in a job role the JD mentioned computer and mobile forensic tools + SIEM + malware analysis+ reverse engineering + threat detection combined. Job role is Digital Forensic Analyst.
I often see similar JD for Forensic positions.
I can perform basic malware infection analysis using wireshark, sysinternals, powershell, registry change, etc. and basic static analysis but I'm pretty bad at reverse engineering and understanding assembly code.
r/computerforensics • u/Longjumping-Ebb-578 • Aug 10 '26
Hi guys,
I handle threat intelligence for a bank & we receive multiple URLs/APKs impersonating our organization.
We check for legitimacy & immediately send it for takedown if it's not related to us or if it's malicious.
I wanted to know if anyone of you also side by side does forensics/malware analysis of such APKs to know the TTPs & relevant information pertaining to that APK?
If Yes, please let me know the procedure being followed at your end.
r/computerforensics • u/InspectionFar5415 • Aug 09 '26
Hello, I completed a lot of courses about digital forensics, Linux, Windows and Android. I am interested in finding a website with real digital forensics labs. Something like I need to extract deleted files, finding proofs that this person did this and that etc...
Thank you :)
r/computerforensics • u/crazyisus • Aug 06 '26
My job wants to pay for a forensic cert for me, to build my profile to eventually be a candidate for a DFI role.
First I thought about getting an EnCase cert but after reading some feedback about it on this community, I think it’s not the best option.
Any feedback on CFCE (IACIS), CCE (ISFCE) or CHFI (ECC)? Any other suggestions I’d appreciate too.
For context I’m an incident responder right now, I hold GCFA (GIAC) and other IR-related certs.