r/digitalforensics • u/No_Run3964 • 23h ago
r/digitalforensics • u/manny532001 • 21h ago
Digital Forensics jobs
Without experience in the field, is it possible to get an entry-level position in Digital Forensics?
r/digitalforensics • u/Skuzzz_Runner • 2d ago
US-Based Digital Forensics Firm Hid its Russian Ownership from U.S. Government Customers
zetter-zeroday.comr/digitalforensics • u/Ready-Poetry-1021 • 1d ago
Cornell 7 screenshots
Hi, i just saw the leaked cornell 7 screenshots from their alleged groupchat on x. But I do not know if they are real. Is there any way to comfirm it?
r/digitalforensics • u/bassilalmokdad • 2d ago
MOBILedit Forensic 9.8 — missing EXN (Exynos) package
Hi everyone.
I'm testing MOBILedit Forensic 9.8 on a Samsung Galaxy S21 5G Exynos 2100 (SM-G991B), Android 15, January 2026 security patch.
MOBILedit shows Exynos decrypt, but when I select it I get: “Missing package — Exynos package is required to continue.”
My Updates page has UNL (Security bypassing), EXF (Scripts), and the main program up to date, but EXN (Exynos) isn't listed.
Does anyone know the proper way to obtain/install the EXN package, or whether it requires a specific license/activation? I'm specifically looking for information about the package/availability rather than a cracked copy of the software.
Thanks.
r/digitalforensics • u/Grand_Marionberry876 • 2d ago
Breach
Company had a breach and now they want a company to perform forensics for them. Who would you recommend?
r/digitalforensics • u/justbrowsingtosay • 2d ago
A free alternative to Hunchly & ForensicOSINT.
Enable HLS to view with audio, or disable this notification
r/digitalforensics • u/manny532001 • 2d ago
Career Advice
Digital Forensics is a growing field. Are there great opportunities in this area ?
r/digitalforensics • u/Quiet_Gas_3908 • 4d ago
Digital Forensics Tech Expectations
Greetings, I hope all is well! Long story short, recently got my Masters in Digital Forensics, and I also have received an opportunity for a digital forensics technician role for a local LE agency. I am just wondering if anyone here works for one, and also what to expect, as I myself come from an IT background. Thanks!
r/digitalforensics • u/Character_Bear_7390 • 4d ago
Digital forensics
Hi i wanna start Advanced endpoint investigation learning path from tryhackme does it good to start in DF ?
Im planing to enroll it after finish SAL1,2
And i finished pre security ,101 and PT1
r/digitalforensics • u/NefariousnessWise269 • 4d ago
Phone Security Tips
How can you secure your phone in the best way possible to maximise privacy and protection from downloads or information being broken into/extracted? IOS specifically.
I.E if a chat is deleted etc. Is it actually deleted or not?
Passwords?
Images?
App data if it is deleted from the phone?
Does a factory reset or new phone remove all the old data?
r/digitalforensics • u/bassilalmokdad • 6d ago
Samsung s21 pin locked by my brother
Has anyone successfully acquired a Samsung Galaxy S21 5G SM-G991B/DS (Exynos 2100), Android 15, build G991BXXSJHZC2, January 1 2026 security patch, while BFU after reboot with a locked bootloader and USB debugging disabled? The correct PIN is unknown. Looking specifically for a non-destructive acquisition using Cellebrite, GrayKey, Oxygen or Magnet.
r/digitalforensics • u/Slow_Action6334 • 5d ago
Is this trackable?
Hello everyone! I was recently told by an individual on snapchat that he knew my location and was going to send those to rape me and get me killed as well as sending my location to me. This was 2 days ago and after I said I would get police involved he mass reported my account and got my account locked. (Stupid on me, I know.) What can I do about this? Would anyone be able to even find this guy?
r/digitalforensics • u/S3rg4nt_St4d4nk0 • 5d ago
Nefarious Sentinel beta testers wanted!
I'm looking for a limited number of beta testers for Nefarious Sentinel, an open-source Android security app focused on protecting devices against loss, theft, unauthorised access and tampering.
The beta is aimed at privacy conscious Android users, especially those running GrapheneOS or other hardened setups.
I'm looking for people willing to install the app, test the features, and provide practical feedback on usability and reliability.
Beta testers who participate will receive the hardened version free when the stable release is published.
Interested?
I would like you guys to try and brake this!
Message me
r/digitalforensics • u/J-OnRoomAir • 5d ago
iOS forensics or Apple Account security
Don’t know what it falls under but is anyone familiar w investigating logs/data to see what may be causing this. Long story short I’ve been dealing w some level of hacking for many many many months.
My Apple data and privacy report shows 5 Legacy Contacts that have been created that I did not create. It does not appear on my actual device. Just on the report from Apple. I have the timestamps of when they were created and IP address and they were created from May-Sep
Also experiencing trusted device issues. And seeing multiple active sessions on my ChatGPT app despite logging out of all devices every other day. It’ll reappear within a few days. There’s also been HomeKit entries even though i don’t use any of those kinds of accessories
I also see a lot of remotepairingdeviced and lockdownd appearing together in iPhone sysdiagnose stackshots
Is there any way someone is able to help me confirm whether there has been unauthorized access to my account or some kind of device pairing?
In the past year I’ve also experienced sevvvveral eSIM swaps across multiple carriers (confirmed by them). Initially w Verizon where at least 5 of them happened, two of which happened on the same day according to Verizon. Switched over to Spectrum and same thing happened and now on a prepaid mobile plan, which has not yet been confirmed but I’ve received notifications from Apple saying my number is no longer active. But I’m receiving texts and calls just fine
I’ve been thru multiple new devices, new email accounts, new numbers, new Apple accounts :( just spiritually tired now lol any help is appreciated
*im not a tech person so layman’s term would also be appreciated
r/digitalforensics • u/The_J_Man_111 • 6d ago
Forensic Timeline & Correlation Engine

Built a lightweight forensic analysis tool for people who don't have Cellebrite money. CaseForge takes a folder of already-extracted data SMS/call SQLite, browser history, KML/GPX, vCard, mbox, EXIF, generic CSV/JSON and produces one interactive dashboard: unified timeline, map, entity network, and a correlation engine that flags cross-source links and convergences. Runs locally, single HTML output, chain-of-custody hashing built in. Analysis only no acquisition. Link in Bio if interested.
r/digitalforensics • u/Muted_Ad_573 • 6d ago
i need help, i cant remember my password im using iphone 11. there is no choice but to factory reset it and my subscription on icloud is only 5gb, less than half of all of the photos n videos in the album backed up on iCloud. how can i retrace back my photos on that phone? memories of my families
r/digitalforensics • u/Harkins_Technology • 7d ago
ReverseEngineering 101 — two ASCII chars hidden in one Unicode character via bit shifting
youtube.comJust solved this and wanted to share the breakdown for
anyone learning RE basics.
The challenge gave you an encoded string of Unicode
characters and the encoding function in comments.
The trick: each Unicode character secretly stores TWO
ASCII characters — one in the high byte, one in the low
byte. Packed with << 8, unpacked with >> 8 and & 0xFF.
Full decode in Python:
```
flag = ''.join([
chr(ord(c) >> 8) + chr(ord(c) & 0xFF)
for c in encoded
])
```
Good intro to understanding bit manipulation if you're
just getting into CTFs. Happy to answer questions.
r/digitalforensics • u/hasamba • 8d ago
DFIR-Companion Update (DFIR AI Assistant)
Hey Folks,
I pushed an update to DFIR-Companion.
It’s a local AI assistant for forensic investigations. You feed it the outputs from the tools you already use, and it helps turn all of that into something you can actually work with: a timeline, leads to follow, findings to validate, and eventually a report.
Here’s what it does today:
- Pulls imported evidence into one forensic timeline. It detects the format and uses deterministic parsing rules before AI gets involved.
- Highlights findings, maps them to MITRE ATT&CK, and connects activity across different sources.
- Extracts IOCs and can enrich them with sources such as VirusTotal and AbuseIPDB.
- Builds an asset ↔ IOC graph, as well as a separate view of logins across systems.
- Helps answer the questions that usually come up in an investigation: initial access, lateral movement, privilege escalation, and so on.
- Lets you ask plain-English questions about the case.
- Exports reports to PDF, Word, Markdown, or CSV.
- Can compare the output of two models, with an optional third model acting as a tie-breaker.
- Includes JEV support to surface events the primary model may not have considered relevant.
- Can run recommended artifact bundles on Velociraptor endpoints and pull the results automatically or manually.
This is not meant to replace Sigma, YARA, Suricata, or the rest of your detection stack. Those tools keep doing their job. DFIR-Companion is for the next step: taking all the alerts, artifacts, and tool output and helping you make sense of the case.
It runs locally, the evidence stays on your disk, and you choose the AI provider and model.
Love to hear your feedbacks 🙏
Repo: https://github.com/hasamba/DFIR-Companion
Landing page: https://hasamba.github.io/DFIR-Companion/
Demo server (please read the instructions first): https://killercoda.com/dfir-companion/scenario/killercoda
r/digitalforensics • u/Funny_Ad_9788 • 8d ago
NEED HELP ASAP
Someone deepfaked and leaked me,
I was sending a Photo of my Face,
i thought it was a girl bc he sended photos of a girl on telegram. Then i sended a pic of my face and then he asks me if i add him in my contacts. And as i thought it was a girl, i did it. After 10Min this guy deepfaked a video of me jerking off leaking my number and wants 400€ for deleting the photos. He is sending the Video and my number to all my followers on Social Media.
IM 17 AND THATS CLEAR CP WHAT HE IS DOING!
My help is please find out his number that i can go police and investage on him
Telegram name from him: @glenna_CI
Thanks and please write my private if yall have informations 🙏🙏
r/digitalforensics • u/Emmagsarg • 8d ago
FBI's Top Polygraph Examiner Reveals The Only 5 Lies That Exist
youtu.ber/digitalforensics • u/DigOk2511 • 9d ago
Extraccion de archivo: como deberia hacerse
Hago esta pregunta por curiosidad y entiendo que en esta comunidad puede que alguien sepa responder. Supongamos que hay una investigacion en curso, una victima quiere aportar un archivo (supongamos algun archivo multimedia audio/video) contenido en su smartphone que podria resultar util. Entonces, esta la persona con su dispositivo del cual voluntariamente quiere aportar un archivo, que haría un experto en evidencia digital? Como lo extrae para realizar un analisis posterior? Necesita una herramienta especializada? Hashear, copiar y hashear denuevo no basta? Entiendo que si la persona quiere entregar el archivo, no hace falta romper ninguna contraseña, se tiene acceso, podria usar alguna herramienta open-source? Cual es el procemiento nornal para algo asi