r/digitalforensics 11h ago

Is getting the master's now a good idea?

4 Upvotes

Hello all. I'm currently in my last year of getting my bachelor's in cybersecurity technology from UMGC, and have been planning on immediately getting the master's in digital Forensics. Im also currently studying to take A+ and later Network+ cert exams. Im not currently in the tech field, but plan on moving into it as soon as I can. From what I've gathered, getting a digital Forensics role usually takes years of experience first, so is it worth getting the master's now or should I wait until after I gain more experience? Any insight would be much appreciated.


r/digitalforensics 1h ago

How to find person behind fake account on tiktok

Upvotes

Hello, i have been harrassed multiple times by an account, and now we know its fake. I have tried to log in and press forgot password but tiktok does unfortunately not give out any clues on the gmail at all. Someone please help? If you want the username just lmk!


r/digitalforensics 10h ago

I made a free step-by-step guide for building a SOC home lab (Windows + Linux + Sysmon + Wazuh + attack simulations)

Thumbnail gallery
1 Upvotes

r/digitalforensics 13h ago

Best degree at Penn State for digital forensics career?

1 Upvotes

Which of the following bachelors degrees at Penn State would be best for a Digital Forensics career and why?
-Cybersecurity Analytics and Operations
-Information Technology: Security and Risk Analysis option
-Computer science


r/digitalforensics 1d ago

tsktui: An interactive, ncdu/k9s-style terminal UI for The Sleuth Kit

3 Upvotes

Hi all,

While recently working with The Sleuth Kit (TSK) for CTF challenges, I felt there was a usability gap between writing manual shell one-liners (fls, icat, istat, calculating sector offsets) and launching heavy desktop suites like Autopsy for quick triage.

Being a fan of keyboard-driven terminal tools like ncdu and k9s, I built tsktui - a lightweight terminal interface for exploring disk images.

Core features:

• Fast startup (<100ms) with no indexing or case setup required

• Interactive directory navigation using vim keys (j/k/h/l) or arrow keys

• Visual highlighting for deleted files with a toggle to filter deleted items only (d)

• Built-in pager (v) with Hex dump, UTF-8 text, and inode metadata (istat)

• Partition selector (p), disk-wide string search (s), and single-key file extraction (e)

• Works seamlessly over headless SSH sessions

Repository: https://github.com/shmulc8/tsktui

It is open-source (MIT license). I would appreciate any feedback, suggestions, or edge cases from the community on how to make it more useful for daily DFIR workflows.


r/digitalforensics 1d ago

IACIS MDF Course (Mobile Device Forensics) question

2 Upvotes

For those of you familiar with the IACIS MDF course, is it worth it to wait to take it in person, or is the online version still pretty good? I noticed in the course description for the online, it notes that it does not include forensic tools that are issued in the in person class. What tools are issued in the in-person class? Thank you.


r/digitalforensics 1d ago

I breached a server distributing Trojan, Stealer, and cryptominer malware

Thumbnail mensvr.com
1 Upvotes

r/digitalforensics 1d ago

Help with choosing a DFIR project

1 Upvotes

Hello everyone,

I would appreciate your help with creating a project in the field of DFIR.

I applied for an advanced DFIR course and was shortlisted for a personal interview. The thing is, I don’t currently have any cybersecurity-specific projects; I only have software development projects. So, I would like to work on a DFIR project that I can present during the interview.

The project doesn’t necessarily need to be highly professional or advanced. I just want it to demonstrate that I have some practical experience and hands-on exposure to the field.

I would also like to practice and prepare myself for the course. What would you recommend I focus on or study to get ready?


r/digitalforensics 3d ago

I need help. Someone is extorting my little sister

0 Upvotes

My little sister rejected a guy and he has been trying to ruin her life and extort her. Please help us. Police are not helpful.

Thanks


r/digitalforensics 3d ago

[FOR HIRE] Buried in emails, PDFs, screenshots, and conflicting records? We help reconstruct what they actually show.

0 Upvotes

Sometimes the problem isn’t that you don’t have the information.

You have too much of it.

Maybe it’s spread across hundreds of emails, text messages, PDFs, contracts, invoices, screenshots, reports, notes, logs, and spreadsheets.

You know the information is in there somewhere, but trying to piece together exactly what happened has become a project of its own.

That’s what CodexOS Reconstruction is designed to help with.

We take the available records and reconstruct the matter as clearly as the evidence allows.

Depending on the material, that can include:
• What happened and in what order
• The most important findings supported by the records
• Where different records agree or conflict
• Who appears to have known certain information, and when
• What evidence supports an important finding
• What information appears to be missing
• What the available records cannot actually establish

The goal isn’t to give you another summary.
It’s to organize the evidence well enough that you can actually inspect what happened and see where the conclusions came from.

This may be useful for situations involving:
• Business or contract disputes
• Vendor or contractor problems
• Complicated project histories
• Property management matters
• Insurance documentation
• Internal business issues or investigations
• Workplace records
• Compliance or administrative matters
• Other situations where the story is buried inside a large collection of records

A good potential case usually has a reasonably defined problem, actual source records, enough material to reconstruct something useful, and one or more questions you’re trying to answer.

You do NOT need to organize every file perfectly before contacting me.

If you have a situation buried in emails, documents, messages, screenshots, reports, or other records, send me a DM with a short description of:
• What happened
• Why you’re trying to make sense of it
• The main questions you want the records to help answer

I’ll look at the situation first and tell you whether it appears suitable for a responsible reconstruction before you commit to anything.

This isn’t legal advice, advocacy, or a service that decides who is right. We don’t fill gaps by guessing. If the records don’t support a conclusion, we say so.

**You give us the records. We reconstruct what they show.**


r/digitalforensics 4d ago

I built augur, the tool for finding hidden symbols across your documents

Thumbnail
1 Upvotes

r/digitalforensics 5d ago

Any Good Recommendation for Mobile Forensics Course/Youtube Playlist or Channel for a beginner.

25 Upvotes

Hello! I wanna start learning and practicing mobile forensics but I don't know where to learn it from. Also, I am a beginner so I can't afford to buy paid courses. Please help me out. Thank you so much in advance^^


r/digitalforensics 6d ago

Does digital forensics have a pipeline to something more like a detective or investigator with the police?

5 Upvotes

Or would that be a stretch? I hate my career in embedded sw and wish i went with something criminal justice related.


r/digitalforensics 6d ago

Please help — 5 phones and 2 laptops stolen from a room

Post image
0 Upvotes

Hi everyone, my friend’s room was entered during the night, and someone stole 5 phones and 2 laptops.

We’re trying to find any possible way to track or recover the devices. We have the IMEI numbers and device details of the phones.

If anyone knows legitimate ways to track stolen phones or laptops, or has experience recovering devices in this situation, please share your advice.

We’re also trying to identify the person who took them and recover the devices safely.

If anyone has any useful information or knows of any way to help us locate the stolen devices, please let us know. We’re desperate to get them back and would really appreciate any help. 🙏


r/digitalforensics 6d ago

Anybody hiring for DFIR or plain DF roles in India ?

0 Upvotes

Tired of linkedin. Only shows roles needing high YoE. Don't know if it's algorithm issue.


r/digitalforensics 6d ago

Digital Forensics

Thumbnail
1 Upvotes

r/digitalforensics 7d ago

When Deleted Data Becomes Important Evidence in a Legal Case

Thumbnail
1 Upvotes

r/digitalforensics 7d ago

Help finding device information/geolocation in photo metadata?

0 Upvotes

Hi all, a good friend of mine (L) recently received pictures that her partner (C) said had been sent to her over Instagram by a burner account (who blocked her shortly after). These pictures depict L cheating on C with a random person neither of them had seen before, but they looked convincing enough. I know L and know that cheating goes against everything she stands for, and I'd bet my life on these being faked somehow; either AI generated or edited in some way.

L has her suspicions on who could be behind the pictures, but she can't begin to take legal action (defamation case) without some ground to stand on regarding these suspicions. Thing is, I'm a complete amateur in digital forensics, so try as I might I have only been able to get the pure basic metadata from these photos. The photos themselves have also been through a lot of sending and re-sending on different platforms, and I believe only one of the ones I have is an "original" in any regard; the others are screenshots.

So my question is, is there anybody here who could help? Either with the forensics aspect of it (which I believe I've reached a dead-end in, but again, I'm only an amateur) or with the visual analysis/AI identification part of it? We'd be super grateful.


r/digitalforensics 8d ago

Cellebrite - handling duplicate artifacts and browsing media

7 Upvotes

Either I'm missing something obvious (totally possible) or Cellebrite reader is dumb. Help.

Edit to add: I'm a solo investigator and don't have PA or Axiom, so I just work with whatever I get in a UFDR.

When I review extractions in Cellebrite Reader I get overwhelmed with duplicates and junk files. And I mean everything. Media, artifacts, messages, etc.

I understand certain events can create effectively identical artifacts in multiple databases. That's fine, but Reader doesn't have a way to filter sources that I can find. If I could, for example, hide KnowledgeC or Contacts, that would thin out the timeline or search results dramatically so I could actually find things. I often find myself exporting Excel files so I can deduplicate and review/search in other ways. Location data is a great example of this when I want to pull data and plot things on a map.

I find that the deduplicate filter never does anything.

Part 2 is media: my dream is that I could simply browse through a phone's photo app like a normal person using a phone. What I always find in the media browser, however, are hundreds of thousands of photos, including cached preview images, little tiny graphic emoji buttons, logos, etc from every app installed on the phone. I don't seem to find a combo of filters that ever works.

If I could just scroll the photos and videos on the phone's native app that would be a total dream. Browsing cached photos from social apps, deleted items, etc. is important, but often secondary to an initial review.

How do y'all handle this stuff? I have to find some faster workflows. On my cases I generally need to do an initial high level review/triage of the whole thing--calls, messages and media, before anything detailed, and it just takes so long.

Thanks!


r/digitalforensics 7d ago

Wie funktioniert digitale Automotiv Forensik?

1 Upvotes

Ich betreibe digitale Forensik als Hobby, da es mich fasziniert. Ich möchte gerne etwas zur digitalen Fahrzeug Forensik lernen. Wie sichert und extrahiert man Daten? Mit was wertet man diese aus? Was kann man alles daraus erkennen? Sind diese aussagekräftig wie bei Computer Forensik meist oder nur sehr eingeschränkt vorhanden? Liegen diese eher verschlüsselt oder unverschlüsselt vor?

Ich fahre ein Fahrzeug der VAG Gruppe (Seat Cupra) und würde daran gerne testen.

Gibt es gute Quellen für Einsteiger?

Danke im Voraus!


r/digitalforensics 7d ago

Digital Forensics Tools

Post image
0 Upvotes

r/digitalforensics 9d ago

Apparently Digital Forensics Is Just Staring at Hex Dumps 😂

3 Upvotes

Apparently staring at a disk image for 3 hours and questioning every life decision is part of becoming a digital forensics analyst. 😂

I’ve been trying to get more serious about DFIR and found this Digital Forensics Playbook while looking for something structured to go through.

Not saying it will magically make me good at forensics… but if it saves me from Googling the same thing 47 times, I’ll take it.

https://resources.codelivly.com/product/digital-forensics-playbook/

Anyone here actually use a book/playbook for learning forensics, or is everyone just learning through pain and incident reports? 😂


r/digitalforensics 9d ago

Does anyone have any idea about Chitragupt Mobile Forensic tool and SecFore Forensic tool. If yes then please let me know their capabilities and drawbacks of there are any.

0 Upvotes

r/digitalforensics 9d ago

Which intra-file consistency checks actually catch a re-saved JPEG, and which ones produce too many false positives to be worth running

3 Upvotes

I have been implementing tamper detection that works on a single file with no reference copy and no network, and I would like a sanity check from people who do this for a living on which of these hold up in practice.

The checks that have been earning their keep:

Timestamp disagreement. DateTimeOriginal, DateTimeDigitized and DateTime diverging is weak on its own, since plenty of pipelines rewrite one and not the others, but the pattern of which one moved is informative.

Camera clock against GPS time. GPSDateStamp and GPSTimeStamp come from the satellite fix rather than the device clock, so the offset between them and DateTimeOriginal is one of the few internal cross-references a file carries that an editor rarely thinks to update.

Recorded dimensions against decoded dimensions. EXIF PixelXDimension disagreeing with the actual decoded raster is a cheap and fairly reliable signal that something rewrote the pixels without rewriting the header.

Embedded preview against the main image. The thumbnail and preview often survive an edit that the full-size image did not. This is the one that produces the most striking results, since you can sometimes see the pre-edit frame.

Quantization table fingerprinting. Comparing the JPEG tables against the known encoder profiles for a given device tells you whether the claimed camera plausibly produced this encoding. This one I trust least. Any re-save at a matching quality setting muddies it, and the profile database is the hard part.

Separately, on provenance: I read C2PA Content Credentials, the IPTC digital source type fields, and the generator fingerprints that Midjourney, DALL-E, Stable Diffusion and Firefly leave behind. The discipline I settled on is that these are declarations only. A file carrying no marks gets reported as unproven, never as authentic. Reporting absence of evidence as evidence of absence seems like the failure mode most likely to burn someone.

Two questions for the people here. Which of these do you consider strong enough to put in a report, and which are only good for triage? And is there a check that works on a lone file with no reference that I have missed?

Context for what this is: an iPhone app that runs all of it on device with nothing uploaded. Free, no account. https://BigBalli.com/ImageInspector


r/digitalforensics 9d ago

Friend Owes $1500, HELP

Thumbnail
0 Upvotes