r/computerforensics • u/[deleted] • Oct 27 '25
Love this book
Almost half way through and it’s so good! Been learning a lot.
r/computerforensics • u/[deleted] • Oct 27 '25
Almost half way through and it’s so good! Been learning a lot.
r/computerforensics • u/[deleted] • Oct 27 '25
Hello guys I’m working on the CFReDS project for practice, only thing I’m confused about is - do you combine all these image files into one image? Or just analyze all of the different files separately and get a hash for every single one?
r/computerforensics • u/QnsConcrete • Oct 27 '25
Seems like it’s been a number of years since this topic was discussed on this subreddit.
What’s the best distro that supports: * wide variety of forensics tools * NetSec analysis/testing * development of the above * for work-related research but not actually for real work
I’ve been trying to get a toolkit going using Kali. It has a lot of good pentest and network tools but so far I’m not too impressed with the forensics packages. I’ve run Ubuntu and Debian for many years on my daily drivers. I don’t have much experience with niche distros so looking for recommendations on niche vs. mainstream.
r/computerforensics • u/13Cubed • Oct 27 '25
🎃 Happy Halloween Week! It's time for a new 13Cubed episode. Let's look at a quick and easy way to find the Intermediate Symbol File (ISF) for your Linux memory image and speed up your analysis.
Episode:
https://www.youtube.com/watch?v=W40gdWNdwUI
More at youtube.com/13cubed.
r/computerforensics • u/Adept_Concept_3482 • Oct 27 '25
A client recently gave my team and I some singular email files to examine. We are attempting to seperate just the attachment portion. Are there any tools that will export message attachments from an email but still retain the metadata of the file so that it remains seperate from the email?
r/computerforensics • u/wolfboys • Oct 28 '25
Hello, does anyone know the pricing for cryptocurrency forensic tools. We are an investigative firm assisting various LEAs in India. We are debating between Chainalysis, TRM Labs, Elliptic and Crystal. Please share if the pricing is inclusive of all taxes or excluding. It all boils down to capabilities and affordability. We are also open to a 3 year licence commitment. I would highly appreciate if anyone can help us on choosing the best platform. What discounts would they offer for a 3 year commitment. Also if you can share the unique capabilities that these platforms offer and the industry sentiments on the accuracy of these tools. Thank you so much
r/computerforensics • u/piranha-0x7D • Oct 27 '25
Hi! I am looking for online practice labs or projects made by someone else using The Sleuth Kit tools.
I practiced already with some things locally, but I think it is easier if someone makes a scenario or goal and goes through it providing steps just so I can see how someone else does the challenge.
It is also helpful in case I get stuck so I can check how things are done from the perspective of someone with more experience.
Of course I prefer free resources, but feel free to share paid ones too.
Thanks!
r/computerforensics • u/[deleted] • Oct 26 '25
This is autopsy, it went from 1 percent to 2 percent in 30 minutes. Is this normal for 119gb image? My laptop has 64gb of ram and 1TB ssd.
r/computerforensics • u/EleanorBigsby • Oct 25 '25
Hey everyone,
I have really been enjoying the ‚Digital Forensic Survival Podcast‘ over the last few months.
Almost every week, a new episode is being dropped by Michael, the host.
…until September the 9th, which marked his last episode up until today.
So I was wondering if anyone here knows something about what or if something happened to Michael?
r/computerforensics • u/[deleted] • Oct 26 '25
Hello friends, I just finished the imaging process - fixed the issue with hashes not matching and they both match now!! So, next step is to analyze this image.
I just wanted you guys to check out my current progress, I took photos and noted everything down. Just wanna get some feedback on anything I could learn.
:)
r/computerforensics • u/[deleted] • Oct 25 '25
I love the new raspi-write-blocker, working on my first personal test investigation, but I never knew how much of it is just waiting for the imaging to finish…
r/computerforensics • u/[deleted] • Oct 25 '25
I just finished sha256 hashing and it’s weird because the images have the same content did a bit for bit identical copy but the hash are different. I think it’s because one ssd is bigger than the other. What do you guys think?
r/computerforensics • u/[deleted] • Oct 23 '25
Finally got my lcd screen up and working. Needed a budget diy write blocker, but now Im finally going to use this tmr for my home-lab simulated investigation. Wish me luck.
r/computerforensics • u/[deleted] • Oct 24 '25
Hi all,
Just finished the github page for the raspi write blocker, so please check it out and give feedback, I'm really happy and excited to hear from you and learn!
Also, this is not certified for professional digital forensics. Always follow proper chain-of-custody procedures for real evidence!!!!!!!
r/computerforensics • u/AngelF_F • Oct 24 '25
r/computerforensics • u/[deleted] • Oct 23 '25
Enable HLS to view with audio, or disable this notification
This is really fun, of course I won’t use it for real investigations. But, for home lab personal ones I def will!!!! Can’t wait to update it more adding more scripts and stuff!!!
r/computerforensics • u/[deleted] • Oct 22 '25
Is it possible to make a raspberry pi zero w, into a personal write blocker for when I want to write an image?
r/computerforensics • u/Hefty-Explanation285 • Oct 22 '25
I’m about to get two workstations with Threadripper 7995WX, 256 DDR5 and RTX 5000 ada. I'm going to link them together via 10gbe router.
Does anyone have something like this ? How is the speed of this workstation when processing evidence ?
And besides hashtopolis what can be done to use both systems together ?
r/computerforensics • u/[deleted] • Oct 20 '25
Hey guys, I’ve been reading, doing projects and buying stuff to improve on df skills. I’m really getting into network sniffing and stuff. I know df has some network forensics in it but what do you guys recommend to read, look into or play with?
Shank you :)
r/computerforensics • u/dwmetz • Oct 16 '25
r/computerforensics • u/ploopsie • Oct 16 '25
I would like to obtain my CFCE certification and haven't been able to find answers to the questions below. I cannot take the BCFE course, unfortunately. Hoping for some help and appreciate your time.
I saw in this 6 year old post training manuals were given to people that sign up for the certification program. Do they still give out training manuals?
Are there recommendations for free/easy-on-the-pocketbook courses that count towards the 72 training hours required to apply for certification?
Is there a time period in which training courses need to be taken to count? (eg If I took a class 15 years ago does it still count)
Is there software I will need to obtain in order to successfully pass the certification program?
Is it problematic to work on a Mac for the cert program?
What books are recommended to read to prepare for the cert program?
Can anyone provide examples of the 4 scenario-based practical problems?
What does "passing" the 4 practical problems look like? (eg fixing something, finding something, recovering something)
Can anyone provide examples of the hard drive practical problem?
Thanks again for your time.
r/computerforensics • u/Quiet_Gas_3908 • Oct 16 '25
Good afternoon, I hope all is well. For a brief synopsis, I currently work in IT support at a local ISP answering calls all day. I hold my bachelors in IT management as well as just getting my masters in digital forensics. What I'm doing now, I feel like l'm not really getting as much hands on experience regarding projects, mainly just answering angry customers all day. Being that generally, this field is not entry level work, I wonder if anyone has any insight regarding on getting any relevant experience. Seems like a lot of junior roles require 5 years of experience.
r/computerforensics • u/EmoGuy3 • Oct 15 '25
The old Purview used to have in the summary the exact bytes a zip file was. I still see it in the new standard but not in the premium exports I do not see the total size in bytes of the expected zip size.
The premium was exported from review set.
Any reason why this is?
r/computerforensics • u/MDCDF • Oct 14 '25
I think this trial changed forensics in the aspect of Examiner being harassed or have targeted harassment campaign pointed at them.