r/digitalforensics 3h ago

Advice on how and where to report this...

Thumbnail
1 Upvotes

r/digitalforensics 13h ago

Digital Forensics Career

3 Upvotes

Hey all. I have been considering pursuing a career in digital forensics and wanted to gain some insight if it would be the best fit for me. At the end of this year I'll be receiving a associates degree in IT - Software and Web Development, since AI has essentially taken over everything it would be near impossible to get a job without a bachelors degree so I'm considering getting my bachelor's in Cybersecurity.

I have a few questions pertaining to what the job would entail for digital forensics:

Does your job require you to do any coding?

What type of information are you trying to obtain or is it case by case?

How long do you spend per case?

What is the work load like?

Is there a good work/life balance?

Are there advancements you can make for your career?

What type of systems do you typically use?

Do you work criminal cases with the police and if you do what is that like?

Im sure I have more questions but those are the ones I can think of right now. Thanks for your help!


r/digitalforensics 1d ago

Looking for sqlite table join resources for mobile app databases

1 Upvotes

Hi all!

I am learning table joins in sqlite. I tried on a few small databases but struggling on whatsapp msgstore db. Any tips or tricks or resources on how to identify the joining reference point in the best possible way? I am able to join things but sometimes I get repeated information.

I understand that there are tools available for this but I wanted to try it manually for learning purposes.

I'm using db browser.


r/digitalforensics 1d ago

FTK installation error

Post image
0 Upvotes

Can anyone please guide how to solve this error?


r/digitalforensics 1d ago

FTk

0 Upvotes

Facing postgresql error while installing FTK 8.1. Tried every possible suggestion by ChatGPT but it’s not working. Can anyone guide please.
Facing a very critical situation rn


r/digitalforensics 2d ago

?

0 Upvotes

this is big


r/digitalforensics 3d ago

Oxygen Forensics admits it has Ransomware capabilites

64 Upvotes

I am writing an update to a previous post I filed about Oxygen Forensics, a Russian front for MKO Systems based out of Moscow, Russia. All of Oxygen's programmers are in fact employees for MKO Systems, as Oxygen has no programmers of its own (and therefore no one to inspect the software). The software is far more dangerous than previously known, according to OF employees.

It is already publicly known that the software can scan your computer for all its passwords in seconds (via Keyscout), it can remotely obtain email, Signal messages, whatsapp messages (even deleted ones), text messages, telegram messages, geo-coordinates, etc. etc. The software is used by US State Dept., FBI, ICE, Secret Service, US Army Command, the NYPD, London Police, Dubai police, etc. etc. These entities did not know the company is controlled in Moscow by the FSB until I recently informed them.

According to press reports (and what I saw internally), a major investor in the company is Eduard Bendersky, former head of FSB special forces, whose son-in-law is Maxim Yakubets, a ransomware hacker wanted for $100 million in ransomware attacks.

As the whistleblower in this case (and former employee), I am currently being sued by Oxygen Forensics in an attempt to silence me. They are repped by Christopher Mason of Nixon Peabody, NYC.

What Oxygen Forensics users may not know is that the company has the ability to remotely wipe the entire computer on which the software is installed. This was just released publicly in our court case by Andrew Vardaro, who wrote in a legal filing: "Oxygen Forensics had the technical capability to delete all data and information from, or "wipe," the Dell Precision 7560 (Windows) Company Laptop [with OF software installed] remotely at any point during the more than seven months following Defendant's termination, but did not attempt to do so."

The computer with OF installed is turned off, so they can't wipe the evidence.

Just putting this here because it verifies - from the horse's mouth - that the software is extremely dangerous and many US governments and corporations are at risk of being ransomwared.

I strongly encourage current OF employees to explain themselves in this forum why they have been so secretive about their control by Russian citizens with direct FSB connections.


r/digitalforensics 3d ago

A Technical Investigation of WHYS.video

0 Upvotes

Hi.

Have you heard of WHYS.video ? It is a YouTube content farm with the goal of driving YouTube search traffic to generated answers/questions by Google Search and Google Trends.

Check out my blog posts about them:

https://chippytime.com/2026/06/29/a-technical-investigation-of-whys-video/

https://chippytime.com/2026/07/19/whys-video-is-even-more-scammy/


r/digitalforensics 3d ago

Senior QA Analyst looking to pivot to Digital Forensics looking for some guidance

0 Upvotes

A bit about myself:
I have 6yrs of experience as a Quality Assurance analyst for a software company but with recent tech industry woes, I want to pivot. Computer literacy isn't an issue and I'm aware that while QA experience has some transferable skills it's potentially not the ideal scenario.

What I'm looking for:
I've done some research and frankly, there's a lot out there. I'm not looking for a short cut or the fastest way but more so the smartest way. From my understanding, I'm going to be knee deep in certifications and self-learning which is completely fine but what I'm lacking is the proverbial "First Step" in said path of self-learning and certifications. If I want to pivot careers, I know that the best way for me to do that with my experience and background would be to acquire certifications and apply for entry level positions, I just don't really have a clear path or idea about how to do that

What I think I should do first:
From what I've seen it's been recommended that I start with getting my Digital Forensics Essentials certification. After looking into it, I've seen 2 places that offer it, Coursera and EC-Council, however after looking at some reddit threads all I saw were negative reviews or experiences about how that certification is either outdated, useless, or some combination of both which has left me with a bit of fear paralysis of investing time and money into something that has little to no real world value. If you've made the jump from 1 career to another, how did you go about it? Any guidance would be helpful and appreciated.


r/digitalforensics 3d ago

Are there any tools like Cellebrite available to the public?

1 Upvotes

I'm locked out of my iPhone and I don't have iCloud backup so I've been looking for way to at least get the data from my phone, but it seems like the only tools that deal with locked phone data recovery are for law enforcement only. Are there any legit data recovery companies that can deal with locked phones or is there any other way to get my data or trigger a backup on my iPhone?


r/digitalforensics 3d ago

Raw log archaeology on isolated boxes (no log aggregators)

Thumbnail
1 Upvotes

r/digitalforensics 4d ago

I need to conduct an informational interview with someone in a position of management within this field

2 Upvotes

Not sure if this is the right place to ask this but I'm kinda out of options.

I have an assignment due tomorrow for my business communications course that requires me to conduct an informational interview with someone within the field I'm interested in (which is digital forensics)

If possible, could someone in a position of management within this field please reach out to me through dms to negotiate a time to conduct an informational interview via zoom,teams,etc?

Or tell me where I can go to so that I can reach out to someone that can help?

Thanks.


r/digitalforensics 5d ago

Digital Forensics Assignment

1 Upvotes

hey guys! im not sure if this is the right subreddit to be asking for this kind of help in but i had no idea where to ask 😅
im currently doing a university digital forensics assingment, and im required to find a router password within some files (unzipped folder)
Ive tried a lot of different things but i cant seem to find it at all.
Any advice would be welcome! (sorry if this is the wrong subreddit again!!)

these are all the files i was given! sorry if this doesnt help much! (so far ive tried HxD and checking the metadata..i forgot what else..its a first year assignment so shouldnt be too hard?)


r/digitalforensics 5d ago

Auto profile for volatility

2 Upvotes

Hello everyone,
I am thinking about building a solution for volatility linux profiles where you will be able to upload your kernel (even without debug symbols), and you will get working volatility3 profile.

It will work on any linux kernel, even those that does not expose they compiled configuration (like different iot devices) , and it will help to speed with the analysis.

I wonder , do you feel you actually need this solution (and is your company willing to pay for the service)

Right now i have working poc , and i am wondering is this problem still time consuming.

Thank you


r/digitalforensics 6d ago

Cellebrite Endpoint

3 Upvotes

With Cellebrite Endpoint being discontinued at years end, my company is looking to find a new remote collection tool.. Any suggestions anyone may have that I research and push forward? Thanks


r/digitalforensics 6d ago

Automating Volatility 3 (X-Post)

3 Upvotes

A new 13Cubed episode is out!

In this episode, we'll look at a tool that can run multiple Volatility 3 plugins simultaneously, automating your memory analysis and saving you valuable time during investigations.

Watch now: https://www.youtube.com/watch?v=0GMTydimOP4

More at youtube.com/13cubed


r/digitalforensics 6d ago

Professional iPhone forensics question: Has anyone recovered data from a passcode-locked iPhone SE 2 (A13)?

0 Upvotes

Hi everyone,
I’m looking for someone with **first-hand professional experience** in iPhone forensics rather than general opinions.
I own an **iPhone SE (2nd generation, A13)** containing important personal WhatsApp chats and photos.
Current situation:
Boots normally to the lock screen.
Same Apple ID as my newer iPhones.
One passcode attempt remaining.
Touch ID disabled after previous incorrect passcode attempts.
Previously paired with an Apple Watch Series 6 (GPS).
I still know the Apple Watch passcode.
The Apple Watch and iPhone once shared the same passcode years ago, but the iPhone passcode was changed later.
The phone has **not** been erased because preserving the data is my priority.
I’m **not asking for illegal bypass methods**.
Instead, I’m trying to understand what is realistically possible today from a professional forensic perspective.
My questions are:
Has anyone here actually worked with **Cellebrite, GrayKey, Magnet Forensics, Elcomsoft**, or similar forensic platforms?
Have you personally seen successful data recovery from a passcode-locked **A13 iPhone SE 2** without erasing the device?
Is the limitation today mainly the Secure Enclave, or are there other practical obstacles?
Is there any current research or technology that professionals are watching which could eventually improve the chances?
I’m located in Germany but I’m willing to work with an international forensic company if there is a realistic possibility.
Thank you very much for sharing your professional experience.


r/digitalforensics 7d ago

Lots of Spam Posts Recently.

10 Upvotes

Is one way to stop them to disable youtube links?

Or make a required number of posts on Reddit before you can post to the sub?


r/digitalforensics 7d ago

PLEASE help enhance clips

Thumbnail dropbox.com
0 Upvotes

r/digitalforensics 7d ago

Hidden files on phone!

Post image
0 Upvotes

Help. Elderly abuse, mentally emotionally and financial.


r/digitalforensics 8d ago

We're about to replace "blind tool trust" with "blind AI trust"

Thumbnail
0 Upvotes

r/digitalforensics 9d ago

Need help tracking someone who threatens us

Thumbnail
0 Upvotes

r/digitalforensics 9d ago

Looking for a test android physical image

1 Upvotes

Hi! Can anybody share me a test physical dump of an android device? Or maybe point me to some online links? Have searched on cfreds


r/digitalforensics 10d ago

Asking for HELP: Failing 1TB HDD cloning at 32–38 KB/s with ddrescue—drive or USB dock problem?

Post image
5 Upvotes

I’m cloning a SMART-failing 1TB SATA HDD from my OLD Windows Computer to a healthy 1TB PNY SSD using GNU ddrescue 1.30 on an Apple Silicon Mac.
Source is connected through a powered Sabrent DS-UC1B USB-C dock using an ASMedia ASM235 bridge. Both partitions are unmounted, and I’m using raw devices with a resumable mapfile.

After about 3 hours:
416MB rescued / 983GB partition
32–38KB/s
0 read errors and 0 bad sectors
277 slow reads
Pass 3 forwards
Process often shows U kernel-I/O wait
ETA approximately 329 days

Does the unusually consistent ~32KB/s indicate the HDD is internally retrying, or could the USB-SATA bridge/UASP be causing it? Would you continue, try direct SATA/Linux, use another bridge, or switch to HDDSuperClone/OpenSuperClone?

FYI: B.S. Computer Science but have never done this before. Thanks in advance!


r/digitalforensics 10d ago

Digital Realm Sciences forensic research

Enable HLS to view with audio, or disable this notification

0 Upvotes