r/computerforensics • u/Easy_Refrigerator788 • 2d ago
r/computerforensics • u/ucfmsdf • Jul 11 '26
Mod Post A Solution To The Content Promotion Issue
Hi everyone. Based off the results of the poll I ran a week or so ago regarding whether standalone content promotion posts should be allowed in the sub, it seems like most sub participants would prefer they not be allowed and, instead, redirected to a megathread. After a bit of contemplation, I've opted to implement a hybrid solution which entails configuration of a recurring megathread and a new rule (Rule 6) that enforces its use while ensuring established subreddit participants are still able to share their Rule-5 compliant content as they always have.
In short, Rule 6 only allows subreddit participants with the "Trusted Contributor" flair to create standalone content promotion posts provided that they adhere to Rule 5 (as always). Anyone without the flair who wishes to promote project/vlog/blog/etc. content must now use the new "Promote Your DFIR Content Here" megathread to do so.
Since very few individuals have the Trusted Contributor flair, this will greatly reduce the number of content promotion posts the subreddit experiences while still allowing reoccurring posts from popular contributors to continue.
For more information about the Trusted Contributor flair, please see the new FAQ entry that covers this topic.
r/computerforensics • u/AutoModerator • Jul 11 '26
Mod Post Promote Your DFIR Content Here
If you lack the Trusted Contributor flair but wish to share your Rule 5-compliant DFIR content with the community, please feel free to do so here as a reply to this post.
For more information about the Trusted Contributor flair, please see the FAQ.
r/computerforensics • u/No_Chip4809 • 4d ago
Need DVR/NVR data
I'm working on a multi DVR/NVR vendor analyzer tool for analyzing cctv footage from various vendors in a single app.(Hackathon Project)
And in this tool you can either connect a dvr hard disk via a write blocker device to your system and use the app to extract data into a digital bit stream copy (.dd or .raw) and then use that from that point. Or you can also provide you ore existing raw file in your system for data extraction.
But I don't have a cctv system at my home, neither do any of my friends to whom I can ask to. And there is only one .dd dvr data I could find on the internet and that's the heimvision's vendor but it's just a 1 hour of 4 camera footage of a doll starting at a wall.🙂
Any advice on this current situation?
r/computerforensics • u/DFIR_Heather • 4d ago
Looking for ISSA Las Vegas Members
Anyone on here a member of or know anyone in ISSA Las Vegas? Looking to host a few people for a meetup when I teach in Vegas in Sept. Hoping to connect with those in cyber or interested in cyber. Thanks in advance.
r/computerforensics • u/13Cubed • 5d ago
Windows Forensics... on macOS
A new 13Cubed episode is out! 🍎
Windows forensics on a Mac usually means firing up a VM first. Not anymore.
IRFlow Timeline is a free, open-source DF/IR timeline tool built natively for macOS. Feed it EVTX, Plaso, $MFT, or $J and go straight to process inspection, lateral movement, persistence, and VirusTotal enrichment.
Featuring the tool's author, Renzon Cruz 👇
r/computerforensics • u/TubbyTortilla • 8d ago
13Cube new training course.
Hey guys. I wanted ask if anyone took or is thinking of taking 13cubes latest course Architecting the hunt. I know the course is about understanding the framework of Threat hunting and I do understand this is not specifically computer forensics but I at least wanted to ask on this subreddit since we all know 13cube or at least aware of 13cubes trainings. I want to buy the course and would appreciate some perspective beforehand. Thank you!
r/computerforensics • u/JohnOldManYes • 7d ago
Average size of an SQLite database you have encountered?
Hello,
I am doing a little bit of research into SQLite forensics, thinking about developing some tools around it.
I was wondering if anyone has any experience with this, particularly when it comes to the average size of the database. Most databases I can get off Kaggle range from 1mb all the way up to multiple gb.
Was wondering what the average investigator would encounter? If I develop any tools for it I have to take alternative approaches if I am looking at very large database so wondering if the need is there or are 99% of db those encounter are of 'easy' size.
Thanks
r/computerforensics • u/No_Pin7764 • 13d ago
Looking for Malware Logs in relation to POS devices
I am currently busy doing a course for my university, and have a project to analyse and correlate different log sources with indicators of compromise specific to point-of-sale (pos) devices. I managed to find a 24 hour pcap of the backoff malware (c2 beconing), but overall I am struggling to find any datasets of an attack specific to pos devices. I am mostly looking at research papers, but perhaps I need to reach out to some of the researchers, as I can't find actual datasets.
Is there anyone that knows where I could find datasets to do a proper writeup? It can be of any pos malware, but we require 3 different log sources (e.g. firewall logs, authentication logs, system logs). I can also generate my own logs, but my professor advised against this unless I really can't manage to find any meaningful data online, as I'd essentially be engineering my own scenario instead of doing analysis.
Please advise. Any help is welcome.
r/computerforensics • u/Firm_Resolution_9491 • 15d ago
IPAD
Alguém já utilizou o iPed forensic data analitycs, poderiam me contar experiências com ferramentas relacionadas?
r/computerforensics • u/theJacofalltrades • 19d ago
When is an EDR download actually worth ordering?
I understand what an EDR download is, but what makes someone decide they actually need one? Is it something you'd request on most serious crashes or only when liability is being disputed?
r/computerforensics • u/Impressive-Wheel-277 • 19d ago
IACIS MDF (Mobile Device Forensics) course question
For those of you familiar with the IACIS MDF course, is it worth it to wait to take it in person, or is the online version still pretty good? I noticed in the course description for the online, it notes that it does not include forensic tools that are issued in the in person class. What tools are issued in the in-person class? Thank you.
r/computerforensics • u/Strange_Curve_2741 • 19d ago
Fed to KPMG?
Hey all, just looking for some advice. Currently a civilian for the feds for about 5 years working in DF. I’ve been interviewing with KPMG as a senior associate in forensic technology. I’m wondering if anyone has any experience working with them and if you guys think it’s a good idea to switch or stay? My biggest issue is pay and growth. My pay will be close to 120k if I stay with my raise next year. But if I go I would imagine I would hopefully be making much more than that.
I’m just tired of office drama and having my hands tied on what I can and can’t do.
r/computerforensics • u/ShadyMoh1998 • 19d ago
Help!!
I recently worked on a malware forensic analysis where, after reviewing the available artifacts, I was able to determine that the malware .exe was executed via GPO on AD.
However, I’m struggling with the next step: how do I determine how the attacker initially gained access and how the malware was introduced into the environment?
For those with experience, what artifacts or investigation techniques do you usually rely on to identify the initial access vector?
r/computerforensics • u/_divine__wolf • 21d ago
Rat .exe file autopsy
Hey guys, I'm really into tech topics related to red teaming, forensics, and malware. I recently got a zip file from my old office — their PC was compromised via a RAT, and they shared the file with me. What information can I gather from it, and how do I perform an autopsy (forensic analysis) on it? Please share methods or tool names — this is new territory for me
r/computerforensics • u/Far-Masterpiece-6933 • 21d ago
Majors?
I’d like to become a Digital forensic examiner. I’m a senior in high school currently, and i’m looking at colleges + majors AND minors, Preferably in the south eastern region, any suggestions?
Also this may be a stretch but I don’t really want to code, but i’m im open to anything that’ll make me successful.
r/computerforensics • u/Ok_Cold7890 • 28d ago
Computer forensics and malware analysis
Hi! forensics professionals, do you perform malware analysis in you day to day work ? If yes, to what level do you perform your analysis? Do you do reverse engineering as well?
I am asking these questions coz in a job role the JD mentioned computer and mobile forensic tools + SIEM + malware analysis+ reverse engineering + threat detection combined. Job role is Digital Forensic Analyst.
I often see similar JD for Forensic positions.
I can perform basic malware infection analysis using wireshark, sysinternals, powershell, registry change, etc. and basic static analysis but I'm pretty bad at reverse engineering and understanding assembly code.
r/computerforensics • u/Longjumping-Ebb-578 • 28d ago
APK file analysis
Hi guys,
I handle threat intelligence for a bank & we receive multiple URLs/APKs impersonating our organization.
We check for legitimacy & immediately send it for takedown if it's not related to us or if it's malicious.
I wanted to know if anyone of you also side by side does forensics/malware analysis of such APKs to know the TTPs & relevant information pertaining to that APK?
If Yes, please let me know the procedure being followed at your end.
r/computerforensics • u/InspectionFar5415 • 29d ago
Exercises
Hello, I completed a lot of courses about digital forensics, Linux, Windows and Android. I am interested in finding a website with real digital forensics labs. Something like I need to extract deleted files, finding proofs that this person did this and that etc...
Thank you :)
r/computerforensics • u/crazyisus • Aug 06 '26
Which forensics cert to get?
My job wants to pay for a forensic cert for me, to build my profile to eventually be a candidate for a DFI role.
First I thought about getting an EnCase cert but after reading some feedback about it on this community, I think it’s not the best option.
Any feedback on CFCE (IACIS), CCE (ISFCE) or CHFI (ECC)? Any other suggestions I’d appreciate too.
For context I’m an incident responder right now, I hold GCFA (GIAC) and other IR-related certs.
r/computerforensics • u/midnightsyllabus • Aug 06 '26
Advice on pursuing master’s in Digital Forensics Abroad
Hi everyone,
I recently completed my Bachelor’s in Forensic Science from NFSU (India) and I’m planning to pursue a Master’s in Digital Forensics abroad. I’d really appreciate hearing from people who are studying, working, or have graduated in this field.
I have a few questions:
● Which countries and universities offer good Master’s programs specifically in Digital Forensics?
● Which universities would you personally recommend?
● What is the approximate tuition fee and overall cost of studying?
● Do universities provide placement support, and how effective is it?
● How difficult is it for an international student and fresher to get a job after graduation?
● What skills, certifications, or experience do employers usually expect for entry-level digital forensics/DFIR roles?
● Do employers in this field require citizenship or security clearance, or are international students eligible for most jobs?
● How are the academics, work-life balance, people, and overall environment for international students?
My goal is to build a career in Digital Forensics/DFIR, so I’d love to hear about your experiences, recommendations, and any advice you wish you had before choosing a university.
Thanks in advance!
r/computerforensics • u/silkandz3faron • Aug 06 '26
Internship at a Private Investigation firm, tips needed! :)
Hello all,
I'm a 4th year bachelors cybersecurity student. I start an internship at a Private Investigation firm soon. What tips do you guys have to give me? They said they can put me on cases with digital evidence. I've got some experience through projects doing disk and ram analysis, as well as artifact collection. They mentioned Id start doing evidence collection on mobile devices, which I haven't had any experience with at all. I'm really nervous and would appreciate any pointers!
Thank you all in advance.
r/computerforensics • u/Arkaem7512 • Jul 30 '26
Help with autopsy
Hi guys (and girls), sorry for my lack of knowledge im very new to this. I've been trying to get autopsy working, but for some reason when i click on certain parts (the add data source, the ingest bit in settings, when i make a new case and sometimes when open it) it gets stuck loading for a long period of time (up to10ish minutes). Is this just a case of it taking forever to load or is something wrong? (i have 32gb ddr5 RAM and a fairly modern CPU and its running from my SSD if that matters) Any help would be greatly apreciated!
r/computerforensics • u/SpiritualAd1908 • Jul 29 '26
Processing RAID disks in FTK
Can FTK reconstruct RAID and process them?
r/computerforensics • u/Stamos117 • Jul 28 '26
NCFI
To those that have attended, how does the funding for your department work? Do they cover equipment costs and the subscription costs for as long as you have the equipment? Specifically for MDE stuff.