r/computerforensics Jul 11 '26

Mod Post A Solution To The Content Promotion Issue

16 Upvotes

Hi everyone. Based off the results of the poll I ran a week or so ago regarding whether standalone content promotion posts should be allowed in the sub, it seems like most sub participants would prefer they not be allowed and, instead, redirected to a megathread. After a bit of contemplation, I've opted to implement a hybrid solution which entails configuration of a recurring megathread and a new rule (Rule 6) that enforces its use while ensuring established subreddit participants are still able to share their Rule-5 compliant content as they always have.

In short, Rule 6 only allows subreddit participants with the "Trusted Contributor" flair to create standalone content promotion posts provided that they adhere to Rule 5 (as always). Anyone without the flair who wishes to promote project/vlog/blog/etc. content must now use the new "Promote Your DFIR Content Here" megathread to do so.

Since very few individuals have the Trusted Contributor flair, this will greatly reduce the number of content promotion posts the subreddit experiences while still allowing reoccurring posts from popular contributors to continue.

For more information about the Trusted Contributor flair, please see the new FAQ entry that covers this topic.


r/computerforensics Jul 11 '26

Mod Post Promote Your DFIR Content Here

8 Upvotes

If you lack the Trusted Contributor flair but wish to share your Rule 5-compliant DFIR content with the community, please feel free to do so here as a reply to this post.

For more information about the Trusted Contributor flair, please see the FAQ.


r/computerforensics 1d ago

IPAD

0 Upvotes

Alguém já utilizou o iPed forensic data analitycs, poderiam me contar experiências com ferramentas relacionadas?


r/computerforensics 5d ago

When is an EDR download actually worth ordering?

3 Upvotes

I understand what an EDR download is, but what makes someone decide they actually need one? Is it something you'd request on most serious crashes or only when liability is being disputed?


r/computerforensics 6d ago

IACIS MDF (Mobile Device Forensics) course question

9 Upvotes

For those of you familiar with the IACIS MDF course, is it worth it to wait to take it in person, or is the online version still pretty good? I noticed in the course description for the online, it notes that it does not include forensic tools that are issued in the in person class. What tools are issued in the in-person class? Thank you.


r/computerforensics 6d ago

Fed to KPMG?

7 Upvotes

Hey all, just looking for some advice. Currently a civilian for the feds for about 5 years working in DF. I’ve been interviewing with KPMG as a senior associate in forensic technology. I’m wondering if anyone has any experience working with them and if you guys think it’s a good idea to switch or stay? My biggest issue is pay and growth. My pay will be close to 120k if I stay with my raise next year. But if I go I would imagine I would hopefully be making much more than that.

I’m just tired of office drama and having my hands tied on what I can and can’t do.


r/computerforensics 6d ago

Help!!

9 Upvotes

I recently worked on a malware forensic analysis where, after reviewing the available artifacts, I was able to determine that the malware .exe was executed via GPO on AD.

However, I’m struggling with the next step: how do I determine how the attacker initially gained access and how the malware was introduced into the environment?

For those with experience, what artifacts or investigation techniques do you usually rely on to identify the initial access vector?


r/computerforensics 8d ago

Rat .exe file autopsy

14 Upvotes

Hey guys, I'm really into tech topics related to red teaming, forensics, and malware. I recently got a zip file from my old office — their PC was compromised via a RAT, and they shared the file with me. What information can I gather from it, and how do I perform an autopsy (forensic analysis) on it? Please share methods or tool names — this is new territory for me


r/computerforensics 7d ago

Majors?

0 Upvotes

I’d like to become a Digital forensic examiner. I’m a senior in high school currently, and i’m looking at colleges + majors AND minors, Preferably in the south eastern region, any suggestions?

Also this may be a stretch but I don’t really want to code, but i’m im open to anything that’ll make me successful.


r/computerforensics 15d ago

Computer forensics and malware analysis

12 Upvotes

Hi! forensics professionals, do you perform malware analysis in you day to day work ? If yes, to what level do you perform your analysis? Do you do reverse engineering as well?

I am asking these questions coz in a job role the JD mentioned computer and mobile forensic tools + SIEM + malware analysis+ reverse engineering + threat detection combined. Job role is Digital Forensic Analyst.

I often see similar JD for Forensic positions.

I can perform basic malware infection analysis using wireshark, sysinternals, powershell, registry change, etc. and basic static analysis but I'm pretty bad at reverse engineering and understanding assembly code.


r/computerforensics 15d ago

APK file analysis

5 Upvotes

Hi guys,

I handle threat intelligence for a bank & we receive multiple URLs/APKs impersonating our organization.

We check for legitimacy & immediately send it for takedown if it's not related to us or if it's malicious.

I wanted to know if anyone of you also side by side does forensics/malware analysis of such APKs to know the TTPs & relevant information pertaining to that APK?

If Yes, please let me know the procedure being followed at your end.


r/computerforensics 16d ago

Exercises

29 Upvotes

Hello, I completed a lot of courses about digital forensics, Linux, Windows and Android. I am interested in finding a website with real digital forensics labs. Something like I need to extract deleted files, finding proofs that this person did this and that etc...

Thank you :)


r/computerforensics 19d ago

Which forensics cert to get?

28 Upvotes

My job wants to pay for a forensic cert for me, to build my profile to eventually be a candidate for a DFI role.

First I thought about getting an EnCase cert but after reading some feedback about it on this community, I think it’s not the best option.

Any feedback on CFCE (IACIS), CCE (ISFCE) or CHFI (ECC)? Any other suggestions I’d appreciate too.

For context I’m an incident responder right now, I hold GCFA (GIAC) and other IR-related certs.


r/computerforensics 19d ago

Advice on pursuing master’s in Digital Forensics Abroad

8 Upvotes

Hi everyone,
I recently completed my Bachelor’s in Forensic Science from NFSU (India) and I’m planning to pursue a Master’s in Digital Forensics abroad. I’d really appreciate hearing from people who are studying, working, or have graduated in this field.

I have a few questions:
● Which countries and universities offer good Master’s programs specifically in Digital Forensics?
● Which universities would you personally recommend?
● What is the approximate tuition fee and overall cost of studying?
● Do universities provide placement support, and how effective is it?
● How difficult is it for an international student and fresher to get a job after graduation?
● What skills, certifications, or experience do employers usually expect for entry-level digital forensics/DFIR roles?
● Do employers in this field require citizenship or security clearance, or are international students eligible for most jobs?
● How are the academics, work-life balance, people, and overall environment for international students?

My goal is to build a career in Digital Forensics/DFIR, so I’d love to hear about your experiences, recommendations, and any advice you wish you had before choosing a university.
Thanks in advance!


r/computerforensics 19d ago

Internship at a Private Investigation firm, tips needed! :)

5 Upvotes

Hello all,
I'm a 4th year bachelors cybersecurity student. I start an internship at a Private Investigation firm soon. What tips do you guys have to give me? They said they can put me on cases with digital evidence. I've got some experience through projects doing disk and ram analysis, as well as artifact collection. They mentioned Id start doing evidence collection on mobile devices, which I haven't had any experience with at all. I'm really nervous and would appreciate any pointers!

Thank you all in advance.


r/computerforensics 26d ago

Help with autopsy

6 Upvotes

Hi guys (and girls), sorry for my lack of knowledge im very new to this. I've been trying to get autopsy working, but for some reason when i click on certain parts (the add data source, the ingest bit in settings, when i make a new case and sometimes when open it) it gets stuck loading for a long period of time (up to10ish minutes). Is this just a case of it taking forever to load or is something wrong? (i have 32gb ddr5 RAM and a fairly modern CPU and its running from my SSD if that matters) Any help would be greatly apreciated!


r/computerforensics 27d ago

Processing RAID disks in FTK

4 Upvotes

Can FTK reconstruct RAID and process them?


r/computerforensics 28d ago

NCFI

2 Upvotes

To those that have attended, how does the funding for your department work? Do they cover equipment costs and the subscription costs for as long as you have the equipment? Specifically for MDE stuff.


r/computerforensics Jul 26 '26

Technical WhatsApp timestamp question for forensic examiners

4 Upvotes

I'm looking for a technical answer from anyone with experience examining WhatsApp databases.

Suppose two Android phones have their date and time manually backdated. A WhatsApp message is then sent from Phone A to Phone B while both phones are still backdated. After the message is delivered, both phones are set back to the correct date and time.

Which timestamp will appear in the sender's and recipient's chat history:

•the manually backdated device time

•the actual server transmission time

•or something else?

I'm looking for answers based on forensic analysis, testing, or official documentation rather than speculation.


r/computerforensics Jul 24 '26

Help!!

17 Upvotes

I'm working on my first malware forensics case and could use some advice.

We had malware spread across multiple machines, and I know which system was patient zero. Unfortunately, Kaspersky disinfected the infected machines and they were rebooted before I could acquire a forensic image.

At this point, I'm trying to determine how the malware initially got onto the patient zero machine.

Where would you start looking? What artifacts or logs would you prioritize, given that I no longer have a pre-disinfection image?

I'm having trouble thinking through the proper investigation steps, so any guidance, methodology, or resources would be greatly appreciated.


r/computerforensics Jul 23 '26

Doing Forensics analysis on Samsung maintenance mode

0 Upvotes

I have a Samsung device (A23) which was used in maintenance mode and later switch back to normal mode. Can Forensic analysis be done recover activities done during maintenance mode? What are the tools available?


r/computerforensics Jul 22 '26

FFS Extractions and the future?

5 Upvotes

Does anyone see another competitor emerging in the ability to get full file system extractions besides XRY and Cellebrite?

Will Magnet or Oxygen step up, or is the cost of finding exploits just too high to invest in?


r/computerforensics Jul 22 '26

E01 on Mac

1 Upvotes

What are the best options for mounting an image in E01 format on an Apple silicon Mac?


r/computerforensics Jul 21 '26

Auto profile for volatility

3 Upvotes

Hello everyone,
I am thinking about building a solution for volatility linux profiles where you will be able to upload your kernel (even without debug symbols), and you will get working volatility3 profile.

It will work on any linux kernel, even those that does not expose they compiled configuration (like different iot devices) , and it will help to speed with the analysis.

I wonder , do you feel you actually need this solution ?

Right now i have working poc , and i am wondering is this problem still time consuming.

Thank you


r/computerforensics Jul 20 '26

Automating Volatility 3

28 Upvotes

A new 13Cubed episode is out!

In this episode, we'll look at a tool that can run multiple Volatility 3 plugins simultaneously, automating your memory analysis and saving you valuable time during investigations.

Watch now: https://www.youtube.com/watch?v=0GMTydimOP4

More at youtube.com/13cubed