#digitalforensics — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #digitalforensics, aggregated by home.social.
-
⏰ Don't Miss Your Chance to Speak at FIRST LAC 2026
Have a story, lesson learned, tool, or innovation to share with the incident response community?
Submit your proposal for the 2026 FIRST Regional Symposium Latin America & Caribbean and showcase your experience in areas such as:🔹 Incident handling case studies
🔹 Threat intelligence
🔹 Cloud security
🔹 AI for incident response
🔹 Digital forensics
🔹 DNS, IPv6, and routing security📅 Deadline: August 16, 2026
📧 https://www.first.org/events/symposium/latam2026/
No marketing presentations—technical and community-focused content only.
#CallForSpeakers #FIRST #CyberSecurity #ThreatIntelligence #DigitalForensics #LACNIC46
-
⏰ Don't Miss Your Chance to Speak at FIRST LAC 2026
Have a story, lesson learned, tool, or innovation to share with the incident response community?
Submit your proposal for the 2026 FIRST Regional Symposium Latin America & Caribbean and showcase your experience in areas such as:🔹 Incident handling case studies
🔹 Threat intelligence
🔹 Cloud security
🔹 AI for incident response
🔹 Digital forensics
🔹 DNS, IPv6, and routing security📅 Deadline: August 16, 2026
📧 https://www.first.org/events/symposium/latam2026/
No marketing presentations—technical and community-focused content only.
#CallForSpeakers #FIRST #CyberSecurity #ThreatIntelligence #DigitalForensics #LACNIC46
-
Join Rich Frawley of ADF Solutions as he shares practical strategies for managing complex ICAC scenes, prioritizing the devices most likely to contain probative evidence, and making faster, more informed decisions in the field. https://www.forensicfocus.com/news/upcoming-webinar-reducing-icac-backlogs-prioritizing-digital-evidence-for-faster-investigations/ #ADFSolutions #ICAC #DigitalForensics #DFIR
-
Turn partial school badges into actionable leads with S21 School Badge Lookup v2.0, fast offline image intelligence built for CSAM and ICAC investigations worldwide. https://www.forensicfocus.com/news/unmasked-early-intelligence-should-not-be-manual/ #DigitalForensics #DFIR #Semantics21 #CSAM #ICAC
-
Read the latest DFIR news - NIST’s new ArtCat digital forensics catalog, Kohberger case methodology, Android intrusion log analysis, offline AI with BelkaGPT, and more. https://www.forensicfocus.com/news/digital-forensics-round-up-august-12-2026/ #DigitalForensics #DFIR
-
🥷 Hoy Miércoles 12 de Agosto a las 8:00 pm (UTC -05:00) iniciamos el Curso OSINT - Open Source Intelligence 2026 🚀 Miércoles 12, Viernes 14, Miércoles 19 y Viernes 21 de Agosto 🧲 De 8:00 pm a 11:00 pm (UTC -05:00) 🪪 WhatsApp: https://wa.me/51949304030 🧑💻 Información: https://www.reydes.com/e/Curso_de_OSINT #OSINT #OpenSourceIntelligence #ThreatIntel #CyberSecurity #DigitalForensics #DFIR -
🛰️ Mañana miércoles 12 de agosto iniciamos el Curso OSINT - Open Source Intelligence 2026 🗓️ Miércoles 12, Viernes 14, Miércoles 19 y Viernes 21 de Agosto ⏰ De 8:00 pm a 11:00 pm (UTC -05:00) 📲 WhatsApp: https://wa.me/51949304030 🌎 Información: https://www.reydes.com/archivos/cursos/Curso_OSINT_Open_Source_Intelligence.pdf #OSINT #ThreatIntel #Privacy #Cti #DigitalForensics #CyberSecurity -
Learn how to identify and decrypt BitLocker Clear Key–protected forensic images using dislocker and bdeinfo, from spotting the “-FVE-FS-” signature to mounting the recovered NTFS volume for analysis. https://www.forensicfocus.com/articles/how-to-process-a-clear-key-bitlocker-image-file-to-generate-a-decrypted-raw-image/ #DigitalForensics #DFIR
-
Explore a selection of the latest DFIR employment opportunities in this week’s Forensic Focus jobs round-up. https://www.forensicfocus.com/jobs/digital-forensics-jobs-round-up-august-10-2026/ #DigitalForensics #DFIR
-
Can trauma show up as misconduct? Paul Gullon-Scott explores how cumulative trauma and organisational stress can shape behaviour in policing and digital forensics and why earlier, trauma-informed support could make all the difference. https://www.forensicfocus.com/articles/misconduct-or-mental-injury-a-question-policing-can-no-longer-avoid/ #DigitalForensics #DFIR
-
New post: Using AI Effectively in Digital Forensics
A decent version of most DFIR software can now be made at home, in a few hours, by a user that does not code. The moat is gone. That is not the scary part.
The scary part is AI tooling sold to folks with no way to verify the output. So what makes someone an expert now? Five qualities, and none is owning a subscription.
https://leapps.org/blog-post?post=2026-08-07-using-ai-effectively-in-digital-forensics
#DFIR #DigitalForensics #AI -
New post: Using AI Effectively in Digital Forensics
A decent version of most DFIR software can now be made at home, in a few hours, by a user that does not code. The moat is gone. That is not the scary part.
The scary part is AI tooling sold to folks with no way to verify the output. So what makes someone an expert now? Five qualities, and none is owning a subscription.
https://leapps.org/blog-post?post=2026-08-07-using-ai-effectively-in-digital-forensics
#DFIR #DigitalForensics #AI -
Discover what’s new on Forensic Focus – trace eight years of innovation with Atola TaskForce, explore how BelkaGPT brings offline AI to digital investigations, learn why the first 60 minutes with digital evidence matter, and more. https://www.forensicfocus.com/news/forensic-focus-digest-august-07-2026/ #DigitalForensics #DFIR
-
In 2017, Dutch investigators infiltrated one of the dark web’s biggest marketplaces and turned user activity into evidence. Learn more in this new video from fern: https://youtu.be/V6d8Yy7Ji68?si=vsj5E82Bzp9_TYic #DigitalForensics
-
From record-breaking imaging speeds to automated RAID reconstruction and 50 Gbit/s networking, discover how TaskForce evolved over eight years into a comprehensive forensic acquisition platform built to remove investigators’ next bottleneck. https://www.forensicfocus.com/articles/the-evolution-of-atola-taskforce-eight-years-of-non-stop-innovation/ #AtolaTechnology #TaskForce #DigitalForensics #DFIR
-
⏰ Don't Miss Your Chance to Speak at FIRST LAC 2026
Have a story, lesson learned, tool, or innovation to share with the incident response community?
Submit your proposal for the 2026 FIRST Regional Symposium Latin America & Caribbean and showcase your experience in areas such as:🔹 Incident handling case studies
🔹 Threat intelligence
🔹 Cloud security
🔹 AI for incident response
🔹 Digital forensics
🔹 DNS, IPv6, and routing security📅 Deadline: August 16, 2026
📧 https://www.first.org/events/symposium/latam2026/
No marketing presentations—technical and community-focused content only.
#CallForSpeakers #FIRST #CyberSecurity #ThreatIntelligence #DigitalForensics #LACNIC46
-
⏰ Don't Miss Your Chance to Speak at FIRST LAC 2026
Have a story, lesson learned, tool, or innovation to share with the incident response community?
Submit your proposal for the 2026 FIRST Regional Symposium Latin America & Caribbean and showcase your experience in areas such as:🔹 Incident handling case studies
🔹 Threat intelligence
🔹 Cloud security
🔹 AI for incident response
🔹 Digital forensics
🔹 DNS, IPv6, and routing security📅 Deadline: August 16, 2026
📧 https://www.first.org/events/symposium/latam2026/
No marketing presentations—technical and community-focused content only.
#CallForSpeakers #FIRST #CyberSecurity #ThreatIntelligence #DigitalForensics #LACNIC46
-
Discover how investigators can use powerful, forensics-specific AI entirely offline with Belkasoft X, keeping sensitive case data secure while accelerating analysis of images, audio, video, chats, and more. https://www.forensicfocus.com/webinars/practical-ai-in-digital-forensics-running-offline-ai-on-your-own-evidence-with-belkagpt/ #DigitalForensics #DFIR #BelkaGPT #AIforensics
-
Reduce unnecessary investigator exposure without changing your workflow: S21 AI Describe v2.0 delivers fast, accurate, structured image and video-frame descriptions entirely offline - available standalone or within S21 VisionX. https://www.forensicfocus.com/news/unmasked-exposure-is-a-workflow-choice/ #Semantics21 #DigitalForensics
-
Read the latest DFIR news - Android 16 intrusion logging, forensic observability for network devices, mental health support gaps for investigators, GrapheneOS duress passwords, privacy app artifacts, and more. https://www.forensicfocus.com/news/digital-forensics-round-up-august-05-2026/ #DigitalForensics #DFIR
-
See how the Metropolitan Police Service used ADF Pro to triage thousands of devices, accelerate investigations, reduce forensic backlogs, and deliver actionable intelligence on the same day as a search warrant. https://www.forensicfocus.com/news/from-backlogs-to-breakthroughs-how-the-metropolitan-police-service-triaged-6000-devices/ #ADFSolutions #ADFPro #DigitalForensics #DFIR
-
What happens when mental health support for digital forensic investigators becomes a tick-box exercise? Paul Gullon-Scott explores the troubling gap between recognising psychological risk and providing the relational, long-term support DFIs actually need.https://www.forensicfocus.com/articles/ticking-a-box-missing-the-person-reflections-from-fee-2026/ #DigitalForensics
-
📱 New post: Every Step You Take, Eight Years Later
Eight years after my original Android UsageStats and Recent Tasks research, the artifacts have changed underneath us:
🧩 Readable XML became two generations of protobuf with tokenized package mappings
🔢 Four headline event types became a vocabulary of 32 values
🔐 Modern UsageStats lives in credential-encrypted /data/system_ce/
🖼️ Snapshot metadata distinguishes a real app thumbnail from a theme-generated substitute⚠️ Big caveat: ACTIVITY_RESUMED does not mean "the user tapped the app." It means an activity entered the resumed lifecycle state. Notifications, system processes, and configuration changes cause it too.
Current ALEAPP parses all of it, validated across Android 10 through 16 test extractions. Thank you to Jessica Hyde and Sarah Edwards for the research this builds on.
leapps.org/blog-post?post=2026-08-03-android-usagestats-recent-tasks
-
📱 New post: Every Step You Take, Eight Years Later
Eight years after my original Android UsageStats and Recent Tasks research, the artifacts have changed underneath us:
🧩 Readable XML became two generations of protobuf with tokenized package mappings
🔢 Four headline event types became a vocabulary of 32 values
🔐 Modern UsageStats lives in credential-encrypted /data/system_ce/
🖼️ Snapshot metadata distinguishes a real app thumbnail from a theme-generated substitute⚠️ Big caveat: ACTIVITY_RESUMED does not mean "the user tapped the app." It means an activity entered the resumed lifecycle state. Notifications, system processes, and configuration changes cause it too.
Current ALEAPP parses all of it, validated across Android 10 through 16 test extractions. Thank you to Jessica Hyde and Sarah Edwards for the research this builds on.
leapps.org/blog-post?post=2026-08-03-android-usagestats-recent-tasks
-
See how Targeted Mobile Extraction and Collect Files in ADF Pro help investigators stay within warrant or consent scope while acquiring only the mobile data that matters. https://www.forensicfocus.com/news/how-to-perform-targeted-mobile-extraction-in-adf-pro/ #ADFSolutions #DigitalForensics
-
Amped Software shared ways on doing forensic analysis to check a deepfaked video
https://blog.ampedsoftware.com/2026/07/28/deepfake-forensics-workflow-for-video-analysis
-
Un uomo in #Canada ha scontato 18 mesi di #reclusione per corruzione di minori e possesso di materiale pedopornografico.
L'username del vero colpevole era simile al suo, fatto salvo per un underscore "_".
-
Un uomo in #Canada ha scontato 18 mesi di #reclusione per corruzione di minori e possesso di materiale pedopornografico.
L'username del vero colpevole era simile al suo, fatto salvo per un underscore "_".
-
The first 60 minutes on scene often decide the rest of the case - Richard Frawley of ADF Solutions breaks down how to identify, preserve, and triage digital evidence before you leave the property. https://www.forensicfocus.com/webinars/the-first-60-minutes-of-digital-evidence-the-investigator-advantage/ #ADFSolutions #DigitalForensics
-
Help shape the future of enterprise DFIR by sharing your insights in Magnet Forensics’ annual survey by August 31, 2026, and receive early access to the findings - plus a chance to win one of two $500 Amazon gift cards. https://www.forensicfocus.com/news/magnet-forensics-invites-you-to-share-your-thoughts-on-the-current-state-of-enterprise-dfir/ #MagnetForensics #DigitalForensics
-
Apple Unified Logs are no longer an edge-case data source.
🔒 Lock/unlock activity
📱 App launches
📶 Connectivity changes
📸 Screenshots
🧭 NavigationMy updated article covers acquisition, macOS 26.4 Info.plist requirements, iLEAPP processing, 132 message predicates across 23 evidentiary themes, and analysis in LAVA/SQLite.
Article + printable guide:
https://leapps.org/blog-post?post=2026-07-29-apple-unified-logs -
Apple Unified Logs are no longer an edge-case data source.
🔒 Lock/unlock activity
📱 App launches
📶 Connectivity changes
📸 Screenshots
🧭 NavigationMy updated article covers acquisition, macOS 26.4 Info.plist requirements, iLEAPP processing, 132 message predicates across 23 evidentiary themes, and analysis in LAVA/SQLite.
Article + printable guide:
https://leapps.org/blog-post?post=2026-07-29-apple-unified-logs -
🚀 New tool! Introducing DLEAPP!
Your suspect used Signal. Not on their phone, on their laptop. Now what?
DLEAPP is the newest member of the LEAPP family. Desktop Logs Events And Protobuf Parser, built for triaging desktop application artifacts from Electron and Chromium apps.
The first public release parses:
💬 Signal Desktop, with decrypted database parsing and macOS Keychain key recovery
🎮 Discord Desktop, with reusable Chromium container readers
📱 WhatsApp Desktop for macOS
🗨️ Wire DesktopEvery artifact is labeled by verified platform instead of a generic "Desktop" tag, so you always know what you are looking at. Windows support is partial right now, and where it is incomplete the tool says so instead of leaving you to find out the hard way.
Free and open source, like everything else in the family.
🔗 Get DLEAPP: https://www.leapps.org/releases#section-dleapp
-
🚀 iLEAPP v2026.2.1 is out!
The Biome rabbit hole keeps going deeper. This release adds 60+ new Biome streams:
🔋 Device power and lock state
📍 Location visits and app location activity
📸 Camera AutoFocus ROI
⚡ Energy mode and boot sessions
🚨 Emergency voice calls
😀 Emoji engagement
🧠 A full Apple Intelligence family, including Safety OverridesSeveral of those came out of research by the awesome Mattia Epifani. Thank you Mattia!
Also in this release:
💬 Signal for iOS: full message and contact parsing, conversation view with attachments, and detection of Signal's timestamped GRDB directories
🔑 Expanded keychain handling: examiner-supplied keychains, a pure Python SQLCipher reader, UFED encrypted keychain dumps, and reuse of a keychain already carried by the extraction
🔔 Notifications overhaul: attachments checked in as media, embedded payload images recovered, payload fields split into their own columns, and notifications no longer reported three times overPlus fixes for addressBook column pruning, a MemoryError during HTML report generation, several Timeline issues, and an SMS rendering crash.
Welcome to four first-time contributors: CynthiavDorp, JSap0914, Sanjays2402, and sandrzejewskipl!
🔗 Get iLEAPP: https://www.leapps.org/releases#section-ileapp
#DFIR #MobileForensics #DigitalForensics #iOS #FLOSS #iLEAPP
-
🌋 LAVA 0.14.0 is out.
Row tagging lands. Tag rows of interest in any artifact table with your own colored tags, add examiner notes, and review everything you flagged from one Tagged Rows hub.Export the tagged set two ways: a self contained HTML report (dark mode, playable media) or a subset LAVA project that reopens in LAVA with media, tags, and a tamper evident provenance record naming its source.
The LEAPP artifact db is opened read only and never written. Tags live in a sidecar SQLite file and each tagged row is anchored with a SHA256 hash.
https://leapps.org/releases#section-lava
#DFIR #DigitalForensics #MobileForensics #OpenSource #InfoSec
-
How far has deepfake technology evolved from a simple novelty to a potent weapon in the arsenal of coercive control? This article dives into the critical intersection of digital media, artificial intelligence, and personal safety.
Don't forget to like, comment, and subscribe for more deep dives into digital ethics!
#DigitalSafety #AIethics #Deepfakes #CoerciveControl #DomesticAbuse #AIEthics #DigitalForensics #LawReform #SyntheticMedia #techethics
-
New iLEAPP parser: the United Airlines iOS app! ✈️
New blog post from the awesome James Habben walking through the research: where the data lived, which rabbit holes were worth chasing, and which ones he left alone.
12 new artifacts in iLEAPP:
👤 Account profile
🧳 Saved travelers and trip passengers
🎫 Trips, boarding passes, and PNR documents
🔎 Booking and flight status searches
📋 Boarding status log
🎬 Inflight entertainment watch history
⌚ Watch complications
💬 iMessage recipients from the app's plugin cacheThe traveler/passenger split, the trip JSON mining, and that late-discovered iMessage plugin cache are the fun ones. Read the write-up, it shows the actual thinking, not just the results.
Thank you James!
📖 Read it: https://leapps.org/blog-post?post=united-ios-app-artifacts
🔗 Get iLEAPP: https://www.leapps.org/releases#section-ileapp#DFIR #MobileForensics #DigitalForensics #iOS #FLOSS #iLEAPP
-
Photos.sqlite in LAVA! 📸
The entire Photos.sqlite parser family in iLEAPP, 42 artifacts, is now converted to LAVA. A massive body of work from the awesome Scott Koenig, covering one of the richest sources of evidence on any iOS device.What it parses:
📷 Basic asset and album data
📍 Assets with valid locations
⭐ Favorites, hidden, trashed, and burst assets
🤖 GenAI-detected images
👥 People and detected faces
📤 Shared albums plus iCloud Shared Photo Library assets and contributors
🔗 iCloud shared links
🗂️ Asset internal resource data
⚙️ Camera, MediaAnalysis, and SlideShow plist configs
📱 Per-version reference tables from iOS 14 all the way through iOS 26
Standardized timestamps, guarded queries across iOS versions, and full LAVA output for every one.Here is why that matters. Photos.sqlite is data heavy. The old HTML report can choke and crash under that many rows. LAVA does not. It handles the volume and stays fast and filterable, exactly when you need it to.
Huge thank you to Scott Koenig for the research and for keeping it current release after release.
🔗 Get iLEAPP: https://www.leapps.org/releases#section-ileapp -
RAPPLER | Philippine & World News | Investigative Journalism | Data | Civic Engagement | Public Interest [Unofficial] @[email protected] ·[DECODED] Who’s paying for your ‘news’?
-
Did you know Samsung's keyboard, Honeyboard, keeps its own clipboard history? Screenshots and all. ALEAPP just got a big upgrade parsing it.
The rebuilt Samsung Honeyboard clipboard artifact now pulls:
⌨️ Clipboard text history (live entries)
🗑️ Deleted clipboard entries recovered from the SQLite WAL, no external tools
🖼️ Clipboard screenshot clips with embedded thumbnails
🕵️ Screenshot source app decoded from Samsung's hidden SEFT trailer
🏷️ Clipboard source app resolved from packages.xml, text or binary ABX on Android 12+
🧩 Dual schema support, old caller_app_uid and new caller_package_name
🕒 UTC timestamps, EXIF capture time, and image dimensionsHeads up: this is not in a tagged release yet. To use it right now you have to run ALEAPP from source. Clone the repo and run it from code, the artifact is already on main.
Big thanks to Al3x101 (MSAB) for the excellent rewrite behind all of this, and to segumarc for the original Honeyboard module we built on. Open source moving mobile forensics forward!
🔗 Run ALEAPP from source: https://github.com/abrignoni/ALEAPP
#DFIR #FLOSS #FOSS #MobileForensics #DigitalForensics #Android
-
New blog post: Be Careful What You Wish For.
We are implementing AI in digital forensics wrong.
Here is a new technology that works like a genie. You make a wish, the genie provides. Need a timeline? Ask the genie. A data source you don't understand? Ask the genie, it comes back parsed. What is not to like?
Plenty, it turns out.
For the last few weeks I have been using Claude extensively on the LEAPPs codebase, reviewing every single PR. That work taught me exactly what the genie can do, what it cannot, and what happens the moment you forget the difference.
So I wrote it down. It is about wishes, monkey's paws, and the one thing the genie can never grant you.
📖 Read it: https://leapps.org/blog-post?post=2026-07-12-be-careful-what-you-wish-for
-
New in iLEAPP and ALEAPP: spotting AI generated images! 🤖
A lot of pictures now carry the answer inside them. The new C2PA Content Provenance artifact reads it two ways:
🧬 C2PA Content Credentials manifests
🏷️ IPTC Digital Source Type in XMP
🛠️ Creator tool, edit actions, ingredients
🐍 Pure Python, no new dependenciesNot in a release yet. Run from source today!
🔗 https://leapps.org/blog-post?post=2026-07-12-ai-image-provenance
Thank you to the IPTC and the C2PA / Content Authenticity folks! -
What? Brigs using an LLM? Yes.
New blog post: The Rules Keep Changing.
I asked Claude to generate a complete iLEAPP artifact on its own, targeting the newly documented SQLite databases in the iOS Biome directory. It came back with fourteen artifacts covering the pre-aggregated Biome databases and the protobuf-based Set.db stores.
All fourteen ran clean on the first full pass. That is 3,668 rows of previously unparsed data.
Was it hands-off? No, and that is exactly the point. The LLM wrote the code. The examiner owned the verification. I reviewed every schema, checked the timestamp conversions, and validated row counts against manual queries. That division of labor is the only version of this workflow I will vouch for.
Coding has been democratized. The days of waiting for a vendor to parse the artifacts you need are ending. But only an expert can and should be generating code with LLMs for casework, because only an expert can verify every output.
Big thanks to the awesome Charlie Rubisoft, whose Biome research made this possible, and to John Hyla, Geraldine Bly, and Alex Caithness for the SEGB work that started this whole thread.
The rules keep changing. Keep up.
📖 Read it: https://leapps.org/blog-post?post=2026-07-11-the-rules-keep-changing
#DFIR #MobileForensics #DigitalForensics #iOS #FLOSS #iLEAPP
-
🔎 Small feature, real impact: the LEAPPs Artifact Browser now shows the sample data behind every parser.
Head to leapps.org/artifacts, click "samples" on any artifact, and you will see the exact test images it was validated against, plus the row count each one produced. For example:
📱 iOS 17.3 | 64 rows
📱 iOS 13.3.1 | 40 rows
📱 iOS 14.3 | 74 rowsWhy it matters: validation. When you document your tools for a case, knowing what a parser was actually tested against is not a nice to have, it is the work. Now that lives right next to the source paths, pulled straight from the module itself. No digging.
More than 840 of our 1,500+ artifacts already carry this, and it is fully searchable. That count climbs every time a contributor adds sample data to a module. 🙌
To everyone in the community who documents their test images: thank you. You are making the whole toolset more transparent and more defensible for all of us. Take a look 👉 leapps.org/artifacts
-
🚀 New releases! iLEAPP and ALEAPP both hit v2026.1.0!
Been a while cooking and this one is big. Both tools move to a fresh calendar versioning scheme and land a mountain of work from the community.
What's new across iLEAPP and ALEAPP:
🌋 Massive LAVA migration is essentially complete. Nearly every artifact now runs on the modern processor with UTC timestamps, relative source paths, and consistent metadata.
🆕 New parsers: Zalo, Discord cache, Home Depot, Oura Ring, Biome app usage, HONOR Media Library, Samsung Secure Folder, Rema 1000, and more.
💬 Conversation views added to WhatsApp, Viber, Kik, Slack, Life360, TikTok, Discord, Reddit, Google Messages, and others.
🎨 Visual identity overhaul with Tabler icons and dark theme updates.
🔎 New App Inventory module to show you exactly what is and isn't parsed in an extraction.
🛠️ Tons of stability fixes: pre-1970 timestamps, reserved-word crashes, glob filename resolution, long Windows paths, and packaging.Huge thank you to everyone who contributed parsers, fixes, and testing. This is what open source forensics looks like when the community shows up.
🔗 Get iLEAPP: https://www.leapps.org/releases#section-ileapp
🔗 Get ALEAPP: https://www.leapps.org/releases#section-aleapp#DFIR #MobileForensics #DigitalForensics #iOS #Android #FLOSS #iLEAPP #ALEAPP
-
Batch LEAPP's new --coverage mode inventories every installed app and every file on your test devices, checks them against what the LEAPP modules actually touched, and hands you the gaps as a ranked list. Ran it against my test corpus today:
📱 5 iOS full filesystem images + a Pixel 8 Pro, one command each
🗃️ 1.3 million files inventoried and mapped to 6,000+ app containers
🚩 Snapchat: unparsed in 5 of 5 images — 29,482 files sitting on disk unread
📉 Facebook, Twitter, and YouTube: no app-specific coverage either
🔍 Instagram: parsed in 4 of 5 images — the odd one out is a bug report waiting to be filed
🤖 Android gaps: Instagram, Signal, Kik, and Telegram
🌋 The whole analysis opens in LAVA, one button from the batch reportIt even caught a mislabeled extraction in my collection — an "Android" image that turned out to be an iPhone 8 the whole time.
If you have ever wanted a data-backed answer to "what module should we build next?" — there it is. Full write-up, charts, and the how-to guides:
🔗 https://leapps.org/blog-post?post=2026-07-08-app-coverage-analysis
Free and open source, as always. Feedback and pull requests welcome!
#DFIR #FLOSS #MobileForensics #DigitalForensics #iOS #Android
-
RAPPLER | Philippine & World News | Investigative Journalism | Data | Civic Engagement | Public Interest [Unofficial] @[email protected] ·What’s OSINT, hash values? Impeachment trial shows nuances in preserving digital evidence
-
When researching online, OSINT browser extensions can help you collect, verify, and save information faster—without constantly switching tools.
Here are some useful browser extensions for OSINT and online investigations 😎👇
Find a high-res pdf ebook with all my cybersecurity related infographics from https://study-notes.org
#osint #digitalforensics #infosec #cybersecurity #informationsecurity
-
Join Cellebrite’s July 7 webinar to learn how responsible AI can help investigators connect evidence, uncover insights faster, and maintain the transparency and defensibility every case demands—register now. https://www.forensicfocus.com/news/upcoming-webinar-ai-is-the-hot-sauce-from-data-overload-to-investigative-insight/ #Cellebrite #AI #DigitalForensics #DFIR
-
#reminder 📱 Cellebrite DI Ltd. is an Israeli digital forensics company behind UFED tools used by law enforcement and enterprises worldwide. Founded in 1999, it has expanded into broader digital intelligence—alongside recurring controversies over investigations and device access. 🌍⚖️ #DigitalForensics #Cybersecurity https://en.wikipedia.org/wiki/Cellebrite
-
Linux investigations move fast, and knowing where to look matters. This cheat sheet highlights key digital forensic artifacts that incident responders, SOC analysts, and DFIR teams should collect when investigating a Linux system 😎👇
Find high-res pdf ebooks with all my Linux and cybersecurity related infographics from https://study-notes.org
#cybersecurity #linux #infosec #pentesting #digitalforensics