r/digitalforensics 3h ago

I need to conduct an informational interview with someone in a position of management within this field

2 Upvotes

Not sure if this is the right place to ask this but I'm kinda out of options.

I have an assignment due tomorrow for my business communications course that requires me to conduct an informational interview with someone within the field I'm interested in (which is digital forensics)

If possible, could someone in a position of management within this field please reach out to me through dms to negotiate a time to conduct an informational interview via zoom,teams,etc?

Or tell me where I can go to so that I can reach out to someone that can help?

Thanks.


r/digitalforensics 1d ago

Digital Forensics Assignment

0 Upvotes

hey guys! im not sure if this is the right subreddit to be asking for this kind of help in but i had no idea where to ask 😅
im currently doing a university digital forensics assingment, and im required to find a router password within some files (unzipped folder)
Ive tried a lot of different things but i cant seem to find it at all.
Any advice would be welcome! (sorry if this is the wrong subreddit again!!)

these are all the files i was given! sorry if this doesnt help much! (so far ive tried HxD and checking the metadata..i forgot what else..its a first year assignment so shouldnt be too hard?)


r/digitalforensics 1d ago

Auto profile for volatility

2 Upvotes

Hello everyone,
I am thinking about building a solution for volatility linux profiles where you will be able to upload your kernel (even without debug symbols), and you will get working volatility3 profile.

It will work on any linux kernel, even those that does not expose they compiled configuration (like different iot devices) , and it will help to speed with the analysis.

I wonder , do you feel you actually need this solution (and is your company willing to pay for the service)

Right now i have working poc , and i am wondering is this problem still time consuming.

Thank you


r/digitalforensics 2d ago

Cellebrite Endpoint

3 Upvotes

With Cellebrite Endpoint being discontinued at years end, my company is looking to find a new remote collection tool.. Any suggestions anyone may have that I research and push forward? Thanks


r/digitalforensics 2d ago

Automating Volatility 3 (X-Post)

3 Upvotes

A new 13Cubed episode is out!

In this episode, we'll look at a tool that can run multiple Volatility 3 plugins simultaneously, automating your memory analysis and saving you valuable time during investigations.

Watch now: https://www.youtube.com/watch?v=0GMTydimOP4

More at youtube.com/13cubed


r/digitalforensics 2d ago

Professional iPhone forensics question: Has anyone recovered data from a passcode-locked iPhone SE 2 (A13)?

0 Upvotes

Hi everyone,
I’m looking for someone with **first-hand professional experience** in iPhone forensics rather than general opinions.
I own an **iPhone SE (2nd generation, A13)** containing important personal WhatsApp chats and photos.
Current situation:
Boots normally to the lock screen.
Same Apple ID as my newer iPhones.
One passcode attempt remaining.
Touch ID disabled after previous incorrect passcode attempts.
Previously paired with an Apple Watch Series 6 (GPS).
I still know the Apple Watch passcode.
The Apple Watch and iPhone once shared the same passcode years ago, but the iPhone passcode was changed later.
The phone has **not** been erased because preserving the data is my priority.
I’m **not asking for illegal bypass methods**.
Instead, I’m trying to understand what is realistically possible today from a professional forensic perspective.
My questions are:
Has anyone here actually worked with **Cellebrite, GrayKey, Magnet Forensics, Elcomsoft**, or similar forensic platforms?
Have you personally seen successful data recovery from a passcode-locked **A13 iPhone SE 2** without erasing the device?
Is the limitation today mainly the Secure Enclave, or are there other practical obstacles?
Is there any current research or technology that professionals are watching which could eventually improve the chances?
I’m located in Germany but I’m willing to work with an international forensic company if there is a realistic possibility.
Thank you very much for sharing your professional experience.


r/digitalforensics 3d ago

Lots of Spam Posts Recently.

11 Upvotes

Is one way to stop them to disable youtube links?

Or make a required number of posts on Reddit before you can post to the sub?


r/digitalforensics 2d ago

PLEASE help enhance clips

Thumbnail dropbox.com
0 Upvotes

r/digitalforensics 2d ago

Hidden files on phone!

Post image
0 Upvotes

Help. Elderly abuse, mentally emotionally and financial.


r/digitalforensics 4d ago

We're about to replace "blind tool trust" with "blind AI trust"

Thumbnail
0 Upvotes

r/digitalforensics 4d ago

Need help tracking someone who threatens us

Thumbnail
0 Upvotes

r/digitalforensics 5d ago

Looking for a test android physical image

1 Upvotes

Hi! Can anybody share me a test physical dump of an android device? Or maybe point me to some online links? Have searched on cfreds


r/digitalforensics 6d ago

Asking for HELP: Failing 1TB HDD cloning at 32–38 KB/s with ddrescue—drive or USB dock problem?

Post image
7 Upvotes

I’m cloning a SMART-failing 1TB SATA HDD from my OLD Windows Computer to a healthy 1TB PNY SSD using GNU ddrescue 1.30 on an Apple Silicon Mac.
Source is connected through a powered Sabrent DS-UC1B USB-C dock using an ASMedia ASM235 bridge. Both partitions are unmounted, and I’m using raw devices with a resumable mapfile.

After about 3 hours:
416MB rescued / 983GB partition
32–38KB/s
0 read errors and 0 bad sectors
277 slow reads
Pass 3 forwards
Process often shows U kernel-I/O wait
ETA approximately 329 days

Does the unusually consistent ~32KB/s indicate the HDD is internally retrying, or could the USB-SATA bridge/UASP be causing it? Would you continue, try direct SATA/Linux, use another bridge, or switch to HDDSuperClone/OpenSuperClone?

FYI: B.S. Computer Science but have never done this before. Thanks in advance!


r/digitalforensics 5d ago

Help to know the location/ IP address of private tiktok

Post image
0 Upvotes

Hi, can someone help us identify the person behind this private TikTok account? The account has been harassing us and making false accusations. We would appreciate any guidance on the proper steps we can take to address this situation. Thank you.


r/digitalforensics 5d ago

Digital Realm Sciences forensic research

Enable HLS to view with audio, or disable this notification

0 Upvotes

r/digitalforensics 5d ago

The Digital Chopshop Thesis

Enable HLS to view with audio, or disable this notification

0 Upvotes

r/digitalforensics 7d ago

Forensic Technology Grad interview

3 Upvotes

I have my first interview on Friday for the Alvarez and Marsal Forensic Technology Graduate Programme in London. I had a 30 minute initial screening interview yesterday so Friday is the first official one. I studied software development in university and in the initial screening the recruiter said they’re not expecting anyone with experience in the field so what kind of things should I prep for, Thanks!


r/digitalforensics 7d ago

Getting Started in Digital Forensics

0 Upvotes

I’m going into digital forensics after originally planning to be a cloud engineer. I do have my CompTIA Network +, is that relevant for this path?

I want to go the law enforcement route but don’t know how to get there. Should I get Security+, or are there better certs for this specific path? Is the FBI route realistic for a fresh grad?

I know I need an internship — what else should I be doing before I graduate? I’m an upcoming senior.


r/digitalforensics 7d ago

ayuda por favor.

1 Upvotes

Hola, necesito su ayuda, mi tabla de particiones ha desaparecido no puedo encontrarla ni con testdisk, ni ning una otra aplicacion, es como si nunca hubiera existido, hay manera de recuperarla? o recuperar solo los datos?


r/digitalforensics 8d ago

Original Research: Favicon Fingerprinting at Internet Scale

Thumbnail bishopfox.com
2 Upvotes

Favicons have been used for fingerprinting for a long time, but I thought this was an interesting way to take that idea much further.

Aaron Ringo (Bishop Fox) built an AI-assisted workflow that hashes, correlates, and enriches millions of favicons to identify software, pivot to related infrastructure, and build a searchable dataset. The post also gets into some interesting use cases around attribution, trend tracking, honeypot detection, and the like.

Thought you all might get a kick out of it.

(Disclosure: I work with Aaron.)


r/digitalforensics 9d ago

Open to New Opportunities | Senior DFIR | Incident Response | Digital Forensics | Cyber Investigations | 7+ Years

1 Upvotes

Hello Cybersecurity Community,

I hope you're all doing well.

I'm currently exploring new opportunities with global organizations for roles in Digital Forensics, Incident Response (DFIR), Cyber Investigations, Insider Threat, Security Operations (SOC), Threat Hunting, and Incident Management. I'm open to remote, hybrid, or on-site opportunities across India, as well as fully remote international roles.

About Me

I bring 7+ years of hands-on experience in cybersecurity, specializing in Digital Forensics and Incident Response (DFIR). Over the years, I have investigated and responded to a wide range of enterprise security incidents, including ransomware attacks, malware infections, phishing campaigns, insider threats, data breaches, and employee misconduct investigations.

My experience spans the complete incident response lifecycle—from detection and triage to forensic acquisition, analysis, containment, eradication, recovery, root cause analysis, and executive reporting.

Core Competencies

  • Digital Forensics (Endpoint, Mobile & Enterprise)
  • Incident Response & Cyber Investigations
  • Malware Analysis
  • Insider Threat Investigations
  • Data Breach Response
  • Ransomware & Phishing Investigations
  • Evidence Acquisition & Preservation
  • Memory & Disk Forensics
  • Threat Hunting
  • Threat Intelligence
  • SOC Operations (L2/L3)
  • Log Analysis & Timeline Reconstruction
  • Enterprise Security Monitoring
  • Root Cause Analysis & Incident Reporting

Technical Expertise

  • Magnet AXIOM
  • FTK
  • Cellebrite UFED
  • Oxygen Forensics
  • CrowdStrike Falcon
  • Microsoft Defender XDR
  • Microsoft Sentinel
  • Splunk
  • IBM QRadar
  • Varonis
  • Qualys
  • Pentera
  • Recorded Future Threat Intelligence Platform
  • Windows & Linux Forensics
  • SIEM, EDR & XDR Technologies
  • IOC & Threat Intelligence Analysis

Professional Certifications

  • EC-Council Certified Ethical Hacker (CEH)
  • EC-Council Certified Hacking Forensic Investigator (CHFI)
  • EC-Council Certified Incident Handler (ECIH)
  • Recorded Future Certified Intelligence Professional / Certified Technician

Roles I'm Interested In

  • Senior Digital Forensics Analyst
  • DFIR Consultant
  • Incident Response Specialist
  • Senior Incident Responder
  • Cyber Investigator
  • Insider Threat Analyst
  • Threat Hunter
  • Senior SOC Analyst
  • Detection & Response Engineer
  • Security Operations Engineer
  • Cyber Incident Manager

If your organization is hiring or you know of any relevant opportunities, I would sincerely appreciate a referral or introduction. I'm happy to share my resume and discuss how my experience can contribute to your team.

Thank you for taking the time to read my post. Any referrals, recommendations, or leads would be greatly appreciated.

Thank you!


r/digitalforensics 8d ago

Do anyone data source to get identity of phone number?? For a OSINT tool

0 Upvotes

r/digitalforensics 9d ago

Police have my Phone

26 Upvotes

As the title states, the police have my phone as it is considered evidence in my case, and are extracting data. My lawyer has advised me not to use iCloud messaging, and I have listened to everything my lawyer has said so far.

In particular, my messages app is considered part of the investigation. My question is: once they extract data from my phone, do they only look at the data from my Messages app, or everything in my phone? I feel like it would be a violation of my privacy if they do look at everything on my phone, and only my messages app, specifically the conversation I had, should only be looked at.

And in case you did wonder, I did contact my lawyer to start a process to release my phone back to me. If you reply, thank you for the help and clarification that you provide.


r/digitalforensics 9d ago

Digital Forensics Career Abroad - Is it realistic for an Indian student to build a career overseas?

7 Upvotes

Hi everyone,

I'm writing this with a lot of hope, and I genuinely want honest opinions even if they're harsh. I'd rather hear the truth than false motivation.

I'm from India and recently completed my Master's in Forensic Science with a specialization in Cyber Forensics from the National Forensic Sciences University (NFSU).

Right now, I'm working as a Digital Forensic Investigator with the CID/State Police on a contractual basis, and I have a little over one year of experience working specifically in digital forensics. My work revolves around forensic investigations and evidence handling not general cybersecurity. I also don't have any certifications like GIAC, EnCE, CHFI, etc., at the moment.

Lately, I've been thinking a lot about my future. One of my biggest goals is to settle abroad not just because of money, but because I'm looking for a better quality of life, stronger career opportunities, and a different lifestyle. Digital forensics is genuinely the field I enjoy, and I'd like to continue building my career in it rather than switching to another domain if possible.

The problem is that when I search online, I find completely different opinions. Some people say digital forensics has excellent opportunities overseas, while others say it's almost impossible for foreigners because many forensic roles require citizenship, security clearance, or local law enforcement experience.

So I'd really appreciate hearing from people who actually work in this field or have gone through this journey.

  • Is it realistically possible for someone with my background to get a digital forensics job outside India?
  • If yes, which countries are actually worth targeting?
  • Are there countries where private-sector DFIR roles are more accessible than government forensic labs?
  • Would I need another Master's abroad, or would experience and certifications be enough?
  • If you were in my position today, what would your roadmap look like over the next 2–5 years?

Please don't sugarcoat your answers. If the chances are very low, tell me that. If I need another 3–5 years of experience before even thinking about moving, I'd rather know now. If I need to pivot towards DFIR, incident response, or another closely related field to make immigration possible, I'm open to hearing that too.

I know many people dream of moving abroad, and I'm no different. I'm simply trying to understand whether this goal is actually achievable in my field or whether I should focus on building my career in India instead.

Thank you for taking the time to read this. Any advice, personal experiences, or reality checks would genuinely mean a lot.


r/digitalforensics 9d ago

Fastest and most practical way to analyze Apache/Nginx logs

Thumbnail
0 Upvotes