r/digitalforensics 3h ago

I need to conduct an informational interview with someone in a position of management within this field

2 Upvotes

Not sure if this is the right place to ask this but I'm kinda out of options.

I have an assignment due tomorrow for my business communications course that requires me to conduct an informational interview with someone within the field I'm interested in (which is digital forensics)

If possible, could someone in a position of management within this field please reach out to me through dms to negotiate a time to conduct an informational interview via zoom,teams,etc?

Or tell me where I can go to so that I can reach out to someone that can help?

Thanks.


r/digitalforensics 1d ago

Digital Forensics Assignment

0 Upvotes

hey guys! im not sure if this is the right subreddit to be asking for this kind of help in but i had no idea where to ask 😅
im currently doing a university digital forensics assingment, and im required to find a router password within some files (unzipped folder)
Ive tried a lot of different things but i cant seem to find it at all.
Any advice would be welcome! (sorry if this is the wrong subreddit again!!)

these are all the files i was given! sorry if this doesnt help much! (so far ive tried HxD and checking the metadata..i forgot what else..its a first year assignment so shouldnt be too hard?)


r/digitalforensics 1d ago

Auto profile for volatility

2 Upvotes

Hello everyone,
I am thinking about building a solution for volatility linux profiles where you will be able to upload your kernel (even without debug symbols), and you will get working volatility3 profile.

It will work on any linux kernel, even those that does not expose they compiled configuration (like different iot devices) , and it will help to speed with the analysis.

I wonder , do you feel you actually need this solution (and is your company willing to pay for the service)

Right now i have working poc , and i am wondering is this problem still time consuming.

Thank you


r/digitalforensics 2d ago

Professional iPhone forensics question: Has anyone recovered data from a passcode-locked iPhone SE 2 (A13)?

0 Upvotes

Hi everyone,
I’m looking for someone with **first-hand professional experience** in iPhone forensics rather than general opinions.
I own an **iPhone SE (2nd generation, A13)** containing important personal WhatsApp chats and photos.
Current situation:
Boots normally to the lock screen.
Same Apple ID as my newer iPhones.
One passcode attempt remaining.
Touch ID disabled after previous incorrect passcode attempts.
Previously paired with an Apple Watch Series 6 (GPS).
I still know the Apple Watch passcode.
The Apple Watch and iPhone once shared the same passcode years ago, but the iPhone passcode was changed later.
The phone has **not** been erased because preserving the data is my priority.
I’m **not asking for illegal bypass methods**.
Instead, I’m trying to understand what is realistically possible today from a professional forensic perspective.
My questions are:
Has anyone here actually worked with **Cellebrite, GrayKey, Magnet Forensics, Elcomsoft**, or similar forensic platforms?
Have you personally seen successful data recovery from a passcode-locked **A13 iPhone SE 2** without erasing the device?
Is the limitation today mainly the Secure Enclave, or are there other practical obstacles?
Is there any current research or technology that professionals are watching which could eventually improve the chances?
I’m located in Germany but I’m willing to work with an international forensic company if there is a realistic possibility.
Thank you very much for sharing your professional experience.


r/digitalforensics 2d ago

Cellebrite Endpoint

3 Upvotes

With Cellebrite Endpoint being discontinued at years end, my company is looking to find a new remote collection tool.. Any suggestions anyone may have that I research and push forward? Thanks


r/digitalforensics 2d ago

Automating Volatility 3 (X-Post)

3 Upvotes

A new 13Cubed episode is out!

In this episode, we'll look at a tool that can run multiple Volatility 3 plugins simultaneously, automating your memory analysis and saving you valuable time during investigations.

Watch now: https://www.youtube.com/watch?v=0GMTydimOP4

More at youtube.com/13cubed


r/digitalforensics 2d ago

PLEASE help enhance clips

Thumbnail dropbox.com
0 Upvotes

r/digitalforensics 2d ago

Hidden files on phone!

Post image
0 Upvotes

Help. Elderly abuse, mentally emotionally and financial.


r/digitalforensics 3d ago

Lots of Spam Posts Recently.

11 Upvotes

Is one way to stop them to disable youtube links?

Or make a required number of posts on Reddit before you can post to the sub?


r/digitalforensics 4d ago

We're about to replace "blind tool trust" with "blind AI trust"

Thumbnail
0 Upvotes

r/digitalforensics 4d ago

Need help tracking someone who threatens us

Thumbnail
0 Upvotes

r/digitalforensics 5d ago

Looking for a test android physical image

1 Upvotes

Hi! Can anybody share me a test physical dump of an android device? Or maybe point me to some online links? Have searched on cfreds


r/digitalforensics 5d ago

Help to know the location/ IP address of private tiktok

Post image
0 Upvotes

Hi, can someone help us identify the person behind this private TikTok account? The account has been harassing us and making false accusations. We would appreciate any guidance on the proper steps we can take to address this situation. Thank you.


r/digitalforensics 5d ago

Digital Realm Sciences forensic research

Enable HLS to view with audio, or disable this notification

0 Upvotes

r/digitalforensics 5d ago

The Digital Chopshop Thesis

Enable HLS to view with audio, or disable this notification

0 Upvotes

r/digitalforensics 6d ago

Asking for HELP: Failing 1TB HDD cloning at 32–38 KB/s with ddrescue—drive or USB dock problem?

Post image
8 Upvotes

I’m cloning a SMART-failing 1TB SATA HDD from my OLD Windows Computer to a healthy 1TB PNY SSD using GNU ddrescue 1.30 on an Apple Silicon Mac.
Source is connected through a powered Sabrent DS-UC1B USB-C dock using an ASMedia ASM235 bridge. Both partitions are unmounted, and I’m using raw devices with a resumable mapfile.

After about 3 hours:
416MB rescued / 983GB partition
32–38KB/s
0 read errors and 0 bad sectors
277 slow reads
Pass 3 forwards
Process often shows U kernel-I/O wait
ETA approximately 329 days

Does the unusually consistent ~32KB/s indicate the HDD is internally retrying, or could the USB-SATA bridge/UASP be causing it? Would you continue, try direct SATA/Linux, use another bridge, or switch to HDDSuperClone/OpenSuperClone?

FYI: B.S. Computer Science but have never done this before. Thanks in advance!


r/digitalforensics 7d ago

Forensic Technology Grad interview

3 Upvotes

I have my first interview on Friday for the Alvarez and Marsal Forensic Technology Graduate Programme in London. I had a 30 minute initial screening interview yesterday so Friday is the first official one. I studied software development in university and in the initial screening the recruiter said they’re not expecting anyone with experience in the field so what kind of things should I prep for, Thanks!


r/digitalforensics 7d ago

Getting Started in Digital Forensics

0 Upvotes

I’m going into digital forensics after originally planning to be a cloud engineer. I do have my CompTIA Network +, is that relevant for this path?

I want to go the law enforcement route but don’t know how to get there. Should I get Security+, or are there better certs for this specific path? Is the FBI route realistic for a fresh grad?

I know I need an internship — what else should I be doing before I graduate? I’m an upcoming senior.


r/digitalforensics 7d ago

ayuda por favor.

1 Upvotes

Hola, necesito su ayuda, mi tabla de particiones ha desaparecido no puedo encontrarla ni con testdisk, ni ning una otra aplicacion, es como si nunca hubiera existido, hay manera de recuperarla? o recuperar solo los datos?


r/digitalforensics 8d ago

Original Research: Favicon Fingerprinting at Internet Scale

Thumbnail bishopfox.com
2 Upvotes

Favicons have been used for fingerprinting for a long time, but I thought this was an interesting way to take that idea much further.

Aaron Ringo (Bishop Fox) built an AI-assisted workflow that hashes, correlates, and enriches millions of favicons to identify software, pivot to related infrastructure, and build a searchable dataset. The post also gets into some interesting use cases around attribution, trend tracking, honeypot detection, and the like.

Thought you all might get a kick out of it.

(Disclosure: I work with Aaron.)


r/digitalforensics 8d ago

Do anyone data source to get identity of phone number?? For a OSINT tool

0 Upvotes

r/digitalforensics 9d ago

Open to New Opportunities | Senior DFIR | Incident Response | Digital Forensics | Cyber Investigations | 7+ Years

2 Upvotes

Hello Cybersecurity Community,

I hope you're all doing well.

I'm currently exploring new opportunities with global organizations for roles in Digital Forensics, Incident Response (DFIR), Cyber Investigations, Insider Threat, Security Operations (SOC), Threat Hunting, and Incident Management. I'm open to remote, hybrid, or on-site opportunities across India, as well as fully remote international roles.

About Me

I bring 7+ years of hands-on experience in cybersecurity, specializing in Digital Forensics and Incident Response (DFIR). Over the years, I have investigated and responded to a wide range of enterprise security incidents, including ransomware attacks, malware infections, phishing campaigns, insider threats, data breaches, and employee misconduct investigations.

My experience spans the complete incident response lifecycle—from detection and triage to forensic acquisition, analysis, containment, eradication, recovery, root cause analysis, and executive reporting.

Core Competencies

  • Digital Forensics (Endpoint, Mobile & Enterprise)
  • Incident Response & Cyber Investigations
  • Malware Analysis
  • Insider Threat Investigations
  • Data Breach Response
  • Ransomware & Phishing Investigations
  • Evidence Acquisition & Preservation
  • Memory & Disk Forensics
  • Threat Hunting
  • Threat Intelligence
  • SOC Operations (L2/L3)
  • Log Analysis & Timeline Reconstruction
  • Enterprise Security Monitoring
  • Root Cause Analysis & Incident Reporting

Technical Expertise

  • Magnet AXIOM
  • FTK
  • Cellebrite UFED
  • Oxygen Forensics
  • CrowdStrike Falcon
  • Microsoft Defender XDR
  • Microsoft Sentinel
  • Splunk
  • IBM QRadar
  • Varonis
  • Qualys
  • Pentera
  • Recorded Future Threat Intelligence Platform
  • Windows & Linux Forensics
  • SIEM, EDR & XDR Technologies
  • IOC & Threat Intelligence Analysis

Professional Certifications

  • EC-Council Certified Ethical Hacker (CEH)
  • EC-Council Certified Hacking Forensic Investigator (CHFI)
  • EC-Council Certified Incident Handler (ECIH)
  • Recorded Future Certified Intelligence Professional / Certified Technician

Roles I'm Interested In

  • Senior Digital Forensics Analyst
  • DFIR Consultant
  • Incident Response Specialist
  • Senior Incident Responder
  • Cyber Investigator
  • Insider Threat Analyst
  • Threat Hunter
  • Senior SOC Analyst
  • Detection & Response Engineer
  • Security Operations Engineer
  • Cyber Incident Manager

If your organization is hiring or you know of any relevant opportunities, I would sincerely appreciate a referral or introduction. I'm happy to share my resume and discuss how my experience can contribute to your team.

Thank you for taking the time to read my post. Any referrals, recommendations, or leads would be greatly appreciated.

Thank you!


r/digitalforensics 9d ago

Fastest and most practical way to analyze Apache/Nginx logs

Thumbnail
0 Upvotes

r/digitalforensics 9d ago

can anyone help me??? hacked account

0 Upvotes

I’m writing this with my heart in my hands because I truly need help. My Microsoft account was stolen, and I’m hoping that someone kind might be willing to help me recover it. Microsoft Support hasn’t been able to help at all. That account contains all of my work-related information and educational files, and I desperately need to get it back.

I still have my original email address as well as the email address it was changed to after my account was hacked. In other words, I know both the old email and the new one that replaced it.

Please, I’m begging for someone who can help me recover my account. I can’t afford to pay right now, but I will do my best to find a way to compensate you somehow. I just really need help getting my account back.

I HAVE PROOFS THAT THIS IS REAL. PLEASE I DON'T HAVE ACCESS TO THAT ACCOUNT AND I HAD TO REINSTALL THE WINDOWS

-- thanks to the people that answered this post, this wasn't an scam, i'm still worried about my account but microsoft finally blocked it so i have to wait if i can recover it, thank u again.

sorry if i bothered some of you i was really sad about and didn't knoe what to do


r/digitalforensics 9d ago

Computer forensics

0 Upvotes

How can i get a real certificate that will get me a job without spending a fortune on the courses i want a way to get proper learning and at least a certificate that could get me somewhere without spending tons of money or if there is even a free option