r/digitalforensics

Is getting the master's now a good idea?

Hello all. I'm currently in my last year of getting my bachelor's in cybersecurity technology from UMGC, and have been planning on immediately getting the master's in digital Forensics. Im also currently studying to take A+ and later Network+ cert exams. Im not currently in the tech field, but plan on moving into it as soon as I can. From what I've gathered, getting a digital Forensics role usually takes years of experience first, so is it worth getting the master's now or should I wait until after I gain more experience? Any insight would be much appreciated.

reddit.com
u/fiachealu — 1 day ago

Best degree at Penn State for digital forensics career?

Which of the following bachelors degrees at Penn State would be best for a Digital Forensics career and why?
-Cybersecurity Analytics and Operations
-Information Technology: Security and Risk Analysis option
-Computer science

reddit.com
u/campane4848 — 1 day ago
▲ 14 r/digitalforensics+2 crossposts

I made a free step-by-step guide for building a SOC home lab (Windows + Linux + Sysmon + Wazuh + attack simulations)

Put together a hands-on PDF for anyone trying to break into SOC/blue team work but stuck on theory with no practical lab experience.

Covers the whole build: isolated VM network, Windows and Linux endpoints, Sysmon telemetry, PowerShell logging, deploying Wazuh as the SIEM, connecting agents, and five safe attack simulation exercises (failed logins, encoded PowerShell, process creation, network connections, file drops).

Then it goes into the actual analyst work: a 10-step investigation workflow, a full practical investigation with an answer key, detection rule writing, an incident response playbook, and an incident report template.

Free download, no signup wall: from codelivly telegram channel

If you want to go further after this, I also put together a full SOC Analyst L1-L2-L3 bundle here: https://resources.codelivly.com/product/soc-analyst-the-complete-l1-l2-l3/

Happy to answer questions if anyone gets stuck on the Wazuh setup or Sysmon config.

▲ 98 r/digitalforensics+7 crossposts

Invadi um servidor de distribuição de malware Trojan, Stealer e Cryptominer

Um SMB exposto e misconfigs me deram acesso a um server parte da cadeia de infecção de um RAT brasileiro com keylogger, desktop capture, shellcode injection, cryptominer e C2 baseado em Tor.

A campanha utiliza múltiplas camadas com repositórios públicos, Blogspot, GitHub, PHP, Tor, Telegram e payloads que se atualizam em cadeia sendo uma Killchain modular, montada para continuar operando mesmo quando um dos estágios quebra a cadeia.

LNK -> VBS -> chunks -> Blogspot -> GitHub -> PHP agent -> chrome.exe

Report completo, feito totalmente por diversaummm
https://mensvr.com/reports/indigo-shark

u/reznovmustdie — 2 days ago

Help with choosing a DFIR project

Hello everyone,

I would appreciate your help with creating a project in the field of DFIR.

I applied for an advanced DFIR course and was shortlisted for a personal interview. The thing is, I don’t currently have any cybersecurity-specific projects; I only have software development projects. So, I would like to work on a DFIR project that I can present during the interview.

The project doesn’t necessarily need to be highly professional or advanced. I just want it to demonstrate that I have some practical experience and hands-on exposure to the field.

I would also like to practice and prepare myself for the course. What would you recommend I focus on or study to get ready?

reddit.com
u/AdCritical6409 — 3 days ago

I need help. Someone is extorting my little sister

My little sister rejected a guy and he has been trying to ruin her life and extort her. Please help us. Police are not helpful.

Thanks

reddit.com
u/These-Coffee-Beans — 5 days ago

Any Good Recommendation for Mobile Forensics Course/Youtube Playlist or Channel for a beginner.

Hello! I wanna start learning and practicing mobile forensics but I don't know where to learn it from. Also, I am a beginner so I can't afford to buy paid courses. Please help me out. Thank you so much in advance^^

reddit.com
u/Standard-Fix-6101 — 7 days ago

[FOR HIRE] Buried in emails, PDFs, screenshots, and conflicting records? We help reconstruct what they actually show.

Sometimes the problem isn’t that you don’t have the information.

You have too much of it.

Maybe it’s spread across hundreds of emails, text messages, PDFs, contracts, invoices, screenshots, reports, notes, logs, and spreadsheets.

You know the information is in there somewhere, but trying to piece together exactly what happened has become a project of its own.

That’s what CodexOS Reconstruction is designed to help with.

We take the available records and reconstruct the matter as clearly as the evidence allows.

Depending on the material, that can include:
• What happened and in what order
• The most important findings supported by the records
• Where different records agree or conflict
• Who appears to have known certain information, and when
• What evidence supports an important finding
• What information appears to be missing
• What the available records cannot actually establish

The goal isn’t to give you another summary.
It’s to organize the evidence well enough that you can actually inspect what happened and see where the conclusions came from.

This may be useful for situations involving:
• Business or contract disputes
• Vendor or contractor problems
• Complicated project histories
• Property management matters
• Insurance documentation
• Internal business issues or investigations
• Workplace records
• Compliance or administrative matters
• Other situations where the story is buried inside a large collection of records

A good potential case usually has a reasonably defined problem, actual source records, enough material to reconstruct something useful, and one or more questions you’re trying to answer.

You do NOT need to organize every file perfectly before contacting me.

If you have a situation buried in emails, documents, messages, screenshots, reports, or other records, send me a DM with a short description of:
• What happened
• Why you’re trying to make sense of it
• The main questions you want the records to help answer

I’ll look at the situation first and tell you whether it appears suitable for a responsible reconstruction before you commit to anything.

This isn’t legal advice, advocacy, or a service that decides who is right. We don’t fill gaps by guessing. If the records don’t support a conclusion, we say so.

**You give us the records. We reconstruct what they show.**

reddit.com
u/Independent-Diver929 — 5 days ago
▲ 25 r/digitalforensics+3 crossposts

Please help — 5 phones and 2 laptops stolen from a room

Hi everyone, my friend’s room was entered during the night, and someone stole 5 phones and 2 laptops.

We’re trying to find any possible way to track or recover the devices. We have the IMEI numbers and device details of the phones.

If anyone knows legitimate ways to track stolen phones or laptops, or has experience recovering devices in this situation, please share your advice.

We’re also trying to identify the person who took them and recover the devices safely.

If anyone has any useful information or knows of any way to help us locate the stolen devices, please let us know. We’re desperate to get them back and would really appreciate any help. 🙏

u/Titan_x_011 — 7 days ago
▲ 5 r/digitalforensics+3 crossposts

I built augur, the tool for finding hidden symbols across your documents

https://reddit.com/link/1vq8cyg/video/btfopmmbvsjh1/player

I built Augur, an open-source tool for seeing what is actually hidden inside a file.

It finds things like zero-width characters and hidden instructions, Trojan Source / bidi controls, mixed-script homoglyphs, EXIF and GPS metadata, C2PA manifests, and data appended after an image.

It can also write a cleaned copy without modifying the original or recompressing the image, then scans the result again to verify the selected stuff is actually gone.

Video shows the real thing - the demo files are generated by a script in the repo, including everything Augur then detects.

https://github.com/dejo1307/augur

reddit.com
u/fairwaycoder — 5 days ago
▲ 2.5k r/digitalforensics+1 crossposts

Apple is working on a way to authenticate that a photo came from an iPhone camera

New code in iOS 27 beta 5 shows that the company is working on something called Apple Reference Image, which is designed to authenticate the source of photos using unique data tied to the iPhone camera hardware that captured them.

In line with Apple’s privacy-focused approach to cloud-based processing of potentially sensitive user data, the company is designing Apple Reference Image in a way that prevents Apple from accessing the raw photo itself.

Instead, the system sends the image to Private Cloud Compute for authentication, while only certain sensor information and photo metadata are sent back to Apple. Interestingly, if Apple determines that a sensor may have been compromised, it may revoke prior authentications associated with that sensor.

9to5mac.com
u/pdfu — 11 days ago

Does digital forensics have a pipeline to something more like a detective or investigator with the police?

Or would that be a stretch? I hate my career in embedded sw and wish i went with something criminal justice related.

reddit.com
u/Next_Answer7481 — 7 days ago
▲ 10 r/digitalforensics+4 crossposts

Digital Forensics

I’m currently on my last year pursuing a BA in Criminology and I’m planning to venture in Digital Forensics/ Cybersecurity
I’m completely new in this field but at the same time have a deep passion for it. I’d love to work with Law Enforcement or Corporate as long as investigations are involved.
I’m also planning to volunteer in relevant institutions/ parastatals as I finish school for the experience and learning.
Any recommendations or advice on roadmaps I should follow?

reddit.com
u/lifeinasonderview — 8 days ago

Cellebrite - handling duplicate artifacts and browsing media

Either I'm missing something obvious (totally possible) or Cellebrite reader is dumb. Help.

Edit to add: I'm a solo investigator and don't have PA or Axiom, so I just work with whatever I get in a UFDR.

When I review extractions in Cellebrite Reader I get overwhelmed with duplicates and junk files. And I mean everything. Media, artifacts, messages, etc.

I understand certain events can create effectively identical artifacts in multiple databases. That's fine, but Reader doesn't have a way to filter sources that I can find. If I could, for example, hide KnowledgeC or Contacts, that would thin out the timeline or search results dramatically so I could actually find things. I often find myself exporting Excel files so I can deduplicate and review/search in other ways. Location data is a great example of this when I want to pull data and plot things on a map.

I find that the deduplicate filter never does anything.

Part 2 is media: my dream is that I could simply browse through a phone's photo app like a normal person using a phone. What I always find in the media browser, however, are hundreds of thousands of photos, including cached preview images, little tiny graphic emoji buttons, logos, etc from every app installed on the phone. I don't seem to find a combo of filters that ever works.

If I could just scroll the photos and videos on the phone's native app that would be a total dream. Browsing cached photos from social apps, deleted items, etc. is important, but often secondary to an initial review.

How do y'all handle this stuff? I have to find some faster workflows. On my cases I generally need to do an initial high level review/triage of the whole thing--calls, messages and media, before anything detailed, and it just takes so long.

Thanks!

reddit.com
u/shoe_box_ — 9 days ago

Help finding device information/geolocation in photo metadata?

Hi all, a good friend of mine (L) recently received pictures that her partner (C) said had been sent to her over Instagram by a burner account (who blocked her shortly after). These pictures depict L cheating on C with a random person neither of them had seen before, but they looked convincing enough. I know L and know that cheating goes against everything she stands for, and I'd bet my life on these being faked somehow; either AI generated or edited in some way.

L has her suspicions on who could be behind the pictures, but she can't begin to take legal action (defamation case) without some ground to stand on regarding these suspicions. Thing is, I'm a complete amateur in digital forensics, so try as I might I have only been able to get the pure basic metadata from these photos. The photos themselves have also been through a lot of sending and re-sending on different platforms, and I believe only one of the ones I have is an "original" in any regard; the others are screenshots.

So my question is, is there anybody here who could help? Either with the forensics aspect of it (which I believe I've reached a dead-end in, but again, I'm only an amateur) or with the visual analysis/AI identification part of it? We'd be super grateful.

reddit.com
u/jindoe0 — 8 days ago
▲ 0 r/digitalforensics+1 crossposts

Friend Owes $1500, HELP

Okay chat here we go. About a year ago I sold a car to a friend from high school. The car was listed everywhere for $2500, and he agreed to pay that amount. His only stipulation was that he would only pay $1000 up front and I would receive the other $1500 at a later time because he didn't want his dad to know how much he was really spending on the car. His dad comes with him to both pickup the car and to transfer the title. No reason to mention the $1500 right? Wrong. Fast forward over the last 11 months. Initially I was reaching out every couple weeks to ask about the money, to which he would always claim, "I don't have it yet but I'll get it soon." That went on up until about 2 weeks ago. I made a post (attached) to which HE replied to. "I didn't pay for it dad did." WHATEVER. Anyways. Couple days ago. I ask again, where's the money? He now claims to know nothing about ever owing me any money at all and that I have fabricated this elaborate scheme to extort money from him because I need the money and he's such an easy source. He now wants proof and evidence. Only issue is that this exchange was done over snap and the messages have long since disappeared. I've tried a data request but it didn't include any chats that had disappeared. If I could get those chats it would prove the whole thing.

What we have already

-Why would he reply to the story if he doesn't owe anything?

Does anyone know of any way to pull up the story so I can see that he actually replied to it?

Is there ANY way possible to get those chats back. At this point I'm willing to go to the police and have them scan my phone to try to get it back. Any suggestions help. End TedTalk.

reddit.com
u/PuckKid1376 — 10 days ago

Apparently Digital Forensics Is Just Staring at Hex Dumps 😂

Apparently staring at a disk image for 3 hours and questioning every life decision is part of becoming a digital forensics analyst. 😂

I’ve been trying to get more serious about DFIR and found this Digital Forensics Playbook while looking for something structured to go through.

Not saying it will magically make me good at forensics… but if it saves me from Googling the same thing 47 times, I’ll take it.

https://resources.codelivly.com/product/digital-forensics-playbook/

Anyone here actually use a book/playbook for learning forensics, or is everyone just learning through pain and incident reports? 😂

u/Potential-Couple-745 — 10 days ago