AI is speeding up digital forensics, but speed without control is how good labs get burned. We dig into a safer way to work: use AI-assisted coding to generate a repeatable process, then test it against a real corpus of known extractions so results stay deterministic, verifiable, and defensible. If you’ve ever felt your LLM results “drift” from run to run, this mindset shift is the difference between a helpful assistant and a hidden liability.
We also get practical with what’s new across the community: a free macOS timestamp utility, Android intrusion logs (and how to extract and parse them when a user has opted in), and a deep look at Apple Unified Logs and log archives as an underrated iOS forensics goldmine. The big takeaway on logs is interpretation: one scary-looking line is not a conclusion. You have to read the surrounding sequence of events to avoid false narratives, and we talk about how newer workflows can process log archives directly from extractions without requiring a Mac.
From there we move into evidence sources that often decide cases: iOS Health database artifacts, LevelDB and IndexedDB for browser forensics, and a standout BitLocker improvement that can auto-unlock secondary encrypted volumes when keys are preserved in a system image. Finally, we walk through reporting at scale with LAVA, the LEAPPs viewer that adds conversation views, analytics, tagging, notes, and LAVA subset exports for massive chats that would otherwise choke HTML reports.
If this helped you rethink your workflow or gave you a new artifact to chase, subscribe, share the episode with your lab, and leave a review so more examiners can find it. What tool or artifact do you want us to test next?
Notes:
Timestamped
https://thebinaryhick.blog/2026/08/16/timestamped/
Brett Shavers Blog Posts
http://linkedin.com/pulse/let-ai-run-your-case-make-you-stupid-brett-shavers-vproc/
Android Logical Extractor
https://github.com/prosch88/ALEX
Tim Korver Blog Posts
https://www.linkedin.com/in/tim-korver/recent-activity/articles/
SANS DFIR Summit & Training
https://www.sans.org/cyber-security-training-events/digital-forensics-summit-2026
MSAB Digital Summit
https://www.msab.com/msab-mobile-forensics-digital-summit-2027/
Cellebrite 101
https://community.cellebrite.com/s/101
HEART Metadata Forensics
https://github.com/MetadataForensics/HEART_by_Metadata_Forensics
Arsenal
https://arsenalrecon.com/products
LEAPPs & LAVA
leapps.org
Subscribe to:
Post Comments (Atom)
-
We come back from a busy conference stretch and go hands-on with new digital forensics tools that speed up real workflows across vehicle, ...
-
We kick off this episode with highlights from the Techno Security Conference, our 80s-themed outfits, packed LEAPP labs, AI panel discussi...
-
A baby camel, a high-speed chase, and a heartfelt tribute set the stage for a season opener that is equal parts human and hard-nosed. We ...
No comments:
Post a Comment