46 episodios
- Send us Fan Mail
AI is speeding up digital forensics, but speed without control is how good labs get burned. We dig into a safer way to work: use AI-assisted coding to generate a repeatable process, then test it against a real corpus of known extractions so results stay deterministic, verifiable, and defensible. If you’ve ever felt your LLM results “drift” from run to run, this mindset shift is the difference between a helpful assistant and a hidden liability.
We also get practical with what’s new across the community: a free macOS timestamp utility, Android intrusion logs (and how to extract and parse them when a user has opted in), and a deep look at Apple Unified Logs and log archives as an underrated iOS forensics goldmine. The big takeaway on logs is interpretation: one scary-looking line is not a conclusion. You have to read the surrounding sequence of events to avoid false narratives, and we talk about how newer workflows can process log archives directly from extractions without requiring a Mac.
From there we move into evidence sources that often decide cases: iOS Health database artifacts, LevelDB and IndexedDB for browser forensics, and a standout BitLocker improvement that can auto-unlock secondary encrypted volumes when keys are preserved in a system image. Finally, we walk through reporting at scale with LAVA, the LEAPPs viewer that adds conversation views, analytics, tagging, notes, and LAVA subset exports for massive chats that would otherwise choke HTML reports.
If this helped you rethink your workflow or gave you a new artifact to chase, subscribe, share the episode with your lab, and leave a review so more examiners can find it. What tool or artifact do you want us to test next?
Notes:
Timestamped - https://thebinaryhick.blog/2026/08/16/timestamped/
Brett Shavers Blog Posts - http://linkedin.com/pulse/let-ai-run-your-case-make-you-stupid-brett-shavers-vproc/
Android Logical Extractor - https://github.com/prosch88/ALEX
Tim Korver Blog Posts - https://www.linkedin.com/in/tim-korver/recent-activity/articles/
SANS DFIR Summit & Training - https://www.sans.org/cyber-security-training-events/digital-forensics-summit-2026
MSAB Digital Summit - https://www.msab.com/msab-mobile-forensics-digital-summit-2027/
Cellebrite 101 - https://community.cellebrite.com/s/101
HEART Metadata Forensics - https://github.com/MetadataForensics/HEART_by_Metadata_Forensics
Arsenal - https://arsenalrecon.com/products
LEAPPs & LAVA - leapps.org - Send us Fan Mail
We come back from a busy conference stretch and go hands-on with new digital forensics tools that speed up real workflows across vehicle, iOS, and Android investigations. We also tour major updates to LEAPPs and LAVA, show how Batch LEAPP changes multi-extraction processing, and end with a hard question about validation that every examiner needs to take seriously.
Show Notes:
North Loop Consulting: Sedgwick and NCL Spectator https://northloopconsulting.com/
Crush Digital Forensic Analysis Workbench: https://github.com/kalink0/crush-forensics
LEAPPS: leapps.org - Send us Fan Mail
AI is becoming more common in digital forensics, but the biggest danger is people trusting it too much. Heather Barnhart discusses a framework that helps examiners assess when AI is appropriate, where it can assist with tasks like triage, and where it should not be used, while keeping trained human experts responsible for decisions.
Notes:
https://www.linkedin.com/posts/heather-barnhart-cellebrite_ai-dfir-digitalforensics-ugcPost-7463670252950847488-b7s-/ - Send us Fan Mail
“The tool said” might be the fastest way to lose a jury. Recorded live at IACIS, we sit down with Stacy Eldridge and Becky Passmore of Parsing The Truth One Bite At A Time, two former FBI senior forensic examiners who build a true crime-ish podcast around one thing most shows ignore: the digital artifacts and the courtroom testimony that prove what happened.
https://parsingthetruth.com/ - Send us Fan Mail
Tool output can look authoritative while still being dangerously easy to misread, and we’ve both seen how fast that goes sideways when a case hits court. Live from the MSAB Digital Summit 2026, we walk through a simple principle that saves careers: an artifact is a clue, not a conclusion. We talk about how “artifact worship” happens, how to build real corroboration, and why multiple records on the same phone are not automatically multiple lines of evidence.
We also get honest about forensic reporting and peer review. Assuming “legal will catch it” is a trap, because attorneys and supervisors may not be able to validate the technical meaning of a timestamp, a parser decision, or an attribution statement. We share practical ways to write clearer digital forensics reports, verify tool parsing, and test your assumptions so you’re not learning hard lessons under oath. If you work mobile device forensics, this section is for you.
From there we shift into training and deep technical skills that are quickly becoming baseline: Android RAM acquisition and analysis, what kinds of artifacts can show up in memory, and why RAM can hold evidence you may never find in a file system extraction. We also unpack protocol buffers (protobuf) and the uncertainty that comes with app data when the .proto schema is missing, plus why that matters when AI and automation start “helping” with interpretation. We wrap with an ALEAPP update, a reminder that a portable tool report isn’t analysis, and a quick look at how standards like Daubert and Frye raise the bar for methodology.
Notes:
Brett Shavers Blogs:
It’s Not Artifact Worship When One Artifact Actually Changes the Case https://www.linkedin.com/pulse/its-artifact-worship-when-one-actually-changes-case-brett-shavers-nwi6c/
I Thought Legal Would Catch It. They didn’t. https://www.brettshavers.com/brett-s-blog/entry/i-thought-legal-would-catch-it-they-didnt
IACIS https://www.iacis.com/events/in-person/2026-orlando-training-conference/
Más podcasts de Tecnología
Podcasts a la moda de Tecnología
Acerca de Digital Forensics Now
A podcast by digital forensics examiners for digital forensics examiners. Hear about the latest news in digital forensics and learn from researcher interviews with field memes sprinkled in.
Sitio web del podcastEscucha Digital Forensics Now, Loop Infinito (by Xataka) y muchos más podcasts de todo el mundo con la aplicación de radio.es

Descarga la app gratuita: radio.es
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app
Descarga la app gratuita: radio.es
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app


Digital Forensics Now
Escanea el código,
Descarga la app,
Escucha.
Descarga la app,
Escucha.




































