Legal Cyber Academy

Digital forensics reference library

The standards, books, journals, tools, datasets and training a digital forensics practitioner — or the lawyer questioning one — actually needs, with the limits of each stated plainly.

This library annotates the 180sources digital forensics actually runs on: standards, books, journals, tools, datasets, conferences and training. Each entry says what the item is, who should read it, and — the part most lists leave out — what it does not cover. Standard numbers, editions and identifiers appear only where they were read off the publisher’s own page, and every entry records the date it was checked.

Start here

A list this long is not a curriculum. These two sequences are, and each one says why every step is where it is.

New to digital forensics

You have no forensics background and want the shape of the whole field before you specialise.

This is the order that gets you from nothing to genuinely useful without wasting money. It goes breadth first, then the rules you will be held to, then one mechanism deep enough to defend, then a tool, then real practice data. Reckon on three to six months of evenings if you are working full time; the first three steps are free and take a fortnight.

9 steps, in order

A lawyer who has to cross-examine an examiner

You are a litigator facing a digital forensics expert and you need to know where the soft ground is.

You are not trying to become an examiner. You are trying to know, precisely, what a competent one should have done, what the record should show, and which of their conclusions the science will not carry. Two focused days gets you through the free material; the paid items matter only if the case turns on method.

9 steps, in order

All reading paths — including moving from IT into DFIR, and preparing for a certification.

The whole library

Grouped by type. The filters narrow what is already on this page — nothing here is loaded on demand, so a print-out, a reader with JavaScript off, and a crawler all get the complete list.

Showing all 180 entries.

Standards and guidance (49)

The spine of the discipline: what a competent examiner is expected to have done, written down by bodies a court will recognise. Read these first, and check for a newer revision before you cite one.

  • Scientific Working Group on Digital Evidence · Version 5.0, published 2026-07-09 · 2026 · SWGDE 17-F-001-5.0

    SWGDE's guidance on analysing historical call detail records and cell site data to reason about where a handset was, and on the limits of that reasoning. The version verified here is 17-F-001-5.0 dated 9 July 2026; it has moved through four earlier versions since 2023, including a retitling from Recommendations to Best Practices.

    Does not cover: It addresses historical records, not live tracking, and not the separate question of reverse location demands — SWGDE handles those in 22-F-004 and 23-F-002. It gives no legal analysis of the process required to obtain the records, and its companion documents on timing advance records and RF propagation surveys cover techniques it does not.

    Working examinerLawyers and courts
  • Forensic Science Regulator (England and Wales) · Version 2, published 5 June 2025; came into force 2 October 2025 · 2025

    The statutory code of practice the Forensic Science Regulator is required to publish under the Forensic Science Regulator Act 2021, setting quality standard requirements for forensic science activities relating to the investigation of crime in England and Wales. Version 2 replaced version 1 and came into force on 2 October 2025.

    Does not cover: It applies only to England and Wales and only to activities designated as forensic science activities under the 2021 Act — it says nothing about civil, regulatory or internal corporate investigations. It sets requirements rather than methods: the technical how-to lives in the Regulator's separate guidance such as FSR-G-218. The earlier digital-specific appendix FSR-C-107 is marked obsolete on gov.uk.

    Working examinerLawyers and courts
  • Ramaswamy Chandramouli, Eric Hibbard · National Institute of Standards and Technology · Revision 2, September 2025 · 2025 · NIST SP 800-88 Rev. 2

    NIST's guidance on clearing, purging and destroying data on storage media, including media-specific techniques and verification. Revision 2 was published in September 2025 and supersedes Revision 1 (2014), which NIST withdrew on 26 September 2025.

    Does not cover: It is a sanitization standard, not a recovery manual: it will not tell you how to carve or reconstruct data from partially wiped media, and it makes no claims about what a given commercial wiping tool actually does. Anyone citing Revision 1 after September 2025 is citing a withdrawn document.

    Working examinerLawyers and courts
  • International Organization for Standardization · Edition 1, published 2025-06 · 2025 · ISO 21043-4:2025

    A 14-page international standard on the interpretation of forensic findings, published in June 2025 as part of the ISO 21043 forensic sciences series. Parts 1 (vocabulary, 2025), 3 (analysis, 2025) and 5 (reporting, 2025) are also published; part 2 is being revised, with ISO/DIS 21043-2 at DIS stage as at September 2026.

    Does not cover: It is a requirements document, not a tutorial: it will not teach you Bayesian reasoning or likelihood ratios, and it contains no digital-forensics worked examples. For those, the ENFSI evaluative reporting guideline is the practical companion.

    Working examinerLawyers and courtsAdvanced
  • International Organization for Standardization · Edition 1, published 2025-06 · 2025 · ISO 21043-5:2025

    A 10-page international standard specifying requirements for forensic reports and for the communication of findings, published June 2025 as part of the ISO 21043 series.

    Does not cover: It does not satisfy any particular court's rules — in England and Wales you still need CrimPR Part 19 and the Forensic Science Regulator's FSR-G-200, and in US federal practice FRCP 26 and FRE 702. It also gives no digital-specific reporting content such as how to present hash verification or extraction limitations.

    Working examinerLawyers and courts
  • Federal Judicial Center / National Academies of Sciences, Engineering, and Medicine · Fourth edition, published December 31, 2025 (the two volumes carry a March 2026 date) · 2025

    The judiciary's own reference work on scientific and technical evidence, produced jointly by the Federal Judicial Center and the National Academies, made up of reference guides written by scientists and judges on individual fields plus chapters on the judge's gatekeeping role. The fourth edition rewrites every guide carried over from 2011 and adds new guides on eyewitness identification, computer science, and artificial intelligence.

    Does not cover: It contains no reference guide on digital forensic examination as a discipline, so there is nothing in it on imaging, hashing, mobile extraction, or tool validation as practised. It is US federal, it states no state's law, and nothing in it binds any court.

    Lawyers and courtsWorking examiner
  • Scientific Working Group on Digital Evidence · Version 2.1, published 2025-08-05 · 2025 · SWGDE 17-F-002-2.1

    SWGDE's guidance on acquiring data from computers and computer storage, including write blocking, live versus dead acquisition, verification and the handling of encrypted and self-encrypting media. The version verified here is 17-F-002-2.1 dated 5 August 2025.

    Does not cover: It is scoped to computers and computer storage: mobile devices are covered by separate SWGDE documents (18-F-003 and 20-F-005), and cloud sources by 23-F-004. It does not evaluate or endorse specific tools, and SWGDE disclaims any warranty as to the guidance.

    Working examiner
  • Scientific Working Group on Digital Evidence · Version 2.0, published 2025-11-20 · 2025 · SWGDE 18-F-002-2.0

    SWGDE's core on-scene collection document, covering preparation, data integrity and security, acquisition approaches, hashing and documentation. The version verified here is 18-F-002-2.0 dated 20 November 2025.

    Does not cover: It is a collection document — it does not cover examination, analysis or interpretation, and it is silent on legal authority for the seizure. SWGDE's own cover page warns there is no warranty as to the work product and that readers must verify on swgde.org that they are using the current version.

    Working examiner
  • Scientific Working Group on Digital Evidence · Version 2.0, published 2025-08-21 · 2025 · SWGDE 18-F-003-2.0

    SWGDE's guidance on the front half of mobile device work: isolating and preserving a seized handset, handling power and network state, and choosing among logical, file system and physical acquisition routes. The version verified here is 18-F-003-2.0 dated 21 August 2025.

    Does not cover: It does not cover analysis or interpretation of extracted data, nor does it address the legal authority for compelling passcodes or biometrics. It cannot keep pace with every handset and OS release, so device-specific limitations still have to be established and documented case by case.

    Working examiner
  • The Sedona Conference · Post-public-comment version, October 2025 · 2025

    A consensus commentary on when mobile device data is within the scope of civil discovery and how to collect and produce it proportionately, covering possession, custody or control over personal devices, targeted versus full extraction, and the form of production for message threads.

    Does not cover: It is not binding and its legal analysis is US civil discovery only, with no coverage of criminal seizure or consent. It is not a technical guide: it does not evaluate extraction tools, address locked or encrypted devices as an engineering problem, or tell you how to validate an extraction. The PDF requires a free Sedona Conference account.

    Lawyers and courtsWorking examiner
  • The Sedona Conference · Sixth edition, December 2025 (fifth edition February 2020, published in The Sedona Conference Journal, Volume 21) · 2025

    A controlled vocabulary for ediscovery and digital information management, defining the terms that appear in ESI protocols, expert reports, and court orders.

    Does not cover: It defines terms; it states no legal standard and resolves no dispute, and its definitions are not authoritative on any technical discipline — a forensic examiner should not treat them as substitutes for the vocabulary of a standards body. The PDF requires a free Sedona Conference account.

    New to the fieldLawyers and courtsWorking examiner
  • Martin Herman, Michaela Iorga, Ahsen Michael Salim, Robert Jackson, Mark Hurst, Ross Leo, Anand Kumar Mishra, Nancy Landreville, Yien Wang · National Institute of Standards and Technology · July 2024 (final; initial public draft February 2023) · 2024 · NIST SP 800-201

    The successor work to NISTIR 8006: a forensic reference architecture that maps the challenges onto the NIST cloud computing reference architecture and identifies where forensic readiness has to be designed in, with mitigation strategies tied to specific architectural elements. It includes a methodology plus a preliminary worked implementation.

    Does not cover: It is architecture, not procedure: there are no step-by-step acquisition instructions, no AWS/Azure/GCP console walkthroughs and no tool guidance, and NIST explicitly expects organisations to adapt it rather than apply it as-is. It also does not address the legal process for compelling provider-held data.

    Advanced
  • Scientific Working Group on Digital Evidence · Version 1.1, published 2024-02-02 · 2024 · SWGDE 23-Q-001-1.1

    SWGDE's guidance for examiners who have to present digital evidence in court or other proceedings, covering preparation, exhibits, scope of testimony and staying within demonstrated competence. The version verified here is 23-Q-001-1.1 dated 2 February 2024.

    Does not cover: It is written for US proceedings and does not address the admissibility tests themselves — no Daubert or Frye analysis, and nothing on English or EU procedure. It is guidance on conduct, not a substitute for witness familiarisation by instructing counsel.

    Working examinerLawyers and courts
  • Scientific Working Group on Digital Evidence · Version 2.1, published 2024-03-07 · 2024 · SWGDE 18-Q-001-2.1

    SWGDE's statement of the minimum a laboratory must do to test a tool before using it in casework, including what to record about the tool, the test data and the outcome. The version verified here is 18-Q-001-2.1 dated 7 March 2024.

    Does not cover: It sets a minimum, not a full validation methodology, and it supplies no test datasets or reference images — you have to source those yourself. It does not certify or approve any tool, and it does not replace an accreditation body's assessment of your methods.

    Working examinerAdvanced
  • United States Courts (rule text as printed by the Committee on the Judiciary, U.S. House of Representatives) · Amended April 24, 2023, effective December 1, 2023; credit line in the official print reads "As amended Apr. 17, 2000, eff. Dec. 1, 2000; Apr. 26, 2011, eff. Dec. 1, 2011; Apr. 24, 2023, eff. Dec. 1, 2023." · 2023

    The federal admissibility rule for expert testimony. The 2023 amendment moved the burden into the rule text — the proponent must demonstrate to the court that it is more likely than not that each of the four requirements is met — and rewrote subsection (d) so that the opinion must reflect a reliable application of the principles and methods to the facts of the case.

    Does not cover: The rule names no methods and endorses no discipline, so it does not tell you whether any particular forensic technique is reliable. It is federal; states that follow older Daubert or Frye formulations were not changed by it.

    Lawyers and courtsWorking examinerAdvanced
  • Eran Salfati, Michael Pease · National Institute of Standards and Technology · NISTIR 8428, 22 June 2022 · 2022 · NISTIR 8428

    An incident-handling framework for operational technology environments, extending conventional DFIR with event-escalation-based response, OT-specific forensic techniques, and the preparation needed to stand up an OT incident response team. Published as a NIST Interagency Report with DOI 10.6028/NIST.IR.8428.

    Does not cover: It is a framework rather than a protocol-level manual: no PLC memory acquisition procedures, no vendor-specific controller instructions, and no treatment of Modbus/DNP3/S7 artefact parsing. It also does not cover safety-instrumented-system engineering or regulatory reporting duties.

    Advanced
  • James R. Lyle, Barbara Guttman, John Butler, Kelly Sauerwein, Christina Reed, Corrine Lloyd · National Institute of Standards and Technology · NISTIR 8354, 21 November 2022 · 2022 · NISTIR 8354

    NIST's scientific foundation review of digital forensics, examining the peer-reviewed literature, academic material and practitioner guidance behind digital investigation techniques. It concludes the techniques rest on established computer science methods and are reliable when properly applied, while naming specific limits.

    Does not cover: It is a literature and foundations review, not a procedure or validation manual: it prescribes no test method, sets no error rates for named tools, and does not tell you how to validate your own lab's workflow. Note the number carefully — this is NISTIR 8354, and it is frequently miscited.

    AdvancedLawyers and courts
  • The Sedona Conference · August 2021; published in The Sedona Conference Journal, Volume 22 (2021) · 2021

    A consensus commentary on auto-deleting and disappearing-message applications: whether adopting them is defensible, what happens to the preservation duty when a trigger occurs, and how Rule 37(e) applies when messages are gone by design.

    Does not cover: It is not binding, and courts have since gone various ways on the same facts, so it cannot be treated as settled law. It offers no technical method for recovering or proving deletion in any specific application. The PDF requires a free Sedona Conference account.

    Lawyers and courtsWorking examiner
  • International Organization for Standardization / International Electrotechnical Commission · Edition 2, published 2020-01; a systematic review closed 2025-06-05 · 2020 · ISO/IEC 27050-3:2020

    A 27-page code of practice setting out requirements and guidance for each ediscovery activity, from initiating a matter and issuing preservation instructions through to producing ESI. It is the operational part of the ISO/IEC 27050 series.

    Does not cover: It is not legal advice and takes no position on privilege, disclosure obligations or sanctions, all of which are jurisdictional. It also predates current generative-AI review workflows. Confirm on iso.org whether the 2025 systematic review has produced a revision before citing it.

    Lawyers and courtsWorking examiner
  • Martin Herman, Michaela Iorga, Ahsen Michael Salim, Robert Jackson, Mark Hurst, Ross Leo, Richard Lee, Nancy Landreville, Anand Kumar Mishra, Yien Wang, Rodrigo Sardinas · National Institute of Standards and Technology · NISTIR 8006, final, August 2020 · 2020 · NISTIR 8006

    A catalogue produced by the NIST Cloud Computing Forensic Science Working Group that aggregates and categorises the forensic challenges of investigating incidents in cloud ecosystems — multi-tenancy, data location, provider dependency, chain of custody across parties, and the rest. The draft circulated from 2014; the final was issued in August 2020.

    Does not cover: It only states challenges; it deliberately offers no solutions, no acquisition procedures and no provider-specific guidance, and it names no APIs or tools. For the architectural response, read NIST SP 800-201 instead.

    Working examinerLawyers and courts
  • The Sedona Conference · Second edition, October 2020; published in The Sedona Conference Journal, Volume 22 (2021). The first edition dates from March 2008 · 2020

    A consensus commentary on getting electronically stored information into evidence — authentication, hearsay, best evidence, and the certification routes — rewritten for the second edition to take account of Rules 902(13) and 902(14).

    Does not cover: It is not binding and no court has adopted it; it is US-focused and does not address criminal admissibility in any depth. It explains the legal framework, not how to acquire or examine the evidence. The PDF requires a free Sedona Conference account.

    Lawyers and courtsWorking examiner
  • United States Courts (rule text as printed by the Committee on the Judiciary, U.S. House of Representatives) · Both subsections added by the amendment of April 27, 2017, effective December 1, 2017; text verified against the official print current to December 1, 2024 · 2017

    Two subsections of Rule 902 that let a party authenticate electronic evidence by written certification instead of live testimony: 902(13) covers a record generated by an electronic process or system that produces an accurate result, and 902(14) covers data copied from an electronic device, storage medium, or file when authenticated by a process of digital identification. Both borrow the certification and pretrial notice machinery of Rule 902(11).

    Does not cover: Self-authentication settles authenticity only; it does not make the evidence relevant, non-hearsay, or admissible, and an opponent can still attack the underlying process. The rules are federal, and state adoption varies.

    Lawyers and courtsWorking examiner
  • International Organization for Standardization / International Electrotechnical Commission · Edition 3, published 2017-11; reviewed and confirmed 2023 · 2017 · ISO/IEC 17025:2017

    The 30-page accreditation standard against which forensic laboratories, including digital forensics units, are assessed for technical competence, impartiality and consistent operation. The third edition (2017) replaced the 2005 edition and was confirmed on systematic review in 2023.

    Does not cover: It is discipline-neutral — there is not a word in it about digital evidence, imaging, hashing or mobile extraction. Accreditation to it says the management system and the declared methods were assessed competent; it makes no claim about any individual case, and scope statements are often narrower than lawyers assume.

    Working examinerLawyers and courts
  • The Sedona Conference · Third edition, October 2017 · 2017

    Fourteen consensus principles on producing electronically stored information in civil litigation, with commentary, revised to reflect the 2015 amendments to the Federal Rules of Civil Procedure. Courts cite it more often than any other non-binding ediscovery text.

    Does not cover: It is consensus guidance, not law, and binds nobody; it addresses civil document production, not criminal discovery or forensic examination technique. The free PDF requires a free Sedona Conference account.

    Lawyers and courtsWorking examiner
  • European Network of Forensic Science Institutes · Version 01, November 2015 · 2015 · ENFSI-BPM-FIT-01

    A 65-page manual from ENFSI's Forensic Information Technology working group covering personnel, equipment, accommodation, peer review, examination protocols, validation and uncertainty of measurement, proficiency testing, handling items, case assessment and prioritisation. It is one of ten ENFSI best practice manuals issued in November 2015 under the EU-funded TEFSBPM project.

    Does not cover: It is version 01 from November 2015 and ENFSI has not published a later version of this manual, so it predates current mobile, cloud and full-disk-encryption realities; ENFSI's own cover material directs readers to check its website for updates. It is a laboratory practice manual, not a technique-by-technique procedure set.

    Working examiner
  • European Network of Forensic Science Institutes · Approved version 3.0; foreword dated 8 March 2015 · 2015

    The output of ENFSI's STEOFRAE project (Strengthening the Evaluation of Forensic Results across Europe): a guideline on evaluating findings against competing propositions and reporting the strength of that evaluation, with an audit template, an implementation roadmap and nine worked case examples.

    Does not cover: The worked examples are drawn mainly from DNA, glass, footwear, speaker recognition and gunshot residue; there is no computer or mobile forensics example, so the transfer to digital evidence is left to the reader. It is a guideline for reporting scientists, not a court rule, and it is dated 2015.

    Working examinerLawyers and courtsAdvanced
  • United States Courts · Replaced in full by the amendment effective December 1, 2015 · 2015

    The federal sanctions rule for lost ESI. It applies only where information that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it and it cannot be restored or replaced through additional discovery, and it reserves the severe measures — adverse inference, dismissal, default — for a finding that the party acted with intent to deprive another party of the information's use.

    Does not cover: It governs civil cases in federal court only, says nothing about criminal matters or state-court practice, and does not define what "reasonable steps" are in any concrete system. Nothing in it addresses the duty to preserve itself, which comes from case law.

    Lawyers and courtsWorking examiner
  • International Organization for Standardization / International Electrotechnical Commission · Edition 1, published 2015-06; reviewed and confirmed 2021; a further systematic review closed 2026-09-03 · 2015 · ISO/IEC 27041:2015

    An 18-page standard on showing that an investigative method is fit for purpose: capturing functional and non-functional requirements, describing the method, and producing evidence that the implementation satisfies those requirements. It explicitly addresses how vendor and third-party testing can be folded into your own assurance argument.

    Does not cover: It is guidance on the shape of a validation argument, not a validation protocol — there are no test datasets, no pass/fail criteria and no worked examples. At 18 pages it will not substitute for a discipline-specific validation methodology.

    Working examinerAdvanced
  • International Organization for Standardization / International Electrotechnical Commission · Edition 1, published 2015-06; reviewed and confirmed 2021; a further systematic review closed 2026-09-03 · 2015 · ISO/IEC 27042:2015

    A 14-page standard that picks up where ISO/IEC 27037 stops, covering the analysis and interpretation of potential digital evidence and the competence and proportionality considerations that go with them.

    Does not cover: It is very short and stays at the level of principles: no file system, mobile or cloud specifics, no statistical framework for evaluating findings, and no report template. For evaluative interpretation with likelihood ratios, ISO 21043-4 and the ENFSI evaluative reporting guideline are the substantive documents.

    Working examinerLawyers and courts
  • International Organization for Standardization / International Electrotechnical Commission · Edition 1, published 2015-03; reviewed and confirmed 2020; a further systematic review closed 2025-12-03 · 2015 · ISO/IEC 27043:2015

    A 30-page standard setting out an idealised, process-class model for investigating incidents involving digital evidence, from readiness through initialisation, acquisition and investigation to reporting. It is the umbrella document that 27037, 27041 and 27042 sit under.

    Does not cover: It is deliberately abstract: no technical procedures, no tooling, and no legal or jurisdictional content. It also does not cover incident management itself — that is the ISO/IEC 27035 series (parts 1:2023 and 2:2023, part 3:2020 and part 4:2024, all published as at September 2026).

    Working examiner
  • Richard Ayers, Sam Brothers, Wayne Jansen · National Institute of Standards and Technology · Revision 1, May 2014 · 2014 · NIST SP 800-101 Rev. 1

    NIST's guidance on seizing, preserving, acquiring and examining mobile phones and their associated media, including the acquisition-level model (manual, logical, physical, chip-off, JTAG) that practitioners still use as shared vocabulary. It supersedes the 2007 first edition of SP 800-101.

    Does not cover: It is still the current NIST revision but is now over a decade old: it does not address Android file-based encryption, iOS Secure Enclave and Data Protection classes, modern checkm8/bootloader exploits, cloud-side account acquisition or the current commercial extraction tools. Do not cite its device coverage or tool capability claims as present-day fact.

    Working examiner
  • International Organization for Standardization / International Electrotechnical Commission · Edition 1, published 2012-10; reviewed and confirmed 2018; a further systematic review closed 2023-12-03 · 2012 · ISO/IEC 27037:2012

    A 38-page international standard covering the first four handling activities for potential digital evidence: identification, collection, acquisition and preservation. It names the device classes in scope, including computer storage media, mobile phones, memory cards, navigation systems, still and video cameras including CCTV, and TCP/IP networks.

    Does not cover: It stops at preservation — analysis, interpretation and reporting are out of scope and are handled by ISO/IEC 27042. It also sets no competence or accreditation requirements and does not tell you which tool to use. ISO's page shows it under systematic review, so check iso.org for a newer edition before citing it as current.

    Working examinerLawyers and courts
  • National Institute of Justice, U.S. Department of Justice · November 2009 · 2009 · NCJ 227050

    A pocket flipbook companion to NIJ's first responder guide, condensing device types, scene securing, documentation, collection and packaging into an on-scene quick reference, with digital evidence considerations by crime category.

    Does not cover: By design it is abbreviated, with no reasoning, no examination guidance and no legal analysis; it cannot substitute for the full second-edition guide. It dates from 2009 and reflects the device landscape of that time.

    New to the field
  • Computer Crime and Intellectual Property Section, Criminal Division, U.S. Department of Justice · 2009 manual, still the version published on the CCIPS documents page · 2009

    The Justice Department's own manual on the Fourth Amendment and statutory rules governing searches of computers and the acquisition of electronic evidence, including warrant drafting, plain view, consent, and the Stored Communications Act and Pen/Trap provisions.

    Does not cover: It is seventeen years old and predates Riley v. California, Carpenter v. United States, and the CLOUD Act, so substantial parts of its Fourth Amendment and stored-data analysis are superseded — nothing in it should be cited without checking current law. It is federal criminal procedure only, and it is not a forensic examination manual.

    Lawyers and courtsWorking examiner
  • National Institute of Justice, U.S. Department of Justice · Second edition, April 2008 · 2008 · NCJ 219941

    NIJ's first-responder guide covering electronic device types and their potential evidence, on-scene tools and equipment, securing and documenting the scene, collection, and packaging, transport and storage of digital evidence, plus a chapter of considerations organised by crime category.

    Does not cover: It stops at the lab door: no examination, analysis or interpretation, and no legal authority analysis for the search or seizure itself. Being a 2008 second edition, it predates smartphone-dominant scenes, cloud accounts, IoT devices and live-encryption decisions, so its device inventory is dated.

    New to the field
  • The Sedona Conference · July 2008; reprinted in The Sedona Conference Journal, Volume 10 Supplement · 2008

    A short statement, endorsed by a large number of federal and state judges, that discovery is a non-adversarial exchange and that counsel have an obligation to cooperate on process even while contesting the merits. It remains a stable, frequently cited citation in discovery opinions.

    Does not cover: It is aspirational: it creates no duty, provides no remedy, and does not tell you what cooperation requires in any concrete dispute. It is a US document with no application outside that system.

    Lawyers and courts
  • National Institute of Justice, U.S. Department of Justice · January 2007 · 2007 · NCJ 211314

    An 81-page NIJ guide on the legal handling of digital evidence: search and seizure issues including the Fourth Amendment, the Electronic Communications Privacy Act and the Privacy Protection Act; maintaining evidence integrity; pretrial preparation including authentication and hearsay; courtroom presentation and expert testimony; and a chapter on child pornography cases. Appendices include consent forms and evidence return stipulations.

    Does not cover: It is US criminal practice and is written from the prosecution side; it gives no civil, eDiscovery or non-US guidance and no defence perspective. Written in 2007, it predates two decades of case law on cell-site data, device searches at the border, warrant particularity for digital devices and provider-held cloud data — treat every legal proposition in it as needing a current check.

    Lawyers and courts
  • Karen Kent, Suzanne Chevalier, Tim Grance, Hung Dang · National Institute of Standards and Technology · August 2006 (final, published 1 September 2006) · 2006 · NIST SP 800-86

    A NIST Special Publication that sets out a four-phase forensic process (collection, examination, analysis, reporting) and applies it to four data sources: files, operating systems, network traffic, and applications. It is written for organisations building forensic capability inside an incident response function rather than for law enforcement labs.

    Does not cover: It has not been revised since 2006, so it predates full-disk encryption as a default, cloud-hosted workloads, smartphones, SSD trim behaviour and modern Windows artefacts; the tool and OS specifics are obsolete even though the process model is not. It gives no legal analysis of admissibility and no US or foreign procedural law.

    New to the fieldWorking examiner
  • National Institute of Justice, U.S. Department of Justice · April 2004 · 2004 · NCJ 199408

    An NIJ special report, produced by the Technical Working Group for the Examination of Digital Evidence, covering policy and procedure, evidence assessment, acquisition, examination, documentation and reporting. It is the second guide in NIJ's digital evidence series, after the first responder guide.

    Does not cover: NIJ states the recommendations are not legal mandates, are not the only correct courses of action, and may not be feasible in all circumstances. Technically it is a 2004 document: no mobile devices, no cloud, no encryption-at-rest defaults, and none of the current tooling.

    New to the fieldWorking examiner
  • Supreme Court of the United States · Decided March 23, 1999 · 1999 · 526 U.S. 137

    The decision extending the Daubert gatekeeping obligation to all expert testimony under Rule 702, including technical and other specialized knowledge, and holding that the Daubert considerations are flexible rather than mandatory, with the trial court's choices reviewed for abuse of discretion.

    Does not cover: It says nothing about what makes any specific technical method reliable and gives no guidance on computer or mobile evidence. Abuse-of-discretion review means it produces few reversals, so it offers little predictive help on close calls.

    Lawyers and courtsWorking examiner
  • Supreme Court of the United States · Decided June 28, 1993 · 1993 · 509 U.S. 579

    The decision holding that the Federal Rules of Evidence, not Frye's general-acceptance test, govern expert scientific testimony, and that the trial judge acts as a gatekeeper for reliability and fit. It offers a non-exclusive list of considerations: testability, peer review and publication, known or potential error rate, standards controlling the technique's operation, and general acceptance.

    Does not cover: It predates every modern digital forensic method and mentions none of them, and its factors are not a test to be applied mechanically. It binds federal courts; a number of states still apply Frye or their own variants.

    Lawyers and courtsWorking examiner
  • United States Courts (rule text as printed by the Committee on the Judiciary, U.S. House of Representatives) · Enacted January 2, 1975; restyled by the amendment effective December 1, 2011; text verified against the official print current to December 1, 2024 · 1975

    An illustration of sufficient authentication: "Evidence describing a process or system and showing that it produces an accurate result." It is the route by which the output of software, an acquisition tool, or an automated system is authenticated through testimony about the tool rather than about the document.

    Does not cover: It sets no threshold for how much validation is enough and names no test, tool, or error-rate standard; those come from case law and Rule 702. It is federal, and it says nothing about weight once the evidence is admitted.

    Lawyers and courtsWorking examiner
  • American Bar Association · Current text of Comment [8] as published by the ABA and verified on 2026-09-12

    The comment on maintaining competence, which provides that to maintain the requisite knowledge and skill a lawyer should keep abreast of changes in the law and its practice, "including the benefits and risks associated with relevant technology," engage in continuing study and education, and comply with applicable CLE requirements.

    Does not cover: It is a comment to a model rule: it is not law anywhere until a jurisdiction adopts it, adoption and wording vary by state, and it sets no standard of what technological competence actually requires. It creates no cause of action and says nothing about a non-lawyer expert's obligations.

    Lawyers and courtsWorking examiner
  • Forensic Science Regulator (England and Wales) · Issue 4; gov.uk page last updated 22 July 2024 · FSR-G-200

    Guidance on the content of reports issued by expert witnesses in the criminal justice system of England and Wales, setting out the legal requirements for expert reports, requirements imposed by certain prosecuting authorities, and advice on applying them.

    Does not cover: It is jurisdiction-specific: it does not address US federal reporting under FRCP 26 or FRE 702, nor civil practice in England and Wales. It is also discipline-neutral, so it gives no digital-specific direction on how to present hashes, extraction scope or tool limitations.

    Working examinerLawyers and courts
  • INTERPOL

    INTERPOL's guidance on establishing and managing a digital forensics laboratory, together with technical guidelines for managing and processing electronic evidence. INTERPOL lists it on its digital forensics page alongside two related publications, Framework for Responding to a Drone Incident and Guidelines for Digital Forensics First Responders.

    Does not cover: INTERPOL's own topic page names the publication but states no version, edition or publication date and provides no direct download link, so the year could not be verified from an official source and is omitted here. It is guidance for law enforcement laboratories, not an accreditation standard, and carries no legal force in any jurisdiction.

    Working examiner
  • Forensic Science Regulator (England and Wales) · Issue 2; gov.uk page last updated 22 July 2024 · FSR-G-218

    The Regulator's guidance on applying the validation requirements of the code of practice to digital forensic methods: demonstrating that a method is fit for its specific intended purpose and that its limitations are understood and stated.

    Does not cover: It is guidance rather than a requirement in itself; the binding requirements sit in the statutory code of practice. It does not validate any tool for you, supplies no reference datasets, and its general validation companion FSR-G-201 is non-digital. Note that FSR-G-201 is 'Forensic science providers: validation', not mobile phone guidance.

    Working examinerAdvanced
  • Organization of Scientific Area Committees for Forensic Science, National Institute of Standards and Technology

    A NIST-administered repository of forensic science standards that have passed technical and quality review by practitioners, researchers, statisticians and legal experts, and been approved by a two-thirds vote of the relevant OSAC subcommittee and the Forensic Science Standards Board. It lists both standards published by external standards development organisations and OSAC Proposed Standards awaiting SDO publication, spanning 24 disciplines.

    Does not cover: Registry listing is not accreditation, certification or a legal requirement, and a method's absence is not evidence it is unsound. Access is mixed rather than uniformly free: OSAC's own proposed standards are free, ASTM documents need a free account, and other SDO-published standards follow that publisher's terms.

    Working examinerLawyers and courts
  • Scientific Working Group on Digital Evidence

    SWGDE's own listing of its published best practices, guidelines, technical notes, positions and considerations for digital and multimedia forensics, together with archived prior versions. As at September 2026 the library holds well over a hundred numbered documents across forensics (F), video (V), audio (A), imaging (I), photography (P), quality (Q) and multi-discipline (M) series.

    Does not cover: SWGDE states that its documents carry no warranty, that they may be revised, deprecated or sunsetted at any time, and that any quotation must include the version number. They are consensus best practices, not accreditation requirements or legal standards, and coverage is uneven — some topics have detailed documents, others none.

    Working examinerLawyers and courts
  • Association of Chief Police Officers · March 2012 · 2012

    The UK guide that states the four ACPO principles for handling digital evidence — do not change the original data, record everything done, have a competent person do any live examination, and place responsibility for compliance on the officer in charge. Its own front matter records that ACPO agreed the revised guide for adoption by police forces in England, Wales and Northern Ireland.

    Does not cover: ACPO was dissolved in 2015 and no longer maintains this guide; there is no official ACPO URL left, so the copy linked here is third-party hosted, and the current UK authority is the Forensic Science Regulator's statutory Code plus College of Policing guidance. It is England, Wales and Northern Ireland only, it predates cloud and modern mobile acquisition entirely, and the principles are a framework, not a method you can validate against.

    Working examinerLawyers and courtsNew to the field

Books (27)

Long-form texts. A few are twenty years old and still the only complete account of their subject; others have aged into museum pieces. Each entry says which.

  • Michael R. Arkfeld · LexisNexis · Fourth edition, with the April 2026 update; supplied with four cross-referenced Best Practices Guides · 2026 · ISBN 9781632840394 (print); ISBN 9781632840400 (ePub)

    A roughly 1,500-page updated treatise covering discovery and admission of electronic evidence against federal and state rules and case law, in eight chapters, with companion Best Practices Guides including an information technology primer for lawyers.

    Does not cover: It is a legal treatise: it does not teach forensic examination, tool validation, or artefact interpretation, and its technology explanations are pitched at lawyers. It is expensive, subscription-priced, and US-only.

    Lawyers and courtsWorking examiner
  • Kara Nance, Chris Eagle · No Starch Press · Second edition · 2026 · ISBN 978-1-7185-0468-4

    The reference manual for Ghidra: core reverse-engineering technique, Ghidra's data displays, the decompiler, collaborative server-based analysis, customisation and new data types, headless operation, and scripting — with Python 3 support through PyGhidra new to this edition.

    Does not cover: A tool manual, not a malware or exploitation course — it teaches Ghidra, not what to look for. Published in March 2026, so there is no accumulated community errata yet, and like any tool-specific book it will date on the project's release cadence.

    Working examinerAdvanced
  • Ganesh Ramakrishnan, Mansoor Haqanee · Packt Publishing · First edition · 2024 · ISBN 978-1-80056-441-1

    Investigation in cloud environments using native tooling and logs alongside conventional forensic technique: AWS, Azure and Google Cloud, then Microsoft 365, Google Workspace and containerised environments including Kubernetes, with attention to which logs must be enabled before an incident to be available after one.

    Does not cover: Cloud provider consoles, log schemas and export mechanisms change on a quarterly cadence, so screenshots and exact log field names will drift quickly; verify against current provider documentation. Nothing on the legal mechanics of compelling provider data across jurisdictions, which is usually the binding constraint rather than the technique.

    Working examiner
  • Amelia Phillips, Bill Nelson, Christopher Steuart · Course Technology (Cengage) · 2024 · ISBN 978-0-357-67288-4

    The long-running course textbook for digital forensics programmes: lab setup and policy, acquisition, operating-system and email and mobile artifacts, report writing and expert-witness basics, with end-of-chapter exercises. Written to be taught from, not read at the bench.

    Does not cover: Textbook breadth means textbook depth — it will not get you through a hard NTFS, memory or mobile problem, and its tool walkthroughs are tied to specific vendor product versions that change faster than the book. Cengage's own product page was not reachable for verification, so confirm the edition statement and check for a newer edition before assigning it.

    New to the fieldWorking examiner
  • Gerard Johansen · Packt Publishing · Third edition · 2022 · ISBN 978-1-80323-867-8

    Forensics placed inside the incident response lifecycle: building a response capability, response frameworks, evidence acquisition, volatile memory, disk and network evidence, threat intelligence, malware analysis, threat hunting, and reporting — with this edition reframed around ransomware.

    Does not cover: Breadth over depth — each technical area gets a working introduction, not the structural detail that Carrier, Ligh or Nikkel provide, so it will not carry you through a contested technical dispute. Light on cloud-native and identity evidence, which is exactly what a fourth edition is meant to address; that edition is listed by Packt as a pre-order and is not published, so the third edition remains current.

    Working examiner
  • Christian Hummert, Dirk Pawlaszczyk (editors) · Springer · First edition · 2022 · ISBN 978-3-030-98466-3

    An open-access reference to the structures underneath mobile evidence, in two parts: mobile file systems (APFS, Ext4, F2FS, QNX6) and the serialisation formats that carry app data (SQLite, property lists, Java serialization, Realm, protocol buffers), each chapter written by a specialist and each noting the forensic value of the structure.

    Does not cover: A format and structure reference, not casework: no acquisition, no device-by-device methodology, no tool workflow, and nothing on Windows. The named decoding tools are 2022-vintage even though the structures are not.

    Advanced
  • Patrick Wardle · No Starch Press · 2022 · ISBN 978-1-7185-0194-2

    Volume I of a series on macOS malware: infection and delivery methods, the persistence mechanisms available on macOS, and static and dynamic analysis of Mach-O binaries with the tooling that actually works on a Mac.

    Does not cover: Malware analysis, not general macOS forensics — it does not cover APFS structures, unified logging as a timeline source, FileVault handling, or mobile. macOS security controls move every annual release, so specific TCC, notarisation and SIP behaviour needs checking against the version in front of you.

    Advanced
  • Bruce Nikkel · No Starch Press · 2021 · ISBN 978-1-7185-0196-6

    Postmortem analysis of Linux systems from the operating system's own structures outward: partition tables and LVM, Linux file systems, directory layout, the systemd journal and other logs, boot reconstruction, installed packages, network configuration, time and locale, login sessions, desktop artifacts, and traces of attached peripherals.

    Does not cover: Postmortem only — acquisition is left to the author's other book. Light on containers and immutable or atomic distributions, and on Btrfs-heavy deployments, all of which have grown since 2021. No Android, despite the shared kernel.

    Working examinerAdvanced
  • Rohit Tamma, Oleg Skulkin, Heather Mahalik, Satish Bommisetty · Packt Publishing · Fourth edition · 2020 · ISBN 978-1-83864-752-0

    A device-by-device walkthrough of mobile acquisition and analysis: iOS and Android internals and file systems, logical and physical extraction, app and SQLite artifacts, cloud extraction, mobile malware and reporting.

    Does not cover: The publisher scopes it to iOS 11-13 and Android 8-10 and it still devotes space to Windows 10 Mobile, a dead platform. It therefore predates the current checkm8 and full-file-system landscape, mature Android Scoped Storage, and today's Cellebrite and GrayKey realities. Note also that Packt's storefront lists only three authors; the title page carries four, including Oleg Skulkin.

    Working examiner
  • Harlan Carvey · Academic Press (Elsevier) · First edition · 2018 · ISBN 978-0-12-811415-5

    Case-driven walkthroughs of Windows examinations where the narration is the analyst's thought process: what question is being asked, which artifact is chosen next, and why a hypothesis was dropped. Deliberately excludes the artifact reference material from the author's other books.

    Does not cover: Not an artifact reference and not a tool manual — it will not tell you where an artifact lives. Images and scenarios are Windows 7/10-era, so the specific parsers shown are dated even though the reasoning transfers.

    New to the fieldWorking examiner
  • Dennis Andriesse · No Starch Press · First edition · 2018 · ISBN 978-1-59327-912-7

    Binary analysis from the format upward on Linux: ELF and PE structure, writing a loader with libbfd, how disassembly actually works and where it goes wrong, ELF code injection, then binary instrumentation with Pin, dynamic taint analysis with libdft, and symbolic execution with Triton.

    Does not cover: Linux, x86-64 and ELF first by design; Windows PE gets one short chapter. The hands-on half depends on a supplied VM and specific 2018 versions of Pin, libdft and Triton, so exercises may need porting. No ARM64, no Ghidra, no fuzzing.

    Advanced
  • Chris Sanders · No Starch Press · Third edition · 2017 · ISBN 978-1-59327-802-1

    How to read a packet capture with Wireshark: capture placement and filtering, the protocols you will actually meet, and worked scenarios that move from a symptom to a conclusion about what the network did.

    Does not cover: A Wireshark and troubleshooting book, not a forensics book: nothing on capture authentication, chain of custody for network evidence, or presenting packet evidence to a court. Written to Wireshark 2.x, so the interface instructions no longer match the current release, and its examples predate the near-total TLS encryption, QUIC and encrypted DNS you will meet in a live capture.

    New to the fieldWorking examiner
  • Pavel Yosifovich, Mark E. Russinovich, Alex Ionescu, David A. Solomon · Microsoft Press (Pearson) · Seventh edition · 2017 · ISBN 978-0-7356-8418-8

    The reference documentation of how Windows actually works: the object manager, processes and threads, virtual memory, handles, tokens and the security model, described at the level of the kernel structures themselves.

    Does not cover: No forensics, no acquisition, no tooling guidance and no case material — it describes the system, not how to examine it. Written against Windows 10 of 2017, so Windows 11-era changes and the later virtualisation-based security features are not here. Check for a newer edition before buying.

    Advanced
  • Brett Shavers, John Bair · Syngress (Elsevier) · First edition · 2016 · ISBN 978-0-12-803340-1

    A survey of covert communication methods an investigator will run into — Tor and TAILS, steganography, encrypted messaging, anti-forensic tooling — and what each one leaves behind on a device.

    Does not cover: The specific tool and protocol detail has moved on fastest of anything in this book: the Tor Browser, TAILS and mobile messaging apps described are several major versions out of date, and it predates the shift to default end-to-end encryption and ephemeral messaging in mainstream apps.

    Working examiner
  • Jaron Bradley · Syngress (Elsevier) · First edition · 2016 · ISBN 978-0-12-804456-8

    Live response and postmortem analysis on macOS using bash and Python tooling the reader writes: startup and persistence mechanisms, scheduling, browser history, memory analysis, credential extraction, exfiltration detection and timelining.

    Does not cover: HFS+-centric and published a year before APFS shipped. It predates System Integrity Protection hardening, TCC, notarisation, Apple Silicon and the Endpoint Security Framework, so the artifact paths and file system chapters are unreliable on any current Mac.

    Working examinerAdvanced
  • Bruce Nikkel · No Starch Press · 2016 · ISBN 978-1-59327-793-2

    The acquisition half of the job done properly with Linux command-line tools: write protection, image formats, attaching subject media, image management and transfer, integrity by cryptographic and piecewise hashing, PKI signatures and RFC 3161 timestamping, drive security (ATA passwords, Opal self-encrypting drives, BitLocker, FileVault), and difficult cases such as RAID, VM images and damaged media.

    Does not cover: The interface and drive coverage was current in 2016 and now predates NVMe-only laptops, soldered storage and hardware-bound encryption where physical imaging is simply not available. Nothing on cloud or mobile acquisition, and nothing on the legal process for obtaining the media in the first place.

    Working examiner
  • Harlan Carvey · Syngress (Elsevier) · Second edition · 2016 · ISBN 978-0-12-803291-6

    The standing treatment of the Windows registry as evidence: hive file structure, the tools and process for parsing it, then separate analysis passes over the system hives and the user hives, with case studies and RegRipper.

    Does not cover: Targets the Windows 7/8.x era; nothing on later Windows 10 build or Windows 11 registry changes, nor on the modern Amcache/BAM/DAM-era interpretation debates. The companion-site tooling is superseded — pull current RegRipper plugin sets from the project repository rather than the book.

    Working examinerAdvanced
  • Jason T. Luttgens, Matthew Pepe, Kevin Mandia (with Ryan Kazanciyan) · McGraw-Hill Education · Third edition · 2014 · ISBN 978-0-07-179868-6

    The incident response process as a discipline: preparation, detection and initial response, live collection from Windows and Unix, forensic duplication, network evidence, evidence handling, then analysis of hosts, traffic, attacker tools and routers, and report writing.

    Does not cover: Published in 2014 and pre-cloud in its assumptions: nothing on SaaS and IaaS log sources, identity-provider evidence, EDR-centric collection, containers, or ransomware as the dominant incident type. Windows and Unix host focus. No fourth edition exists and McGraw Hill no longer carries a live product page for it, so the tooling must be replaced wholesale even where the method holds; this entry is verified against the Library of Congress record.

    Working examiner
  • Michael Hale Ligh, Andrew Case, Jamie Levy, AAron Walters · Wiley · First edition · 2014 · ISBN 978-1-118-82509-9

    Memory acquisition and analysis across Windows, Linux and macOS, written by the people who built Volatility: process and kernel structures, code injection, rootkit detection, registry and event logs recovered from RAM, the GUI subsystem, network state, and case studies.

    Does not cover: Written against Volatility 2.x and Python 2 for Windows 7/8-era kernels, so the commands as printed largely do not run — Volatility 3 replaced the plugin API and syntax. No coverage of modern kernel mitigations, virtualisation-based security, hypervisor-assisted acquisition, or cloud instance memory capture.

    AdvancedWorking examiner
  • Harlan Carvey · Syngress (Elsevier) · Fourth edition · 2014 · ISBN 978-0-12-417157-2

    An artifact-by-artifact working guide to Windows examination: Volume Shadow Copies, file metadata, registry analysis, malware detection on a dead box, timeline construction and artifact correlation. Written as a bench manual rather than a textbook.

    Does not cover: Explicitly targets Windows 8 and is positioned by the author as a complement to the second edition (XP) and third (Windows 7) rather than a replacement, so it does not carry that earlier material forward. Nothing on Windows 10 or 11 artifacts, SRUM, ETW, OneDrive and cloud-sync artifacts, or BitLocker-by-default. The scripts and tool versions are 2014-era.

    Working examiner
  • Brett Shavers · Syngress (Elsevier) · First edition · 2013 · ISBN 978-1-59749-985-9

    A book about the attribution gap: how you get from "this account or this machine did it" to "this person did it", using physical investigation, surveillance, interviews and case timelines alongside the forensic artifacts.

    Does not cover: Not a technical examination manual — it assumes someone else is doing the artifact work. Written before shared-device and cloud-account realities became the norm, so it says little about multi-user cloud sessions, mobile-device co-location data, or the modern volume of automated account activity.

    Working examinerLawyers and courts
  • Richard Bejtlich · No Starch Press · 2013 · ISBN 978-1-59327-509-9

    How to build and run network security monitoring: where to place sensors, what to collect (full packet capture, session data, alert data), and how to work a case from an alert through the collected evidence to a conclusion about scope.

    Does not cover: Written in 2013 against Security Onion of that era and a network model where most traffic was inspectable. It predates ubiquitous TLS, encrypted SNI, QUIC, cloud-native east-west traffic and the shift of visibility from the wire to identity and endpoint telemetry. The reasoning about collection tiers survives; the assumption that you can read the payload does not.

    Working examiner
  • Michael Sikorski, Andrew Honig · No Starch Press · First edition · 2012 · ISBN 978-1-59327-290-6

    A course in Windows malware analysis built around sixty-odd labs with real samples: safe lab construction, static and dynamic analysis, x86 disassembly, debugging, packing and obfuscation, anti-disassembly and anti-VM tricks, and shellcode.

    Does not cover: Fourteen years old and built on IDA Pro and OllyDbg against 32-bit Windows XP-era samples. Nothing on Ghidra or x64dbg, nothing on .NET, PowerShell and script loaders, living-off-the-land technique, packed Go or Rust binaries, or EDR telemetry. The fundamentals chapters age well; treat the tool walkthroughs as historical.

    Working examinerAdvanced
  • Eoghan Casey · Academic Press (Elsevier) · Third edition · 2011 · ISBN 978-0-12-374268-1

    A single-author treatment of digital evidence that puts investigative reasoning and admissibility ahead of tooling, then works through Windows, Unix, Macintosh, mobile and network evidence sources. Roughly half the book is about how to reason from evidence to a defensible conclusion and how that conclusion survives a courtroom.

    Does not cover: The technical chapters are 2011-vintage: nothing on cloud accounts as a primary evidence source, modern smartphone full-disk encryption, APFS, Windows 10/11 artifacts, or SSD/TRIM recovery limits. The US and European legal discussion predates more than a decade of Fourth Amendment and data-protection development, so the law here must be re-checked, not cited.

    Working examinerLawyers and courts
  • Brian Carrier · Addison-Wesley Professional · First edition · 2005 · ISBN 978-0-321-26817-4

    A byte-level reference to volume and file system structures: DOS/MBR, GPT, Apple, BSD and Solaris partitioning, then the on-disk layout and recovery behaviour of FAT, NTFS, Ext2/Ext3 and UFS. Each file system gets both a conceptual model and the actual data structure field listings.

    Does not cover: Written against XP/2000-era NTFS and pre-ext4 Linux. The on-disk structures it documents have barely changed and still hold, but there is nothing here on ext4, exFAT, APFS, ReFS, SSD wear-levelling and TRIM, or full-disk encryption. The Sleuth Kit appendix describes a 2005 command-line era that today's Autopsy does not resemble. Print is out of print; the e-book is still sold.

    AdvancedWorking examiner
  • Dan Farmer, Wietse Venema · Addison-Wesley Professional · First edition · 2004 · ISBN 978-0-201-63497-6

    A short, dense book about the physics of digital evidence: the order of volatility, how long deleted data actually persists, what abstraction layers hide, and how to reason about an adversary who has had root. Examples come from Solaris, FreeBSD and Linux.

    Does not cover: Twenty years old and Unix-centric: no Windows, no mobile, no cloud, no modern encryption, and the persistence measurements were taken on spinning disks with no TRIM. The reasoning is durable; every empirical number in it should be treated as historical.

    Advanced
  • Fred Chris Smith, Rebecca Gurley Bace · Addison-Wesley Professional · First edition · 2002 · ISBN 978-0-201-75279-3

    A book for technologists who are about to testify: how the gatekeeping standards work, how to establish and defend qualifications, how to present technical material to a lay fact-finder, and where technical witnesses habitually lose credibility.

    Does not cover: The legal framing is early post-Daubert and pre-dates the 2023 amendment to Federal Rule of Evidence 702 and two decades of digital-evidence case law, so treat every legal proposition as needing current authority. Its case studies (the Microsoft antitrust deposition, the Mitnick investigation) are historical, and there is no digital forensics technique content at all.

    Lawyers and courtsWorking examiner

Journals (10)

Where the research is published. Useful when you need a defensible answer about error, uncertainty or a method's limits, rather than a procedure.

  • Springer · 2025 · ISBN 978-3-031-71024-7 (Advances in Digital Forensics XX)

    The post-conference edited volumes of the annual IFIP Working Group 11.9 International Conference on Digital Forensics, published by Springer as the numbered Advances in Digital Forensics series. Volume XX covers the twentieth conference and appeared in 2025; the working group's site lists the twenty-third conference for January 2027, so the series is live.

    Does not cover: Papers are not freely hosted anywhere official — these are Springer books, so expect to buy the volume or the chapter, or use a library. Because volumes appear after the conference, the content is typically a year or more behind the DFRWS stream.

    Advanced
  • Elsevier · 2020 · ISSN 2666-2817

    The main peer-reviewed research journal for digital forensics. It was called Digital Investigation from 2004 through 2019 and was folded into Elsevier's Forensic Science International family in 2020, when the new title and ISSN 2666-2817 took over; the DFRWS USA, EU and APAC conferences publish their accepted research papers here as special issues.

    Does not cover: It is a research venue, not a how-to: there is no step-by-step tool procedure, and papers assume you already know the underlying artefacts and terminology. Access is the real limit — Elsevier gates articles behind a subscription, with single-article purchase typically around $30-40, so plan on library access or the free DFRWS copies.

    AdvancedWorking examiner
  • Elsevier · 2019 · ISSN 2589-871X

    A fully open-access journal in Elsevier's Forensic Science International family, indexed in DOAJ under Creative Commons licences and funded by article processing charges rather than subscriptions. It deliberately takes the cross-cutting material — policy, quality management, education, interpretation and reporting — that the discipline-specific FSI titles do not.

    Does not cover: It is not a digital forensics journal and rarely carries device- or artefact-level technical research; for that you need FSI: Digital Investigation. It also does not publish standards themselves, only commentary and research about them.

    Working examinerLawyers and courtsAdvanced
  • Journal of Law & Cyber Warfare · 2012 · ISSN 2578-6229 (online), 2578-6245 (print)

    A peer-reviewed law journal founded in 2012 covering the law of cyber conflict — attribution and evidence, sovereignty, national security policy, autonomous and AI-enabled systems, and critical infrastructure defence. It is indexed in HeinOnline's Law Journal Library and in JSTOR, and is actively publishing through 2026.

    Does not cover: It publishes no technical forensics research — no acquisition, examination or tool work at all. Access is mixed: abstracts and citation metadata are free on the site and a subset of pieces appears in full, but the complete text of bound-issue articles comes through HeinOnline or JSTOR.

    Lawyers and courtsAdvanced
  • Digital Forensic Research Workshop (DFRWS) · 2001

    The peer-reviewed paper track of the DFRWS conferences, which have run since the first workshop in 2001 and now cover three regions — DFRWS USA, DFRWS EU (rebranding as the Digital Forensics Conference Europe) and DFRWS APAC. DFRWS's own submission rules confirm accepted research papers are published as special issues of Forensic Science International: Digital Investigation.

    Does not cover: Only the paper track is archived this way — presentation and demonstration proposals are not part of the printed proceedings, and DFRWS explicitly rejects general data-analysis work that does not address a forensic question. It is not a substitute for a subscription if you need FSI: Digital Investigation papers that did not come out of a DFRWS special issue.

    AdvancedWorking examiner
  • American Academy of Forensic Sciences / Wiley · ISSN 0022-1198 (print), 1556-4029 (online)

    The flagship journal of the American Academy of Forensic Sciences, published by Wiley. AAFS runs a Digital & Multimedia Sciences section (now styled Forensic Digital & Multimedia Sciences), and this is the journal that section publishes in alongside the other forensic disciplines.

    Does not cover: Digital and multimedia work is a minority of the content, so it is not a place to browse for artefact-level research; you will find far more digital forensics per issue in FSI: Digital Investigation. It is fully subscription-gated on Wiley Online Library.

    AdvancedLawyers and courtsWorking examiner
  • Chartered Society of Forensic Sciences / Elsevier · ISSN 1355-0306

    The peer-reviewed journal of the Chartered Society of Forensic Sciences, published by Elsevier. The Society describes it as focusing on the collection and use of forensic and crime scene evidence, and it carries a long-running strand on how forensic conclusions should be expressed.

    Does not cover: Digital evidence is a small slice of its output, and it publishes almost no artefact-level technical work. Elsevier subscription access applies, with the usual per-article purchase price.

    AdvancedLawyers and courts
  • Association of Digital Forensics, Security and Law (ADFSL), hosted by Embry-Riddle Aeronautical University · 2006 · ISSN 1558-7223

    An open-access, double-blind peer-reviewed journal that deliberately sat at the intersection of digital forensics, security and law, published by ADFSL and hosted on Embry-Riddle's Scholarly Commons under a CC BY-NC 4.0 licence. Volume 1 appeared in 2006 and the archive currently stops at Volume 17 (2022); the journal's own site states it is not taking new submissions at this time.

    Does not cover: It is publishing nothing new — submissions are closed and there has been no content since 2022, so nothing here reflects developments in the last few years. Coverage of specific modern artefacts (recent iOS and Android versions, current cloud platforms) is therefore thin to absent.

    Working examinerLawyers and courtsAdvanced
  • Digital Investigation

    PaywalledSuperseded or dormant

    Elsevier · 2004 · ISSN 1742-2876

    The predecessor title of Forensic Science International: Digital Investigation. It published from 2004 to 2019 under ISSN 1742-2876 and then the title changed; there is no new content under this name.

    Does not cover: It publishes nothing at all any more, so it is useless as a current-awareness source. Articles are still on ScienceDirect behind the same Elsevier paywall as the successor title.

    AdvancedWorking examiner
  • Economic Crime Institute, Utica College · 2002

    A defunct early journal of the field. IJDE published from Volume 1, Issue 1 (Spring 2002) to Volume 6, Issue 1 (Spring 2007) out of Utica College's Economic Crime Institute, and then stopped; the original utica.edu address now redirects away and there is no live journal site.

    Does not cover: It is dead — nothing after 2007, no DOIs, no publisher of record, and no stable URL other than the Internet Archive. Do not present it as a current journal, and do not rely on it for anything about modern devices, file systems or cloud services.

    AdvancedWorking examiner

Papers and reports (10)

Individual papers and reports that get cited on their own — foundational definitions, scientific-foundation reviews, and the handful of articles that set the vocabulary everyone else uses.

  • Elsevier (Forensic Science International: Digital Investigation) · 2020 · DOI 10.1016/j.fsidi.2019.200888

    Eoghan Casey's paper in Forensic Science International: Digital Investigation on how digital forensic practitioners should form and state evaluative opinions, importing the strength-of-evidence reasoning used elsewhere in forensic science into digital evidence and proposing a standardised scale for preliminary opinions.

    Does not cover: It addresses how to express an opinion, not how to reach it — no examination methodology and no artefact analysis. Elsevier paywall applies, and adoption of the proposed scale is not universal, so do not present it as a settled standard.

    AdvancedLawyers and courts
  • Eoghan Casey, Sean Barnum, Ryan Griffith, Jonathan Snyder, Harm van Beek, Alexander J. Nelson · Digital Investigation (Elsevier) · Digital Investigation, volume 22, September 2017 · 2017 · doi:10.1016/j.diin.2017.08.002

    The paper that introduced CASE, the Cyber-investigation Analysis Standard Expression, an open community-developed specification language aligned with the Unified Cyber Ontology for representing and exchanging cyber-investigation information. It is co-authored by a NIST researcher and supersedes the earlier DFAX approach.

    Does not cover: It is a specification rationale paper from 2017, not current CASE documentation: the ontology and bindings have moved on since publication, so use the CASE community site for the live schema. It contains no forensic technique and no guidance on interpreting artefacts.

    Advanced
  • Hon. Paul W. Grimm, Daniel J. Capra & Gregory P. Joseph · Baylor Law Review, 69 Baylor L. Rev. 1 (2017) · 69 Baylor Law Review 1, Winter 2016-2017 issue · 2017

    A law review article by a federal judge who writes extensively on digital evidence, the Reporter to the Advisory Committee on Evidence Rules, and a leading evidence practitioner, written as Rules 902(13) and 902(14) were being adopted. It works through the authentication routes for electronic evidence and explains what the new self-authentication provisions were designed to do.

    Does not cover: It was written before the rules took effect, so it contains no case law applying them and does not reflect nine years of subsequent practice. It is US federal and addresses admissibility, not examination method.

    Lawyers and courtsWorking examinerAdvanced
  • Executive Office of the President, President's Council of Advisors on Science and Technology · September 2016 · 2016

    A presidential advisory report distinguishing foundational validity — whether a method works at all, shown by empirical studies with measured error rates — from validity as applied by a particular examiner, and applying that distinction to feature-comparison disciplines such as latent prints, firearms marks, and bitemarks.

    Does not cover: It is not digital-forensics-specific and examines no digital method; its subject is feature-comparison pattern disciplines. It was produced by an advisory body, was rejected by the Department of Justice at the time, and has no legal force; courts cite it selectively.

    Lawyers and courtsWorking examinerAdvanced
  • Elsevier (Digital Investigation) · 2010 · DOI 10.1016/j.diin.2010.05.009

    Simson Garfinkel's 2010 paper in Digital Investigation arguing that the 'golden age' of digital forensics was ending and naming the forces that would end it: storage volume, device and format diversity, pervasive encryption, cloud storage and mobile platforms. It is one of the most cited papers in the field.

    Does not cover: It is a forward-looking position paper from 2010, with no method, no data and predictions you should now check against what actually happened rather than cite as current fact. The Elsevier copy is paywalled; a DFRWS-hosted or author copy is the practical route in.

    AdvancedWorking examiner
  • Elsevier (Digital Investigation) · 2009 · DOI 10.1016/j.diin.2009.06.016

    Garfinkel, Farrell, Roussev and Dinolt's DFRWS 2009 paper, published in Digital Investigation, arguing that digital forensics could not be a science without shared, redistributable test data, and introducing the corpora — including the real-data disk images and the govdocs document set — that the field went on to use.

    Does not cover: It does not validate any tool itself and does not tell you how to design a test plan; it makes the case for corpora and describes the ones the authors built. Some of the datasets it describes have since moved or been superseded, so check current hosting before relying on a link.

    Advanced
  • National Research Council / The National Academies Press · 2009 consensus study report · 2009 · DOI 10.17226/12589; ISBN 0-309-13130-8 (paperback)

    The congressionally requested report that found much of US forensic practice lacked demonstrated validity, consistent standards, and independence from law enforcement, and recommended a national institute to set and enforce them. It reset how courts and commentators talk about forensic reliability.

    Does not cover: It is not digital-forensics-specific: digital and multimedia evidence receives only brief treatment and none of its recommendations were written with computer or mobile examination in mind. It is also seventeen years old, its central recommendation was never implemented, and it is a policy report with no legal force.

    Lawyers and courtsWorking examinerAdvanced
  • International Journal of Digital Evidence · 2003

    Brian Carrier's paper in IJDE 2003, Volume 1, Issue 4, which modelled forensic tools as stacks of abstraction layers — bytes to file system to file to application content — and pointed out that every layer translation introduces potential error that the tool's output hides. Note that the IJDE table of contents prints 'Tool' singular even though the paper is usually cited as 'Tools'.

    Does not cover: It is a conceptual model, not a test methodology — no procedures, no reference data, no measured error rates. There is no DOI and no live publisher copy; use the Internet Archive capture of the issue.

    AdvancedWorking examiner
  • International Journal of Digital Evidence · 2002

    Eoghan Casey's paper in IJDE 2002, Volume 1, Issue 2, which took apart the then-common claim that digital evidence is exact and argued that error, uncertainty and data loss are intrinsic to it and must be stated. It proposed expressing a level of certainty in conclusions rather than asserting them flatly.

    Does not cover: It offers a framework for talking about uncertainty, not a method for measuring it, and gives you no error rates for any tool. IJDE never issued DOIs, so cite it by volume, issue and season; there is no publisher-hosted copy left.

    AdvancedLawyers and courtsWorking examiner
  • Digital Forensic Research Workshop (DFRWS) · 2001

    The report from the first Digital Forensic Research Workshop, held in 2001, which set out a research agenda and a shared vocabulary for a field that at that point had neither. It is the document that proposed the examination process framework and the term 'digital forensic science', and it is conventionally cited as Palmer (2001); DFRWS's own page for it names no individual author.

    Does not cover: It is a 2001 agenda document: the technology discussion is obsolete, there is no method you can apply, and several of its open problems have since been solved or reframed. Do not cite it for any current technical proposition.

    Working examinerAdvancedLawyers and courts

Tools (36)

Documentation, not downloads. What each tool is genuinely for, and — more usefully — what it is not for.

  • Arsenal Recon · 2026

    A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.

    Does not cover: This is a mounting and access tool — it acquires nothing, parses no artefacts, and produces no findings. Arsenal's own products page lists an all-tools subscription rather than a free tier, so budget for a licence; open-source mounting via ewfmount is an alternative but does not give you the full-disk, shadow-copy, or boot-to-VM behaviour. Booting a suspect image alters the mounted working copy, so the discipline about what is evidence and what is a derived copy has to be yours.

    Working examinerAdvanced
  • Sleuth Kit Labs · Autopsy 4 · 2026

    An open-source graphical forensic platform built over The Sleuth Kit, with an ingest-module architecture for keyword search, hash matching, web and email artefacts, and timeline review. It is now maintained by Sleuth Kit Labs, which also sells the commercial Cyber Triage product.

    Does not cover: Autopsy is an analysis platform, not an acquisition tool, and it has no write-blocking of its own — you still need a hardware blocker or a verified imaging step upstream. Its mobile and cloud coverage is thin compared with a paid mobile suite, and large multi-terabyte cases will expose its performance limits well before a commercial processing engine does.

    New to the fieldWorking examiner
  • Belkasoft · 2026

    Belkasoft's flagship acquisition and analysis product, covering computer, mobile, drone, vehicle, and cloud evidence in one case. It is split by customer type: Belkasoft X Forensic is offered to government customers, while Belkasoft X Corporate targets businesses for internal investigations and ediscovery. Belkasoft also publishes free Triage and Live RAM Capturer utilities.

    Does not cover: Pricing is not published — the page directs you to sales — and the government-versus-corporate product split means the edition available to you may not be the one described in published literature. Artefact coverage is smaller than the market leaders', so a negative result carries less weight and should be checked against another tool. Mobile extraction depth in particular does not match a dedicated mobile vendor, and the suite offers nothing for reverse engineering or network analysis.

    Working examiner
  • Simson Garfinkel · bulk_extractor 2 · 2026

    An open-source scanner that reads a disk image, memory image, or directory from end to end and extracts features — email addresses, URLs, credit card numbers, telephone numbers, EXIF data, JSON, and more — without reference to the file system. Version 2 is the current line and the repository is actively released.

    Does not cover: It produces features, not context — a recovered email address has no file, no timestamp, and no attribution, so on its own it establishes very little and must be tied back to an allocated artefact to mean anything. False positives are routine, particularly on the credit card and telephone scanners, and it does not identify files, parse applications, or reconstruct anything. It is also not a keyword search tool for a defined term list.

    Working examinerAdvanced
  • CAINE project (Nanni Bassetti); Tsurugi Linux project · CAINE 14 / Tsurugi 26.03 · 2026

    Two maintained live Linux distributions assembled for digital forensics. CAINE 14 'Lightstream' is built on Ubuntu 24.04 and is notable for a write-blocking system that locks all block devices read-only by default, with a GUI to unblock deliberately. Tsurugi Linux ships a LAB analysis edition, a lighter Acquire edition for imaging, and the BENTO portable live-response toolkit; its current LAB release is version 26.03.

    Does not cover: A distribution is a bundle, not a validated instrument: the tools inside carry their own versions, quirks, and maintenance states, and you are responsible for knowing which version of which tool produced a result. Software write blocking is a configuration that can be changed or can fail, and it is not equivalent to a hardware write blocker for evidentiary purposes. Neither distribution covers mobile acquisition meaningfully, and neither substitutes for a licensed suite on large or complex cases.

    New to the fieldWorking examiner
  • Cellebrite · Inseyets · 2026

    Cellebrite's mobile forensics flagship, now branded Inseyets and positioned within the company's broader Case-to-Closure platform. The familiar component names persist inside it rather than having been retired: UFED, Physical Analyzer, Kiosk, CFID, Reader, and C-TEK are all listed as parts of the Inseyets suite.

    Does not cover: Pricing is quote-based and licensing is typically annual and per-seat, with access to the newest extraction methods tied to a current subscription; there is no perpetual option to rely on. Take particular care with its parsed output: automatic decoding of chat and location data can be wrong or incomplete, and the defensible practice is to verify significant findings against the underlying database — often with the LEAPP tools or a SQLite browser. The naming change also means older reports and expert declarations reference product names that no longer match current marketing, which needs explaining rather than assuming.

    Working examinerAdvanced
  • GCHQ · CyberChef 11 · 2026

    A browser-based tool published by GCHQ that chains together hundreds of data operations — encodings, ciphers, compression, hashing, timestamp conversion, parsing, and extraction — into a visible recipe. It runs entirely client-side and is actively released.

    Does not cover: CyberChef transforms data you already have; it acquires nothing, parses no artefact formats, and keeps no case record. Although it runs locally in the browser, treat the hosted instance with care and use a local copy for sensitive material. It is not a cryptanalysis tool — it applies operations you specify and will not break modern encryption.

    New to the fieldWorking examiner
  • sqlitebrowser project · 3.13 · 2026

    An open-source cross-platform GUI for creating, browsing, querying, and editing SQLite and SQLCipher databases, with a spreadsheet-like table view and a full SQL editor. Point releases are infrequent but the repository remains active and nightly builds are published.

    Does not cover: It is a database editor, not a forensic tool, and it will happily write to evidence — always work on a copy, and be aware it does not handle write-ahead log and journal files the way a forensic SQLite parser does, so records still sitting in a -wal file or in freelist pages can be invisible or misleading. It does not recover deleted rows, carve database fragments, or maintain any audit trail of what you did.

    New to the fieldWorking examiner
  • Eric Zimmerman · 2026

    A large collection of free single-purpose Windows artefact parsers — among them MFTECmd, PECmd, LECmd, JLECmd, AmcacheParser, SBECmd, EvtxECmd, RECmd, and the Timeline Explorer and Registry Explorer GUIs. The tools are still distributed from ericzimmerman.github.io, with a Get-ZimmermanTools helper that pulls the current set.

    Does not cover: These are parsers, not a platform — there is no case management, no image mounting, no acquisition, and no cross-artefact correlation beyond what you build yourself in a spreadsheet or Timeline Explorer. They are Windows-artefact tools and will not help with macOS, Linux, or mobile data, and each tool assumes you already have the artefact file extracted.

    Working examinerAdvanced
  • Exterro · 2026

    The long-established Forensic Toolkit, originally AccessData's and now owned and sold by Exterro, which acquired the product line. It covers processing of computer and mobile data, distributed indexing and keyword search, artefact analysis, timeline visualisation, and Mac file system examination.

    Does not cover: Pricing is quote-based through Exterro sales and the deployment has real infrastructure requirements — a database back end and, for distributed processing, more than one machine — so it is not a laptop tool. Do not confuse it with the free FTK Imager, which shares the brand and does only imaging and preview. Its mobile coverage is not competitive with a dedicated mobile suite, and it does nothing for memory, network, or reverse engineering work.

    Working examinerAdvanced
  • FTK Imager

    Partly free

    Exterro · 2026

    A free Windows imaging and preview tool, originally from AccessData and now distributed by Exterro, which acquired the FTK line. It creates raw, E01, and AD1 images, captures live RAM, previews file systems before acquisition, and produces hash verification reports.

    Does not cover: It images and previews; it does not analyse — no keyword indexing, no artefact parsing, no timeline, no case management, all of which sit in the paid FTK product. It is not a write blocker and nothing about running it prevents you from writing to a source device, so hardware or OS-level blocking remains your responsibility. Distribution is via Exterro's site and is gated behind their download form rather than an unconditional public link, and its memory capture is basic compared with a purpose-built acquisition tool.

    New to the fieldWorking examiner
  • Ghidra

    Free

    U.S. National Security Agency · Ghidra 12 · 2026

    An open-source software reverse engineering framework released by the NSA, with a disassembler, a decompiler producing C-like output, scripting in Java and Python, and support for many processor architectures. The former ghidra-sre.org address now redirects to the GitHub project.

    Does not cover: Ghidra is static analysis: it does not run the sample, so packed, encrypted, or heavily obfuscated code needs dynamic analysis or unpacking first, and its debugger integration is not a substitute for a purpose-built sandbox. Decompiler output is a reconstruction, not source code, and treating it as literal in a report is an error. It has no role in disk, memory, or mobile examination.

    Advanced
  • hashcat project; Openwall · Hashcat 7 · 2026

    The two standard open-source password recovery tools. Hashcat is GPU-driven and supports a very wide range of hash and container formats with dictionary, rule, mask, and hybrid attacks. John the Ripper, from Openwall, has broader format coverage in its jumbo build and a large set of extraction utilities that pull hashes out of files and containers. Both remain actively developed.

    Does not cover: Neither breaks properly implemented modern cryptography — success depends entirely on the password being guessable and the key derivation being weak or the iteration count low, and a strong passphrase on a current container is not recoverable in any useful time. They provide no evidence handling, no case record, and no legal authority; running them on data you are not authorised to decrypt is the problem, not the tool. Results are also easy to misstate in a report, since a recovered password says nothing about who set or knew it.

    Working examinerAdvanced
  • Yamato Security; WithSecure · Hayabusa 4 / Chainsaw 2 · 2026

    Two open-source Rust tools that apply Sigma and their own rules directly to Windows event log (EVTX) files and produce a prioritised, timeline-ordered set of hits. Hayabusa comes from Yamato Security; Chainsaw is published by WithSecure (the repository now lives under WithSecureOpenSource). Both are actively released.

    Does not cover: Both are rule-driven detection over event logs and nothing more: they do not collect the logs, do not parse other artefact types, and will miss anything no rule describes. Neither reconstructs what happened — a hit is a lead requiring corroboration from other artefacts — and a quiet result often means logging was never enabled rather than that nothing occurred.

    Working examinerAdvanced
  • Alexis Brignoni · 2026

    A family of open-source Python parsers for mobile and returns data: iLEAPP for iOS logs, events and plists, ALEAPP for Android, and RLEAPP for returns and records from cloud and carrier providers. All three are released very frequently and are among the most actively maintained tools in mobile forensics.

    Does not cover: They parse extractions; they do not acquire them. Getting a file system or full extraction off a modern locked iPhone or Android device still requires a commercial tool, a service, or lawful process, and none of the LEAPP tools assist with that. They also do not decrypt, do not bypass passcodes, and do not manage a case — and because modules are community-contributed, coverage and quality vary between artefacts.

    Working examinerAdvanced
  • Eric Zimmerman · Kroll · 2026

    A Kroll-owned Windows triage tool that collects forensically relevant files from a live or mounted system using configurable Targets, then runs parsers over what it collected using Modules. It bypasses file locks with raw disk reads and preserves original timestamps on the copies.

    Does not cover: Note the licence carefully: the project documentation states KAPE is free for government, educational, research, and internal company use, and that as of 1 January 2026 it is no longer available for commercial use — meaning third-party networks or paid engagements. That rules it out for most consulting and expert-witness work, which is exactly where many practitioners previously used it. Technically, KAPE is also a triage collector, not an imager — it copies selected files and does not give you unallocated space, deleted file recovery, or a verifiable full-disk image.

    Working examinerAdvanced
  • Joachim Metz · libyal · 2026

    An open-source library and tool set for the Expert Witness Compression Format (E01/Ex01), including ewfacquire to create images, ewfverify to check their integrity hashes, ewfinfo to read the metadata, and ewfmount to expose an image as a raw device. The repository remains actively maintained.

    Does not cover: These are format tools, not a forensic workflow: nothing here write-blocks the source device, manages chain of custody, or analyses content. Support for the newer Ex01 variants and for vendor-specific metadata extensions lags the commercial tools that wrote them, so verify round-tripping before relying on it, and note that a successful hash verification proves the image is unchanged since acquisition — not that the acquisition was sound.

    Working examinerAdvanced
  • Magnet Forensics · 2026

    A commercial digital forensics platform that acquires, processes, and reports on computer, mobile, cloud, and vehicle data in a single case, organised around artefact recovery rather than raw file system browsing. AXIOM Cyber is the variant aimed at corporate incident response, internal investigations, and ediscovery, adding remote endpoint collection.

    Does not cover: Pricing is quote-based — Magnet publishes none — so budget and renewal terms have to be negotiated, and licences are per-examiner. Artefact-driven analysis is a convenience that can become a blind spot: the suite shows you what its parsers know about, so anything outside that coverage needs manual file system work or an open-source parser, and its parsed output should be verified against the underlying database before it goes in a report. It is not a reverse engineering or network forensics tool.

    Working examinerAdvanced
  • Ulf Frisk · MemProcFS 5 · 2026

    An open-source memory forensics tool that mounts a RAM image (or live memory) as a virtual file system, so processes, handles, registry, and network state appear as browsable files and directories rather than plugin output. It ships a Python and C API and a plugin ecosystem.

    Does not cover: Like Volatility it analyses memory and does not acquire it. It is not a substitute for disk analysis, has a steeper setup cost on non-Windows hosts, and its output conventions are its own — you cannot assume a Volatility plugin name maps to a MemProcFS path.

    Advanced
  • MSAB · 2026

    A commercial mobile forensics family from the Swedish vendor MSAB, sold as separate modules rather than one product: XRY Logical for live and file system extraction, XRY Physical for bypassing the operating system, XRY Pro combining advanced extraction and decryption, plus XRY Cloud, XRY Photon for screen-scraping app data, and XRY Camera for device documentation.

    Does not cover: Pricing is not published — MSAB directs enquiries to sales, and the modular licensing means the capability you need may not be in the licence you have. Device support is not identical to Cellebrite's, so a handset one tool cannot reach may still be reachable by the other; never treat a failed extraction on one vendor's tool as proof the data is unobtainable. It is a mobile tool only, with no role in computer, memory, or network examination.

    Working examinerAdvanced
  • Nuix · 2026

    A commercial investigation and data-processing platform aimed at very large unstructured data sets, combining forensic-style processing with ediscovery-grade indexing, deduplication, and export. Nuix now positions its offerings under the Nuix Neo platform, with Workstation still listed as a product alongside Nuix Discover for review.

    Does not cover: Pricing is quote-based and the platform is genuinely expensive and infrastructure-heavy, with processing performance tied to hardware you provide — this is not a tool for a single-examiner engagement. It is a processing and search engine, not a device forensics suite: it does not acquire media, examine mobile devices, analyse memory, or recover file-system-level artefacts, so it complements rather than replaces Autopsy, X-Ways, or a mobile tool. Review and production workflow live in Nuix Discover or a separate review platform, not in Workstation.

    AdvancedLawyers and courts
  • The Plaso project · 2026

    An open-source Python framework that extracts timestamps from hundreds of artefact types across a disk image or directory and writes them into a single normalised storage file. log2timeline is the extraction front end; psort and psteal filter, sort, and export the result.

    Does not cover: Plaso produces an enormous, noisy event set and does no interpretation — deciding which of several million events matter is entirely the examiner's job, and timestamp semantics (created, modified, accessed, and what each means on which file system) are not resolved for you. It is not an acquisition tool, not a reporting tool, and its output is not readable without psort or a front end such as Timesketch.

    Working examinerAdvanced
  • radareorg; RizinOrg · radare2 6 / Rizin 0.9 · 2026

    Two closely related open-source reverse engineering frameworks. radare2 is the original Unix-style command-line toolkit for binary analysis, patching, and debugging; Rizin is a fork of radare2 that set out to stabilise the API and command set and ships the Cutter GUI. Both are actively developed and release regularly.

    Does not cover: Both have a famously steep command syntax and neither is a forensic suite — no case management, no reporting, no evidence handling. Their decompilers are weaker than Ghidra's, they do not defeat packing or obfuscation on their own, and the fork means scripts and plugins are not reliably portable between the two.

    Advanced
  • Harlan Carvey · RegRipper 3.0 · 2026

    An open-source Perl tool that runs a library of plugins against Windows registry hives and reports the values that matter forensically, with each plugin documenting the key it read. RegRipper 3.0 is the current line and the repository remains actively updated.

    Does not cover: RegRipper reads hives; it does not extract them from an image, does not recover deleted registry keys from hive slack (tools such as Arsenal's Registry Recon or a dedicated hive parser are for that), and does not interpret the registry for you beyond what a plugin's author chose to report. Plugin coverage varies in age and quality, and a missing plugin is not evidence of a missing artefact.

    Working examinerAdvanced
  • Rob Lee and the SIFT team · SANS Institute · 2026

    A free Ubuntu LTS-based virtual machine appliance from SANS that bundles more than a hundred open-source incident response and forensic tools, pre-configured and dependency-resolved. It is still actively updated by Rob Lee and a small team and underpins several SANS DFIR courses.

    Does not cover: SIFT is a packaged collection with no tool of its own, so every limitation of Volatility, Plaso, or TSK applies unchanged inside it. It is an analysis environment rather than an acquisition platform and offers no write blocking as a virtual machine, it has no case management or reporting layer, and its tool versions lag upstream — check the version of any tool you cite rather than assuming it is current.

    Working examinerAdvanced
  • Sigma

    Free

    SigmaHQ · 2026

    An open, structured YAML format for describing detections in log data, plus a community rule repository and the pySigma/sigma-cli tooling that converts a rule into the query language of a particular SIEM or log platform. The rule repository is actively released by SigmaHQ.

    Does not cover: Sigma is a format, not an engine — it collects, parses, and detects nothing by itself, and every rule depends on log sources being configured and retained before the incident. Conversion is imperfect: a rule's behaviour on one backend is not guaranteed to match another, and field mappings must be validated per environment before a result is relied upon.

    Working examinerAdvanced
  • Brian Carrier · Sleuth Kit Labs · TSK 4 · 2026

    A C library and a set of command-line tools (fls, icat, istat, mmls, blkls, tsk_recover and others) that read volume systems and file systems directly from a disk image. It is the engine underneath Autopsy and a component in many other tools.

    Does not cover: TSK parses file systems; it does not carve by content, does not interpret application artefacts such as browser or registry data, and has no case management or reporting layer. Its file system support is broad but not universal — newer or proprietary formats may need a different reader, and it will not acquire an image for you.

    Working examinerAdvanced
  • Timesketch project (code owned by Google) · 2026

    An open-source web application for collaborative timeline analysis, built around the idea of a sketch that several analysts annotate, tag, and search at once. It ingests Plaso storage files, CSV, and JSONL. The project states plainly that it is code owned by Google rather than an official Google product.

    Does not cover: Timesketch is a review and collaboration layer only — it parses nothing itself, so the quality of what you see is entirely the quality of the Plaso run or CSV you fed it. It requires a server deployment (Docker or equivalent) rather than running as a desktop application, and it produces no forensic report or exhibit format of its own.

    Working examinerAdvanced
  • Rapid7 · Velociraptor 0.77 · 2026

    An open-source endpoint visibility and DFIR platform built around VQL, a query language for collecting artefacts, monitoring events, and hunting across a fleet of agents. Development is sponsored by Rapid7, with the code still published under the Velocidex organisation.

    Does not cover: It is a collection and hunting platform, not an analysis suite — VQL gets you the data, and you still need Volatility, Plaso, or the EZ Tools set to work it properly. Deploying agents on endpoints is an intrusive act with consent, authority, and chain-of-custody consequences that the tool does not manage for you, and VQL has a real learning curve that a GUI suite does not impose.

    AdvancedWorking examiner
  • The Volatility Foundation · Volatility 3 · 2026

    An open-source memory analysis framework that parses RAM images into processes, network state, loaded modules, injected code, registry hives resident in memory, and command history. Volatility 3 is the actively developed line; Volatility 2 is legacy and should not be the basis of new work, though its documentation is still used for plugin comparison.

    Does not cover: Volatility parses memory; it will not acquire it, and a bad acquisition is not recoverable in analysis. Nothing in the framework repairs a smeared or torn dump taken from a running system, and it will not tell you about activity that left no trace in RAM at capture time — for the acquisition step you need a separate tool such as Magnet DumpIt or the acquisition side of a commercial suite.

    AdvancedWorking examiner
  • Wireshark Foundation · 2026

    The standard open-source packet analyser, with a GUI, the tshark command-line equivalent, several thousand protocol dissectors, and a display filter language. It is published by the Wireshark Foundation, which also runs the SharkFest conferences.

    Does not cover: Wireshark reads captures; it does not tell you what was not captured, and it is a poor tool for summarising large volumes — a multi-gigabyte PCAP is a job for Zeek logs, with Wireshark reserved for the specific conversations that matter. It cannot decrypt TLS without keys, does not reconstruct sessions across gaps in a capture, and offers nothing for endpoint or disk evidence.

    New to the fieldWorking examinerAdvanced
  • X-Ways Software Technology AG · 2026

    A commercial Windows forensic examination environment from the German publisher X-Ways Software Technology AG, built on their WinHex disk editor and known for running from a portable installation with very low overhead. Licences are perpetual and protected by a local or network dongle, or by a bring-your-own-device arrangement.

    Does not cover: Pricing is not published on the product page — quotes are retrieved through the order pages, and downloads are restricted to existing customers with trials available only to law enforcement, government, and some corporations. The interface is dense and unforgiving, with a learning curve that makes it a poor first suite. Mobile and cloud coverage is minimal compared with Magnet or Cellebrite, and it is Windows-only.

    Advanced
  • VirusTotal · YARA 4 / YARA-X 1 · 2026

    A pattern-matching language and scanner for identifying files by their content — strings, byte sequences, and structural conditions — used to label malware families and find known artefacts at scale. YARA-X is a ground-up rewrite in Rust from the same maintainers and is now the forward direction of the project; the original YARA 4.x line still receives releases and remains widely deployed.

    Does not cover: YARA matches patterns you already know about — it finds nothing novel, and a clean scan is not evidence of a clean system. It does not unpack, deobfuscate, or emulate, so packed samples defeat naive rules; it makes no behavioural judgement, so a match tells you a file resembles something, not what it did.

    Working examinerAdvanced
  • The Zeek Project; Open Information Security Foundation (OISF) · Zeek 8 / Suricata 8 · 2026

    Two complementary open-source network monitoring engines, both actively released. Zeek (formerly Bro) turns traffic into structured, protocol-aware logs — connections, HTTP requests, DNS queries, TLS handshakes, files seen — using its own scripting language. Suricata, from OISF, is a signature and rule-driven IDS/IPS that also produces rich EVE JSON records and can extract files.

    Does not cover: Neither is a packet analyser: Zeek discards the payload it summarised and Suricata keeps only what a rule told it to, so if you need the actual bytes you needed a full capture and Wireshark. Suricata detects what its rules describe and is blind to everything else; Zeek detects nothing by default and only records. Both require deployment at a network vantage point before the incident — neither can be applied retroactively.

    AdvancedWorking examiner
  • National Institute of Standards and Technology

    NIST's long-running programme that builds tool specifications, test assertions, test procedures and test data for categories of forensic function — disk imaging, hardware and software write blocking, deleted file recovery, file carving, string searching, media preparation, mobile device and cloud data extraction, Windows registry and SQLite tools — and publishes the resulting test reports with DHS Science and Technology.

    Does not cover: CFTT tests functions against its own written requirements; it does not certify, approve or rank products, does not test every tool or every version, and its reports can lag current releases by years. A CFTT report on an old version says nothing directly about the build you actually ran.

    Working examinerLawyers and courts
  • National Institute of Standards and Technology

    A CFTT offshoot that packages NIST's test methodology so labs can run it themselves and optionally share results: distributed as bootable Linux ISOs and a portable Windows web-server build, with report templates. Current suites cover disk imaging, forensic media preparation, hardware write blocking, string searching, SQLite recovery, mobile device acquisition and cloud data extraction, with companion datasets in CFReDS.

    Does not cover: It does not cover every forensic function (memory, timeline reconstruction, most analysis tools have no suite), and a self-run result is not a NIST endorsement or a NIST-issued report. Running the suite proves behaviour on NIST's test data, not that your whole examination workflow is sound.

    Working examiner

Datasets and practice material (11)

Images, corpora and challenges you can practise on and publish against. The only honest way to learn a technique is on data whose ground truth someone else already knows.

  • DFRWS · 2023

    The annual research challenges set alongside the DFRWS conferences, with scenario data, documentation and published results kept as repositories in the DFRWS GitHub organisation. Editions available there include 2005 (memory analysis), 2006, 2009 (PlayStation 3), 2012-2013, 2015, 2017 and 2018 (IoT), 2021 (multisource analysis and correlation) and 2023.

    Does not cover: There is no guided walkthrough and no tool that will simply parse these formats for you; the 2021 and 2023 sets in particular assume you can write your own parsers for embedded memory. The older challenges target platforms nobody encounters any more, and several repositories have not been touched since 2021-2024, so treat them as archived research data rather than a maintained course.

    Advanced
  • Simson Garfinkel and contributors · Digital Corpora · 2009

    A public repository of forensic disk images, memory dumps, mobile extractions, network packet captures and file corpora assembled for forensic research and teaching. The data is held in Amazon S3 (s3://digitalcorpora/) under the AWS Open Data Sponsorship Program and served from downloads.digitalcorpora.org.

    Does not cover: CC0 covers only the original site content: copyrighted software and third-party material sitting inside the disk images and packet dumps keep their own terms, so redistribution of an image is not automatically clean. The Real Data Corpus of secondhand drives bought worldwide, which was the site's one collection of genuine third-party personal data, is marked "no longer available" and cannot be obtained.

    New to the fieldWorking examiner
  • Simson Garfinkel and contributors · Digital Corpora · 2009

    A corpus of 986,278 real files harvested from US government web servers, distributed as numbered archives on Digital Corpora. The published statistical report (contributed by Forensic Innovations, Inc.) breaks the collection down by type and originating platform — hundreds of thousands of documents, text files, images and hypertext files across Windows, UNIX, DOS and Macintosh origins.

    Does not cover: It is a bag of files, not evidence: there is no file system, no disk image, no timeline and no scenario, so nothing here supports a recovery, attribution or timeline exercise. The files are real published documents, so any copyright notices inside them still apply.

    Working examinerAdvanced
  • Digital Corpora · 2009

    A scripted corporate scenario covering the first four weeks of a fictional patent-search company, from 13 November 2009 to 12 December 2009. It ships daily hard drive images and daily RAM captures for each computer, USB drive images, inbound and outbound packet captures, final-day images of every system, and simulated case paperwork including detective reports, warrants and affidavits.

    Does not cover: The answer keys, hash sets and scenario emails are encrypted and released only to faculty at accredited institutions, so a self-studying practitioner has no authoritative marking scheme. The environment is Windows-era 2009 with no mobile, cloud or modern endpoint telemetry, so it teaches method rather than current artefacts.

    New to the fieldWorking examiner
  • Ali Hadi

    A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.

    Does not cover: Downloads are spread across Archive.org, Mega and GitHub rather than one maintained host, and Challenge 11 is listed as only partly available — expect to hunt for links. The cases are single-host and mostly Windows; there is no mobile, cloud or enterprise-scale material.

    Working examiner
  • Centri

    A gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.

    Does not cover: The platform states it is aimed at people who already have experience with security tooling rather than beginners, and the free tier gives you challenges only — no lab instances. It is defensive operations practice, not legal or expert-witness work.

    Working examiner
  • National Institute of Standards and Technology

    A NIST repository of documented simulated digital evidence — images and data sets with known ground truth — developed with National Institute of Justice support. Holdings include scenario images (hacking case, data leakage case), Windows registry and Unicode string-search sets, Mac and mobile images, memory images, file carving and deleted-file-recovery sets, and reference/control drives.

    Does not cover: These are constructed data sets, not real casework: they will not reproduce the scale, messiness or encryption of a live exhibit, and NIST states the portal is under development and may be reorganised. Most sets are explicitly not the Federated Testing data, so do not substitute one for the other.

    Working examinerNew to the field
  • CyberDefenders

    Partly free

    CyberDefenders

    A blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.

    Does not cover: Part of the catalogue is marked PREMIUM and needs a paid account; the site does not publish its prices on the challenge listing, so check before assuming a lab is open. The question-and-answer format rewards finding a specific string and teaches nothing about scoping, reporting or defending an opinion.

    New to the fieldWorking examiner
  • ForensicArtifacts

    A community-maintained, machine-readable knowledge base of digital forensic artefact definitions — where an artefact lives and how to collect it — expressed in YAML and licensed Apache-2.0. It is documented at artifacts.readthedocs.io and coordinated through the forensicartifacts Google Group and the Open Source DFIR Slack.

    Does not cover: These are definitions, not data: there is no evidence to practise on and nothing here parses an artefact once you have collected it. Coverage reflects contributor interest, so it is uneven, and it carries no interpretation — knowing where a key lives says nothing about what its value means in a given case.

    Working examinerAdvanced
  • Joshua Hickman · The Binary Hick

    A maintained index of populated mobile test images produced by Joshua Hickman and linked from his blog: Android 7 through 14, and iOS 13, 14 (with a macOS Big Sur image), 15, 16 and 17. Most are hosted by Digital Corpora, with one iOS 14 set on MediaFire.

    Does not cover: The page states no explicit licence or terms, and the author asks to be told about broken links, so treat availability as best-effort rather than guaranteed. Coverage stops at the versions listed, and there is no accompanying answer key or exercise — these are reference images, not a course.

    Working examiner
  • National Institute of Standards and Technology

    A NIST library of collected software, supported by DHS and law enforcement partners, from which file profiles are computed and published as the Reference Data Set: digital signatures of known, traceable application files. The site distributes current RDS hash sets, separate non-RDS hash sets and legacy tooling, under a stated NIST redistribution policy.

    Does not cover: The RDS is a known-file list, not a malware or contraband list — presence means 'known software', never 'benign', and absence means 'not in the library', never 'suspicious'. Coverage of niche, bespoke, non-English and very recent software is patchy, and the published sets and formats change between releases, so record which release you used.

    Working examiner

Conferences (10)

Where the field talks to itself. Split roughly between research venues and vendor user conferences; the entries say which is which.

  • American Academy of Forensic Sciences · 2027

    The annual meeting of the American Academy of Forensic Sciences, a multidisciplinary body of over 6,500 members organised into twelve sections, one of which is Digital & Multimedia Sciences. The 79th Annual Scientific Conference is scheduled for 15-20 February 2027 at the Rosen Shingle Creek Hotel in Orlando, Florida.

    Does not cover: It is not a place to learn a tool or pick up techniques — presentations are short scientific abstracts, the digital section is a small part of a very large meeting dominated by pathology, toxicology and criminalistics, and much of the week will be irrelevant to a digital examiner. Registration rates and abstract deadlines are published annually on the conference site.

    AdvancedLawyers and courts
  • Cellebrite · 2026

    Cellebrite's customer event programme. Through 2026 the listing is dominated by regional user forums and government forums — Toronto, Halifax, Bern, Seattle, Jakarta, several US district attorney technology days, a London CTF — with the large C2C User Summit itself shown as a 2027 event.

    Does not cover: This is a vendor programme: the content is about Cellebrite products, not about mobile forensics independently of them, and nothing here is peer reviewed or a substitute for validating the tool yourself. The large annual user summit is not scheduled during 2026 — the site shows the next C2C User Summit in 2027 — and many forums are invitation-based or restricted to law enforcement and government, with no public price list.

    Working examiner
  • Forum of Incident Response and Security Teams · 2026

    The annual conference of FIRST, the global forum of incident response and security teams, which comprises over 800 member teams in more than 100 countries. The 2026 edition ran 14-19 June 2026 in Denver, Colorado.

    Does not cover: It is not a digital forensics conference: expect little on disk or mobile artefacts and nothing on expert testimony or litigation. Much of the programme assumes you work inside a response team, and some material and side meetings are member-oriented; registration fees are published per edition on the conference site.

    Working examinerAdvanced
  • High Technology Cyber Investigation Association · 2026

    HTCIA, founded in 1986 and describing itself as "the oldest association exclusively dedicated to advancing high technology and cyber investigations", runs a calendar of chapter meetings and regional training events. The flagship event currently listed is the Ohio HTCIA Salt Fork Conference, whose 2026 edition — its 25th — ran 20-22 May 2026 at Salt Fork State Park Lodge, Kimbolton, Ohio, offering 20 hours of training credit.

    Does not cover: The association's own site does not currently list an HTCIA International Conference for 2026, and none appears on the members' events calendar, so the historic annual international event should not be assumed to be running — regional and chapter events are what is live. These are training and networking events, not research venues, and much of the calendar is US-centric.

    Working examinerLawyers and courts
  • International Association of Computer Investigative Specialists · 2026

    IACIS runs "an annual training event in Orlando, Florida the last week of April and the first week of May each year", with the next Orlando conference scheduled for 19-30 April 2027 and roughly 800-900 students attending across the two weeks. The flagship course is Basic Computer Forensic Examiner (BCFE), with advanced offerings in mobile device forensics, Windows, Linux and scripting; a 2026 Budapest event is also listed at €4,800.

    Does not cover: Attendance is limited to IACIS members, regular or associate, so it is not open registration, and the site does not publish standard fees for the Orlando event — only that the fee covers instruction and that meals, hotel and travel are separate (online courses are listed at $995 each). There are no research talks and no vendor exhibition in the conference sense.

    New to the fieldWorking examinerAdvanced
  • Magnet Forensics · 2026

    Magnet Forensics' online DFIR conference, delivered over several weeks of sessions. The 2026 edition has taken place and its recordings are published as a free replay library, searchable by speaker, theme, language and week, covering mobile forensics, cloud investigations, video analysis and corporate investigations.

    Does not cover: It is a vendor-hosted event and a fair proportion of the sessions are delivered by Magnet product specialists around Magnet tooling, so it is not a neutral survey and not peer reviewed. Being virtual, it gives you none of the corridor contact of an in-person conference, and the in-person Magnet User Summit — Austin, Texas, 8 to 10 March 2027 — is a separate, paid event.

    New to the fieldWorking examiner
  • Relativity · 2026

    Relativity's annual user and legal-technology conference, now branded RelFest. The main 2026 event is RelFest Chicago, 29 September to 1 October 2026 at the Hyatt Regency Chicago, with over 100 general and breakout sessions and workshops; regional editions in London (15-16 June 2026) and Sydney (21 April 2026) are listed as free. The organisers report over 3,000 attendees from 33 countries.

    Does not cover: It is a vendor user conference centred on the Relativity platform, so it teaches that ecosystem rather than e-discovery or forensics in general, and there is no forensic acquisition, artefact or expert-testimony content. The Chicago edition is paid and the site does not publish its rates on this page; the London and Sydney editions are the free ones.

    Lawyers and courtsWorking examiner
  • SANS Institute · 2026

    SANS's annual practitioner summit, with the 2026 edition running 15-16 October 2026 at the Hilton Arlington Rosslyn in Arlington, Virginia, followed by SANS courses 17-22 October. Both the summit and the courses can be attended in person or virtually.

    Does not cover: It is a practitioner and vendor-adjacent event, not a research conference: talks are not peer reviewed and should not be cited as if they were. It also assumes you already do the work — there is no beginner track in the summit itself, and the legal and expert-testimony side is barely represented.

    New to the fieldWorking examinerAdvanced
  • Comexposium · 2026

    A long-running US digital forensics and investigations conference, now produced by Comexposium. The site lists one 2026 edition: San Diego, California, 20-22 October 2026 at the Town & Country Resort.

    Does not cover: It is not a research venue and not a deep technical one: sessions skew introductory and several are vendor-delivered, so an experienced examiner may find little new in the track content. The programme and registration rates are published annually on the site rather than fixed — check there. Only the San Diego 2026 date is currently listed.

    Working examinerLawyers and courts
  • DFRWS

    The research conference series for digital forensics, running as DFRWS USA (July), a European edition renamed the Digital Forensics Conference Europe from 2027 (formerly DFRWS EU), DFRWS APAC in the autumn, and a Digital Forensics Doctoral Symposium alongside the European event. Papers are peer-reviewed and published, and the workshop format puts authors in front of practitioners.

    Does not cover: It is a research venue, not training: talks assume you already know the artefacts, and nobody will teach you a tool. There is little here on the legal or courtroom side, and the certification and vendor-suite content practitioners often want is at the commercial user conferences instead.

    AdvancedWorking examiner

Blogs and channels (15)

Independent and vendor blogs and video channels. The fastest-moving layer of the literature, and the first place a new artefact gets documented.

  • 13Cubed

    Partly free

    Richard Davis

    A YouTube channel and companion training site covering Windows, Linux and macOS endpoint forensics, memory analysis and threat hunting. The YouTube videos are free; the on-demand courses on training.13cubed.com are paid.

    Does not cover: It is endpoint-centric: there is essentially nothing on mobile, cloud or network forensics, and nothing on report writing, disclosure or testimony.

    New to the fieldWorking examiner
  • Devon Ackerman and contributors

    A curated DFIR reference index — training and degree programmes, certifications, job postings, tools by platform, conferences, podcasts, preservation letter templates and research repositories — maintained by Devon Ackerman with Mary Fernandez, Tony Knutson and Nathan Turner. It also runs a near-daily news digest.

    Does not cover: It indexes rather than teaches — no tutorials, no original artifact research, and its links are not quality-graded.

    New to the fieldWorking examiner
  • A DFIR blog aimed explicitly at beginners, paired with a searchable training directory at training.dfirdiva.com that indexes over 500 free and low-cost courses across forensics, incident response, malware analysis, OSINT, Linux, networking and programming.

    Does not cover: It curates other people's training rather than delivering deep technical research of its own, and it does not cover expert-witness work, retention or testimony.

    New to the fieldWorking examiner
  • DFIR Training

    Partly free

    Brett Shavers

    Brett Shavers' DFIR portal: a calendar of training events worldwide, a tool directory, a resource library, a book index and a blog on the state of the field. Some listings and downloads are open, others sit behind registration or a paid membership.

    Does not cover: It aggregates and comments rather than teaching technique, and course listings reflect what providers submit, so absence from the calendar means nothing.

    New to the fieldWorking examiner
  • The long-running digital forensics news site and discussion forum, publishing articles, interviews, tool announcements and a regular digest, alongside practitioner forums organised by tool and platform.

    Does not cover: Forum answers are unvetted and vary widely in quality, and vendor-supplied articles sit alongside independent reporting without always being obviously separated.

    New to the fieldWorking examinerAdvanced
  • The research blog of Hexordia, a mobile forensics training and consulting firm, with posts from a named group of contributors including Jessica Hyde, Adam Hachem, Nicholas Dubois, Elizabeth McPherson, Debbie Garner and Kim Gatson.

    Does not cover: It is mobile-first, with little on Windows endpoint, cloud or network work, and it is a vendor blog for a training company, so posts often point toward Hexordia courses.

    Working examinerAdvanced
  • Alexis Brignoni

    Alexis Brignoni's blog on mobile forensics and open-source tooling, closely tied to the xLEAPP family of parsers — iLEAPP, ALEAPP, RLEAPP and VLEAPP — which he maintains with others.

    Does not cover: Coverage is mobile and open-source-tool centred; it does not address commercial tool workflows in depth, nor computer-side or cloud forensics.

    Working examinerAdvanced
  • Magnet Forensics' blog and resource library, mixing artifact research and how-to posts with webinars, white papers, case studies and product content across mobile, cloud, vehicle and media forensics.

    Does not cover: It will not tell you the limits of Magnet's own tools, it rarely compares against competitors or open-source parsers, and there is no independent validation of the claims made.

    New to the fieldWorking examiner
  • The DFIR section of the SANS institutional blog, written by SANS instructors and course authors on topics tied to their teaching — cloud imaging, ransomware trends, mobile artifacts and case retrospectives.

    Does not cover: It is a marketing channel for SANS training as well as a technical blog, so posts often stop short of the depth the corresponding course delivers, and coverage follows the course catalogue rather than the field.

    Working examinerAdvanced
  • A daily handler diary — distinct from the SANS DFIR blog — in which a rotating roster of volunteer handlers writes up whatever they are currently seeing in honeypot data, malware samples, exploit traffic and log telemetry.

    Does not cover: It is network and threat oriented, not evidentiary: almost nothing on imaging, chain of custody, mobile handsets or anything you would put in an expert report.

    Working examinerAdvanced
  • Joshua Hickman

    A research blog by Joshua Hickman covering mobile and Apple-platform artifacts, timestamp semantics and the test images he builds and publishes for the community.

    Does not cover: It is deliberately narrow — mobile and Apple artifacts — with nothing on enterprise incident response, network forensics or ediscovery workflow.

    Working examinerAdvanced
  • Phill Moore

    A weekly roundup of everything published in digital forensics that week — blog posts, tool releases, presentations, podcasts and job listings — with links and one-line summaries.

    Does not cover: It aggregates and does not teach or evaluate — there is no tutorial content, no quality judgement on what it links to, and nothing on legal or courtroom practice.

    Working examinerAdvanced
  • Harlan Carvey

    Harlan Carvey's long-running blog on Windows incident response, registry analysis, investigative methodology and the discipline of documenting how you reached a conclusion.

    Does not cover: It is Windows-centric: very little on mobile, macOS or cloud, and nothing on the mechanics of testimony or disclosure.

    Working examinerAdvanced
  • David Cowen

    David Cowen's daily-blog project, running to over 800 numbered posts plus the Sunday Funday challenges, Solution Saturday write-ups and the Forensic Lunch video series, covering Windows artifacts, NTFS internals, cloud logging and DFIR programming.

    Does not cover: Nothing published since April 2025, so no coverage of current tool versions or recent Windows and cloud changes; the archive is also heavily Windows-focused with little mobile or macOS content.

    Working examinerAdvanced
  • mac4n6

    FreeSuperseded or dormant

    A macOS and iOS forensic research blog, authored under the handle @iamevltwin with occasional contributors, covering Apple artifacts, analysis tooling and conference presentations.

    Does not cover: It stops before recent macOS and iOS releases, so nothing here covers the newest Apple Intelligence, Journal or system-log changes beyond early 2025, and there is no Windows, Android or cloud content.

    Working examinerAdvanced

Podcasts (4)

Interview and news shows. Good for keeping current and for hearing how practitioners actually talk about a problem; not a substitute for training.

  • Alexis Brignoni and Heather Charpentier · 2023

    A podcast hosted by Alexis Brignoni and Heather Charpentier, both working examiners, covering current digital forensics news, new research and interviews with researchers. Note that it is a podcast, not a blog, and it is unrelated to the consulting firm that uses the same name at digitalforensicsnow.com.

    Does not cover: It is mobile-heavy, informal and assumes you already work in the field; it does not cover legal procedure, expert-witness practice or anything structured enough to substitute for training.

    Working examinerAdvanced
  • The interview podcast from Forensic Focus, featuring researchers, vendors and police digital forensics staff on their current work. Recent guests include Ben Dimmock, David Shipley, Marcus Rowe of Leica Geosystems, Phil Anderson and Paul Gullon-Scott.

    Does not cover: Publishes irregularly, roughly monthly with gaps, and several episodes are effectively vendor interviews; it is not a source of step-by-step technique.

    New to the fieldWorking examiner
  • A short daily audio briefing, typically five to ten minutes, summarising the Internet Storm Center diaries and the day's notable vulnerabilities and exploitation activity.

    Does not cover: It is vulnerability and threat news only — no forensic technique, no case discussion, and nothing on evidence handling or expert work.

    Working examiner
  • Digital Detectives

    FreeSuperseded or dormant

    Sharon D. Nelson and John W. Simek

    A Legal Talk Network podcast hosted by Sharon D. Nelson and John W. Simek on digital forensics, ediscovery and information security for a legal audience.

    Does not cover: Nothing published since late 2023, so no coverage of recent amendments, recent case law or current tools; it was always aimed at lawyers rather than examiners, so technical depth is shallow throughout.

    New to the fieldLawyers and courts

Free training (8)

Training that genuinely costs nothing, plus a few that are free to start. Where something is only partly free, the entry says exactly which part.

  • 2016

    A free eight-hour online unit from The Open University on its OpenLearn platform, classified as Level 3 (advanced undergraduate entry), with a free statement of participation on completion.

    Does not cover: It has not been updated since 2019, so tool and platform references are stale and there is nothing on mobile, cloud or modern endpoint artifacts. There are no hands-on labs and no exercises against real images.

    New to the field
  • Antisyphon runs selected courses on a Pay What You Can model, stating that it wants to help people who cannot afford conventional training prices. Courses confirmed on the page at the time of checking are SOC Core Skills in the Age of AI with John Strand (live and on-demand) and the Professionally Evil CISSP Mentorship Program (live, multiple instructors).

    Does not cover: I could not confirm from the site whether a payment of zero is accepted, so treat this as low-cost rather than proven free until you check at registration. The Pay What You Can slate rotates and is small — most of Antisyphon's catalogue, including its forensics-adjacent courses, is normally priced, and there is no deep disk or mobile forensics in the PWYC offerings.

    New to the fieldWorking examiner
  • A DFIR training company that publishes a substantial block of genuinely free self-paced courses alongside its paid catalogue. Confirmed free titles include C5W-100 Introduction to Digital Forensics, Linux Forensics Distributions, Intro to Linux from a Forensics Perspective (Ubuntu and Tsurugi), Writing Forensics Reports, Computer Data Representation, Working with Files, Prepare Your Forensic Environment, Working with Virtual Hard Disk, several Spanish-language courses on evidence acquisition and Windows forensics, and a set of case-study workshops.

    Does not cover: The free courses are foundational: no mobile forensics, no cloud, no memory analysis of any depth, and the paid catalogue is where the advanced material sits. It is a commercial training vendor, so the free tier functions as a funnel.

    New to the fieldWorking examiner
  • An Open edX platform hosting long-form, university-length classes in low-level computing: x86-64 assembly, OS internals, firmware and UEFI, debuggers (WinDbg, GDB, IDA, Ghidra, Binary Ninja, HyperDbg), reverse engineering, vulnerability classes, exploitation, fuzzing, trusted computing and Bluetooth security. Actively maintained — 2025 additions include AFL++ fuzzing, Bluetooth reconnaissance and TPM programming in Python, with an introductory emulator course listed for 2026.

    Does not cover: The site publishes no price or checkout page and I could not confirm a cost statement either way, so treat the free status as unverified until you see it at registration. Content-wise it is systems and reverse engineering, not forensics: no imaging, no chain of custody, no mobile, no evidentiary or legal material, and the courses assume real C and assembly ability.

    Advanced
  • A download library of reference posters and cheat sheets, of which 37 are filed under Digital Forensics and Incident Response — artifact maps, timestamp reference tables, tool command references and filter syntax sheets. Download requires a free SANS account rather than payment.

    Does not cover: They are reference cards, not training — no explanation, no exercises, no methodology. They also function as advertising for the corresponding paid SANS course, and coverage follows the course catalogue rather than the field.

    Working examinerAdvanced
  • TCM Security Academy publishes six courses explicitly marked Free Course: AI 100: Fundamentals (4h), Linux 100: Fundamentals (2h), Practical Help Desk (16h 30m), Practical Security Fundamentals (8h 30m), Programming 100: Fundamentals (3h) and Soft Skills for the Job Market (7h). The rest of the catalogue and all certifications are paid.

    Does not cover: No forensics, no incident response, no memory or mobile content in the free tier at all — those sit behind paid courses and the PJIR-style certifications. It is a commercial academy and the free courses are a funnel.

    New to the field
  • A browser-based hands-on security learning platform. The free tier gives limited access to learning paths, access to rooms marked free, and one hour of AttackBox use per day. Paid plans are Premium at about EUR 10.50 per month billed annually and MAX at about EUR 17.99 per month billed annually, which unlock full path access, unlimited AttackBox and certificates.

    Does not cover: The free tier is deliberately partial: most structured paths, certificates and unlimited lab time are paywalled, and the one-hour daily AttackBox limit makes longer forensic exercises awkward. The platform as a whole is offensive-security weighted, so DFIR content is a minority of it.

    New to the fieldWorking examiner
  • The Volatility Foundation keeps the Volatility Framework — currently Volatility 3 — free and open source on GitHub, with the accompanying project documentation. Separately it endorses instructor-led memory forensics courses; the Foundation's site does not publish prices for those, and the Malware and Memory Forensics class is a commercial offering run through memoryanalysis.net.

    Does not cover: The free material is reference documentation, not a course: no curriculum, no exercises, no instructor. It covers memory only — nothing on disk imaging, mobile, cloud or reporting — and the structured teaching sits in the paid classes.

    Working examinerAdvanced

How this list is maintained

Every entry was checked against the publisher’s own page, and each one prints the date that check was made. Where an edition, an ISBN or a standard number could not be confirmed at source, the field is left off rather than reconstructed — a wrong standard number is the one error on a page like this that propagates into other people’s work.

Standards are revised. ISO reaffirms or replaces on a roughly five-year cycle, SWGDE revises continuously, and NIST withdraws publications outright. Treat every version label here as “what was current on the verification date” and confirm at source before you cite it.

Inclusion is not endorsement, and nothing here is legal advice. Several entries are listed precisely because a reader will meet them in an opponent’s report and needs to know what they do and do not establish.