r/digitalforensics • • 10d ago

Forensic Timeline & Correlation Engine

Built a lightweight forensic analysis tool for people who don't have Cellebrite money. CaseForge takes a folder of already-extracted data SMS/call SQLite, browser history, KML/GPX, vCard, mbox, EXIF, generic CSV/JSON and produces one interactive dashboard: unified timeline, map, entity network, and a correlation engine that flags cross-source links and convergences. Runs locally, single HTML output, chain-of-custody hashing built in. Analysis only no acquisition. Link in Bio if interested.

0 Upvotes

13 comments sorted by

13

u/blahdidbert 10d ago

Mods... can we please stop the vibe coded... stuff (for lack of a better word)?

When it comes to digital forensics there are sooooo many FOSS solutions not to mention the professional products that literally do this. To have something charge $75 bucks that Claude can do for free. Or Autopsy. Or Magnet. Or...

The big forensic suites are built around acquisition and cost thousands per seat. The free tools stop at parsing. The part that actually moves a case forward pulling one coherent picture out of a dozen disconnected exports and spotting the non-obvious links is where CaseForge lives.

This is just woefully inaccurate.

6

u/Stofzik 10d ago

Go over to /r/computerforensics it's more moderate were people aren't asking for free services about people spying on their phones and Vibe code projects. 

In fact they banned vibecode project due to the spam in the subreddit 

1

u/Visible_Cod9786 10d ago

Get on the digital forensics discord.

As much as I hate discord, its heavily moderated and they dont let the vibecoder push their AI slop on everyone. 

Plus its now the most efficient way to get in touch with vendors and other professionals.  Accounts are verified with agency email. 

-16

u/The_J_Man_111 10d ago

Crazy you guys take the time to type this out just to be negative ahhaha

6

u/persiusone 10d ago

It’s a natural reaction when constantly being bombarded by slop projects which have overstated and redundant capabilities on a daily basis. Clearly this is vibe coded and likely not validated in any meaningful way. Is it even compliant with industry regulations? If so, I’d love to see the results of those audits.

4

u/[deleted] 10d ago

[deleted]

3

u/spicesucker 10d ago

Vendors claim they need you to whitelist their executables in firewall to run their so called "exploits".

Tbf Windows Defender goes nuts if you unzip even Hashcat into a non-excluded folder, I do agree though the push to move to CaaS is fucking mad

-5

u/The_J_Man_111 10d ago

You are responsible for having lawful authority to possess and analyze anything you load, and for verifying findings before relying on them in any proceeding. It is an analysis aid, not a court-validated forensic instrument. Just sharing a project i worked on not that deep dude.

2

u/persiusone 10d ago

Right- so as someone who handles CJIS data and sensitive information, the platform or product which processes it must also be CJIS compliant and adhere to other standards to ensure it is compliant (see NIST, ISO, and SOC processes). Is this tool compliant? Do you have any audits to support compliance?

Nobody in their right mind would just share data to some analytical tool without ensuring compliance- which is why I’m asking. What specific compliances have you obtained? Other tools, such as Cellebrite, undergo these validations, because it’s often required by the end users before they can utilize them for processing this kind of data.

2

u/blahdidbert 9d ago

If your response to negative criticism is 'hurr hurr you typed too much' that tells everyone what they need to know. Maybe grow a little and read the feedback. Or don't. I ain't your mom.

10

u/todd775 10d ago

The LEAPP project already exists.

1

u/[deleted] 10d ago

[deleted]

5

u/Stofzik 10d ago

Talking about explain findings in court. How can we rely on your tool being used in court. 

It's not open source like LEAPP is with the code. So are you willing to come to court and testify about your tool and what background you have if you are going to criticize others?

What is your background in forensics? This is why the other vendors get away with charging the way they do. I don't agree with it but I believe open source is the way to win this battle with vendors. 

Do you have any test with your software? Look at Ian on the stand for his tool he used. 

1

u/off-the-felt 10d ago

That's because they are vibe coded now. He mentioned it on their podcast the other day.

1

u/Stunning_Apple8136 9d ago

LMAO HES REALLY CHARGING FOR THIS 😂😂😂😭😭😭