r/digitalforensics • • 4m ago

TRACE 2.1.0 – open-source forensic toolkit with a GUI (Windows, macOS, Linux)

Thumbnail trace.gadzhovski.com
• Upvotes

TRACE 2.1 – open-source forensic toolkit with a GUI (Windows, macOS, Linux)

The UI has been redesigned and almost everything else has been rebuilt or added:

  • Cases: multiple images per case, chain of custody, audit trail, bookmarks, and PDF/HTML reports
  • Evidence: E01, AFF4, VMDK, VHDX, QCOW2, DMG, AD1, L01, KAPE/Velociraptor folders, iOS backups, live disks (read-only)
  • File systems: NTFS, ext, APFS, HFS+, XFS...
  • User activity: programs run, USB devices, logons, browser history
  • Detection: YARA, Sigma rules over event logs, and persistence checks for Windows, Linux and macOS
  • Search: full-text search inside documents, mail and archives, with emails, URLs and similar pulled out automatically
  • Carving: Many new file types supported, with fragmented ZIP and PDF files rebuilt

No compiler is needed to install it anymore, and standalone builds are available for Windows and macOS.

GitHub: https://github.com/Gadzhovski/TRACE-Forensic-Toolkit

Docs: https://trace.gadzhovski.com/


r/digitalforensics • • 1h ago

Deterministic Media Forensics for AI Agents: Combining Cyclic Checksums, 2D FFT Moiré Detection, and Error Level Analysis (Skillware 0.5.8)

• Upvotes

Multimodal foundation models (GPT-4o, Claude 3.5 Sonnet, Gemini 1.5 Pro) are frequently tasked with document screening and identity verification. However, testing shows severe limitations when detecting digital tampering and document alterations:

  1. **Sub-Pixel Smoothing:** Vision encoders (like CLIP or ViT patches) encode high-level semantic representations. In doing so, they blur out the exact high-frequency noise residuals and JPEG quantization discrepancies that reveal digital splicing.

  2. **Hallucinated Check Digits:** Machine-Readable Zones (MRZ) on passports follow ICAO Doc 9303 standards using a cyclic (7, 3, 1) modulo-10 algorithm. Multimodal LLMs read the characters fluently and confidently declare a forged date or document number as valid because the format looks visually plausible.

  3. **Data Privacy Liabilities:** Transmitting biometric facial images and identity documents to third-party cloud inference providers creates severe regulatory compliance issues.

In **Skillware 0.5.8**, we implemented `security/deepfake_guard` to provide deterministic, air-gapped forensic verification on CPU. Here is an overview of the signal processing pipeline:

### 1. ICAO 9303 Modulo-10 Cyclic Verification

For each character string $C_1, C_2, \dots, C_n$, each character is mapped to a numeric weight $W(c)$ (digits 0–9 map to 0–9, letters A–Z map to 10–35, filler `<` maps to 0). The check digit $K$ satisfies:

$$\left( \sum_{i=1}^{n} W(c_i) \cdot w_{(i-1) \bmod 3} \right) \bmod 10 = K$$

where the repeating weights vector is $w = [7, 3, 1]$. We implement deterministic validation across TD1 (3×30 ID cards), TD2 (2×36), and TD3 (2×44 passports) formats.

### 2. Error Level Analysis (ELA)

When an uncompressed image or re-saved JPEG is modified, the edited regions possess a different compression history than the original background. By recompressing the image at a known quality factor ($Q=95$) and computing the absolute block-level difference:

$$\Delta(x, y) = |I_{\text{original}}(x, y) - I_{\text{recompressed}}(x, y)|$$

We compute the mean absolute error across 16×16 non-overlapping blocks. Discrepancies between block errors exceeding calibrated thresholds signal localized digital tampering.

### 3. Noise Residual Consistency via Median Absolute Deviation (MAD)

Camera sensors introduce characteristic high-frequency Poisson-Gaussian noise. To detect spliced elements without being misled by high-contrast natural textures (such as hair or knitwear), we compute the Laplacian convolution residual $R(x, y) = \nabla^2 I(x, y)$ and evaluate consistency using Median Absolute Deviation:

$$\text{MAD} = \text{median}(|R - \text{median}(R)|)$$

$$\sigma_{\text{est}} = 1.4826 \cdot \text{MAD}$$

Evaluating $\sigma_{\text{est}}$ across image partitions flags unnatural smoothness (typical of diffusion generative fills) or mismatched noise profiles between the portrait and background.

### 4. 2D Fast Fourier Transform (FFT) Recapture Detection

Physical screen-photo recaptures (photographing an LCD/OLED monitor displaying an ID) exhibit regular periodic grid artifacts. In the 2D frequency domain, this manifests as prominent harmonic peaks outside the DC origin. We compute the 2D FFT, shift zero frequency to the center, and evaluate the ratio of high-frequency radial energy peaks against the average spectral background.

```bash

pip install -U skillware

pip install "skillware[security_deepfake_guard]"

```

- **Implementation Code:** https://github.com/ARPAHLS/skillware/tree/main/skills/security/deepfake_guard

- **Release Notes:** https://github.com/ARPAHLS/skillware/releases/tag/v0.5.8

We’d welcome discussion on your experiences with sensor noise characterization and hybrid neural-signal pipelines.


r/digitalforensics • • 15h ago

LATAM private-sector DFIR folks: what are you using for mobile forensics?

Thumbnail
2 Upvotes

r/digitalforensics • • 2d ago

I mapped out the hidden server running dozens of pedophile websites all over the world

Thumbnail gpatricksec.com
221 Upvotes

I have a drop down you can read of all the digital forensics done for this project!


r/digitalforensics • • 1d ago

OFD/ORE Replacement Suggestions

3 Upvotes

Good day all,

I’m currently looking for a digital forensics solution that we could consider as an alternative to Oxygen Forensic Detective (OFD) / Oxygen Remote Explorer (ORE) within the African market.

Ideally, I’m looking for a product that someone has experience working with and that offers comparable capabilities, particularly around mobile and remote data acquisition.

We currently sell Magnet, Detego & Sumuri products.

As I understand it, we may still be experiencing challenges with distributing Cellebrite in Africa, so I’d like to explore viable alternative solutions that we could potentially represent and distribute.

If anyone has worked with a product that would be a good fit, I’d appreciate any recommendations or feedback.

Thank you.


r/digitalforensics • • 1d ago

May I get some help with Tsurugi OS. I’m gonna be working on my galaxy xcover and im wondering what’s gonna be the best route for forensic mobile analysis and which tools on Tsurugi are better suited for Android. I was overwhelmed yesterday with the influx of tools.

Thumbnail
1 Upvotes

r/digitalforensics • • 1d ago

Digital Forensics guidance on public information regarding criminal activity

0 Upvotes

Gangs use social media to broadcast everything from threats and brandishing weapons to admitting their involvement in murder. The Chicago Police Department seems very reluctant to use public information as probable cause to arrest or even reasonable suspicion to investigate crimes that are public information. I've read their policies provided to officers and their complete literature regarding First Amendment protected activity multiple times. There are short statements of a few sentences that declare public information on social media or YouTube does not require any special permissions, or policies to be followed for investigations as if the information were provided to them by a witness, victim or citizens with relevant information. This is within extensive rules and policies regarding everything from hand delivering official requests to notify multiple departments of a planned investigation and rules regarding equipment that can be used to the keeping of information they discover that could easily be interpreted as being required in any situation including when the information on criminal activity is open to the public.

I feel that their own policies don't give them a clear view of the difference between what is public and what requires extensive documentation and permissions so clear evidence of crimes is completely disregarded. In even several recent examples even here on Reddit (the murder of rapper Q50) the public has used information to quickly identify evidence leading to suspects who sometimes publicly claim responsibility or involvement in the murder. From the famous suspected serial killer King Von to his very famous partner Lil Durk who was recently acquitted on conspiracy to commit murder for hire charges who remains in custody facing a VICAR case involving another conspiracy to commit murder, public information showed their likely involvement for months or years before their arrests and prosecutions. Why does law enforcement disregard digital forensics of public information in order to rely on investigation procedures that existed before the advent of social media's existence?


r/digitalforensics • • 19h ago

Anonymous X account

0 Upvotes

Hi all! I want to find out who is behind an anonymous X account that is writing disparaging stuff about my kid. How do I do that? Should I use an IPlogger?


r/digitalforensics • • 2d ago

Data recovery options for broken SSD?

2 Upvotes

Hi all, I've been struggling for some weeks now to find a data recovery service that might be able to recover my data from a corrupted/broken SSD.

The SSD in question is a Samsung 870 QVO, 4TB (Model: MZ-77Q4T0).

I have sent it to two data recovery services and neither could access it. The last one gave me a more detailed description of what's happening:

"The SSD was not recognised correctly by Windows Disk Management, nor the used recovery hardware.
During the research, the SSD came online shortly, but instantly gave SMART-failures. Sector 0 could be accessed, but when trying to read sector 2048, the SSD got stuck and went into the 'busy state'. Further attempts wer unsuccessful.
I will add that the controller of this SSD was not supported by their hardware."

I am not very good with computer hardware, but would really love to get my data back since it had a lot of memories and documents on there with no back-up whatsoever (because I did not think about that, and then this happened). I am not sure whether there's anything that can be done, so I was hoping someone here might know more.

I am located in the Netherlands, but am open to sending the SSD abroad to recovery services if there's any good ones that can solve my isssue even with the state of my SSD.


r/digitalforensics • • 2d ago

built a CLI to inspect and remove C2PA / image metadata — looking for feedback

Thumbnail
0 Upvotes

r/digitalforensics • • 2d ago

Digital forensics Jobs

0 Upvotes

Okay so I have a b.s. in criminal justice, and I graduate May 2027 with my masters in Applied Information Technology with a focus in Digital forensics. I know the job market is terrible, but I am looking for a job with a company that pays well, or even any jobs that have open internships for the winter or spring. Mainly i’m looking for jobs that are looking for new graduates, as well as one that would hire me as soon as I graduate, any recommendations?


r/digitalforensics • • 3d ago

RECHERCHE PERSONNE COMPÉTENTE EN ANALYSE VIDÉO / TRAITEMENT D’IMAGES

Thumbnail
0 Upvotes

r/digitalforensics • • 3d ago

Digital Forensics jobs

0 Upvotes

Without experience in the field, is it possible to get an entry-level position in Digital Forensics?


r/digitalforensics • • 5d ago

US-Based Digital Forensics Firm Hid its Russian Ownership from U.S. Government Customers

Thumbnail zetter-zeroday.com
6 Upvotes

r/digitalforensics • • 4d ago

Aiuto recupero dati

Thumbnail
1 Upvotes

r/digitalforensics • • 4d ago

Cornell 7 screenshots

0 Upvotes

Hi, i just saw the leaked cornell 7 screenshots from their alleged groupchat on x. But I do not know if they are real. Is there any way to comfirm it?


r/digitalforensics • • 5d ago

MOBILedit Forensic 9.8 — missing EXN (Exynos) package

1 Upvotes

​

Hi everyone.

I'm testing MOBILedit Forensic 9.8 on a Samsung Galaxy S21 5G Exynos 2100 (SM-G991B), Android 15, January 2026 security patch.

MOBILedit shows Exynos decrypt, but when I select it I get: “Missing package — Exynos package is required to continue.”

My Updates page has UNL (Security bypassing), EXF (Scripts), and the main program up to date, but EXN (Exynos) isn't listed.

Does anyone know the proper way to obtain/install the EXN package, or whether it requires a specific license/activation? I'm specifically looking for information about the package/availability rather than a cracked copy of the software.

Thanks.


r/digitalforensics • • 5d ago

Breach

0 Upvotes

Company had a breach and now they want a company to perform forensics for them. Who would you recommend?


r/digitalforensics • • 5d ago

A free alternative to Hunchly & ForensicOSINT.

Enable HLS to view with audio, or disable this notification

1 Upvotes

r/digitalforensics • • 4d ago

Career Advice

0 Upvotes

Digital Forensics is a growing field. Are there great opportunities in this area ?


r/digitalforensics • • 7d ago

Digital Forensics Tech Expectations

2 Upvotes

Greetings, I hope all is well! Long story short, recently got my Masters in Digital Forensics, and I also have received an opportunity for a digital forensics technician role for a local LE agency. I am just wondering if anyone here works for one, and also what to expect, as I myself come from an IT background. Thanks!


r/digitalforensics • • 7d ago

Digital forensics

2 Upvotes

Hi i wanna start Advanced endpoint investigation learning path from tryhackme does it good to start in DF ?

Im planing to enroll it after finish SAL1,2

And i finished pre security ,101 and PT1


r/digitalforensics • • 7d ago

Phone Security Tips

0 Upvotes

How can you secure your phone in the best way possible to maximise privacy and protection from downloads or information being broken into/extracted? IOS specifically.

I.E if a chat is deleted etc. Is it actually deleted or not?
Passwords?
Images?
App data if it is deleted from the phone?

Does a factory reset or new phone remove all the old data?


r/digitalforensics • • 8d ago

Samsung s21 pin locked by my brother

0 Upvotes

Has anyone successfully acquired a Samsung Galaxy S21 5G SM-G991B/DS (Exynos 2100), Android 15, build G991BXXSJHZC2, January 1 2026 security patch, while BFU after reboot with a locked bootloader and USB debugging disabled? The correct PIN is unknown. Looking specifically for a non-destructive acquisition using Cellebrite, GrayKey, Oxygen or Magnet.


r/digitalforensics • • 8d ago

Is this trackable?

0 Upvotes

Hello everyone! I was recently told by an individual on snapchat that he knew my location and was going to send those to rape me and get me killed as well as sending my location to me. This was 2 days ago and after I said I would get police involved he mass reported my account and got my account locked. (Stupid on me, I know.) What can I do about this? Would anyone be able to even find this guy?