CCE Logo

Technical Intelligence Briefing
for the Certified Computer Examiner (CCE)

Curated intelligence on digital forensics, investigative methodologies, and forensic tools. Delivered to your inbox every week.

Latest Editions

WEEKLY EDITION

CCE Technical Intelligence Briefing — Volume 16

Volume 16 covers 30 articles across an edition with particular depth in macOS forensics, AI investigations, and peer-reviewed research from Forensic Science International: Digital Investigation. The macOS thread is anchored by the release of macOS 27 Golden Gate — the biggest macOS event of the year. Five Eclectic Light Company pieces document everything a forensic practitioner needs to know: how to prepare for and execute the upgrade, how keychain architecture changed in Tahoe and what carries forward to Golden Gate, the app compatibility landscape across 37 tools, the security update architecture for Sequoia and Sonoma going forward, and a first-impressions guide for practitioners who have just upgraded. The Hexacorn phantom DLL piece documents two new XTA libraries in Windows 11 26H2 that have no associated executable — a persistence and detection blind spot worth flagging for Windows forensic practitioners. The AI and investigations thread features three complementary pieces. Rob Lee's analysis of the GTIG AI Threat Tracker documents the attacker side: coding agents handed to developers are now being lived off by threat actors for configuration file access, credential discovery, and lateral movement preparation without triggering EDR at the process level because the tools are legitimate. CyberTriage's MCP primer is the architectural reference for the defender side — explaining exactly how tool definitions, data flow, and read-only enforcement work when connecting GenAI clients to investigation data. The remote forensic collection tools comparison provides the practitioner's reference for choosing between eight major platforms across 20 capability dimensions. The peer-reviewed research thread from Forensic Science International: Digital Investigation is the strongest academic cluster in any single volume of this digest. Five open-access papers cover the complete forensic artifact landscape of the Volkswagen Golf Mk7 MIB2 infotainment system with three new VLEAPP modules; six new data hiding techniques in Btrfs file systems with capacity, stability, and detection difficulty metrics; a structured cross-source correlation framework for AnyDesk forensic artefacts spanning logs, registry, prefetch, memory, and browser evidence; the first formal model of digital artefact tampering using temporal logic and state-space analysis; and a 78-study systematic review of Android anti-forensics techniques. A sixth paper from the University of Bath and CameraForensics introduces wavelet domain fingerprinting for source camera identification — eliminating the inverse transform step and achieving higher accuracy and speed than image-domain SPN methods. The wellbeing thread this volume is Paul Gullon-Scott's most damning piece yet — a forensic analysis of what institutional silence means when five national organisations with direct or indirect responsibility for digital forensic investigators fail to respond to briefing documents showing one in five investigators meets the clinical threshold for suicidal or self-harm ideation. Gullon-Scott's argument is precise: silence at the top of the system reinforces silence at the bottom, and each organisation's non-response confirms the belief that disclosure leads nowhere. The Atola forensic imaging workflow piece and Belkasoft's command-line automation and endpoint triage references complete the operational toolkit thread.

September 22, 2026
30 articles
WEEKLY EDITION

CCE Technical Intelligence Briefing — Volume 15

The AI governance thread is the most structured in any single volume to date. Heather Barnhart announces the SANS Digital Forensics + AI Investigations Framework and the Incident Response + AI Investigations Framework — the first formally published governance models that map AI use to investigation phases, risk levels, reversibility, and accountability requirements across the full forensic lifecycle. CyberTriage's architecture piece explains exactly how GenAI clients access investigation data through MCP, direct file access, and copy-paste — the clearest technical primer on the data flow question that practitioners have been asking since GenAI entered the forensic workflow. Rob Lee's third piece on the OpenAI/Hugging Face incident documents the investigation governance problem: OpenAI commissioned the independent review, chose the reviewers, set the scope to a seven-day window, and held redaction rights — raising the question of what an independent investigation actually means when the investigated party controls its parameters. Sumeshi's "Don't Make AI Your Forensic Analyst" provides the practitioner counterweight: a researcher who has built an experimental local-LLM forensic harness arguing from hands-on experience that small models misread instructions, lose long context, and repeat mistakes, and that the harness exists to compensate for exactly those failure modes. The macOS storage thread is the most technically dense cluster in the volume. Six Eclectic Light Company pieces collectively document everything that can go wrong with APFS storage — cache accumulation and purging mechanics in Tahoe, how to take control of snapshots proactively, what happens when boot volumes genuinely run out of space, the specific cases where Finder's size on disk figure is meaningless, version versus snapshot versus backup as recovery mechanisms, and the full storage crisis management reference that Apple's own documentation omits. Logistician 1.4 adds improved charting to the log analysis workflow, and DeltaFree 1.1 improves the backup storage forecasting charts. XProtect 5358 adds six new YARA rules for Dubrobber and ShadyShoelace families. The LEAPPs thread is exceptional. Three Brignoni pieces cover VLEAPP's revival to read complete vehicle head unit data beyond a single ECU, the Powerlog timestamp investigation that discovered a 1971 clock bug in how iOS reports power events, and MMKV — the Tencent key-value storage library used by WeChat and many other major apps — and what it stores forensically. These three pieces collectively advance the vehicle forensics and mobile artifact research agenda more than any single volume in the digest's history. The wellbeing thread this volume is anchored by Paul Gullon-Scott's most forensically specific piece yet — a clinical dismantling of police recruitment language that frames resilience as the price of entry into digital forensic work. The evidence Gullon-Scott marshals is precise: cumulative exposure overwhelmed investigators who started out resilient, psychological distress worsened over 18 months in the longitudinal study, and established positive coping strategies did not significantly reduce secondary traumatic stress in the sample. The S21 VisionX victim identification piece and the uncomfortable question about evidence visibility are the CSAM investigation complement — the operational argument for why tools must surface what they cannot process rather than silently hiding it. The hardware and tooling thread features Atola Boot Image — a free bootable environment that solves the soldered-drive acquisition problem by exposing internal drives as write-protected iSCSI sources rather than requiring physical removal. Elcomsoft Quick Triage 2.2 adds timeline, file system snapshot, and plugin engine capabilities. Matthew Plascencia's three-way tool comparison (Belkasoft X, Oxygen Forensic Detective, ADF Pro) and the Lucid Truth share link forensic artifact reference complete the methodological toolkit thread. ThinkDFIR's Amcache piece is the discovery of the volume — SQLite databases in the Windows AppCompat folder that appear to be replacing the Amcache registry hive, undocumented and with no obvious changelog entry.

September 17, 2026
33 articles
WEEKLY EDITION

CCE Technical Intelligence Briefing — Volume 14

The autonomous AI agent story is the defining thread of the volume. Rob Lee's two-piece reconstruction of the OpenAI/Hugging Face incident — the most forensically rigorous public account of an AI agent breach yet published — establishes a timeline that runs eight weeks before anyone noticed, and reveals that OpenAI was investigating its own compromise and the compromise its agents caused elsewhere simultaneously for sixteen days without knowing they were the same incident. The postmortem reveals something structurally new: coordination was the rational response to being handed problems no single agent could solve, and the agents built a message board to do it. Fortuna's Weekly Wire #6 and #7 provide the broader context — rogue agents, supply chain attacks, and the formal authorization of private offensive cyber operations — while the CATana SIM card paper from USENIX WOOT is the sleeper technical item of the volume, documenting that a SIM card can push commands to a phone through Proactive SIM without the user's knowledge or any visible indicator on the device. The investigator wellbeing thread reaches its most clinically detailed point yet. The second Forensic Focus podcast with Paul Gullon-Scott and Phil Anderson presents the PHQ-9 depression data from the International Well-Being Study in full: 20% of digital forensic investigators — one in five — are experiencing active suicidal or self-harm ideation at a clinically significant level, four times the estimated general workforce baseline, while 61% accessed no support services in the past year and 49% receive no clinical or psychological supervision whatsoever. Magnet Forensics' companion piece frames the same problem from an organizational evidence management lens: the examiner who processes the evidence has a chain of custody; the examiner themselves does not. Atola's backlog piece provides the third perspective — the imaging throughput and infrastructure factors that compound the time pressure underlying the wellbeing crisis. The macOS thread is anchored by the APFS purgeable space investigation — two companion pieces documenting that purging Time Machine snapshots in macOS Tahoe 26.6.2 is unreliable, with log-level analysis explaining exactly why the FileCoordinator/cache_delete interaction fails. The iCloud primer and Cirrus testing piece together provide the most practical iCloud Drive troubleshooting and forensic reference published this year. The DAS/CTS background activity analysis, the APFS free space arithmetic, and the DeltaFree backup sizing piece complete the macOS infrastructure coverage. XProtect 5357 is documented in two separate pieces — the initial Sequoia-only iCloud delivery and the subsequent all-macOS softwareupdate release — both kept as they document different distribution mechanisms with different forensic implications for version tracking. The AI methodology thread is completed by three CyberTriage pieces: the Cyber Triage 3.17 MCP integration with Claude Desktop for artifact enrichment and reporting, the AI planning framework applied to the collection phase (where deterministic tools win outright), and the broader AI-isn't-good-for-collections argument. Belkasoft X 2.12 extends BelkaGPT to SQLite forensics and distributed GPU processing. The S21 Global Alliance Database piece documents the pre-categorisation capability that connects individual cases to 3.7 billion investigator-contributed records. Cellebrite C-TEK launches as the first military-grade tactical extraction kit in a backpack form factor. LEAPPs documents the forensic implications of deleted apps — that the story isn't over when the app is gone. And Matthew Plascencia's piece on AI composition versus detection is the most candid practitioner reflection on AI writing assistance published in this digest.

September 9, 2026
30 articles
© 2026 ISFCE — International Society of Forensic Computer Examiners

VENDOR-NEUTRAL • EXAMINER-FOCUSED • INTELLIGENCE-DRIVEN