Score
Collecting, validating, and analyzing digital artifacts and chains of evidence to reconstruct system state, identities, reasoning, and causality during incident recovery or investigation.
Event reconstruction in digital forensics suffers from fragmented perspectives, inconsistent terminology, and methodological fragmentation, lacking a systematic, unifying framework. Method: This paper proposes the first unified temporal event reconstruction framework tailored for digital forensics—adapting classical forensic reconstruction models to the digital domain; constructing a comprehensive, lifecycle-spanning conceptual map of temporal reconstruction; and conducting a systematic literature review (SLR) coupled with conceptual modeling to clarify terminological relationships and process elements. Contribution/Results: The study identifies three core challenges—data scale, temporal distortion, and semantic ambiguity—and establishes an extensible classification system. It delivers a consensus-based terminology set and a standardized process paradigm, thereby providing a rigorous theoretical foundation for the development and evaluation of automated event reconstruction tools.
This study addresses the absence of a systematic framework in digital vehicle forensics (DVF), where evidence is fragmented across in-vehicle systems, mobile devices, manufacturer backends, and third-party services. Through a structured review of academic literature, standards, and real-world cases, this work identifies eight core characteristics of DVF for the first time, incorporates an adversarial perspective, formalizes the initial forensic triage problem, and proposes a feature-driven prioritization workflow. The resulting reproducible conceptual framework clarifies strategies for selecting and correlating evidence sources, significantly enhancing the efficiency and rigor of forensic investigations in accident reconstruction, criminal inquiries, and cybersecurity incident response—while explicitly accounting for safety, legal, and privacy constraints.
This study addresses the challenges of insufficient evidentiary reliability and lack of traceability in current AI-assisted digital forensics, particularly when large language models (LLMs) are involved, which often fail to meet judicial standards for trustworthiness. To overcome these limitations, the authors propose an automated framework that integrates LLMs with a Digital Forensics Knowledge Graph (DFKG), enabling end-to-end traceability of forensic data through deterministic unique identifiers (UIDs). The framework further incorporates a cross-validation mechanism to ensure both the integrity of the evidence chain and contextual consistency. Evaluated on a real-world 13 GB dataset, the approach achieves over 95% accuracy in forensic item extraction, establishing a novel, auditable, scalable, and legally compliant paradigm for AI-assisted digital investigations.
Large language models (LLMs) face critical challenges in digital forensics—including low transparency, opaque reasoning, and non-reproducible outputs—that hinder judicial admissibility. To address these, this paper introduces the “reasoning constraint hierarchy,” a novel conceptual framework grounded in the Model Context Protocol (MCP). We embed MCP throughout the forensic workflow—spanning evidence analysis, interpretation, and report generation—to establish an auditable, verifiable LLM-assisted forensic framework. Through formal theoretical modeling and multi-scenario empirical validation, we systematically demonstrate that MCP significantly enhances analytical traceability, procedural auditability, and legal admissibility of conclusions. This work is the first to establish MCP as the foundational architecture for compliant, forensically sound LLM deployment. It provides both theoretical grounding and practical guidance for developing automated, verifiable, and accountable intelligent forensic systems.
In digital forensics, the atomicity and integrity of storage snapshots lack rigorous definitions that jointly guarantee both instantaneousness and causal ordering—undermining evidentiary admissibility in legal proceedings. To address this, we propose a novel atomicity definition grounded in causal consistency, overcoming the limitation of conventional time-based atomicity models. We further rectify conceptual flaws in existing integrity definitions and introduce a revised, theoretically sound yet engineering-practical integrity criterion—explicitly supporting copy-on-write (CoW) implementations. Our approach integrates causal modeling, formal snapshot semantics, CoW mechanism analysis, and formalization of forensic quality criteria, yielding a verifiable snapshot semantic framework. This work establishes the first theoretical foundation for forensic tool design that unifies causal ordering with instantaneous state capture, thereby significantly enhancing the forensic validity and judicial admissibility of live data acquisition.
This study addresses the longstanding disconnect between detection engineering and digital forensics, which has led to a gap between real-time alerts and post-incident analysis. To bridge this divide, the authors propose a unified detection-and-forensics methodology based on Velociraptor that triggers targeted evidence collection immediately upon detection events, thereby integrating monitoring and forensic workflows. The approach introduces an innovative four-stage framework that transforms forensic artifacts into reusable, testable detection rules, enabling efficient initial triage without requiring full disk imaging. By leveraging BaseVQL data sources—such as Prefetch, USN Journal, and WMI—it facilitates cross-artifact correlation and periodic analysis, allowing effective screening even in the absence of Windows Event Logs. This significantly reduces data acquisition volume while supporting continuous monitoring.
This study addresses the challenges posed by rapid evolution in digital forensic systems and tools, which induces drift in evidentiary behaviors and tool outputs, thereby undermining result reproducibility and trustworthiness. To mitigate this, the authors propose a test-driven forensic methodology that introduces state-transition testing for causal attribution, encoding forensic expectations as executable specifications. The approach integrates virtual machine environments with computer vision–guided GUI automation to simulate authentic user interactions and verify system state changes. An open web platform is developed to facilitate sharing and replication of experiments. The method’s efficacy is demonstrated through five case studies, including a regression analysis across 25 versions of Autopsy, which uncovered numerous undocumented, substantial changes in its reporting output.
This study addresses the challenges in digital forensics posed by heterogeneous network data, whose incompatible schemas and timestamp formats hinder reliable evidence correlation and timeline reconstruction, while existing preprocessing methods suffer from poor reproducibility. To overcome these limitations, this work proposes a deterministic forensic preprocessing framework that transforms raw data into a standardized, reproducible form through three core operations: schema normalization, temporal normalization, and provenance tracking. The framework innovatively formalizes the preprocessing pipeline using set-theoretic constructs and rigorously proves its determinism, information preservation, and provenance completeness. Furthermore, it introduces a bounded-memory, chunk-based streaming architecture enabling scalable processing. Empirical evaluation on the UNSW-NB15, IoT-23, and TON_IoT datasets demonstrates 100% output consistency and efficient handling of datasets ranging from millions to hundreds of millions of records.
This work addresses the scarcity of production-grade Security Operations Center (SOC) logs for research due to stringent privacy constraints, which has led prior studies to rely on synthetic or outdated data. To bridge this gap, the authors propose a methodology that, for the first time, transforms real-world financial-sector SIEM logs into reusable research artifacts while adhering to strict privacy boundaries. The approach preserves investigation-relevant structures through structured anonymization, mapping to the MITRE ATT&CK framework, deterministic validation, and large language model (LLM)-based behavioral compliance checks. The resulting artifact comprises 37 HIKARI challenges suitable for effective model training and demonstrates its utility by accurately identifying LLM policy violations across 200 SOCpilot incidents, thereby validating its balanced trade-off between privacy preservation and analytical fidelity.
This study addresses the forensic challenge posed by proprietary surveillance device file systems, which lack public documentation and hinder video data recovery after deletion. Focusing on Honeywell’s private file system, this work presents the first systematic analysis of three deletion mechanisms—formatting, data expiration, and overwriting—by integrating binary comparison, file system reverse engineering, metadata analysis, and data recovery techniques. The investigation reveals distinct residual characteristics of video data under each deletion method and demonstrates the practical feasibility of recovering deleted footage. Furthermore, the research establishes a reusable methodological framework for digital forensics on similar proprietary file systems, significantly enhancing both the efficiency and accuracy of forensic investigations.