# DFRWS EU 10-Year Review and Future Directions in Digital Forensic Research

## Full Text

This Markdown is an automated text extraction for search and reading tools. The [hosted PDF](10YearReviewAndFutureDirectionsDigitalForensic.pdf) is the authoritative publication source.

Source PDF: [10YearReviewAndFutureDirectionsDigitalForensic.pdf](10YearReviewAndFutureDirectionsDigitalForensic.pdf)
Source SHA-256: `6fe9593b1bf093bf0e173bbc211727d79a5d8b3bd65a2ef8a1571d00c14212a0`
Generated with `pdftotext -nopgbrk`; formatting and reading order may differ from the PDF.

---

Forensic Science International: Digital Investigation 48 (2024) 301685

Contents lists available at ScienceDirect

Forensic Science International: Digital Investigation
journal homepage: www.elsevier.com/locate/fsidi

DFRWS EU 2024 - Selected Papers from the 11th Annual Digital Forensics Research Conference Europe

DFRWS EU 10-year review and future directions in Digital
Forensic Research
Frank Breitinger a, *, Jan-Niclas Hilgert b, Christopher Hargreaves c, John Sheppard d,
Rebekah Overdorf a, Mark Scanlon e
a

School of Criminal Justice, Faculty of Law, Criminal Justice and Public Administration, University of Lausanne, 1015 Lausanne, Switzerland
Fraunhofer FKIE, Bonn, Germany
Department of Computer Science, University of Oxford, United Kingdom
d
Department of Computing and Mathematics, South East Technological University, Waterford, Ireland
e
Forensics and Security Research Group, School of Computer Science, University College Dublin, Ireland
b
c

A R T I C L E I N F O

A B S T R A C T

Keywords:
Digital forensics research
Digital forensic science
DFRWS
Research trends
Future directions

Conducting a systematic literature review and comprehensive analysis, this paper surveys all 135 peer-reviewed
articles published at the Digital Forensics Research Conference Europe (DFRWS EU) spanning the decade since its
inaugural running (2014–2023). This comprehensive study of DFRWS EU articles encompasses sub-disciplines
such as digital forensic science, device forensics, techniques and fundamentals, artefact forensics, multimedia
forensics, memory forensics, and network forensics. Quantitative analysis of the articles’ co-authorships,
geographical spread and citation metrics are outlined. The analysis presented offers insights into the evolution
of digital forensic research efforts over these ten years and informs some identified future research directions.

1. Introduction
The first Digital Forensic Research Workshop (DFRWS) was held in
the USA in 2001 and produced the seminal report: “A Road Map for
Digital Forensic Research” (Palmer et al., 2001), which has informed
digital forensics research for over two decades. Since then, the
not-for-profit DFRWS organisation was formed and now organises three
digital forensic academic conferences each year; DFRWS USA, EU (est.
2014), and APAC (est. 2021).
The DFRWS EU conference has significantly contributed to the dig­
ital forensic research community in Europe and globally through many
publications, keynotes, workshops, tutorials, panels, and community
discussions and networking. However, the priorities of the DFRWS EU
research community have not been studied. Consequently, this paper
serves as a review of the accepted full research papers published in the
ten years of proceedings of DFRWS EU 2014–2023 to analyse the impact
of the conference’s output. As part of the discussion, potential future
research directions and best practices are discussed, aiming to increase
the discipline’s research efforts and foster its development into a more
mature scientific domain.

Related work. There are other trend analysis papers for digital fo­
rensics, with “Digital forensics research: The next 10 years” by Garfinkel
(2010) being the most cited. Since this initial work from 2010, a similar
study has been published by Luciano et al. (2018). Other works took a
slightly different approach and considered trends, such as number of
publications, primary vs. secondary research, citation counts, country of
origin, academia vs industry, type of publication, and keywords used
(Dezfoli et al., 2013; Baggili et al., 2013; Caviglione et al., 2017; Hors­
man and Aney Biju Mammen, 2020). Given all the review articles, Ca­
sino et al. (2022) decided to do a review of reviews where they reviewed
109 review papers and 51 reports and identified seven research areas in
digital forensics. They also included a year-wise analysis of the literature
reviewed. The most recent article is by Reedy (2023) and includes ref­
erences to 260 papers from multiple journals. While DFRWS EU was not
cited specifically, it did include those from the special DFRWS pro­
ceedings issues of FSI: Digital Investigation. Focusing a survey on a
specific conference provides highly contextualised insights and en­
courages community engagement, while tracking the conference’s
evolution and its impact on the field. In addition, this approach facili­
tates tailored recommendations and insights. With DFRWS EU’s decade

* Corresponding author.
E-mail addresses: frank.breitinger@unil.ch (F. Breitinger), hilgert@cs.uni-bonn.de (J.-N. Hilgert), christopher.hargreaves@cs.ox.ac.uk (C. Hargreaves), john.
sheppard@setu.ie (J. Sheppard), rebekah.overdorf@unil.ch (R. Overdorf), mark.scanlon@ucd.ie (M. Scanlon).
https://doi.org/10.1016/j.fsidi.2023.301685
Available online 15 March 2024
2666-2817/© 2024 The Author(s). Published by Elsevier Ltd on behalf of DFRWS. This is an open access article under the CC BY-NC-ND license
(http://creativecommons.org/licenses/by-nc-nd/4.0/).

F. Breitinger et al.

Forensic Science International: Digital Investigation 48 (2024) 301685

milestone, a longitudinal study spanning this ten-year period for this
particular venue emerges as a significant point of interest within the
community.
Contributions. This paper makes the following contributions.

(Gruber et al., 2023a; Schneider et al., 2021; Ottmann et al., 2022;
Coates and Breitinger, 2022) were added manually to the analysis.

• A systematic review and categorisation of all 135 full research
DFRWS EU articles from 2014 to 2023.
• Quantitative analysis and visualisation of the articles’ metadata
including co-authorship patterns, geographical spread, and citation
metrics.
• Potential future directions are suggested to aid digital forensic re­
searchers in setting their research agendas.

Step 1 - Screening: Articles were sorted by year for initial screening
by an individual. This step aimed to create, gather, and assign pre­
liminary tags, e.g., theme and content. Each article was given a main
category, potential tags, and identified trends. For example, Boztas
et al. (2015) produced:
DFRWS session title: Investigating New Hardware
Main category: Device forensics
Other possible tags: Small-scale device forensics, artefact, data
acquisition, data analysis
Possible trends: Experiment
Step 2 - Classification creation: The gathered main categories and
possible tags were generalised to narrow down this exhaustive list.
This resulted in a classification, which is explained in the next step.
Step 3 - Article organisation: Each article was reviewed and sum­
marised. Based on the summary and classification, articles were then
re-tagged to match one of the categories, and then re-reviewed with
this categorical context.
Step 4 - Analysis and synthesis: Lastly, the collected information
was analysed and identified common themes, patterns, or trends
across the literature.

2.2. Qualitative analysis methodology

Article Outline. First, the methodology used is outlined, followed by
the Quantitative Insights and the Qualitative Findings. Based on the
analysis, some Future Directions: Research and Best Practices are out­
lined. The last two sections provide the Limitations and the Conclusion.
2. Quantitative and qualitative methodology
The relatively small dataset size necessitated a focus on content for
qualitative and metadata for quantitative analysis, maximizing the value
of each approach.
Article Collection. Accepted articles are published open access in a
special issue of Elsevier’s Forensic Science International: Digital Inves­
tigation (FSI: DI, formerly Digital Investigation). However, authors may
opt-out of Elsevier publication. Consequently, the majority of articles
were accessed via the Elsevier website and the non-Elsevier articles were
added manually. Extended abstracts, posters, etc., were not included.

Classification. The need for a new classification arose from the un­
suitability of existing ones. Existing, focused taxonomies, such as data
fragment classification techniques by Poisel et al. (2014, Fig. 1), and
memory acquisition techniques by Latzo et al. (2019), are com­
plemented by broader ones like IoT Forensics by Yaqoob et al. (2019,
Fig. 4). However, these are still insufficient. Comprehensive taxonomies
like by Casino et al. (2022) and Wu et al. (2020) cover domains such as
multimedia, cloud, IoT, blockchain, and computer, but neglect aspects
like digital forensic process or evidence validation. Consequently, the
classification developed, shown in Fig. 1, differs from existing ones. It
does not claim to encompass all of digital forensic science, but reflects a
decade of DFRWS EU publications.

2.1. Quantitative analysis methodology
Elsevier’s Article and Abstract APIs were used to collect quantitative
information on all available papers including author names, affiliations,
institutions, countries, and article keywords, abstracts, and text. This
dataset was then augmented with the total and yearly citation data,
which is accessible via Google Scholar. The data were collected on Sept.
5, 2023.
Dataset Limitations. One paper (Gruber et al., 2023a) was not listed on
Google Scholar. Four DFRWS self-published, i.e., non-Elsevier, papers

Fig. 1. Categorisation of DFRWS EU published work with indications of the numbers of papers and best paper awards per category.

2

F. Breitinger et al.

Forensic Science International: Digital Investigation 48 (2024) 301685

3. Quantitative insights
3.1. Citations
Fig. 2 shows yearly citations for each DFRWS EU paper as of Sept. 5,
2023. The graph is dominated by the two most cited papers from Karbab
et al. (2018) and Servida and Casey (2019). Excluding 2023 papers, all
received at least one citation. The average and median citations were
23.6 and 13.0, respectively. 73.3 % of papers had 5 or more citations,
57.0 % had 10 or more, 11.9 % had 50 or more, and 2.2 % had 100 or
more.
3.2. Author countries
Fig. 3 illustrates the diversity of DFRWS EU author affiliations by
country. While most authors are based in European institutions,
particularly Germany (aside from 2015), there are consistent contribu­
tions from outside Europe. In 2023, non-European authors even out­
numbered European. The graph also highlights the COVID-19
pandemic’s effect on geographical diversity (2020–2022 saw fewer nonEuropean papers), and the impact of DFRWS APAC’s establishment in
2020 (noted by a decrease in Asian-based papers).

Fig. 4. A graph (Bastian et al., 2009) demonstrating the co-authorship ac­
cording to the country of the authors’ institutions. All authors of the paper (not
only the primary) were considered and for authors with multiple affiliations in
different countries, the first listed was chosen. Each node represents a country
C i and an edge between nodes N C i and N C j indicates that an author from C i
co-authored a paper with an author from C j . The edges are weighted by the
number of collaborations. Note that all countries have self-loops, indicating that
authors from the same countries collaborated on the same paper. Nodes are
coloured by continent. Node size is determined by degree.

Fig. 4 indicates significant collaboration between authors from
different countries and continents, despite most submissions coming
from Europe. While many cross-institution papers originate within the
same country, particularly Germany and the US, the graph’s diverse
non-self connections reveal numerous cross-country collaborations.

Fig. 2. Citations per year. Each line represents a single paper and the number
of citations it receives per year. The coloured lines are the three papers with the
highest citations.

3.3. Author collaborations
Fig. 5 displays DFRWS EU author collaborations. Most clusters are
small and isolated, indicating single papers by authors with no other
DFRWS EU papers. Some of the larger clusters are interconnected —
Green (centred around node A) to Blue (containing nodes G, E, and H)
and Gold (centred around node C) to Purple (containing nodes B, F, and
D). The largest two clusters have 31 nodes. The first is centred around a
single author, Felix Freiling (A). The gold cluster shares this structure,
centred around Mourad Debbabi (C). Some smaller clusters follow a
related “bow tie” pattern, with one main author having 2 papers with 2
sets of co-authors. The other largest cluster, in purple, has several larger
nodes (B - Mark Scanlon, D - Nhien-An Le-Khac, and F - Elias Bou-Harb)
linking many smaller ones, indicating regular collaboration within the
cluster. The blue cluster has the same structure, although with fewer
connections. The three larger nodes are G - Harald Baier, E − Frank
Breitinger, and H - Ricardo J. Rodríguez. The large pink cluster at the top
with no central node stems from a single paper (Park et al., 2018) with
authors not involved in other DFRWS EU papers. The majority of the
remaining clusters result from single-paper publications.

Fig. 3. The number of authors per affiliation country per year. The left-most
bar for each year represents the number of authors from Europe, the next
from the Americas, etc. Note that this graph does not take into account the
relatively rare case of multiple papers by the same author in a single year. Such
authors are intentionally counted multiple times in the graph, since the aim is
to understand where authors come from by paper – not on an individual level.

3

F. Breitinger et al.

Forensic Science International: Digital Investigation 48 (2024) 301685

memory dumps). \Henseler and van Loenhout (2018) focused on edu­
cation judges, prosecutors and lawyers (intersection of law & policy)
while Hitchcock et al. (2016) discussed a training model for field triage
for first responders. Lastly, Freiling and Zoubek (2017) conducted a
student experiment among graduate students aimed at exploring factors,
strategies, and tools that impact the outcome of an investigation.
Standardisation also received significant attention, although the
contributions do not evenly spread over the years. Most of the work in
this category targeted a unified representation of information. For
instance, Cruz et al. (2015) presented a distributed data storage format
that leverages AFF4 and can be used for incident response, Casey et al.
(2015) explored CybOXTM for storing and sharing digital forensic in­
formation, and Stelly and Roussev (2018) presented Nugget a
domain-specific language. Concerning setting standards, three articles
were found. Amann and James (2015) aimed at building robustness and
resilience investigation laboratories based on survey findings, while
Nemetz et al. (2018) presented a corpus of SQLite databases, which may
be used as a standardised dataset. Ottmann et al. (2022) outlined quality
criteria for ‘forensically sound’ acquisition of main memory. Lastly, Park
et al. (2018) conducted a case study on the data protection legislation
and government standards to implement Digital Forensic Readiness as a
mandatory requirement.
The digital forensic process as a whole was targeted by 12 publica­
tions. This category includes works targeting to improve the process or
evidence handling. Thus, articles focusing on evidence validation,
evaluation, interpretation, or attribution can be found here. Biedermann
and Vuille (2016), Mutawa et al. (2016), Gruber et al. (2023a, 2023b)
discussed various aspects of improving the handling, presentation, and
understanding of digital evidence in forensic investigations. Topics
included comprehensive evidence presentation, behavioural analysis,
and addressing contamination risks. Schneider et al. (2021) com­
plemented these thoughts by showcasing that a significant portion of
low-cost USB flash drives sold as original contained non-trivial user
data, highlighting the widespread issue of poor sanitisation practices
and potential implications for forensic investigations. Karafili et al.
(2020), Franqueira and Horsman (2020), Casey et al. (2020) introduced
advanced tools and methods to aid forensic analysts in conducting in­
vestigations and producing high-quality reports. The research focused
on argumentation-based reasoners and structured argumentation tech­
niques to improve communication, quality, and analysis. Within the
area of the digital forensic process is the work by van Baar et al. (2014)
who described Digital Forensics as a Service (DFaaS) and thus a para­
digm shift. Pringle and Burgess (2014) presented FCluster, which serves
as middleware, offering a secure environment for forensic data pro­
cessing, ensuring data integrity control rather than functioning as an
application program.
Other papers focused on the uncertainty within digital forensic
traces. For example, Sandvik and Årnes (2018) conducted an investi­
gation into the reliability of clocks under low power conditions, and
showed that this can cause clocks to adjust, but at present it is not
possible to say how likely such behaviour is. Spichiger (2023) presented
an approach to evaluate potentially unreliable location-based evidence
gathered by mobile phones using a reference device. Lastly, one article
fell into Law & Policy, namely the work by Sokol et al. (2020) who
explored the use of IP addresses in court decisions, examining their role
as digital evidence and issues related to anonymization.

Fig. 5. A graph (Bastian et al., 2009) exhibiting author collaborations. Each
node represents an author A i and an edge between nodes N A i and N A j in­
dicates that authors A i and A j co-authored a DFRWS EU paper. The colours
represent communities with more than 7 members, per Blondel et al. (2008)’s
community detection. The 10 largest are coloured, and the authors with the
most publications (at least 5) are labelled (A–H). Node size is determined by the
number of papers. (For interpretation of the references to color in this figure
legend, the reader is referred to the Web version of this article.)

3.4. Best paper awards
Fig. 1 provides an overview of the distribution of the 16 Best Paper
Awards1 that were awarded since the establishment of DFRWS EU across
our classification. While the data does not point to a singular research
area being favoured by the forensic community, there is a noticeable
concentration of awards in the fields of Digital Forensic Science, Device
Forensics, and Memory Forensics, highlighting their significance in the
community. Notably, areas such as Multimedia, or Artefact Forensics
have not received awards.
4. Qualitative findings
The following subsections, corresponding to the green boxes in
Fig. 1, organise the qualitative analysis into categories aiming to provide
a thematic overview of DFRWS EU research.
4.1. Digital forensic science
This category encompasses general topics, including standardisation,
legal and ethical considerations in digital investigations, and improving
the reliability and resilience of digital investigations, education, and the
investigative process. A total of 25 papers belong to this category –
highlighting the importance of establishing foundational principles in
this practitioner-oriented field.
Education-related articles mostly overlap with other Digital Forensic
Science categories. Specifically, two articles presented data synthesis
frameworks, EviPlant by Scanlon et al. (2017) and ForTrace by Göbel
et al. (2022), which can be used to create scenarios (e.g., disk images,

4.2. Device forensics
The forensic analysis of digital devices has been present at each
iteration since the first DFRWS EU. Mobile device forensics has focused
on several platforms. Iqbal et al. (2014) addressed the acquisition and
analysis of Windows tablet artefacts running the Windows RT operating
system, a version of Windows 8 designed to run on ARM architectures.
Minnaard (2014) analysed the memory of an Android phone, two
wireless routers and two HP laptops, one running Windows and the

1
Including ten annual Best Paper and six Best Student Paper Awards intro­
duced in 2019, of which two were awarded in 2020.

4

F. Breitinger et al.

Forensic Science International: Digital Investigation 48 (2024) 301685

other Linux, to determine the longevity and types of traces left behind
from radio signals of nearby and in range 802.11 networks in a range of
environmental and configuration states. Saleem et al. (2016) looked at
the application of multi-criteria decision analysis to ensure investigators
chose the most appropriate tools. The work was evaluated by comparing
two tools on two mobile devices in several different instances of illegal
activity. Groβ et al. (2021) proposed a method for the recovery of
encryption keys on Android devices with file-based encryption. Jennings
et al. (2023) examined the Apple Health database (from the Apple
iPhone and Apple Watch), for inaccuracies and inconsistencies around
time and location data in the context of workout activities.
Servida and Casey (2019) examined home-based IoT devices, e.g.,
alarms and surveillance cameras, and their associated smartphone ap­
plications to extend approaches for the IoT trace collection and analysis.
While general mobile device forensics methods could be used, the au­
thors found that IoT platforms sometimes require device-specific ap­
proaches. Torabi et al. (2020) used AI to detect compromised IoT
devices, infer and monitor scanning and botnet campaigns, and discover
DDoS victims based on backscattered packets towards the darknet.
Zhang et al. (2020) published a case study on reverse engineering the
Mirai botnet command and control server-side executables and live
processes that were extracted from the memory and disk images from a
controlled installation. The authors summarised their findings in a road
map for Mirai botnet server forensics to aid future investigations.
Safaei Pour et al. (2019) proposed a data-driven methodology,
dubbed L1-PCA, to infer and characterise Internet-scale IoT exploita­
tions. The authors correlated large volumes of network telescope data
with IoT-specific information to identify patterns of IoT probing cam­
paigns. The authors identified IoT-orchestrated campaigns using
Shodan-searching for open resolvers that can be abused for performing
amplification attacks.
Sandvik et al. (2022, 2023) published two papers on IoT forensics.
The first paper introduced a model to quantify data volatility in IoT
devices and implemented it on Contiki OS and the Coffee File System,
approximating data lifetime based on system data writing processes.
Building upon this, the authors extended their research to fog systems,
highlighting challenges like identifying data processing nodes and the
need for efficient triage methods. They proposed a technique for pri­
oritising evidence collection in fog systems by calculating the weight of
paths passing through nodes based on service probabilities.
Fukami et al. (2017) presented a study on NAND flash memory
chip-off analysis that explored thermal-based chip-off methods’ impact
on raw bit error rates, showing an increase of up to 259 %. The paper
introduced a mitigation strategy that leverages NAND manufacturers’
read-retry mechanisms, reducing raw bit error rates by 94.6 %. van
Zandwijk (2017) used bit-error statistics in NAND flash as a source of
forensic information was evaluated. Files were added to USB drives
through the controller at different retention times, examining how
retention time differences were reflected in the statistics of bit errors.
Sayakkara et al. (2020) explored electromagnetic side-channel
analysis for uninstrumented software activity monitoring on an IoT
device. They utilised a HackRF software-defined radio to capture EM
emissions from an Arduino Leonardo. Automated feature selection was
employed to identify the most relevant input channels out of 20,000,
reducing data for machine learning models by 99.5 % while maintaining
over 93 % accuracy.
There have been three papers looking at the acquisition and analysis
of evidence from entertainment devices. Boztas et al. (2015) investi­
gated a Samsung smart television, Davies et al. (2015) looked at a Sony
Playstation 4 running several firmware versions, and Barr-Smith et al.
(2021) examined a Nintendo Switch. More recently, there have been two
papers on automotive forensics. Gomez Buquerin et al. (2021) examined
the feasibility of automotive forensics using a generic automotive
forensic process on a state-of-the-art vehicle over an OBD diagnostics
interface to collect data from ECUs and identified gaps that need to be
addressed. Lee et al. (2023) offered approaches to data analysis and

recovery of evidence from built-in video devices such as those used for
dashcam footage in Kia, Hyundai, and Genesis vehicles. Bordjiba et al.
(2018) presented a framework for the detection, mitigation, and inves­
tigation of phone call scamming campaigns based on complaints that
originated at device end-points. Other niche areas of device forensics
have included the extraction and analysis of data from a Programmable
Logic Controller found in industrial control systems (Rais et al., 2022),
and a forensic readiness framework for investigations following the
sabotage of components produced during the 3D printing process (Rais
et al., 2023).
4.3. Digital forensic techniques and fundamentals
Papers in this section represent techniques that are used in some
phases of the investigative process: either improvements to acquisition,
techniques used as part of the analysis or overall process improvements
such as triage.
In terms of acquisition, Freiling et al. (2017) analysed the effect of
abstraction layers on forensic evidence acquisition. The authors were
the first to formally characterise the loss of digital evidence from only
having access to data at higher levels of abstraction, e.g., cloud storage,
as opposed to traditional low-level data acquisition, i.e., physical com­
plete storage acquisitions – with the difference being referred to as the
semantic gap. This semantic gap broadens further in virtualised envi­
ronments where data is mapped from virtualised blocks to underlying
storage blocks and in TRIM-enabled SSDs.
Alendal et al. (2018) published reverse engineering of Samsung’s
secure boot enforced common criteria mode and a corresponding tech­
nique to circumvent it to facilitate forensic acquisition from the device.
Disabling this mode, featured on several Samsung devices, through the
leveraging of a security vulnerability discovered as part of their
research, the authors open the device up to direct storage and RAM
acquisitions by misusing the devices’ firmware update protocol.
Closser and Bou-Harb (2022) authored the first DFRWS paper to
discuss the acquisition of forensic information from quantum mechani­
cal computers. Their work introduced a live forensic recovery approach
and a proof-of-concept experiment targeting quantum computer gates
with the view to recovering binary values from a quantum system. The
authors highlighted the unique forensic challenges posed by quantum
computer forensics, including decoherence, entanglement and noise.
Zoubek and Sack (2017) proposed a selective deletion method for
legal data protection in digital evidence acquisition and storage. This
method, implemented as a plugin for the Digital Forensic Framework
(DFF), allows the deletion of non-relevant or privileged data and asso­
ciated metadata, preserving the authenticity and integrity of the evi­
dence. The forensic examiner specifies the data to be removed. While the
implementation focused on NTFS-structured devices, the authors sug­
gested its extensibility to other file systems.
Several papers have discussed triage techniques to enhance the
digital forensic process. Vidas et al. (2014) introduced OpenLV
(formerly LiveView), a triage tool that maps a disk image to a virtual
hard disk, bypassing login passwords for virtualisation and booting. This
facilitates an easier review of the image content using the Windows OS
to explore the data live, albeit virtualised. It is advantageous with
specialist software or for creating suspect system screenshots. Har­
greaves and Marshall (2019) presented a novel triage approach using
synchronisation artefacts from one device to infer content or events on
another, potentially inaccessible or absent device. Demonstrated with a
prototype, SyncTriage, this technique aims to expedite investigations by
partly bypassing the ‘gain access’ phase of the digital forensic process.
While SyncTriage attempts to bypass the problem of gaining access,
other papers present techniques for breaking into encrypted data. Kanta
et al. (2023) considered optimising word lists for performing dictionary
attacks based on suspects’ interests, and importantly also ranks the
words in the wordlist to try to accelerate identifying the correct pass­
word. Bichara de Assumpção et al. (2023) provided a method for
5

F. Breitinger et al.

Forensic Science International: Digital Investigation 48 (2024) 301685

retrieving the BitLocker Volume Master Key from a TPM for data
decryption.
In addition to triage, comprehensive investigation techniques have
also been explored. Bollé and Casey (2018) advocated for searching
links between artefacts in cases, demonstrated with email addresses and
tested with 207 real cases. Open-source intelligence, often considered a
related field, was discussed by Matthews et al. (2021). The study
involved collecting, analysing, and presenting open data from Snapchat,
with discussions on provenance and reliability. This prompts the ques­
tion of integrating open-source intelligence within digital forensics,
rather than it being a separate entity.
Other analysis techniques broadly relate to data recovery. Zoubek
et al. (2016) discussed an approach for data recovery from RAIDs by
automatically detecting the RAID parameters using block-level entropy
measurement and generic heuristics. Both Dewald and Seufert (2017)
and Bayne et al. (2018) considered data carving. The former uses a
pattern-based data carving method to search for metadata structures of
inodes in ext4 (discussed in file system artefacts in 4.4). The latter shows
how GPUs can be leveraged to improve the performance of pattern
matching operations and focuses on the carving application of pattern
matching and provides a tool ‘OpenForensics’ to implement the concepts
in the paper. Sester et al. (2021) investigated the related area of file type
identification and surveyed methods available, which were divided into
signature-based, statistical approaches, and computational intelligence
approaches. It then goes on to advance this area with n-gram analysis
based on support vector machines and neural networks. A technique was
also presented by Wüst et al. (2017), which advances the ability to open
recovered corrupted files by monitoring a viewer program’s operation
when opening non-corrupt files, and then instruments while opening
one that is corrupt - referred to as a ‘force open’ approach, evaluated on
PNG, JPG, and PDF files.
Nine papers have been published on hashing, approximate match­
ing/fuzzy hashing, and perceptual hashing. Martín-Pérez et al. (2021)
proposed a classification scheme for similarity digest algorithms, dis­
tinguishing them at three abstraction levels: bytewise, syntactic, and
semantic. The former compares the byte sequences forming the digital
artefacts, and the latter two utilise the artefacts’ internal structures and
contextual attributes, respectively. Martín-Pérez et al. (2021) also out­
lined potential attacks against these algorithms, including collision,
inversion, and substitution attacks.
Approximate matching can be used in three contexts; searching, e.g.,
alternative/similar version detection, streaming, e.g., file transfer
detection, and clustering, e.g., organising an unknown input set (Bjel­
land et al., 2014). Breitinger and Roussev (2014) proposed an auto­
mated approximate matching evaluation framework by relating
approximate matching results to the longest common substring (LCS)
using real-world data. LCS was proposed as the technique to be used for
a ground truth determined by algorithmic means – facilitating the
automated testing, evaluation and comparison of approximate matching
algorithms.
Hashing and approximate matching are computationally intensive,
with approximate matching being more demanding (Breitinger et al.,
2014). Published work focused on improving the speed of these tech­
niques in digital forensic investigations (Breitinger et al., 2014; Winter
et al., 2014; Penrose et al., 2015; Liebler et al., 2019). Breitinger et al.
(2014) introduced an approximate matching technique that reduces
lookup complexity from O (x) to O (1) for known file matching. Winter
et al. (2014) presented hash indexing strategies based on metric trees
and locality-sensitive hashing. Penrose et al. (2015) outlined a fast triage
contraband detection approach with 99.9 % accuracy, employing partial
disk cluster sampling and pre-computed Bloom filters. Liebler et al.
(2019) extended three approximate matching lookup strategies, i.e.,
hash-database for hash-based carving (hashdb), hierarchical Bloom
filter trees (hbft), and (3) flat hash maps (fhmap), each with its ad­
vantages and disadvantages depending on the use case. Coates and
Breitinger (2022) presented a novel approach for identifying document

similarity using a fast estimation of the Levenshtein Distance based on
compressing documents in signature representations and using those
signatures for comparison. Liebler and Baier (2019) introduced apx-­
bin, an approach combining cryptographic hashing and approximate
matching for executable binary-related similarity. This addresses vari­
ations due to compiler settings and modifications, enhancing executable
classification.
McKeown and Buchanan (2023) explored perceptual hashing for
robust image signatures, considering features like histograms, statistical
data, colour, texture, edge histograms, and frequency domain stats. They
evaluated perceptual hashing methods, such as PDQ, Neuralhash, and
pHash library, assessing their performance through Hamming distance
scores between unrelated images and variants.
There are also various other techniques presented that broadly are
categorised as ‘behaviour analysis’. At a low level, Alrabaee et al. (2015)
discussed a technique for detecting reused functions in binary code and
provided a demonstration of identifying the RC4 function in Zeus reused
from the Citadel malware. Other techniques include authorship verifi­
cation, i.e., determining if two documents originate from the same
author, and Halvani et al. (2016) presented a technique to group
browser activity into ‘sessions’ which allows inference whether activity
is one-off or repetitive (Gresty et al., 2016).
This shows that while some techniques receive significant attention,
e.g., hashing, other practical areas have had fewer published papers at
the conference, such as triage, gaining access to encrypted data, and
behavioural analysis.
4.4. Artefact forensics
This section discusses papers that investigate the artefacts, or
forensic traces left by some part of the technology stack (file systems,
operating systems, applications). Despite it being a core area, only 14
papers were published.
Five papers were identified targeting file system artefacts. These
papers cover both relatively new file systems but also include forensic
advancements concerning well-established file systems. Lanterna and
Barili (2017) discussed ‘deduplicated’ file systems and covered both
OpenDedup and the Windows 2012 Deduplication (W2012Dedup),
including a deep dive into the hexadecimal of file chunk storage, and the
higher-level implications for deleted file recovery. Prade et al. (2020)
covered the less common file system ReFS and built on existing work to
analyse the internal structures and develop a page carver for deleted
data. The work includes an extension of The Sleuth Kit to include sup­
port for ReFS, providing practitioners with a practical means of
accessing data within this file system (Dewald and Seufert, 2017).
considered file carving on ext4 (also included in Sec 4.3). The authors
used a pattern-based data carving method to search for metadata
structures of inodes allowing improved recovery of data from ext4 file
systems. Nordvik et al. (2019) focused on NTFS, specifically the Object
ID Index, including multiple experiments with file creation, copying,
moving etc. and shows how this artefact can be used to link external
devices to computers to which it has been attached, detect manipula­
tions, and show which boot session a file belongs to. Finally, a more
general technique by Bahjat and Jones (2019), discusses a new method
for assigning dates and times to file fragments based on the other data
that they are surrounded by, further developing the digital stratigraphy
technique.
A total of four papers on Operating System Artefacts were published,
with the first of these appearing in 2019. Of the four papers, one had a
focus on Windows forensics, two on macOS forensics, and one examined
several Unix-based operating system artefacts including macOS. Atwal
et al. (2019) conducted eight experiments on the macOS Spotlight to
determine occasions when metadata records for deleted files persist in
the metadata store, and when they are recoverable from the unused
space on the filesystem. Palmbach and Breitinger (2020) focused on the
Windows Operating System and its resilience to timestomping
6

F. Breitinger et al.

Forensic Science International: Digital Investigation 48 (2024) 301685

techniques. The scope of the experiments was limited to the use of three
timestomping tools on the artefacts $LogFile, prefetch, $USNjrnl,
*.lnk files and Windows event logs. From the experiments, the authors
presented five rules for the detection of timestamp inconsistencies on
Windows systems. A study of timestamp behaviour was conducted by
Thierry and Müller (2022) on Linux, OpenBSD, FreeBSD and macOS to
determine what timestamps are modified by a given operation. The
authors also present a framework for testing POSIX compliance for a
selection of software libraries and applications on the operating systems.
Additionally, the authors examined the effects of timestomping on
MACB timestamps on these systems. More recently, Joun et al. (2023)
proposed a methodology to identify potential evidence spoliation by
finding all available traces relating to deleted files on macOS systems,
alongside a tool and released a dataset as part of the work.
Given the importance of understanding artefacts that are generated
by the use of software, there are surprisingly few papers that provide an
analysis of application-level artefacts. BitTorrent Sync is discussed by
Farina et al. (2014). Schipper et al. (2021) covered the Riot.im appli­
cation that uses the Matrix protocol. On the mobile side, van Zandwijk
and Boztas (2019) examined Apple Health, focusing on determining the
accuracy of steps and distances recorded, which involved the use of 600
trials by five subjects, including analysis of where on the body the device
was located. Also in the mobile area, Horsman and Conniss (2015) take a
more ‘offence focused’ approach considering driving offences, doc­
umenting artefacts such as CurrentPowerlog.powerlog on iOS to
differentiate normally answered calls from those answered hands-free,
or to determine if a device was unlocked, or that applications have
been used.
Formalised and peer-reviewed artefact analysis is surprisingly
scarce, likely due to the rapid evolution of artefacts and the difficulty in
creating specific experimental data. However, some research does adopt
a more general approach to artefacts, e.g., Choi et al. (2019) considered
three messenger applications (KakaoTalk, NateOn, QQ messenger) but
the focus is also on the encrypted backing store databases. This provides
generalisable findings, but with those specific applications as examples,
therefore providing both short and long-term contributions.

Numerous studies addressed memory acquisition challenges. Among
these, Bauer et al. (2016) investigated cold-boot attacks on DDR3
memory. They discovered that vendors’ scrambling of memory to pre­
vent undesired side effects posed challenges for forensic investigators,
necessitating descrambling for detailed examination. In response, they
proposed a technique requiring at most 128 bytes of plain text for
content retrieval. A year earlier, Stüttgen et al. (2015) identified firm­
ware rootkits as a significant threat – highlighting the potential of
acquiring firmware through memory forensics, specifically by capturing
specific ranges often overlooked by standard acquisition tools. A
comprehensive evaluation of 12 memory acquisition methods spanning
from user-mode tools to kernel-level, DMA, emulation, and virtualisa­
tion techniques was presented by Gruhn and Freiling, (2016). Using
atomicity and integrity as benchmarks, their results highlighted the ef­
ficacy of user-mode tools for process memory, while cold-boot attacks
and virtualization were best for full dumps. They also found that
kernel-level methods often violated the integrity by altering the content
within memory. While the software tools evaluated by Gruhn and
Freiling (2016) only focused on Windows, Stüttgen and Cohen (2014)
presented a Linux technique using a ‘parasite’ kernel module for
version-independent memory acquisition – later added to the Rekall
framework.
With respect to innovative acquisition methods, Latzo et al. (2020)
introduced BMCLeech, a framework leveraging Baseboard Management
Controllers (BMCs) – co-processors designed for server management.
Although the method had constraints, like accessing only the initial
4 GiB of memory, it emerged as a notably stealthy memory acquisition
technique. Zubair et al. (2022) explored the growing realm of Industrial
Control Systems, presenting a novel method for acquiring memory from
Programmable Logic Controllers, commonly found in this sector. Addi­
tionally, they detailed potential threats and their identification based on
the retrieved memory. Recent research delved into memory acquisition
techniques leveraging the UEFI (Tobias Latzo Florian Hantke and
Freiling, 2021). The authors introduced a methodology and corre­
sponding implementation, allowing investigators to mimic a cold-boot
attack by executing the acquisition code straight from the UEFI,
resulting in a notably high atomicity.
Accurate identification of operating system structures is essential for
subsequent memory analysis. Cohen (2015) examined the variations of
structures and offsets across different versions of Windows and its
Kernel. After analysing multiple versions of the Kernel and a specific
Windows driver, Cohen observed that while structure layouts remained
largely consistent across versions, global constants showed significant
variations. Within the Linux domain, Socała and Cohen (2016) intro­
duced an automated profile generation methodology, which poses a
challenge given the multitude of kernel versions and configurations to
account for. Their innovative technique, integrated into the Rekall
framework, harnesses the kernel’s source code and real-time target
system data to generate viable profiles.
Windows in-memory analysis research has been a focal point in
recent years. Sylve et al. (2016) addressed the time-consuming issue of
scanning memory for Windows kernel object allocations by limiting the
scan to specific memory pages, identified through a special bitmap
structure. However, this more performant method may miss artefacts
outside the Kernel’s current virtual address space. Otsuki et al. (2018)
introduced a technique for reconstructing stack traces in Windows x64
memory dumps, with case studies on malware analysis. Fernández-Ál­
varez and Rodríguez (2023) discussed DLL injection in Windows, a
malware capability, and proposed a solution to locate DLLs in a process’s
memory by combining pages of the same DLL across multiple processes
and dumps. Uroz and Rodríguez (2020) explored the value and chal­
lenges of verifying digitally signed files extracted from memory in
Windows memory analysis.
A novel technique was introduced for the stealthy extraction of TLS
master secrets from memory (Taubmann et al., 2016). This method
employed virtual machine introspection to capture memory snapshots,

4.5. Multimedia forensics
Gloe et al. (2014) conducted a study on source device authentication
in AVI and MP4-like video streams. They discovered unique character­
istics across 19 digital cameras, 14 mobile phones, and 6 editing tools.
These traits allowed them to attribute devices to specific makes and
models based on variations in container formats, compression algo­
rithms, acquisition parameters, and file structure.
Mullan et al. (2019) ran a two-year study on JPEG image header
analysis. The authors focused on smartphone image provenance iden­
tification, covering various smartphone models, hardware iterations,
firmware versions, and imaging applications. In 2020, they extended
their work by creating an open-set model for camera-make prediction
using JPEG header data (Mullan et al., 2020). The model achieved over
90 % accuracy with unmodified images and 55–75 % for post-processed
images.
Two papers, DeepUAge (Anda et al., 2020) and Vec2UAge (Anda
et al., 2021), contributed to the automation of Child Sexual Exploitation
Material (CSEM) investigation through underage facial age estimation
using deep learning techniques on the VisAGe dataset. DeepUAge ach­
ieved a mean absolute error (MAE) of 2.73 years in 2020, while
Vec2UAge improved upon this in 2021, achieving an MAE of 2.36 years
using facial embeddings and a bespoke neural network.
4.6. Memory forensics
Over the past decade, memory forensics research has been a funda­
mental and steady focus of DFRWS EU, accounting for approximately 14
% of all published papers in this domain.
7

F. Breitinger et al.

Forensic Science International: Digital Investigation 48 (2024) 301685

followed by a brute force strategy to locate the master secret within. A
similar approach using virtual machine introspection for the extraction
of SSH key material was presented by Sentanoe and Reiser (2022).
However, their method requires knowledge about the memory layout of
the data structures used by the SSH implementation. Diving into more
specialised memory analysis, Pridgen et al. (2017) explored the recovery
of artefacts from runtime environments, notably the HotSpot Java Vir­
tual Machine. Additionally, Fernández-Álvarez and Rodríguez (2022)
shed light on traces present in the memory of the Telegram Desktop
Application for Windows, whereas Nissan et al. (2023) employed sup­
port vector machines to reconstruct query activities from memory
snapshots. Awad et al. (2023) worked on the memory structure of a
particular Programmable Logic Controller including forensic artefacts,
establishing a research foundation for this progressively vital domain.

which is usually loaded into memory for ARM architectures to avoid
cold boot attacks. Palutke and Freiling (2018) presented Styx which is a
system hiding itself in memory and overcoming tools performing
software-based memory acquisition. Göbel and Baier (2018) described
hiding information, i.e., steganography, in the ext4 timestamp attribute.
Freiling and Hösch (2018) (focus on disk) and Schneider et al. (2020)
(focus on memory) conducted experiments where graduate students had
to distinguish their forgeries from originals, and showed the difficulty of
the manipulation task. In particular, it showed that manipulation is
often more effortful than detection. Based on their findings, Schneider
et al. (2022) focused on assessing the factors contributing to successful
experiments in digital evidence tampering, drawing insights from pre­
vious studies and their experimental errors.
4.8.2. Malware
The work in malware has largely focused on malware detection and
code authorship. Alrabaee et al. (2014) presented a multi-layered
approach to code authorship by examining software library functions,
a code syntax dictionary and the way registers are manipulated. Based
on this initial work, Alrabaee et al. (2019) produced BinChar for code
authorship which used CNN and Bayesian probability. MalDozer, an
Android tool for the detection and attribution of malicious applications
using deep learning on API method calls, was presented by Karbab et al.
(2018). 2019 also saw a paper on the MalDy system, a malware detec­
tion and threat attribution framework using supervised machine
learning techniques (Karbab and Debbabi, 2019), a paper on the use of
similarity hashing for classifying Window Portable Executable malware
(Shiel and O’Shaughnessy, 2019), and work that provided a taxonomy of
Windows OS Auto-Start Extensibility Points (ASEP) and a Volatility
plugin called Winesap (Uroz and Rodríguez, 2019). An empirical study
on the behaviour characteristic of the most prominent software supply
chain attacks and an investigative framework that determines attack
likelihood in a piece of distributed software was presented by Andreoli
et al. (2023). Rathore et al. (2023) proposed Android malware detection
models and a defence strategy against adversarial attacks known as
MalV-Patch.

4.7. Network forensics
Research in cloud and network forensics, while not as dominant as
other areas, has seen significant advancements. A central challenge is
the amount of captured network traffic, often including irrelevant data
to the investigation. Divakaran et al. (2017) addressed this issue by
introducing a framework that identifies and correlates anomalous pat­
terns indicative of malicious actions. Their approach does not require a
learning phase and achieves high accuracy with a low false positive rate.
Another strategy employing Behavioural Service Graphs to extract evi­
dence from infected machines within a campaign is presented by Bou-­
Harb and Scanlon (2017). Moreover, Lamshöft et al. (2022) dived
deeper into malware in network traffic, presenting a threat analysis
centred around covert channels via syslog and port scans, while also
introducing a deep convolutional neural network-based detection
method. In addition to malware, Dinh et al. (2015) focused on spam.
They presented a software framework that extracts features from emails,
stores them in a central database and performs detection and catego­
risation into campaigns.
Turning to the intricacies of network forensics, Spiekermann et al.
(2017) addressed the complications in capturing data within virtual
environments, presenting a framework and tool for capture in
OpenFlow-controlled networks.
Gugelmann et al. (2015) presented a tool for HTTP/S analysis.
Harnessing correlation and frequent pattern detection, the authors first
limit existing events, which are subsequently visualised to represent a
timeline of HTTP and HTTPS activity.
The importance of cloud forensics was already highlighted by
Roussev and McCulley (2016). The authors examined Google Docs ar­
tefacts, outlining the limitations of traditional forensic approaches in
handling cloud-native artefacts. Additionally, Boucher and Le-Khac
(2018) discussed the often-overlooked aspect of synced evidence and
the ambiguity of artefact origin (local/synced) and proposed a novel
framework as a first step and demonstrated its application to Google
Chrome.
Recent research has ventured into the realm of cryptocurrency fo­
rensics. Thomas et al. (2022) introduced a blockchain query system
designed from a forensic point of view, ensuring the forensic soundness
of their implementation.

5. Future directions: Research and best practices
After a comprehensive analysis of ten years’ worth of research and
presentations at DFRWS EU, this section offers suggestions and recom­
mendations for strategically advancing the digital forensics field in the
evolving landscape of the future.
5.1. Artificial intelligence and digital forensics
AI’s use in digital forensics is growing, though it is still very much in
its early stages. Most existing research focuses on traditional AI appli­
cations – particularly clustering and classification tasks, but many dig­
ital forensic domains have not yet fully exploited AI’s potential. There is
a compelling need to explore diverse areas and integrate AI into various
investigative stages (Du et al., 2020). The advent of Large Language
Models, in particular, could significantly advance digital forensics
(Scanlon et al., 2023). However, there is limited discussion on key
digital forensic issues like explainability, which is crucial for AI’s suc­
cessful integration into digital investigations. Forensics of AI systems, as
suggested by Baggili and Behzadan (2020) and Schneider and Breitinger
(2023), is an intriguing, largely unexplored frontier within the DFRWS
EU and broader digital forensic community.

4.8. Miscellaneous
This section describes topics that could have been divided into other
sections, but taken together, they represent an important topic area for
discussion.

5.2. Digital forensic datasets

4.8.1. Anti-forensics
Anti-forensics, i.e., discussing techniques and performing experi­
ments that hamper investigations, has been identified as one of the
miscellaneous subcategories with a total of six articles. Nilsson et al.
(2014) discussed the possibility of hiding the full-disk encryption key,

Data and datasets are crucial in research, facilitating experimenta­
tion and ensuring result comparability and reproducibility (Garfinkel
et al., 2009). A study by Grajeda et al. (2017) noted a positive trend
towards researchers sharing their datasets, and these datasets being used
8

F. Breitinger et al.

Forensic Science International: Digital Investigation 48 (2024) 301685

by others – a finding echoed in this review.
However, it is often challenging to determine whether a dataset was
reused or created, and if created, its availability. To improve discover­
ability, authors should clearly state these details in the abstract and
keywords, using terms like ‘dataset’ or ‘corpora’. This aids automatic
data parsing, such as using the Elsevier API. Including datasets in NIST’s
CFReDS project at cfreds.nist.gov is also recommended, though the
ability to directly cite individual datasets would be beneficial.
There’s a need for mechanisms linking datasets with articles,
enabling queries like “return all articles using dataset X”. This is vital as
each study provides insights about a dataset, contributing to a
comprehensive understanding. As Roussev (2011) emphasised, estab­
lishing ground truth for any non-trivial dataset is challenging, especially
for an individual researcher.

5.6. Research priorities and their balance
Fig. 1 reveals a discrepancy in authors’ focus on different categories.
For instance, Multimedia, and Network Forensics have fewer articles
than Digital Forensic Science. This discrepancy might seem due to
recurring authors dominating certain topics, but the decision on article
acceptance rests with the technical program committee, not the authors.
Thus, the research priorities and imbalances reflect broader trends in the
digital forensics community. Furthermore, some categories, like multi­
media forensics, have existing communities/venues. Another trend
observed, reflected in the comparatively low number of articles in
Artefact Forensics, is that the conference shifts to ‘enduring work’, i.e.,
work that remains relevant over time. For example, while an analysis of
an application-specific artefact likely becomes invalid with the next
application update, a novel standard or technique has longer durability.
Other DFRWS initiatives such as DFIR Review2 may also act as an
alternative route for specific artefact research.

5.3. Implementations/tools
Over the past decade, numerous techniques and frameworks have
been introduced, often accompanied by implementations and tools for
evaluation. Similar to the need for datasets, these must be accessible to
the community. Wu et al. (2020)’s study found that only half of the tools
developed in the research were publicly available, a pattern echoed in
this study. The lack of a standardised protocol makes it challenging to
ascertain if a tool has been published in a research paper. Echoing Wu
et al. (2020), there is a clear need for a structured process for publishing
tools. As suggested in Digital Forensic Datasets, developers should
highlight their work in keywords/abstracts and release their tools as
open source. A centralised repository for digital forensics tools could be
one viable solution, where each tool is tested and documented before
approval, which would benefit forensic practitioners and academia,
strengthening future investigations and research alike.

6. Limitations
This study’s data collection and analysis largely relied on manual
methods, with decisions influenced by the authors’ expertise. While
significant efforts were made to ensure consistency, it is acknowledged
that different researchers might reach different conclusions based on
their interpretations. Despite potential subjectivity, the authors believe
most decisions were made carefully and reasonably.
The diversity of the articles posed a challenge, as many could not be
clearly assigned to just one single category. The goal was to find the most
fitting categorisation, but it is recognised that other researchers,
including the article authors, may have categorised their work differ­
ently. This also applies to the classification in Fig. 1.
7. Conclusion

5.4. Call for Papers, topics, and published work

DFRWS EU has run for 10 years and has contributed significant
research to the digital forensics community. By examining this single
publishing venue, it is possible to gain insights into digital forensic
research in Europe, and to some extent worldwide. Some areas are the
focus of the research community and some areas form a critical part of
the digital forensic process, e.g., file systems, and application artefacts
that see less published research. In the Interpol review of digital evi­
dence, Reedy (2023) states “digital forensics, now increasingly being
referred to as digital forensic science, has reached a threshold of
maturity both as computer science and forensic science”. DFRWS EU
consistently includes papers classified as ‘digital forensic science’, and
these continue to formalise the discipline and improve the quality of
results in the field. While this is essential for digital forensics to align
with other forensic science fields, without this formalisation being
complemented by peer-reviewed technical work including techniques
that allow data to be extracted from data sources, and an understanding
of artefacts that allow the interpretation of this data in the context of
investigating crime, the technical capabilities within the field could
formalise, but stagnate, risking missing important evidence as technol­
ogy rapidly changes.

The digital forensics research landscape constantly evolves, as re­
flected in the DFRWS EU Call for Papers (CfP). New topics of interest
include cloud, covert channels (e.g., Tor, VPN), digital evidence sharing
and exchange, digital forensic preparedness/readiness, implanted
medical devices, SCADA/industrial control systems, smart power grid
forensics, smart building forensics, vehicle forensics (e.g., drones, cars),
and virtual currencies. Topics previously listed at a high level in 2014,
such as application analysis, database forensics, digital evidence storage
and preservation, filesystem forensics, multimedia analysis, traffic
analysis, traceback and attribution, are now subcategorised under the
areas above. Comparing the latest CfP with the presented topics at
DFRWS EU, notably several CfP topics received minimal attention. This
does not imply topic irrelevance, but rather presents research opportu­
nities. Examples include smart power grid forensics, smart building fo­
rensics, and digital evidence and the law.
5.5. Inclusion and collaboration
Sec. 3 reveals diverse author origins and collaboration patterns, yet
some European countries are unrepresented, and silos exist within the
community. The under-representation of certain [European] countries
indicates a need for broader international participation for a more in­
clusive global perspective. Despite growing international participation,
many authors maintain isolated collaborations or consistent partner­
ships with few peers, as seen in the small grey clusters in Fig. 5. Research
indicates that collaboration enhances productivity, as many studies
require interdisciplinary, equipment-dependent, and project-based ap­
proaches (Lee and Bozeman, 2005). Therefore, increased collaboration
and knowledge sharing can enrich the diversity of perspectives in the
digital forensics community.

CRediT authorship contribution statement
All authors contributed in an equal manner.
Declaration of competing interest
The authors declare that they have no known competing financial
interests or personal relationships that could have appeared to influence
2

9

https://dfrws.org/dfir-review/

F. Breitinger et al.

Forensic Science International: Digital Investigation 48 (2024) 301685

the work reported in this paper.

Breitinger, F., Roussev, V., 2014. Automated evaluation of approximate matching
algorithms on real data. Digit. Invest. 11, S10–S17. https://doi.org/10.1016/J.
DIIN.2014.03.002.
Breitinger, F., Baier, H., White, D., 2014. On the database lookup problem of
approximate matching. Digit. Invest. 11, S1–S9. https://doi.org/10.1016/J.
DIIN.2014.03.001.
Casey, E., Back, G., Barnum, S., 2015. Leveraging CybOXTM to standardize representation
and exchange of digital forensic information. Digit. Invest. 12, S102–S110. https://
doi.org/10.1016/J.DIIN.2015.01.014.
Casey, E., Jaquet-Chiffelle, D.O., Spichiger, H., Ryser, E., Souvignet, T., 2020. Structuring
the evaluation of location-related mobile device evidence. Forensic Sci. Int.: Digit.
Invest. 32, 300928 https://doi.org/10.1016/J.FSIDI.2020.300928.
Casino, F., Dasaklis, T.K., Spathoulas, G.P., Anagnostopoulos, M., Ghosal, A., Borocz, I.,
Solanas, A., Conti, M., Patsakis, C., 2022. Research trends, challenges, and emerging
topics in digital forensics: a review of reviews. IEEE Access 10, 25464–25493.
Caviglione, L., Wendzel, S., Mazurczyk, W., 2017. The future of digital forensics:
challenges and the road ahead. IEEE Security & Privacy 15 (6), 12–17.
Choi, J., Yu, J., Hyun, S., Kim, H., 2019. Digital forensic analysis of encrypted database
files in instant messaging applications on Windows operating systems: case study
with KakaoTalk, NateOn and QQ messenger. Digit. Invest. 28, S50–S59. https://doi.
org/10.1016/J.DIIN.2019.01.011.
Closser, D., Bou-Harb, E., 2022. A live digital forensics approach for quantum mechanical
computers. Forensic Sci. Int.: Digit. Invest. 40, 301341 https://doi.org/10.1016/J.
FSIDI.2022.301341.
Coates, P., Breitinger, F., 2022. Identifying document similarity using a fast estimation of
the Levenshtein Distance based on compression and signatures. In: Proceedings of
the Digital Forensics Research Conference Europe. DFRWS EU.
Cohen, M.I., 2015. Characterization of the windows kernel version variability for
accurate memory analysis. Digit. Invest. 12, S38–S49. https://doi.org/10.1016/J.
DIIN.2015.01.009.
Cruz, F., Moser, A., Cohen, M., 2015. A scalable file based data store for forensic analysis.
Digit. Invest. 12, S90–S101. https://doi.org/10.1016/J.DIIN.2015.01.016.
Davies, M., Read, H., Xynos, K., Sutherland, I., 2015. Forensic analysis of a Sony
PlayStation 4: a first look. Digit. Invest. 12, S81–S89. https://doi.org/10.1016/j.
diin.2015.01.013.
Dewald, A., Seufert, S., 2017. AFEIC: advanced forensic Ext4 inode carving. Digit. Invest.
20, S83–S91. https://doi.org/10.1016/J.DIIN.2017.01.003.
Dezfoli, F.N., Dehghantanha, A., Mahmoud, R., Sani, N.F.B.M., Daryabar, F., 2013.
Digital forensic trends and future. Int. J. Cyber-Secur. Digital Forensics 2 (2), 48–77.
Dinh, S., Azeb, T., Fortin, F., Mouheb, D., Debbabi, M., 2015. Spam campaign detection,
analysis, and investigation. Digit. Invest. 12, S12–S21. https://doi.org/10.1016/J.
DIIN.2015.01.006.
Divakaran, D.M., Fok, K.W., Nevat, I., Thing, V.L., 2017. Evidence gathering for network
security and forensics. Digit. Invest. 20, S56–S65. https://doi.org/10.1016/J.
DIIN.2017.02.001.
Du, X., Hargreaves, C., Sheppard, J., Anda, F., Sayakkara, A., Le-Khac, N.A., Scanlon, M.,
2020. SoK: Exploring the state of the art and the future potential of artificial
intelligence in digital forensic investigation. In: The 13th International Workshop on
Digital Forensics (WSDF), Held at the 15th International Conference on Availability,
Reliability and Security (ARES). ARES ’20. ACM, New York, NY, USA.
Farina, J., Scanlon, M., Kechadi, M.T., 2014. BitTorrent Sync: first impressions and
digital forensic implications. Digit. Invest. 11, S77–S86. https://doi.org/10.1016/J.
DIIN.2014.03.010 arXiv:1409.8174.
Fernández-Álvarez, P., Rodríguez, R.J., 2022. Extraction and analysis of retrievable
memory artifacts from Windows Telegram Desktop application. Forensic Sci. Int.:
Digit. Invest. 40, 301342 https://doi.org/10.1016/J.FSIDI.2022.301342.
Fernández-Álvarez, P., Rodríguez, R.J., 2023. Module extraction and DLL hijacking
detection via single or multiple memory dumps. Forensic Sci. Int.: Digit. Invest. 44,
301505 https://doi.org/10.1016/J.FSIDI.2023.301505.
Franqueira, V.N., Horsman, G., 2020. Towards sound forensic arguments: structured
argumentation applied to digital forensics practice. Forensic Sci. Int.: Digit. Invest.
32, 300923 https://doi.org/10.1016/J.FSIDI.2020.300923.
Freiling, F., Hösch, L., 2018. Controlled experiments in digital evidence tampering. Digit.
Invest. 24, S83–S92. https://doi.org/10.1016/J.DIIN.2018.01.011.
Freiling, F., Zoubek, C., 2017. Do digital investigators have to program? A controlled
experiment in digital investigation. Digit. Invest. 20, S37–S46. https://doi.org/
10.1016/J.DIIN.2017.01.004.
Freiling, F., Glanzmann, T., Reiser, H.P., 2017. Characterizing loss of digital evidence
due to abstraction layers. Digit. Invest. 20, S107–S115. https://doi.org/10.1016/J.
DIIN.2017.01.012.
Fukami, A., Ghose, S., Luo, Y., Cai, Y., Mutlu, O., 2017. Improving the reliability of chipoff forensic analysis of NAND flash memory devices. Digit. Invest. 20, S1–S11.
https://doi.org/10.1016/j.diin.2017.01.011.
Garfinkel, S.L., 2010. Digital forensics research: the next 10 years. Digit. Invest. 7,
S64–S73.
Garfinkel, S., Farrell, P., Roussev, V., Dinolt, G., 2009. Bringing science to digital
forensics with standardized forensic corpora. Digit. Invest. 6, S2–S11.
Gloe, T., Fischer, A., Kirchner, M., 2014. Forensic analysis of video file formats. Digit.
Invest. 11, S68–S76. https://doi.org/10.1016/J.DIIN.2014.03.009.
Göbel, T., Baier, H., 2018. Anti-forensics in ext4: on secrecy and usability of timestampbased data hiding. Digit. Invest. 24, S111–S120. https://doi.org/10.1016/J.
DIIN.2018.01.014.
Göbel, T., Maltan, S., Türr, J., Baier, H., Mann, F., 2022. ForTrace - a holistic forensic
data set synthesis framework. Forensic Sci. Int.: Digit. Invest. 40, 301344 https://
doi.org/10.1016/J.FSIDI.2022.301344.

References
Alendal, G., Dyrkolbotn, G.O., Axelsson, S., 2018. Forensics acquisition — analysis and
circumvention of samsung secure boot enforced common criteria mode. Digit. Invest.
24, S60–S67. https://doi.org/10.1016/J.DIIN.2018.01.008.
Alrabaee, S., Saleem, N., Preda, S., Wang, L., Debbabi, M., 2014. OBA2: an onion
approach to binary code authorship attribution. Digit. Invest. 11, S94–S103. https://
doi.org/10.1016/J.DIIN.2014.03.012.
Alrabaee, S., Shirani, P., Wang, L., Debbabi, M., 2015. SIGMA: a Semantic Integrated
Graph Matching Approach for identifying reused functions in binary code. Digit.
Invest. 12, S61–S71. https://doi.org/10.1016/J.DIIN.2015.01.011.
Alrabaee, S., Debbabi, M., Wang, L., 2019. On the feasibility of binary authorship
characterization. Digit. Invest. 28, S3–S11. https://doi.org/10.1016/J.
DIIN.2019.01.028.
Amann, P., James, J.I., 2015. Designing robustness and resilience in digital investigation
laboratories. Digit. Invest. 12, S111–S120. https://doi.org/10.1016/J.
DIIN.2015.01.015.
Anda, F., Le-Khac, N.A., Scanlon, M., 2020. DeepUAge: improving underage age
estimation accuracy to aid CSEM investigation. Forensic Sci. Int.: Digit. Invest. 32,
300921 https://doi.org/10.1016/J.FSIDI.2020.300921.
Anda, F., Dixon, E., Bou-Harb, E., Le-Khac, N.A., Scanlon, M., 2021. Vec2UAge:
enhancing underage age estimation performance through facial embeddings.
Forensic Sci. Int.: Digit. Invest. 36, 301119 https://doi.org/10.1016/J.
FSIDI.2021.301119.
Andreoli, A., Lounis, A., Debbabi, M., Hanna, A., 2023. On the prevalence of software
supply chain attacks: empirical study and investigative framework. Forensic Sci. Int.:
Digit. Invest. 44, 301508 https://doi.org/10.1016/J.FSIDI.2023.301508.
Atwal, T.S., Scanlon, M., Le-Khac, N.A., 2019. Shining a light on Spotlight: leveraging
Apple’s desktop search utility to recover deleted file metadata on macOS. Digit.
Invest. 28, S105–S115. https://doi.org/10.1016/j.diin.2019.01.019.
Awad, R.A., Rais, M.H., Rogers, M., Ahmed, I., Paquit, V., 2023. Towards generic
memory forensic framework for programmable logic controllers. Forensic Sci. Int.:
Digit. Invest. 44, 301513 https://doi.org/10.1016/J.FSIDI.2023.301513.
Baggili, I.M., Behzadan, V., 2020. Founding the domain of AI forensics. February 7, 2020.
In: Proceedings of the Workshop on Artificial Intelligence Safety, Co-located with
34th AAAI Conference on Artificial Intelligence, SafeAI@AAAI 2020. vol. 2560 of
CEUR Workshop Proceedings. CEUR-WS.org, New York City, NY, USA, pp. 31–35.
https://ceur-ws.org/Vol-2560/paper53.pdf.
Baggili, I., BaAbdallah, A., Al-Safi, D., Marrington, A., 2013. Research trends in digital
forensic science: an empirical analysis of published research. In: Digital Forensics
and Cyber Crime: 4th International Conference, ICDF2C 2012, Lafayette, IN, USA,
October 25-26, 2012, Revised Selected Papers 4. Springer, pp. 144–157.
Bahjat, A.A., Jones, J., 2019. Deleted file fragment dating by analysis of allocated
neighbors. Digit. Invest. 28, S60–S67. https://doi.org/10.1016/J.DIIN.2019.01.015.
Barr-Smith, F., Farrant, T., Leonard-Lagarde, B., Rigby, D., Rigby, S., Sibley-Calder, F.,
2021. Dead man’s switch: Forensic autopsy of the Nintendo Switch. Forensic Sci.
Int.: Digit. Invest. 36, 301110 https://doi.org/10.1016/j.fsidi.2021.301110.
Bastian, M., Heymann, S., Jacomy, M.. Gephi: an Open Source Software for Exploring
and Manipulating Networks. http://www.aaai.org/ocs/index.php/ICWS
M/09/paper/view/154.
Bauer, J., Gruhn, M., Freiling, F.C., 2016. Lest we forget: cold-boot attacks on scrambled
DDR3 memory. Digit. Invest. 16, S65–S74. https://doi.org/10.1016/J.
DIIN.2016.01.009.
Bayne, E., Ferguson, R.I., Sampson, A.T., 2018. OpenForensics: a digital forensics GPU
pattern matching approach for the 21st century. Digit. Invest. 24, S29–S37. https://
doi.org/10.1016/J.DIIN.2018.01.005.
Bichara de Assumpção, M., dos Reis, M.A., Marcondes, M.R., Eleutério, P.M.d.S.,
Vieira, V.H., 2023. Forensic method for decrypting TPM-protected BitLocker
volumes using Intel DCI. Forensic Sci. Int.: Digit. Invest. 44, 301514 https://doi.org/
10.1016/J.FSIDI.2023.301514.
Biedermann, A., Vuille, J., 2016. Digital evidence, ‘absence’ of data and ambiguous
patterns of reasoning. Digit. Invest. 16, S86–S95. https://doi.org/10.1016/J.
DIIN.2016.01.011.
Bjelland, P.C., Franke, K., Årnes, A., 2014. Practical use of approximate hash based
matching in digital investigations. Digit. Invest. 11, S18–S26. https://doi.org/
10.1016/J.DIIN.2014.03.003.
Blondel, V.D., Guillaume, J.L., Lambiotte, R., Lefebvre, E., 2008. Fast unfolding of
communities in large networks. J. Stat. Mech. Theor. Exp. 2008, P1000.
Bollé, T., Casey, E., 2018. Using computed similarity of distinctive digital traces to
evaluate non-obvious links and repetitions in cyber-investigations. Digit. Invest. 24,
S2. https://doi.org/10.1016/J.DIIN.2018.01.002.
Bordjiba, H.E., Karbab, E.B., Debbabi, M., 2018. Data-driven approach for automatic
telephony threat analysis and campaign detection. Digit. Invest. 24, S131–S141.
https://doi.org/10.1016/j.diin.2018.01.016.
Bou-Harb, E., Scanlon, M., 2017. Behavioral Service Graphs: a formal data-driven
approach for prompt investigation of enterprise and internet-wide infections. Digit.
Invest. 20, S47–S55. https://doi.org/10.1016/J.DIIN.2017.02.002.
Boucher, J., Le-Khac, N.A., 2018. Forensic framework to identify local vs synced
artefacts. Digit. Invest. 24, S68–S75. https://doi.org/10.1016/J.DIIN.2018.01.009.
Boztas, A., Riethoven, A., Roeloffs, M., 2015. Smart TV forensics: digital traces on
televisions. Digit. Invest. 12, S72–S80. https://doi.org/10.1016/j.diin.2015.01.012.

10

F. Breitinger et al.

Forensic Science International: Digital Investigation 48 (2024) 301685

Gomez Buquerin, K.K., Corbett, C., Hof, H.J., 2021. A generalized approach to
automotive forensics. Forensic Sci. Int.: Digit. Invest. 36, 301111 https://doi.org/
10.1016/j.fsidi.2021.301111.
Grajeda, C., Breitinger, F., Baggili, I., 2017. Availability of datasets for digital
forensics–and what is missing. Digit. Invest. 22, S94–S105.
Gresty, D.W., Gan, D., Loukas, G., Ierotheou, C., 2016. Facilitating forensic examinations
of multi-user computer environments through session-to-session analysis of Internet
history. Digit. Invest. 16, S124–S133. https://doi.org/10.1016/J.DIIN.2016.01.015.
Groß, T., Busch, M., Müller, T., 2021. One key to rule them all: recovering the master key
from RAM to break Android’s file-based encryption. Forensic Sci. Int.: Digit. Invest.
36, 301113 https://doi.org/10.1016/j.fsidi.2021.301113.
Gruber, J., Humml, M., Schröder, L., Freiling, F.C., 2023a. Formal verification of
necessary and sufficient evidence in forensic event reconstruction. In: Proceedings of
Digital Forensics Research Conference Europe. DFRWS EU.
Gruber, J., Hargreaves, C.J., Freiling, F.C., 2023b. Contamination of digital evidence:
understanding an underexposed risk. Forensic Sci. Int.: Digit. Invest. 44, 301501
https://doi.org/10.1016/J.FSIDI.2023.301501.
Gruhn, M., Freiling, F.C., 2016. Evaluating atomicity, and integrity of correct memory
acquisition methods. Digit. Invest. 16, S1–S10. https://doi.org/10.1016/J.
DIIN.2016.01.003.
Gugelmann, D., Gasser, F., Ager, B., Lenders, V., Hviz, 2015. HTTP(S) traffic aggregation
and visualization for network forensics. Digit. Invest. 12, S1–S11. https://doi.org/
10.1016/J.DIIN.2015.01.005.
Halvani, O., Winter, C., Pflug, A., 2016. Authorship verification for different languages,
genres and topics. Digit. Invest. 16, S33–S43. https://doi.org/10.1016/J.
DIIN.2016.01.006.
Hargreaves, C., Marshall, A., 2019. SyncTriage: using synchronisation artefacts to
optimise acquisition order. Digit. Invest. 28, S134–S140. https://doi.org/10.1016/J.
DIIN.2019.01.022.
Henseler, H., van Loenhout, S., 2018. Educating judges, prosecutors and lawyers in the
use of digital forensic experts. Digit. Invest. 24, S76–S82. https://doi.org/10.1016/J.
DIIN.2018.01.010.
Hitchcock, B., Le-Khac, N.A., Scanlon, M., 2016. Tiered forensic methodology model for
Digital Field Triage by non-digital evidence specialists. Digit. Invest. 16, S75–S85.
https://doi.org/10.1016/J.DIIN.2016.01.010.
Horsman, G., Aney Biju Mammen, M., 2020. A glance at digital forensic academic
research demographics. Sci. Justice 60 (5), 399–402. https://doi.org/10.1016/j.
scijus.2020.06.003.
Horsman, G., Conniss, L.R., 2015. Investigating evidence of mobile phone usage by
drivers in road traffic accidents. Digit. Invest. 12, S30–S37. https://doi.org/
10.1016/J.DIIN.2015.01.008.
Iqbal, A., Al Obaidli, H., Marrington, A., Jones, A., 2014. Windows Surface RT tablet
forensics. Digit. Invest. 11, S87–S93. https://doi.org/10.1016/j.diin.2014.03.011.
Jennings, L., Sorell, M., Espinosa, H.G., 2023. Interpreting the location data extracted
from the Apple Health database. Forensic Sci. Int.: Digit. Invest. 44, 301504 https://
doi.org/10.1016/J.FSIDI.2023.301504.
Joun, J., Lee, S., Park, J., 2023. Discovering spoliation of evidence through identifying
traces on deleted files in macOS. Forensic Sci. Int.: Digit. Invest. 44, 301502 https://
doi.org/10.1016/j.fsidi.2023.301502.
Kanta, A., Coisel, I., Scanlon, M., 2023. Harder, better, faster, stronger: optimising the
performance of context-based password cracking dictionaries. Forensic Sci. Int.:
Digit. Invest. 44, 301507 https://doi.org/10.1016/J.FSIDI.2023.301507.
Karafili, E., Wang, L., Lupu, E.C., 2020. An argumentation-based reasoner to assist digital
investigation and attribution of cyber-attacks. Forensic Sci. Int.: Digit. Invest. 32,
300925 https://doi.org/10.1016/J.FSIDI.2020.300925 arXiv:1904.13173.
Karbab, E.M.B., Debbabi, M., 2019. MalDy: Portable, data-driven malware detection
using natural language processing and machine learning techniques on behavioral
analysis reports. Digit. Invest. 28, S77–S87. https://doi.org/10.1016/J.
DIIN.2019.01.017 arXiv:1812.10327.
Karbab, E.M.B., Debbabi, M., Derhab, A., Mouheb, D., 2018. MalDozer: automatic
framework for android malware detection using deep learning. Digit. Invest. 24,
S48–S59. https://doi.org/10.1016/J.DIIN.2018.01.007.
Lamshöft, K., Neubert, T., Hielscher, J., Vielhauer, C., Dittmann, J., 2022. Knock, knock,
log: threat analysis, detection & mitigation of covert channels in syslog using port
scans as cover. Forensic Sci. Int.: Digit. Invest. 40, 301335 https://doi.org/10.1016/
J.FSIDI.2022.301335.
Lanterna, D., Barili, A., 2017. Forensic analysis of deduplicated file systems. Digit. Invest.
20, S99–S106. https://doi.org/10.1016/J.DIIN.2017.01.008.
Latzo, T., Palutke, R., Freiling, F., 2019. A universal taxonomy and survey of forensic
memory acquisition techniques. Digit. Invest. 28, 56–69.
Latzo, T., Brost, J., Freiling, F., 2020. BMCLeech: introducing stealthy memory forensics
to BMC. Forensic Sci. Int.: Digit. Invest. 32, 300919 https://doi.org/10.1016/J.
FSIDI.2020.300919.
Lee, S., Bozeman, B., 2005. The impact of research collaboration on scientific
productivity. Soc. Stud. Sci. 35 (5), 673–702. https://doi.org/10.1177/
0306312705052359.
Lee, J.H., Hyeon, B.S., Jeon, O.Y., Park, N.I., 2023. Analysis of real-time operating
systems’ file systems: built-in cameras from vehicles. Forensic Sci. Int.: Digit. Invest.
44, 301500 https://doi.org/10.1016/j.fsidi.2023.301500.
Liebler, L., Baier, H., 2019. Towards exact and inexact approximate matching of
executable binaries. Digit. Invest. 28, S12–S21. https://doi.org/10.1016/J.
DIIN.2019.01.027.
Liebler, L., Schmitt, P., Baier, H., Breitinger, F., 2019. On efficiency of artifact lookup
strategies in digital forensics. Digit. Invest. 28, S116–S125. https://doi.org/10.1016/
J.DIIN.2019.01.020.

Luciano, L., Baggili, I., Topor, M., Casey, P., Breitinger, F., 2018. Digital forensics in the
next five years. In: Proceedings of the 13th International Conference on Availability.
Reliability and Security, pp. 1–14.
Martín-Pérez, M., Rodríguez, R.J., Breitinger, F., 2021. Bringing order to approximate
matching: classification and attacks on similarity digest algorithms. Forensic Sci.
Int.: Digit. Invest. 36, 301120 https://doi.org/10.1016/J.FSIDI.2021.301120.
Matthews, R., Lovell, K., Sorell, M., 2021. Ghost protocol – Snapchat as a method of
surveillance. Forensic Sci. Int.: Digit. Invest. 36, 301112 https://doi.org/10.1016/J.
FSIDI.2021.301112.
McKeown, S., Buchanan, W.J., 2023. Hamming distributions of popular perceptual
hashing techniques. Forensic Sci. Int.: Digit. Invest. 44, 301509 https://doi.org/
10.1016/J.FSIDI.2023.301509.
Minnaard, W., 2014. Out of sight, but not out of mind: traces of nearby devices’ wireless
transmissions in volatile memory. Digit. Invest. 11, S104–S111. https://doi.org/
10.1016/j.diin.2014.03.013.
Mullan, P., Riess, C., Freiling, F., 2019. Forensic source identification using JPEG image
headers: the case of smartphones. Digit. Invest. 28, S68–S76. https://doi.org/
10.1016/J.DIIN.2019.01.016.
Mullan, P., Riess, C., Freiling, F., 2020. Towards open-set forensic source grouping on
JPEG header information. Forensic Sci. Int.: Digit. Invest. 32, 300916 https://doi.
org/10.1016/J.FSIDI.2020.300916.
Mutawa, N.A., Bryce, J., Franqueira, V.N., Marrington, A., 2016. Forensic investigation
of cyberstalking cases using Behavioural Evidence Analysis. Digit. Invest. 16,
S96–S103. https://doi.org/10.1016/J.DIIN.2016.01.012.
Nemetz, S., Schmitt, S., Freiling, F., 2018. A standardized corpus for SQLite database
forensics. Digit. Invest. 24, S121–S130. https://doi.org/10.1016/J.
DIIN.2018.01.015.
Nilsson, A., Andersson, M., Axelsson, S., 2014. Key-hiding on the ARM platform. Digit.
Invest. 11, S63–S67. https://doi.org/10.1016/J.DIIN.2014.03.008.
Nissan, M.I., Wagner, J., Aktar, S., 2023. Database memory forensics: a machine learning
approach to reverse-engineer query activity. Forensic Sci. Int.: Digit. Invest. 44,
301503 https://doi.org/10.1016/J.FSIDI.2023.301503.
Nordvik, R., Toolan, F., Axelsson, S., 2019. Using the object ID index as an investigative
approach for NTFS file systems. Digit. Invest. 28, S30–S39. https://doi.org/10.1016/
J.DIIN.2019.01.013.
Otsuki, Y., Kawakoya, Y., Iwamura, M., Miyoshi, J., Ohkubo, K., 2018. Building stack
traces from memory dump of Windows x64. Digit. Invest. 24, S101–S110. https://
doi.org/10.1016/J.DIIN.2018.01.013.
Ottmann, J., Breitinger, F., Freiling, F., 2022. Defining atomicity (and integrity) for
snapshots of storage in forensic computing. In: Proceedings of the Digital Forensics
Research Conference Europe. DFRWS EU.
Palmbach, D., Breitinger, F., 2020. Artifacts for detecting timestamp manipulation in
NTFS on windows and their reliability. Forensic Sci. Int.: Digit. Invest. 32, 300920
https://doi.org/10.1016/j.fsidi.2020.300920.
Palmer, G., et al., 2001. A road map for digital forensic research. In: First Digital Forensic
Research Workshop. Utica, New York, pp. 27–30.
Palutke, R., Freiling, F., 2018. Styx: countering robust memory acquisition. Digit. Invest.
24, S18–S28. https://doi.org/10.1016/J.DIIN.2018.01.004.
Park, S., Akatyev, N., Jang, Y., Hwang, J., Kim, D., Yu, W., Shin, H., Han, C., Kim, J.,
2018. A comparative study on data protection legislations and government standards
to implement Digital Forensic Readiness as mandatory requirement. Digit. Invest.
24, S93–S100. https://doi.org/10.1016/J.DIIN.2018.01.012.
Penrose, P., Buchanan, W.J., Macfarlane, R., 2015. Fast contraband detection in large
capacity disk drives. Digit. Invest. 12, S22–S29. https://doi.org/10.1016/J.
DIIN.2015.01.007.
Poisel, R., Rybnicek, M., Tjoa, S., 2014. Taxonomy of data fragment classification
techniques. September 26-27, 2013, Revised Selected Papers 5. In: Digital Forensics
and Cyber Crime: Fifth International Conference, ICDF2C 2013. Springer, Moscow,
Russia, pp. 67–85.
Prade, P., Groβ, T., Dewald, A., 2020. Forensic analysis of the resilient file system (ReFS)
version 3.4. Forensic Sci. Int.: Digit. Invest. 32, 300915 https://doi.org/10.1016/J.
FSIDI.2020.300915.
Pridgen, A., Garfinkel, S., Wallach, D.S., 2017. Picking up the trash: exploiting
generational GC for memory analysis. Digit. Invest. 20, S20–S28.
Pringle, N., Burgess, M., 2014. Information assurance in a distributed forensic cluster.
Digit. Invest. 11, S36–S44. https://doi.org/10.1016/J.DIIN.2014.03.005.
Rais, M.H., Awad, R.A., Lopez, J., Ahmed, I., 2022. Memory forensic analysis of a
programmable logic controller in industrial control systems. Forensic Sci. Int.: Digit.
Invest. 40, 301339 https://doi.org/10.1016/j.fsidi.2022.301339.
Rais, M.H., Ahsan, M., Ahmed, I., 2023. FRoMEPP: digital forensic readiness framework
for material extrusion based 3D printing process. Forensic Sci. Int.: Digit. Invest. 44,
301510 https://doi.org/10.1016/j.fsidi.2023.301510.
Rathore, H., Nandanwar, A., Sahay, S.K., Sewak, M., 2023. Adversarial superiority in
android malware detection: lessons from reinforcement learning based evasion
attacks and defenses. Forensic Sci. Int.: Digit. Invest. 44, 301511 https://doi.org/
10.1016/J.FSIDI.2023.301511.
Reedy, P., 2023. Interpol review of digital evidence for 2019–2022. Forensic Sci. Int.:
Synergy 6, 100313.
Roussev, V., 2011. An evaluation of forensic similarity hashes. Digit. Invest. 8, S34–S41.
Roussev, V., McCulley, S., 2016. Forensic analysis of cloud-native artifacts. Digit. Invest.
16, S104–S113. https://doi.org/10.1016/J.DIIN.2016.01.013.
Safaei Pour, M., Bou-Harb, E., Varma, K., Neshenko, N., Pados, D.A., Choo, K.K.R., 2019.
Comprehending the IoT cyber threat landscape: a data dimensionality reduction
technique to infer and characterize Internet-scale IoT probing campaigns. Digit.
Invest. 28, S40–S49. https://doi.org/10.1016/j.diin.2019.01.014.

11

F. Breitinger et al.

Forensic Science International: Digital Investigation 48 (2024) 301685
Stüttgen, J., Cohen, M., 2014. Robust Linux memory acquisition with minimal target
impact. Digit. Invest. 11, S112–S119. https://doi.org/10.1016/J.DIIN.2014.03.014.
Stüttgen, J., Vömel, S., Denzel, M., 2015. Acquisition and analysis of compromised
firmware using memory forensics. Digit. Invest. 12, S50–S60. https://doi.org/
10.1016/J.DIIN.2015.01.010.
Sylve, J.T., Marziale, V., Richard, G.G., 2016. Pool tag quick scanning for Windows
memory analysis. Digit. Invest. 16, S25–S32. https://doi.org/10.1016/J.
DIIN.2016.01.005.
Taubmann, B., Fradrich, C., Dusold, D., Reiser, H.P., 2016. TLSkex: harnessing virtual
machine introspection for decrypting TLS communication. Digit. Invest. 16,
S114–S123. https://doi.org/10.1016/J.DIIN.2016.01.014.
Thierry, A., Müller, T., 2022. A systematic approach to understanding MACB timestamps
on Unix-like systems. Forensic Sci. Int.: Digit. Invest. 40, 301338 https://doi.org/
10.1016/j.fsidi.2022.301338.
Thomas, T., Edwards, T., Baggili, I., 2022. BlockQuery: toward forensically sound
cryptocurrency investigation. Forensic Sci. Int.: Digit. Invest. 40, 301340 https://
doi.org/10.1016/J.FSIDI.2022.301340.
Tobias Latzo Florian Hantke, L.K., Freiling, F., 2021. Bringing forensic readiness to
modern computer firmware. In: Proceedings of the Digital Forensics Research
Conference Europe. DFRWS EU.
Torabi, S., Bou-Harb, E., Assi, C., Debbabi, M., 2020. A scalable platform for enabling the
forensic investigation of exploited IoT devices and their generated unsolicited
activities. Forensic Sci. Int.: Digit. Invest. 32, 300922 https://doi.org/10.1016/j.
fsidi.2020.300922.
Uroz, D., Rodríguez, R.J., 2019. Characteristics and detectability of Windows auto-start
extensibility points in memory forensics. Digit. Invest. 28, S95–S104. https://doi.
org/10.1016/J.DIIN.2019.01.026.
Uroz, D., Rodríguez, R.J., 2020. On challenges in verifying trusted executable files in
memory forensics. Forensic Sci. Int.: Digit. Invest. 32, 300917 https://doi.org/
10.1016/J.FSIDI.2020.300917.
van Baar, R.B., van Beek, H.M., van Eijk, E.J., 2014. Digital Forensics as a Service: a game
changer. Digit. Invest. 11, S54–S62. https://doi.org/10.1016/J.DIIN.2014.03.007.
van Zandwijk, J.P., 2017. Bit-errors as a source of forensic information in nand-flash
memory. Digit. Invest. 20, S12–S19. https://doi.org/10.1016/j.diin.2017.01.005.
URL: https://www.sciencedirect.com/science/article/pii/S1742287617300294.
DFRWS 2017 Europe.
van Zandwijk, J.P., Boztas, A., 2019. The iPhone Health App from a forensic perspective:
can steps and distances registered during walking and running be used as digital
evidence? Digit. Invest. 28, S126–S133. https://doi.org/10.1016/J.
DIIN.2019.01.021.
Vidas, T., Kaplan, B., Geiger, M., 2014. OpenLV: empowering investigators and firstresponders in the digital forensics process. Digit. Invest. 11, S45–S53. https://doi.
org/10.1016/J.DIIN.2014.03.006.
Winter, C., Steinebach, M., Yannikos, Y., 2014. Fast indexing strategies for robust image
hashes. Digit. Invest. 11, S27–S35. https://doi.org/10.1016/J.DIIN.2014.03.004.
Wu, T., Breitinger, F., O’Shaughnessy, S., 2020. Digital forensic tools: recent advances
and enhancing the status quo. Forensic Sci. Int.: Digit. Invest. 34, 300999.
Wüst, K., Tsankov, P., Radomirović, S., Dashti, M.T., 2017. Force Open: lightweight black
box file repair. Digit. Invest. 20, S75–S82. https://doi.org/10.1016/J.
DIIN.2017.01.009.
Yaqoob, I., Hashem, I.A.T., Ahmed, A., Kazmi, S.A., Hong, C.S., 2019. Internet of Things
forensics: recent advances, taxonomy, requirements, and open challenges. Future
Generat. Comput. Syst. 92, 265–275. https://doi.org/10.1016/j.future.2018.09.058.
Zhang, X., Upton, O., Beebe, N.L., Choo, K.K.R., 2020. IoT botnet forensics: a
comprehensive digital forensic case study on Mirai botnet servers. Forensic Sci. Int.:
Digit. Invest. 32, 300926 https://doi.org/10.1016/j.fsidi.2020.300926.
Zoubek, C., Sack, K., 2017. Selective deletion of non-relevant data. Digit. Invest. 20,
S92–S98. https://doi.org/10.1016/J.DIIN.2017.01.006.
Zoubek, C., Seufert, S., Dewald, A., 2016. Generic RAID reassembly using block-level
entropy. Digit. Invest. 16, S44–S54. https://doi.org/10.1016/J.DIIN.2016.01.007.
Zubair, N., Ayub, A., Yoo, H., Ahmed, I., 2022. PEM: remote forensic acquisition of PLC
memory in industrial control systems. Forensic Sci. Int.: Digit. Invest. 40, 301336
https://doi.org/10.1016/J.FSIDI.2022.301336.

Saleem, S., Popov, O., Baggili, I., 2016. A method and a case study for the selection of the
best available tool for mobile device forensics using decision analysis. Digit. Invest.
16, S55–S64. https://doi.org/10.1016/j.diin.2016.01.008.
Sandvik, J.P., Årnes, A., 2018. The reliability of clocks as digital evidence under low
voltage conditions. Digit. Invest. 24, S10–S17. https://doi.org/10.1016/J.
DIIN.2018.01.003.
Sandvik, J.P., Franke, K., Abie, H., Årnes, A., 2022. Quantifying data volatility for IoT
forensics with examples from Contiki OS. Forensic Sci. Int.: Digit. Invest. 40, 301343
https://doi.org/10.1016/j.fsidi.2022.301343.
Sandvik, J.P., Franke, K., Abie, H., Årnes, A., 2023. Evidence in the fog – triage in fog
computing systems. Forensic Sci. Int.: Digit. Invest. 44, 301506 https://doi.org/
10.1016/j.fsidi.2023.301506.
Sayakkara, A., Miralles-Pechuán, L., Le-Khac, N.A., Scanlon, M., 2020. Cutting through
the emissions: feature selection from electromagnetic side-channel data for activity
detection. Forensic Sci. Int.: Digit. Invest. 32, 300927 https://doi.org/10.1016/j.
fsidi.2020.300927.
Scanlon, M., Du, X., Lillis, D., 2017. EviPlant: an efficient digital forensic challenge
creation, manipulation and distribution solution. Digit. Invest. 20, S29–S36. https://
doi.org/10.1016/J.DIIN.2017.01.010.
Scanlon, M., Breitinger, F., Hargreaves, C., Hilgert, J.N., Sheppard, J., 2023. ChatGPT for
digital forensic investigation: the good, the bad, and the unknown. Forensic Sci. Int.:
Digit. Invest. 46, 301609 https://doi.org/10.1016/j.fsidi.2023.301609.
Schipper, G.C., Seelt, R., Le-Khac, N.A., 2021. Forensic analysis of Matrix protocol and
Riot.im application. Forensic Sci. Int.: Digit. Invest. 36, 301118 https://doi.org/
10.1016/J.FSIDI.2021.301118.
Schneider, J., Breitinger, F., 2023. Towards AI forensics: did the artificial intelligence
system do it? J. Inf. Secur. Appl. 76, 103517 https://doi.org/10.1016/j.
jisa.2023.103517.
Schneider, J., Wolf, J., Freiling, F., 2020. Tampering with digital evidence is hard: the
case of main memory images. Forensic Sci. Int.: Digit. Invest. 32, 300924 https://doi.
org/10.1016/J.FSIDI.2020.300924.
Schneider, J., Lautner, I., Moussa, D., Wolf, J., Scheler, N., Freiling, F., Haasnoot, J.,
Henseler, H., Malik, S., Morgenstern, H., Westmand, M., 2021. In search of lost data:
a study of flash sanitization practices. In: Proceedings of the Digital Forensics
Research Conference Europe. DFRWS EU.
Schneider, J., Düsel, L., Lorch, B., Drafz, J., Freiling, F., 2022. Prudent design principles
for digital tampering experiments. Forensic Sci. Int.: Digit. Invest. 40, 301334
https://doi.org/10.1016/J.FSIDI.2022.301334.
Sentanoe, S., Reiser, H.P., 2022. SSHkex: leveraging virtual machine introspection for
extracting SSH keys and decrypting SSH network traffic. Forensic Sci. Int.: Digit.
Invest. 40, 301337.
Servida, F., Casey, E., 2019. IoT forensic challenges and opportunities for digital traces.
Digit. Invest. 28, S22–S29. https://doi.org/10.1016/j.diin.2019.01.012.
Sester, J., Hayes, D., Scanlon, M., Le-Khac, N.A., 2021. A comparative study of support
vector machine and neural networks for file type identification using n-gram
analysis. Forensic Sci. Int.: Digit. Invest. 36, 301121 https://doi.org/10.1016/J.
FSIDI.2021.301121.
Shiel, I., O’Shaughnessy, S., 2019. Improving file-level fuzzy hashes for malware variant
classification. Digit. Invest. 28, S88–S94. https://doi.org/10.1016/J.
DIIN.2019.01.018.
Socała, A., Cohen, M., 2016. Automatic profile generation for live Linux Memory
analysis. Digit. Invest. 16, S11–S24. https://doi.org/10.1016/J.DIIN.2016.01.004.
Sokol, P., Rózenfeldová, L., Lučivjanská, K., Harašta, J., 2020. IP addresses in the context
of digital evidence in the criminal and civil case law of the Slovak Republic. Forensic
Sci. Int.: Digit. Invest. 32, 300918 https://doi.org/10.1016/J.FSIDI.2020.300918.
Spichiger, H., 2023. A likelihood ratio approach for the evaluation of single point device
locations. Forensic Sci. Int.: Digit. Invest. 44, 301512 https://doi.org/10.1016/J.
FSIDI.2023.301512.
Spiekermann, D., Keller, J., Eggendorfer, T., 2017. Network forensic investigation in
OpenFlow networks with ForCon. Digit. Invest. 20, S66–S74. https://doi.org/
10.1016/J.DIIN.2017.01.007.
Stelly, C., Roussev, V., 2018. Nugget: a digital forensics language. Digit. Invest. 24,
S38–S47. https://doi.org/10.1016/J.DIIN.2018.01.006.

12
