- Research Article
- 10.1016/j.fsidi.2026.302103
- Jun 1, 2026
- Forensic Science International: Digital Investigation
- Lukas Jaeckel + 1 more
- Research Article
- 10.1016/j.fsidi.2026.302089
- Jun 1, 2026
- Forensic Science International: Digital Investigation
- Scott Lorenz + 4 more
- Research Article
- 10.1016/j.fsidi.2026.302112
- Jun 1, 2026
- Forensic Science International: Digital Investigation
- Stephin Paul
- Research Article
- 10.1016/j.fsidi.2026.302102
- Jun 1, 2026
- Forensic Science International: Digital Investigation
- Dilpreet Kaur Gill + 1 more
The rise in cyber-attacks has intensified the challenges faced by digital forensics and security analysts, who must investigate complex incidents quickly while handling large volumes of heterogeneous evidence. Current tools lack standardisation, resulting in incomplete representations and poor interoperability. Ontologies address this by providing structured vocabularies that ensure consistency, enable integration, and support structured and AI-assisted reasoning. In this paper, we introduce OCAI, a novel ontology for cyber-attack attribution and investigation. Built on the widely adopted STIX 2.1 standard, OCAI extends it with investigation- and attribution-specific knowledge. We add new objects, relationships, and axioms that deliver richer, more consistent, and extensible knowledge representation useful for the investigation and attribution process. Through empirical evaluation on real-world cyber-attacks, we refined OCAI to address critical gaps and ensure broader representational coverage. Comparative analysis shows that OCAI provides a broader and more comprehensive representation of cyber-attack investigation and attribution than existing ontologies. Moreover, its integration into a reasoning-based attribution tool demonstrates improvements in knowledge representation and reasoning capabilities. Our novel ontology establishes a robust foundation for advancing cyber-attack investigations and attribution. • The paper introduces OCAI, the first ontology for cyber-attack investigation and attribution. • OCAI extends STIX 2.1 with investigation and attribution knowledge. • The paper enhances ontology expressiveness through real-world cyber-attack case studies. • Demonstrates applicability through integration into a reasoning-based attribution tool.
- Research Article
- 10.1016/j.fsidi.2026.302105
- Jun 1, 2026
- Forensic Science International: Digital Investigation
- Zhihao Li + 5 more
- Research Article
- 10.1016/j.fsidi.2026.302101
- Jun 1, 2026
- Forensic Science International: Digital Investigation
- Hangyeol Kim + 3 more
- Research Article
- 10.1016/j.fsidi.2026.302100
- Jun 1, 2026
- Forensic Science International: Digital Investigation
- Dirk Pawlaszczyk + 6 more
SQLite databases play a central role in mobile phone forensics. Mobile applications frequently use them for data storage. Efficient extraction and interpretation of SQLite data are crucial for reconstructing device usage and user activities. In practice, digital forensic investigators must formulate and analyse complex SQL queries to retrieve evidence from various heterogeneous databases. This task requires extensive expertise in SQL, database schemas, and application-specific data logic. In this paper, we investigate an LLM-based approach to assist digital forensic investigators by automating the generation of SQL queries for forensic analysis. This enables investigators to query SQLite databases more efficiently and with less technical effort. First, we propose a mobile forensic dataset that captures typical investigative questions and database structures. We then use this dataset to fine-tune a local LLM. We introduce ForSQLiteLM, a Llama 3.2-3B bf16 model. It is optimized on a self-defined, domain-specific dataset tailored to mobile forensic scenarios. We compare ForSQLiteLM with several state-of-the-art LLMs to evaluate its effectiveness in generating forensic queries. We show that effective forensic Text-to-SQL generation can be achieved with a locally deployable 3B-parameter LLM by combining realistic SQLite schemas, execution-based evaluation, and domain- specific fine-tuning. Finally, as a proof of concept, we demonstrate how the proposed model can be integrated into the FQLite data retrieval tool via a retrieval-augmented generation (RAG) pipeline. • LLM-based approach to assist investigators by automating the generation of SQL queries for forensic analysis. • Introduction of a novel and unique dataset for mobile forensics. • Fine-tuning of an LLM with a domain dataset. • Benchmark study of the finetuned model with other LLM. • Proof-of-Concept study.
- Research Article
- 10.1016/j.fsidi.2026.302075
- Mar 1, 2026
- Forensic Science International: Digital Investigation
- Research Article
- 10.1016/s2666-2817(26)00043-0
- Mar 1, 2026
- Forensic Science International: Digital Investigation
- Research Article
1
- 10.1016/j.fsidi.2026.302062
- Mar 1, 2026
- Forensic Science International: Digital Investigation
- Luca Maiano + 2 more