LSU Cyber Team Releases First Open-Source Tool to Recover Fragmented Digital Evidence at Scale, Solves Two 20-year-old Grand Challenges, Wins $750K from NSA

By Elsa Hahne

October 06, 2026

When criminals delete files, wipe drives or destroy devices, the evidence often survives in scattered pieces. No publicly available tool has been able to put those pieces back together until now.

LSU’s team used their tool to solve the 2006 and 2007 grand challenges launched by DFRWS, the world’s premier digital forensics conference.

Scalpel3 team

LSU’s Scalpel3 team includes nine student co-authors, some of whom are not pictured. From left to right: Tyler Saizan, Professor Golden G. Richard III, Mingyang Li, Assistant Professor James Ghawaly, Karley Waguespack, George Hendrick and Samuel Goodwin.

– Photo by Elsa Hahne

A team of LSU researchers has released Scalpel3, the first open-source tool that can automatically reconstruct fragmented files from damaged or deliberately wiped computers and devices. This solves a longstanding problem in digital forensics with direct implications for criminal investigations and national security.

Scalpel3 just solved two long-standing grand challenges in digital forensics for the first time, reconstructing every fragmented file.

In addition, LSU’s team has been awarded $750,000 by the National Security Agency, or NSA, for continued development of Scalpel3. The award comes through the NSA’s National Centers of Academic Excellence in Cybersecurity program, where LSU holds the most selective designation as a Center of Academic Excellence in Cyber Operations, or CAE-CO.

“The mission of LSU’s College of Engineering is to solve critical problems. This new cybersecurity tool—free and available to the public—is an example of the ingenuity of our computer science team and the value they bring to Louisiana and the world.”

Vicki Colvin, Dean of the LSU College of Engineering

Recovering files when the roadmap normally provided by a filesystem is missing or destroyed, also called file carving, is a workhorse technique in digital forensics. Existing forensic tools can handle files stored in one contiguous piece, but when a file is broken into fragments and scattered across a drive, as happens routinely on real devices, investigators have been largely out of luck. Reassembling fragments by brute force means searching an astronomically large number of possible orderings.

Scalpel3 solves this problem with a massively parallel architecture that exploits the internal structure of each file format to narrow all possible options down.

The Broken Touchdown graphic illustrates the capabilities of Scalpel3

“The Broken Touchdown” illustrates how Scalpel3 can put fragmented files back into the correct order.

– Graphics by Nam Nguyen

The creation of Scalpel3 builds on two decades of work by LSU Professor Golden G. Richard III, director of the LSU Cyber Center and a faculty member in the Division of Computer Science and Engineering in the LSU College of Engineering with a joint appointment in the LSU Center for Computation and Technology. He started developing Scalpel in 2005, and the tool has been a staple of forensic practice since then.

“Previous tools available to law enforcement, including the first versions of Scalpel, simply could not detect fragmented files, such as deleted photos in child exploitation cases, wiped malware in intrusion investigations or data pulled from physically damaged phones,” Richard said. “I thought I was done developing Scalpel, but then colleagues in the intelligence community reached out to ask if I wouldn’t mind giving it another go to give investigators a faster and more practical way to recover fragmented digital evidence.”

LSU cybersecurity graduate Lauren Bristol

LSU cybersecurity graduate Lauren Bristol helped develop the visualization component of the Scalpel3 tool: “I am grateful to have had the opportunity, and excited to see how the additional insight the visulization provides to developers and analysts can impact the accuracy and efficiency of file-carving.”

Scalpel3 was created by Richard, who developed the backend architecture, and Assistant Professor James Ghawaly together with a team of nine LSU student researchers. Seven students worked on specific file types: Karley Waguespack (ELF), Samuel Goodwin (PDF), George Hendrick (MP3), Tre Landaiche III (RAR), Mingyang Li (7-Zip), Tyler Saizan (ZIP and Microsoft Office documents) and Jacob Tucker (JPG). Samuel Hildebrand and Joshua McCain worked with Ghawaly on the development of MoDiCo, the machine learning model that is now fully integrated into Scalpel3. MoDiCo was trained to recognize and effectively sort as many as 619 different file types.

“You can think of it as a bucket where you have pieces from elephant puzzles, giraffe puzzles and dog puzzles all mixed together. MoDiCo looks at each piece individually and figures out which type of puzzle it belongs to.”

James Ghawaly, Assistant Professor of Computer Science and Engineering with a joint appointment in the LSU Center for Computation and Technology

“One of the most rewarding parts of working on Scalpel3 has been taking a problem that seems almost computationally impossible and finding ways to make it solvable,” said Waguespack, lead student author and LSU doctoral student in computer science from New Iberia, Louisiana. “By using what we know about the internal structure of different file formats, we can dramatically reduce the number of possible reconstructions the system has to consider. Making that work available as open source means other researchers and practitioners can now use it, evaluate it and continue improving it.”

Scalpel3 can now recover images, executable programs, audio, archives and modern Microsoft Office documents, with more formats in development under the NSA award. Recovery of deleted executables matters particularly in intrusion and malware cases, where attackers routinely delete their tools after use.

The software—more than 200,000 lines of C code—is freely available under an open-source license at github.com/nolaforensix/scalpel3-release. The research will be published in the December 2026 issue of Forensic Science International: Digital Investigation, the leading journal in the field, and is already available online. In addition, the team’s paper “Tesserae and MoDiCo: A Billion-Fragment Dataset and Multi-Branch Architecture for File Fragment Classification” was just selected among roughly 40,000 submissions to NeurIPS, the premier international conference focused on machine learning, artificial intelligence, and computational neuroscience.​

Watch LSU cybersecurity graduate Lauren Bristol solve the 2026 DFRWS  digital forensics grand challenge in 36 seconds using the Scalpel3 tool she helped develop together with her advisor, LSU Professor Golden G. Richard III, director of the LSU Cyber Center and a faculty member in the Division of Computer Science and Engineering in the College of Engineering with a joint appointment in the LSU Center for Computation and Technology. Scalpel3 is the first and only publicly available tool that can recover fragmented digital evidence for law enforcement and national security investigations.