Gå frakoblet med Player FM -appen!
Christmas Miracle: Android Memory Forensics. Doing what we didn't know was possible.
Manage episode 389529612 series 3505865
Ever thought about the thin line between privacy and morality? Well, join us, , as we deep-dive into the ethical complexities surrounding this issue in today’s digital age. We bring to you exciting updates from a recent workshop in Panama, where enlightening exchanges with digital forensics experts from all over the world were had.
Our exploration takes us through the workings of XRY and XRY Pro, as well as RAMDCoder, a game-changer in analyzing memory dumps from Android devices. We'll show you just how to navigate this tool, offering a glimpse into the future with the upcoming updates that promise to revolutionize device profiling. Intriguing, isn't it? Get ready as we take on mobile device forensics, focusing on the Samsung Galaxy S21 Ultra, and the treasure trove of data within its RAM. Learn from our experiences, including how we recovered from missing a crucial step in the extraction process. Oooops user error strikes again!
As we wrap up, we'll discuss phishing attacks and the crucial role organizations play in preventing them. We believe in the power of research and validation, especially in the digital forensics field. We’ll also share insights from Jessica Hyde of Hexordia, underscoring the importance of peer-reviewed research in our field. Get a good laugh as we humorously compare Apple to Darth Vader, highlighting the challenges they present for forensic examiners. SEGB for the WIN! This is an episode that you will not want to miss!
Notes:
Chat encryption: A moral responsibility or a moral abdication?
https://arstechnica.com/tech-policy/2023/12/meta-defies-fbi-opposition-to-encryption-brings-e2ee-to-facebook-messenger/
What makes epoch timestamps tick?
https://www.cclsolutionsgroup.com/post/what-makes-epoch-timestamps-tick
CheatSheet: https://assets-global.website-files.com/5f02f2c93eab87a6ea84e2f3/656da27da36e0c5cd1715d8a_EpochCheatsheet.pdf
MSAB XRY:
https://www.msab.com/
BrowserState.db last_visited_time?
https://doubleblak.com/beta/browserstate
SEGB Parsers!
https://github.com/cclgroupltd/ccl-segb
Kapitler
1. Christmas Miracle: Android Memory Forensics. Doing what we didn't know was possible. (00:00:00)
2. Chat Encryption and Child Safety (00:00:06)
3. Privacy vs. Child Protection (00:09:33)
4. Exploring RAM Memory in Android Devices (00:21:55)
5. Extracting and Analyzing RAM from Samsung Galaxy S21 (00:30:40)
6. RAM Extraction and Data Analysis (00:35:45)
7. Information Security Solutions and Tool Development (00:49:45)
8. Enhancements to Artifact Selection and Parsing (00:58:29)
9. Alex from CCL Solutions Group SEGB Parser Demo (01:03:24)
28 episoder
Manage episode 389529612 series 3505865
Ever thought about the thin line between privacy and morality? Well, join us, , as we deep-dive into the ethical complexities surrounding this issue in today’s digital age. We bring to you exciting updates from a recent workshop in Panama, where enlightening exchanges with digital forensics experts from all over the world were had.
Our exploration takes us through the workings of XRY and XRY Pro, as well as RAMDCoder, a game-changer in analyzing memory dumps from Android devices. We'll show you just how to navigate this tool, offering a glimpse into the future with the upcoming updates that promise to revolutionize device profiling. Intriguing, isn't it? Get ready as we take on mobile device forensics, focusing on the Samsung Galaxy S21 Ultra, and the treasure trove of data within its RAM. Learn from our experiences, including how we recovered from missing a crucial step in the extraction process. Oooops user error strikes again!
As we wrap up, we'll discuss phishing attacks and the crucial role organizations play in preventing them. We believe in the power of research and validation, especially in the digital forensics field. We’ll also share insights from Jessica Hyde of Hexordia, underscoring the importance of peer-reviewed research in our field. Get a good laugh as we humorously compare Apple to Darth Vader, highlighting the challenges they present for forensic examiners. SEGB for the WIN! This is an episode that you will not want to miss!
Notes:
Chat encryption: A moral responsibility or a moral abdication?
https://arstechnica.com/tech-policy/2023/12/meta-defies-fbi-opposition-to-encryption-brings-e2ee-to-facebook-messenger/
What makes epoch timestamps tick?
https://www.cclsolutionsgroup.com/post/what-makes-epoch-timestamps-tick
CheatSheet: https://assets-global.website-files.com/5f02f2c93eab87a6ea84e2f3/656da27da36e0c5cd1715d8a_EpochCheatsheet.pdf
MSAB XRY:
https://www.msab.com/
BrowserState.db last_visited_time?
https://doubleblak.com/beta/browserstate
SEGB Parsers!
https://github.com/cclgroupltd/ccl-segb
Kapitler
1. Christmas Miracle: Android Memory Forensics. Doing what we didn't know was possible. (00:00:00)
2. Chat Encryption and Child Safety (00:00:06)
3. Privacy vs. Child Protection (00:09:33)
4. Exploring RAM Memory in Android Devices (00:21:55)
5. Extracting and Analyzing RAM from Samsung Galaxy S21 (00:30:40)
6. RAM Extraction and Data Analysis (00:35:45)
7. Information Security Solutions and Tool Development (00:49:45)
8. Enhancements to Artifact Selection and Parsing (00:58:29)
9. Alex from CCL Solutions Group SEGB Parser Demo (01:03:24)
28 episoder
ทุกตอน
×Velkommen til Player FM!
Player FM scanner netter for høykvalitets podcaster som du kan nyte nå. Det er den beste podcastappen og fungerer på Android, iPhone og internett. Registrer deg for å synkronisere abonnement på flere enheter.