verification and validation of findings

21
Digital Shield, Inc. Verifying and Validation of Findings

Upload: cellebrite

Post on 27-Jun-2015

841 views

Category:

Technology


3 download

DESCRIPTION

Mobile forensics has come a long way over the past decade. The more complex it becomes, the greater the need for forensic examiners to "trust but verify" -- to validate that their process is acquiring evidence correctly, and that it is acquiring the correct evidence.

TRANSCRIPT

Page 1: Verification and Validation of Findings

Digital Shield, Inc. Verifying and Validation of Findings

Page 2: Verification and Validation of Findings

Who Are We? • Former Local LE

• Conduct Live Case Work

• Specialize in Training & Dev.

• We like this stuff

Page 3: Verification and Validation of Findings

• We conduct investigations

• Testify to findings in Court / Defend our results

• How are you validating information produced by tools?

• Challenged in court yet?

So Why Are We Here?

Page 4: Verification and Validation of Findings

State of Mobile Forensics • Come along way in last few years

• Logical

• File systems

• Physical

• Password extract / bypass

• Applications

• OH MY!

Page 5: Verification and Validation of Findings

Forensics “Trust but Verify”

• Tools produce decoded data • Do you believe the tools extracted ALL the data? • Ok it extracted it, but was it decoded? • Detective is it possible you could have missed anything?

Page 6: Verification and Validation of Findings

Validation Techniques • Hand Scroll Analysis

• Database Searches

• Unallocated space

Page 7: Verification and Validation of Findings

Hand Scroll Analysis • Thumbing through a Phone

• Documenting all visible information on the phone

• Time Consuming UGH!!

• Validation collected information

• May not have access to all data through interface

Page 8: Verification and Validation of Findings

Database Verification

Page 9: Verification and Validation of Findings

Sample Number One

Page 10: Verification and Validation of Findings

Sample One Verify

Page 11: Verification and Validation of Findings

Sample Number Two

Page 12: Verification and Validation of Findings

Sample Two Verify

Page 13: Verification and Validation of Findings

Sample Number Three Verify

Page 14: Verification and Validation of Findings

Sample Number Three Verify

Page 15: Verification and Validation of Findings

Sample Number Four “Decoded”?

Is the Application supported for Decoding? If not then what?

Page 16: Verification and Validation of Findings

3rd Party Tools

Page 17: Verification and Validation of Findings

What tools do you use?

• Cellebrite • XRY • Oxygen • IEF • EPILOG • Are you serious?

Page 18: Verification and Validation of Findings

EPILOG – SQLite Deleted?

Page 19: Verification and Validation of Findings

IEF Mobile -- SMS Unallocated

Page 20: Verification and Validation of Findings

IEF Mobile – Snapchat / Skype

Page 21: Verification and Validation of Findings

Questions?

More Information? Digital Shield, Inc.

[email protected]

321-704-1336

Hanover, Maryland

Grant, Florida