Artwork

Content provided by Heather Charpentier & Alexis "Brigs" Brignoni, Heather Charpentier, and Alexis "Brigs" Brignoni. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Heather Charpentier & Alexis "Brigs" Brignoni, Heather Charpentier, and Alexis "Brigs" Brignoni or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Christmas Miracle: Android Memory Forensics. Doing what we didn't know was possible.

1:14:38
 
Share
 

Manage episode 389529612 series 3505865
Content provided by Heather Charpentier & Alexis "Brigs" Brignoni, Heather Charpentier, and Alexis "Brigs" Brignoni. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Heather Charpentier & Alexis "Brigs" Brignoni, Heather Charpentier, and Alexis "Brigs" Brignoni or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

Send us a Text Message.

Ever thought about the thin line between privacy and morality? Well, join us, , as we deep-dive into the ethical complexities surrounding this issue in today’s digital age. We bring to you exciting updates from a recent workshop in Panama, where enlightening exchanges with digital forensics experts from all over the world were had.
Our exploration takes us through the workings of XRY and XRY Pro, as well as RAMDCoder, a game-changer in analyzing memory dumps from Android devices. We'll show you just how to navigate this tool, offering a glimpse into the future with the upcoming updates that promise to revolutionize device profiling. Intriguing, isn't it? Get ready as we take on mobile device forensics, focusing on the Samsung Galaxy S21 Ultra, and the treasure trove of data within its RAM. Learn from our experiences, including how we recovered from missing a crucial step in the extraction process. Oooops user error strikes again!
As we wrap up, we'll discuss phishing attacks and the crucial role organizations play in preventing them. We believe in the power of research and validation, especially in the digital forensics field. We’ll also share insights from Jessica Hyde of Hexordia, underscoring the importance of peer-reviewed research in our field. Get a good laugh as we humorously compare Apple to Darth Vader, highlighting the challenges they present for forensic examiners. SEGB for the WIN! This is an episode that you will not want to miss!
Notes:
Chat encryption: A moral responsibility or a moral abdication?
https://arstechnica.com/tech-policy/2023/12/meta-defies-fbi-opposition-to-encryption-brings-e2ee-to-facebook-messenger/
What makes epoch timestamps tick?
https://www.cclsolutionsgroup.com/post/what-makes-epoch-timestamps-tick
CheatSheet: https://assets-global.website-files.com/5f02f2c93eab87a6ea84e2f3/656da27da36e0c5cd1715d8a_EpochCheatsheet.pdf
MSAB XRY:
https://www.msab.com/
BrowserState.db last_visited_time?
https://doubleblak.com/beta/browserstate
SEGB Parsers!
https://github.com/cclgroupltd/ccl-segb

  continue reading

Chapters

1. Christmas Miracle: Android Memory Forensics. Doing what we didn't know was possible. (00:00:00)

2. Chat Encryption and Child Safety (00:00:06)

3. Privacy vs. Child Protection (00:09:33)

4. Exploring RAM Memory in Android Devices (00:21:55)

5. Extracting and Analyzing RAM from Samsung Galaxy S21 (00:30:40)

6. RAM Extraction and Data Analysis (00:35:45)

7. Information Security Solutions and Tool Development (00:49:45)

8. Enhancements to Artifact Selection and Parsing (00:58:29)

9. Alex from CCL Solutions Group SEGB Parser Demo (01:03:24)

21 episodes

Artwork
iconShare
 
Manage episode 389529612 series 3505865
Content provided by Heather Charpentier & Alexis "Brigs" Brignoni, Heather Charpentier, and Alexis "Brigs" Brignoni. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Heather Charpentier & Alexis "Brigs" Brignoni, Heather Charpentier, and Alexis "Brigs" Brignoni or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

Send us a Text Message.

Ever thought about the thin line between privacy and morality? Well, join us, , as we deep-dive into the ethical complexities surrounding this issue in today’s digital age. We bring to you exciting updates from a recent workshop in Panama, where enlightening exchanges with digital forensics experts from all over the world were had.
Our exploration takes us through the workings of XRY and XRY Pro, as well as RAMDCoder, a game-changer in analyzing memory dumps from Android devices. We'll show you just how to navigate this tool, offering a glimpse into the future with the upcoming updates that promise to revolutionize device profiling. Intriguing, isn't it? Get ready as we take on mobile device forensics, focusing on the Samsung Galaxy S21 Ultra, and the treasure trove of data within its RAM. Learn from our experiences, including how we recovered from missing a crucial step in the extraction process. Oooops user error strikes again!
As we wrap up, we'll discuss phishing attacks and the crucial role organizations play in preventing them. We believe in the power of research and validation, especially in the digital forensics field. We’ll also share insights from Jessica Hyde of Hexordia, underscoring the importance of peer-reviewed research in our field. Get a good laugh as we humorously compare Apple to Darth Vader, highlighting the challenges they present for forensic examiners. SEGB for the WIN! This is an episode that you will not want to miss!
Notes:
Chat encryption: A moral responsibility or a moral abdication?
https://arstechnica.com/tech-policy/2023/12/meta-defies-fbi-opposition-to-encryption-brings-e2ee-to-facebook-messenger/
What makes epoch timestamps tick?
https://www.cclsolutionsgroup.com/post/what-makes-epoch-timestamps-tick
CheatSheet: https://assets-global.website-files.com/5f02f2c93eab87a6ea84e2f3/656da27da36e0c5cd1715d8a_EpochCheatsheet.pdf
MSAB XRY:
https://www.msab.com/
BrowserState.db last_visited_time?
https://doubleblak.com/beta/browserstate
SEGB Parsers!
https://github.com/cclgroupltd/ccl-segb

  continue reading

Chapters

1. Christmas Miracle: Android Memory Forensics. Doing what we didn't know was possible. (00:00:00)

2. Chat Encryption and Child Safety (00:00:06)

3. Privacy vs. Child Protection (00:09:33)

4. Exploring RAM Memory in Android Devices (00:21:55)

5. Extracting and Analyzing RAM from Samsung Galaxy S21 (00:30:40)

6. RAM Extraction and Data Analysis (00:35:45)

7. Information Security Solutions and Tool Development (00:49:45)

8. Enhancements to Artifact Selection and Parsing (00:58:29)

9. Alex from CCL Solutions Group SEGB Parser Demo (01:03:24)

21 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide