Obtaining Critical Real-Time Evidence From The Cloud

Vladimir Katalov presents his research at DFRWS EU 2018.

There is quite a lot of information on the smartphone, that’s probably the most available source now for all the data, including the private data, business data, a lot of [passwords], documents, mails, and everything else. And we have to find a way how to get that effectively and fast.

There are several methods acquiring the data from the smartphones. There are some that work well on a lowest level, through JTAG or chip-off, when I just read the memory from the device. That method, unfortunately, doesn’t work for most modern devices, because all the data is encrypted there or there is simply no debug port or there is a full-disk encryption there.

