Digital Forensics Now
A podcast by digital forensics examiners for digital forensics examiners. Hear about the latest news in digital forensics and learn from researcher interviews with field memes sprinkled in.
Digital Forensics Now
Bite The Log Archive Cracker And You’re Hooked
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
AI is speeding up digital forensics, but speed without control is how good labs get burned. We dig into a safer way to work: use AI-assisted coding to generate a repeatable process, then test it against a real corpus of known extractions so results stay deterministic, verifiable, and defensible. If you’ve ever felt your LLM results “drift” from run to run, this mindset shift is the difference between a helpful assistant and a hidden liability.
We also get practical with what’s new across the community: a free macOS timestamp utility, Android intrusion logs (and how to extract and parse them when a user has opted in), and a deep look at Apple Unified Logs and log archives as an underrated iOS forensics goldmine. The big takeaway on logs is interpretation: one scary-looking line is not a conclusion. You have to read the surrounding sequence of events to avoid false narratives, and we talk about how newer workflows can process log archives directly from extractions without requiring a Mac.
From there we move into evidence sources that often decide cases: iOS Health database artifacts, LevelDB and IndexedDB for browser forensics, and a standout BitLocker improvement that can auto-unlock secondary encrypted volumes when keys are preserved in a system image. Finally, we walk through reporting at scale with LAVA, the LEAPPs viewer that adds conversation views, analytics, tagging, notes, and LAVA subset exports for massive chats that would otherwise choke HTML reports.
If this helped you rethink your workflow or gave you a new artifact to chase, subscribe, share the episode with your lab, and leave a review so more examiners can find it. What tool or artifact do you want us to test next?
Notes:
Timestamped - https://thebinaryhick.blog/2026/08/16/timestamped/
Brett Shavers Blog Posts - http://linkedin.com/pulse/let-ai-run-your-case-make-you-stupid-brett-shavers-vproc/
Android Logical Extractor - https://github.com/prosch88/ALEX
Tim Korver Blog Posts - https://www.linkedin.com/in/tim-korver/recent-activity/articles/
SANS DFIR Summit & Training - https://www.sans.org/cyber-security-training-events/digital-forensics-summit-2026
MSAB Digital Summit - https://www.msab.com/msab-mobile-forensics-digital-summit-2027/
Cellebrite 101 - https://community.cellebrite.com/s/101
HEART Metadata Forensics - https://github.com/MetadataForensics/HEART_by_Metadata_Forensics
Arsenal - https://arsenalrecon.com/products
LEAPPs & LAVA - leapps.org
Welcome And Field Catch-Up
SPEAKER_03Welcome to the DataFensic Now podcast. My name is Alexis Rick Winoni, and I'm accompanied by my co-host, the customer DataFrestic Professional, the Terminology hater that's good all the time, the one and only the incorporable, third carpentier, music is higher up by Jane Ibert and can be found at Tillerman Sound.com. Yeah. Yes, the AI terminology hater.
SPEAKER_00I hate a lot of the words that go with AI. I won't say why on the podcast because then we'll have to mark it explicit.
SPEAKER_03But I it is not they're not explicit words. You just have a uh too much of a forensics mind. I'm not, you know, but I'm not gonna even go there.
SPEAKER_01Good idea. Good idea.
SPEAKER_03Yeah, yeah. Folks that work data forensics in our field, anyways.
unknownYeah, thank you.
SPEAKER_03So uh good afternoon, Heather. Uh uh the rare uh Sunday that we're doing a show.
SPEAKER_00I know we haven't done one in so long, and I don't know, Sunday just worked this time, so here we are.
SPEAKER_03Yeah, yeah. As you can see, I'm not in my uh cupboard under the stairs like uh like a forensic DITAR forensics Harry Potter. I'm actually in a big room.
SPEAKER_00Away, away from home.
SPEAKER_03Yeah, yeah. You might be wondering. Well, you're not wondering because you know, but if folks are wondering, I am in the beautiful state of Alabama, enjoying the southern hospitality. Uh well, I'm from Florida, so I guess I'm also in the south. But either way, a beautiful place. I'm here for this week. I'll be doing some work over here, so I am uh I am staying here, so it's good stuff.
SPEAKER_00Very nice, very nice. Yeah, no uh no posters and little cupboards. So and my stuff's gone too. I uh rearranged my whole office and I haven't had a chance to hang my my signs back up.
SPEAKER_03So yeah, she does have some animals behind her head.
unknownOh yeah.
SPEAKER_00These are my AI animals.
SPEAKER_03Oh my gosh.
SPEAKER_00If you could see them up close, they're all doing uh they're doing digital forensics.
SPEAKER_03Well, you know, you put your love for forensics and your love for nature all together, the uh the forensics know white from upstate New York, of course.
SPEAKER_00Yes, everything has to be animals.
SPEAKER_03All right, so uh what's going on? What you being up to lately?
SPEAKER_00Uh not I mean, not nothing, everything, but nothing all at once. So, like seriously, um just working and you know, same same old stuff for me. I've there's been a ton of stuff in digital forensics we have to talk about, but personally, not really a ton of new exciting information. How about you?
AI-Assisted Coding Without Hallucinations
SPEAKER_03So uh folks that that know me for a little bit, um, I've been using a lot of AI lately and looking for ways to uh kind of integrate it into our workflows because you know, at a certain point I do have a resistance to it, but at a certain point I'm also have accepted that it's gonna be here and it's gonna stay here. So we and it will be used. So, how do we do that properly, right? So I've been having those discussions with folks in the industry, with folks in the community. And at least from my end, I'm doing a lot of AI assisted coding, and I've been at this little bit of a tear, which I'll explain maybe later, in regards to how can we go about circumventing, for lack of a better term, AI stochastic, you know, random generated answers into a more deterministic, uh verifiable and validatable, which is a word I think I just made up uh way of operating. So validatable. If it's not a word, I wanna I wanna uh coin it right now. I mean it works validatable that that you can validate.
SPEAKER_00It works like what you were saying.
SPEAKER_03Yeah, you know what? I'm gonna Google it. I'm not even sure that's even a word, but anyways, so that's what's going on.
SPEAKER_00I have a feeling it's gonna be a new meme later, right?
SPEAKER_03It's validatable, of course. I mean, sounds like a word, I think it is. I mean, could I use it at a Scrabble game? I don't know. We'll find out.
SPEAKER_00I'm gonna challenge you.
SPEAKER_03So uh so what what do we have? What do we had for today? What's going on?
SPEAKER_00Yeah, so um kind of we have like a list of all kinds of things that are new in digital forensics. Some of them we're just gonna mention, some of them we'll show maybe uh some of the tools and stuff.
New Free Tools And Blogs
SPEAKER_00So uh yeah, uh first thing up, uh Josh Hickman has a new blog post called Timestamped. So he created a new Timestamp tool. Um, and uh Lexis is gonna bring it up so everybody can see.
SPEAKER_02Yeah, it's it's pretty it's pretty neat. And uh so what uh Heather, what uh what operating system is this for?
SPEAKER_00So I'm not showing this because it's for Mac OS and I'm on a Windows machine.
SPEAKER_03So Boo boo boo that girl, like the movie Boo that girl. Well, I mean you you can be perfect, you know. I mean, I mean you could be, you just decide not to, but it's okay. All right, we'll still love you. We'll still love you.
SPEAKER_00So Josh created this timestamp tool for macOS because he wanted uh a tool compatible with mac OS that I I think he mentioned when we were chatting, like something like Deco that worked, and he created this little tool. It is free and it is up on the binary hip blog post, I believe.
SPEAKER_03Yep, yep. And look, you can change the uh change the your time zones here. As you can see, I'm in central because where I am at in Alabama where I'm central time, that's why a local, but then you can change it from local, which is central where I'm at, to whatever. And UTC as as God intended, of course.
SPEAKER_00It has the decode and encode too. So if you wanted to encode a timestamp as well, so pretty cool little tool and free. I love free.
SPEAKER_03Oh, yeah, yeah. And look, I mean, I'm like uh, you know, BRICS is hating on Windows. Windows is fine, I'm not hating on Windows. I just I am of the belief that uh if I'm doing mobile forensics, I want to operate in the environment that's closest to it. And you will tell me, well, you know, uh Android is not macOS, and that's not APFS. No, I get it, it's true, but iOS is, and there's a lot of similarities in regards to uh the Unix-like environment. But um again, that's me. No hate on folks that are using Windows, you know, with their long path issues.
SPEAKER_00No, I have that today.
SPEAKER_03Yeah, um, but I bet you have it every day. So uh so no hate on on your uh self-imposed limitations. I still love you very much. All of you, all of you.
SPEAKER_00I keep thinking about getting a Mac though just to have it for uh whatever purpose I may need it, right? But those the MacBook Neos are actually like really inexpensive. So I may get one just for testing purposes, and so I have one so you can stop telling me how horrible I am.
SPEAKER_03You're not horrible. You just could you just could be more uh prettier, I guess. Forensically forensically prettier, that's what I mean.
SPEAKER_00Okay. Well, thanks. Um, so yeah, check out at the binary hick that timestamp tool. Um, Brett Shavers, uh, he's been continuing to hit the nail on the head with his blogs. So if you're not signed up to uh Brett Shavers, if you don't follow him on LinkedIn, one of his most recent ones, I love the name of this, is Let AI run your case and it will make you stupid. So it's a good read. And he just continues to put out great blog posts.
SPEAKER_03Can I can I can I go into my AI thing now or do are we doing it later?
SPEAKER_00You could do it whenever you want.
SPEAKER_03Okay, the rest of the show. No. Um see I I mean uh and and and Trubett's point, well for sure, if you're if um if you're using a uh LLMs in the traditional model of hey, give me an answer to this question, you're gonna run into problems. And so the way I'm thinking about it is hey LM, give me the process to get to the answer of something. And let's codify that process uh literally in code, like codifying code, duh, right? Um, and I say that and because you when you codify the process, you have steps one, through three, four, and five, right? And then you can go and verify that output and then validate steps one, two, three, four, and five, right? Which is something you can do by taking pure LLM output and then just presenting it. And you can tell, you can tell me, yeah, you can take that LLM output and also verify it, right? But again, we run into the problem of if I come with this situation again, I have no, I have no guarantee I will have the same output. So I have to do the verification from that LLM time and time and time and time again, hoping that it's always right. Whereas if you take the process out and you can run it, I say offline, but for lack of a better term, you run that process, you codify it, for example, in a program or a process, then it's repeatable a million times, and and you know what you will get every single time. Um, so what does that mean for us? It means that, and it's something that I am uh I did a post some time ago in LinkedIn about one of the skill sets that uh detail forensic examiners will need to have in the near future is an understanding of code, of being able to read code and understand code and know what it's doing. Because as of now, the only way I can rid the LLM of that stochastic slash indeterminism is by generating deterministic output. And and I think examiners will need to have that skill to be able to generate that. Um, so how so how they do be like, my gosh, what that mumbo jumbo, what the hell does that mean? So, in concrete, for me, it means that I will do uh uh an artifact for the leaps, which is just plain code, I will run it, I will use a testing system to test it. Um, and then I will need and not use the word that I use for it, and then what you do is you run that code, and then it will run and get the same output every single time on a million extractions afterwards. So instead of telling the LM, hey, give me the solution or to this problem, give me the steps, the plan, and the and the code that will solve this problem consistently without regressions, time and time and time again. Does that make sense, Heather, more or less?
SPEAKER_00It totally makes sense. It makes a lot of sense to me too, because I am currently when I'm using AI at all, which is not a ton, I'm doing the ask it a question, get the answer. And it's screwing me all up because I'm not doing it the way you're talking about. And I need to learn that. I think we all need to learn that if we're working in digital forensics. I agree with you 100%, because the way I'm doing it is gonna just I'm not using it for cases, but the way I'm doing, if I was using it for cases, it's gonna get me in trouble. I'm not gonna understand the outputs.
SPEAKER_03No, yeah, and to your point, that that understanding, there's there's some prerequisites. I mentioned code. There's a big prerequisite, is having a big collection of test images. Um, a corpus. I like the word corpus. I think I got that from the academic side of the field, right? A corpus of data or a body of data. And with multiple extractions, multiple operating system versions, multiple versions of the app itself, and constantly be adding new extractions to that corpus of data, because then you can uh create the code that will give you the answers for current versions as they as they come in out, because obviously what you had working maybe six months ago might not work today, or it'll be a bit different. So you have to constantly update. What does that mean? It means two things. It means you have to have that collection in a way that your tooling can access it to verify there's no regression, that you that the answer, the code that comes out doesn't change anything. And second of all, it means that we will all have to learn how to do test data, which a lot of people don't like. And no, we will have to generate, have our phones. I say phones because mobile forensics, but it applies to anything across the board. Um, actually, well, I'm gonna jump quickly ahead on one topic, but now we have a leap for desktop. I say desktop, but computer things, right? Not uniquely for Windows, not only uniquely for Mac, not uniquely for Linux, kind of all of them together. We'll talk about that in a second. But then you need test data for your different applications, different operating system, and keep it and maintain it because newer uh developments, um, when you ask the tool for solutions for the code to get to a solution, you will have to run a whole bunch of tests, make sure that nothing that's done in the past changes, and that the outputs that you're getting for the present execution of that code is correct, right? So, so uh, I think all examiners, if you want to do uh let me put it, let me let me put it this last piece, right? Thinking that uh we're gonna wait for the tool providers to give us solutions, it's it's out of it's out the window, like at least on the parsing side. Um, with the tooling at our hands, like it has democrat democratized or make it make a democratic process, right? We can all partake in the parsing process now with LLM tools, which means the lag of time between some data structure in an application and the support that data structure, now it can collapse to almost immediately. Um and this right way of doing it and a wrong way of doing it. And we're talking about the that what I believe is the right way of doing it, which means you need all those skills. Um, because the day of waiting for a tool vendor to give you a solution for for now, it's not, I mean, not that it's not happening, but look, I don't know how vendors are gonna respond to this the AI in this manner. I have no idea. Um the leaps we have grown for we've done what more than 150, I want to say 150 apps. Well, definitely more than 200 artifacts in a matter of a month. Yeah, thanks to this AI assisted, uh, AI assisted coding. I mean, it's just insane. And I don't I don't know. I don't know how the how the market's gonna react to every everyone being able to get to those solutions if they know what they're doing. But then coming back for Silco to what to what uh Brett says, um a lot of folks will do it not the right way, and uh what's gonna happen, right? Uh they're gonna get in trouble. So we gotta be really careful and be cognizant of what our skill set is. And and if we don't have that level of skill to use this properly, then we need to actually work on it so we can achieve it before we try any any any use of these technologies. Make sure that we do it right.
SPEAKER_00Yeah, so I keep joking that uh Alexis is moving so fast with all of these artifacts that there's not gonna be anything left for me to go try and parse on my own. Um, he he made the comment though, there's like millions of apps in the app store, so I should be good. Uh, but it's moving that fast to where I was like, oh, I was good, I wanted to look at that one and it's done. Um, and that's gonna be it's gonna be great.
SPEAKER_03Well, I mean, I mean to to to to that point. So uh I mean it's it's it's it's it's not an unknown point that there's millions of apps and little support. Everybody knows that. But what I found interesting, I was doing some a little bit of a research on it because I'm I'm building um or working on some um data structures for different classes that I'm building, and uh the amount of apps in the app store is linearly growing in a way that we weren't expecting, right? Um, we're pretty much the e the year is not over yet, and there are more new apps in the app stores than that new apps in the app store last year by pretty much let me put it this way all the new apps that were put in the app stores by the end of the year. We already now in September, actually, my I lie. We're in September now. My stats are from July. Um, the stats from July to August, we achieved it. We did in half a year, pretty much what was done last year. Does that make sense? So that means that there's a lot of new apps. Um, can you can you guess why? I think it's pretty obvious, right? Why why more apps? It's AI, right?
SPEAKER_00People are doing faster.
SPEAKER_03So now we have to respond, supporting them faster. So uh it's an interesting um environment that we're in. And I resisted use of AI in general for a long time, but now my focus is really on how can we do this in a way that doesn't burn us and burn our cases. And uh, you know, I'm always open to that discussion and and options and ideas on that.
SPEAKER_00Nice. All right. Uh what else do we have?
Android Intrusion Logs And ALeapp Parser
SPEAKER_00So Christian Peter, uh, he put out a new blog and updates to his Android logical extractor tool, otherwise known as Alex. Um he he now grabs the Android intrusion logs. So Android intrusion logs are an opt-in forensic log on Android devices, started with Android 16. And what it does is it records device and network activities that help investigate uh potential spyware attacks, I guess. Did I get all that right? Yeah. So so Christian Peters uh Alex tool now will um extract those from your device, from your Android device. And Kevin Pagano actually created a parser for them in A Leap as well. So if you're able to get those, if your user has opted in, uh extraction is really easy and parsing is really easy. Because it's supportive.
SPEAKER_03Oh no, though I mean that and and um Alex and you I just can't believe uh the price for these tools, you know. Um it's it's mind-boggling. Um, the the the acquisition that you have to do by zero dollars and zero cents and uh and all you get from it. Um I I I I see his him and his work as uh as a kindred uh like soulmates. My our project and and his projects are soulmates, right? Uh where we try to provide this free to the community, and uh there's so many cases that are being solved by the use of the combined extraction tools from him and then our parsing tools from our side. So I'm I'm really happy that he's adding that support. And then you got folks like Kevin. And if people don't know Kevin, everybody knows Kevin, but if you don't know Kevin, um he he's been one of the uh you know kind of my right-hand man in many things on the project, one of the main core developers and maintainers of the leaps, and uh he's immediately gave support to some of those. So that's that's that's awesome.
SPEAKER_00Yeah, definitely.
Unified Logs Research And Interpretation
SPEAKER_00Um, Tim Corver, uh, if you're not familiar with him based off of our past podcast where we've talked about him, he does a lot with the unified logs. Um, so his unified logs uh posts have just been on fire. He's been posting uh blog after blog after blog or blog post after blog post about the unified logs and his research. So if you don't follow him on LinkedIn, follow him on LinkedIn. All those blog posts are up and available.
SPEAKER_03And the interesting, the interesting thing about his blog post. So so for a long time, for well, maybe a couple of years, he was exp he was uh working on on the lock archives, right? On the Apple Unified logs. And we say lock, we say folks that are kind of new in the in the business. So we say lock archive because that's the kind of the extension that it gets when it when the the Apple tool itself brings it out. But it's the Apple Unified logs, that's what the content is, and it's really neat, it's millions and millions of records of things happening on the device. So he and others like Leonel, Notari, and some others, really well-known folks, have been going to the Apple Unified logs and checking out what of all those millions of rows of log are important, because not everything is important. Some entries are like, I don't even care for that, but some are important, some might be turn by and turn directions, right? And maybe you deleted that from your phone, but it lives in the Apple Unified log for a certain amount of time. Um, and there's a lot of data, like biometric locks, uh unlocks, I should say. And and when you take your phone and wakes up, or when you put it in your pocket, right? It uses this LiDAR, leader, light lidar, like a radar type of thing that it uses, like uh so it detects it's in your pocket or not. A lot of interesting artifacts. Folks that are working um uh crash reconstruction investigations are really leaning in into these logs, okay? So he has gone talking about those artifacts for a couple of years, and we have I say we like the leap group, we have taken those and incorporated it into the tool, into our tooling for parsing, which is fantastic. And I have a guide where I put all the different discoveries from Lionel, Tim, Heather as well, she's been involved in this, and put them all together in a guide. That's in our in leaps.org, and and you can find that there. And go into the blog section and you'll find it there. Now, where am I going with this? We've been focused on what artifacts and what lines, but now what Tim is doing, which I appreciate, is saying, you can have all these logs, it's great, but are we interpreting them correctly? We need to look not at the one line of a log, but at the collection of line of events before and after what you think might be important. And he gives a great example. He's talking about the what would you expect to see when you pick up a phone, an iPhone? Would you see it kind of waking up, the let the screen turning on, the biometric unlock happening, and then you get in the phone. And then he contrasted it with another series of events that sounded similar, but they were not an unlock of the phone. And the log of the line said biometric kit. And if you don't read the whole log or don't understand it, you will come to the wrong conclusion that, oh yeah, the person took up the phone and and unlocked it. And that was not what that's not what happened in that series of events. So I the the big teaching point that I like about his blog post is look, you need to understand it, but also leak look look at the totality of the events. This, like the smoking gun, we think of smoking gun like the one thing that tells me something. And his point is there is no one thing, there is many things. That become a one thing. And that's the type of mindset we need to have when approaching not only these logs, but any particular uh pieces of digital evidence to prove or disprove anything in a case.
SPEAKER_00Yeah, definitely.
Processing Log Archives Without A Mac
SPEAKER_00Um, just to kind of carry on with the unified logs, I don't know if everybody saw, but Alexis did a new blog post as well or revamped his blog post about the log archive. Um, it's now easier than ever to process the unified logs in iLeap. You don't even need a Mac anymore. So maybe I won't buy that Mac. See, you're just maybe, maybe you will.
SPEAKER_03You sound like Bill that he's not regretting buying the Mac after I told him to buy the Mac. I'll explain what that means in a second after after Heather uh laughs about my accurate representation of her uh tone there. Totally accurate.
SPEAKER_00I don't know if I care for for this tonight.
SPEAKER_03Um we haven't had our show in a while, so I'll give you a little bit of a hard time. That's true. You know I love you. Come on.
unknownYeah.
SPEAKER_00So you now can take your full file system extraction point eye leap at it and process the unified logs without all of the extra steps with the MacBook. Um, I believe you, uh Alexis, incorporated the mandate tool into the process to be able to be able to do that.
SPEAKER_03Yeah, yeah. So uh so let me I'll explain that in half a second. So before let me get to the Bill thing. So Bill, the the uh digital forensics, the mobile forensic wizard, is a good friend of ours, teaches with us at Iasis. Nice guy. And uh for the last year I had him made by a Mac so he could take the Apple unified logs, follow the conversion process on a Mac to create logs, uh JSON files that the leaps could digest. Because in the past, we had no way of reading the logs directly from the extraction, neither from an exporting, neither export nor directly. We couldn't do it, so we had to go through a multi-step process where a Mac was in the middle to get that in a JSON that the tool could read. Okay. Well, now to the point that Heather just brought, now we don't have to do any of that. So, what we're doing is we have a uh we use the main DNS, um, I think it's in Rust, or is it Go? Well, implementation of their own parser, which is fantastic. I have to thank um Kevin Pagano again. He's like, Hey, I'm playing with this, you might want to check it out. And I think he said it on a Friday night and he sent me into this rabbit hole. I think I went to bed like a four o'clock in the morning on Saturday. Just just just going through it. Yeah, but I was happy because the results are amazing. I I believe that um thanks to this implementation, Kevin's assist, and the code that we did over there, we are the best that the leaps have the best log archive slash apple unified log parser at implementation that that is exist in the market. I say market, quote unquote, because we don't charge for our tool, but in the in the community uh sphere, the best there is. We and it's pretty fast because again, the code that Mandya uses is extremely, extremely fast. Why are you smirk? Why are you smirking so much, lady?
SPEAKER_00Because I'm putting a comment up. I like whoever Devil Kitchen is. Mac users have a superiority complex.
SPEAKER_03Well, I mean, I mean, it's not it's not a it's not a complex if it's true, you know. If we're actually super I'm just kidding. I'm just kidding.
SPEAKER_00I had to share it. I had to.
SPEAKER_03I'm just kidding. Look, look, I look, I I I love, I love uh, I love I everybody love everybody like the movie. Well, the the funny thing is that not not only um this this tooling, it has um the menu support, it's on Mac, it's also on Windows. Don't get me wrong, so you can run this on Windows, no problem. That's that's a that's a cool thing. And um, and Johan, again, really well known. Again, I'm I'm surrounded by such smart people. I gotta make a pause here. It look, you can say, Oh, breaks all these things. Look, I do nothing, I am indebted to the people around me. Uh, the the only reason things work is that people like Heather and Johan and James and Kevin and the whole crew that's that's with me actually makes things happen. So I uh it's up, it's them. So Johan did uh he compiled it also for the for the Macs directly themselves, uh, for the ARM inf um architecture, which is something that obviously I wouldn't have been able to do. So um like well, anyways, uh as I'm as I'm giving props to our tooling. Um now it's really fast. And you what you do is this you point it to your extraction, you select log archive, and it goes. Actually, I think I let me see because I want to show a picture since we're on the topic.
SPEAKER_00Oh, I have one. You gave you give me one.
SPEAKER_03Oh, yeah. Yeah, can you can you bring that up, please?
SPEAKER_00Yep, let me just find it.
SPEAKER_03So uh as you can see, I have to wear readers now, but okay, that's another story for my thing. All right, so so what do we see here? So this is the the log of the tool of a uh I leave when it runs, and you'll see that I selected the log archive artifacts. So you select that and it goes, and something that I like a lot is the the uh the timer there. It says how many records has processed, how much how much of the source data percentage-wise has it uh be able to extract and convert, how much time has else, and how much time is left. And it's pretty accurate, which is something I'm really annoyed talking about Windows. Windows tells you, yeah, five minutes, eight minutes, ten minutes, five days, two minutes a month, you know, and you're like, and all that in a matter of two minutes. Like, what the heck? When will this be done? Right, but but this is pretty accurate because the way Lock Archives I set up, the trace v3 files, you can actually count them how many are there, know how much size wise they are, and then you can calculate the process mathematically pretty accurate. So when the system says it's an hour left, it's an hour, which you say, well, an hour that's a long time. Um, I'm not gonna mention other tooling by name, but other tooling, um, well-resourced tooling that people pay money for. I've been trying to process a lock archive for a week, like from Monday to Friday, and that thing's still spinning and spinning and spinning and spinning. And uh, I don't know, I don't know what I don't know what to tell you. So the the leaps are pretty pretty good at this. This is kind of like a small extraction of of lock archive. Let's say if you have like 300 megabytes of lock archive, it's really compressed because it's text, it could turn into 10-15 gigs of log, which is a lot, right? Imagine when it's bigger, it's getting about 40 gigs, 50 gigs of log. It's it's crazy. But the tool in a few hours, you get all that information. And then you can see there, there's any any errors reading any of those uh points, it will let you know because we're big on then you know when something doesn't work. But notice below it, below the the counter there, it says found, you know, this three million, three and a half million records for the lock archive, the whole thing. And then it breaks it down per artifact. Let me see if I can see a few of those, right? The time changes, the flashlight was on or off, apps that were executed. Has the personal hotspot been on? It has it been in airplane mode or not? Has the look at the lock status of the device, the Wi-Fi status? There's a ton, a ton of artifacts inside there. I believe this is one of the most understated, underused, unknown data sources for iOS forensics. I mean, I don't I don't know what you think that's accurate, Heather?
SPEAKER_00No, I totally agree. I mean, some of those, I some of those um artifacts that are parsed, I helped with. And like that doesn't even that doesn't even scratch the surface of what is in those log archives. There's so much research to be done. Um, I mean, we need an army of people to be able to parse all of them. But if you find anything that's interesting and have the test data or even just want test data, I'll generate the test data. I'd love to find more of these really um, I don't know, unique artifacts that are not really parsed by anything.
SPEAKER_03Yeah, and this is this is a call to all of you listening or watching, yeah, because participate. Um think of of events, a series of events that you want to test. Okay, what happens with the phone with if I whatever, if I drop it, or if I or if I do certain events with the phone. If if Apple comes out with an announcement, yeah, your phone does X now. Well, is that X or Y or C recorded in the lock archive?
SPEAKER_01Right.
SPEAKER_03You'll be surprised if when you click on that around the screen, and correct me if I'm wrong, Heather, but if you click on the screen, there's a lock archive on where coordinate you pressed on the screen. I think that's one of your lock archives.
SPEAKER_00Everything's in there, it's insane. It's insane.
SPEAKER_03So so imagine me able to prove that, yeah, this coordinate on the phone, which is the upper right corner, was pressed, for example. I mean, it could be important for your case, I think. So uh, so folks need to uh, I believe we folks need by folks being us, everybody, um, get more involved in this level of research. Um, yeah, because we push we push the field forward. Um, we we don't we don't wait for anybody else, we do we do it ourselves.
SPEAKER_00Yeah, and the the way that I come up with which types of um I guess uh actions I want to look at in the unified logs is from my cases, usually. So something weird will have happened in one of my cases. I'll be like, oh, I wonder, I wonder if they turned the flashlight on or if they manipulated the flashlight. It always comes from some kind of casework, or even if you're a true crime person, if you're watching these true crime podcasts, get those thoughts, like, oh, if we knew this about the phone, we we could have probably come to this conclusion or whatever, and and research that because there's so many unique artifacts to find.
SPEAKER_03Oh, absolutely. I'm I'm really excited about that capability. Um, I'm trying to run it to run it all all my cases that involve an iOS, an iPhone device. Yeah, and because you're oh, and which leads me to one more thing. Um, it's a lot of data, so you won't be able to put it in an HTML report. So, what that means is that yeah, if you run the leaps and the leaps by default throw out HTML, you're not gonna get everything. And the report will tell you that you're missing part of that data. So it tells you that, but it gives you the solution. What you need to do is download lava, leaps, l-e-a-p s dot or g download lava, and look at the uh open the extraction with lava, and then you'll see it there. Um, folks, there'll be some confusion because you're thinking that lava is another parsing tool, and it's not. You parse with your regular leaps, any of the leaps, a leap, I leap, d leap, v leap, r leap, any of them, you parse it, and then that folder, open it with lava, and then lava will be able to show you uh large amounts of data with no problem. All right, and we're still making the tool better. So, any comments on that, please head over to one of the leaps and leave a comment there um in the repositories. But um, and then you'll be able to see all those three, five, ten, fifteen million uh records of lock, which HTML just chokes. Your browser will crash, it won't fit. That's just how it is. But Lava can handle it. So remember, Lava is a viewer, the leaps are the tools for the parsing. And then with Lava, and I believe the more I don't use the HTML at all. I use Lava, period, because Lava has a lot of other functionalities that we'll talk about a bit later in the show.
SPEAKER_00Yeah. So
Summits Training And Celebrite Community 101
SPEAKER_00all right, um, there's a couple of summits coming up that were just announced. Well, one was just announced, and another one is coming up really soon. So I just wanted to mention them. The SANS uh D first summit and training is Thursday, October 15th, uh through October 22nd. I think the 15th and the 16th is the free virtual option um that gives you access to select talks related to that summit. Um, and then they have training courses that are in person, you can attend in person at the Hilton in Arlington. So uh always, always some really good talks if you if you have the time to tune in. Um, and then another digital summit that was just announced is the MSAB Digital Summit. That one will be March 16th through the 18th of 2027. And they're actually looking for speakers right now. So if you have some topic that you want to present or want to speak about, uh I don't know, maybe a case study or something, uh, you can submit your proposal until December 1st of this year. Um, it was a really great conference as well.
SPEAKER_03Oh, absolutely. That's one of the things, um, you know, a few of the good things that came out of the COVID era, uh, which we all want to forget. Um, but is that yeah, a conferences back in the day, there were no online conferences like that. You had to go and pay to be in person. So then the COVID, a lot of the conferences move online. So we some of those online aspects have remained, which is a good thing because now it's more accessible to everybody. So yeah, don't miss the opportunity. It's online, free, or uh at a minimum cost, go participate. You'll learn a lot by doing that.
SPEAKER_00Definitely. Um, another thing that was announced since we did the last podcast, I think it was announced last week, was celebrate's new 101. So um Celebrate has the Celebrate 101. If you have a Celebrate community account, you could log into your Celebrate community account and um go to the community tab. So this is a place where you can connect with other digital forensic professionals, you can exchange ideas, exchange best practice. Um, there's resources, you can get answers and learn directly from some of the celebrite experts. So you like you have access to Jared Barnhart, Heather Barnhart, Ian Wiffin, Paul Lorenz. I'm missing some and I'm gonna get yelled at, but there's a whole bunch of different celebrite experts that you have access to. I know I'm missing somebody big.
SPEAKER_03Um whoever, whoever, whoever she didn't mention just means that you need to get good. You suck. Get good, okay.
SPEAKER_00Um Heather Barnhart. Oh, jeez.
SPEAKER_03You said it. You said it already.
SPEAKER_00You said I said Jared.
SPEAKER_03Oh, oh well.
SPEAKER_00Um, so there's also besides that, there's um there's a tab in there called communities, and there's a different community for different topics. So one for physical analyzer, one for UFED. There's an advanced uh uh community led by Ian. Um, there's also another tab that is for resources, so all their white papers, blogs, videos, um, and any resources that Celebrite has put out will be there. I don't know if anybody has seen the Celebrite locations cheat sheet that um Ian did, and I'm sure he did it in collaboration with other people. Um, but the locations cheat sheet is amazing. It is hanging right by my desk. Um, locations can be super confusing on which ones are are good, which ones actually show where the device was at what time. And that cheat sheet gives you liter literally a guide to what each location source may mean.
SPEAKER_03Um I I I I I love the fact that it also shows it to you by levels, degrees of certainty.
SPEAKER_00Yeah.
SPEAKER_03And and the more I've been in this field, the more black and white things are not, the more one and zero they're not. There's degrees of how good of a data source uh it something is for whatever location purpose. So I agree with you. It's a great, great uh document. And uh if anything, go go get that. It's really good.
SPEAKER_00Yeah, and that's just one of the documents that's available there in the 101 uh celebrate can new celebrate community. So go in, check it out, ask all the hard questions. They're there, they're there awaiting your questions.
SPEAKER_01Yeah.
SPEAKER_00Um all right, so what do we have next? So
Parsing iOS Health Data With Heart
SPEAKER_00I looked recently at a tool that is put out by Metadata Forensics, and I'm actually gonna share it here. Let me see if I can share my screen. Window. There we go. So what this is, is it is a parser for health events and activity. It reports activity. So health events and activity put out by Metadata Forensics, and it gives you all of your good iOS, um, all of your iOS health data, right? So your heart rate, your steps, your walking, your calories burns, your flights, all of that good health data. They've recently been adding quite a few new artifacts. Um, some of them I don't even know what they mean yet, and they need to be researched. So um, walking step length is one double support time. There's a glossary on Metadata Forensics GitHub page, but some of these still need to be researched. Um walking steadiness uh is another one of the new artifacts. I'm like, what how do you even measure that?
SPEAKER_03That sounds like the are you drunk measure.
SPEAKER_00Yeah, so I didn't even know that was stored there. So I I'm looking forward to grabbing some of these new artifacts that they're talking about and actually testing them to see what they're you know, what they're actually showing.
SPEAKER_03I I'm not saying that it's a thing to measure if you're drunk. Don't get me wrong though. Let's say a break set. I didn't say it, I said it sounds like that, but just something something we learn is that if you go by the name of a field and you assume the meaning, you're gonna be most likely wrong nine times out of ten. So uh so be careful with that.
SPEAKER_00Definitely. So this is what the tool looks like. Um, what you'll do is uh it's browse input, so you'll point it at your full file system, choose where you want that output to go. You can set a date range if you need to. You can select which artifacts you want to include. Um, they have the timestamp display here with UTC or your device local time. Um, and then just hit process and go. I already processed one. So let me share that screen so we don't all sit and wait. Not that it took long because it didn't take long. Um, so this is what your output will look like. Um, you can see here we have steps, and don't mind my my gray on the screen here. This is uh like a really large curved monitor. I got some nice new monitors, so it'll fit to your screen. Um so you have the steps and the step duration. I mean, there's all of that good health data. Another little tool to parse the health data, except I think this one, this one parses more categories than I've seen in a lot of other tools. Um, flights climbed. We've got, oh, here's where's our I don't have the walking steadiness in my test data, but I have walking asymmetry, which I have no idea what that means. So I'll be testing that. Um, but you can pop over to their glossary as well. Um connected device history. Go ahead.
SPEAKER_03No, I said I I like the the fact that you know the the the leaps uh background of the tooling it makes me really happy. The the leaps tooling is MIT, so it's free for anybody to use and adapt and and distribute freely or newly again. Or no, no, no, it doesn't have to be free, but the point is that yeah, people can take the leaps and use it to build new things, and that makes me uh uh really happy that that's the case.
SPEAKER_00So the gloss rays actually right here in the report. Um, so walking steadiness, this is an estimate of your stability while walking. iPhone calculates walking steadiness using your walking speed, step length, double support time, and walking asymmetry data that's stored in health. Definitely something I want to test before I go presenting this in any of my cases.
SPEAKER_03But so so so I was right then.
SPEAKER_00You were right. Are you drunk? Yeah, I mean, honestly, if you have a case and it involves somebody potentially intoxicated, I mean this could maybe come in handy, yeah. Who knows?
SPEAKER_03Yeah, so but uh but don't don't don't go now getting drunk to test it, uh you know. So don't don't be gonna test it. I'm gonna get hammered now.
SPEAKER_00I think I might have to.
SPEAKER_03I'm not much of a drinker anymore, but we'll do it in a conference so make to make sure uh that if you do anything stupid, we can record you during the process, okay?
SPEAKER_00So if I test this and we write a I write a blog on this or something, then um there'll have to be pictures from the night out, maybe.
SPEAKER_03Oh no, I mean I I think it'll be the most popular blog you will ever put out in your life. So we're gonna be all looking forward to that. You fall into a fountain or something.
SPEAKER_00Jeez. So I talked with James, who works at Metadata Forensics, and he plans on doing some blogs on some of these new artifacts, he just hasn't yet. But that glossary, um, that glossary is great to just get uh an idea of what these health health database artifacts store.
SPEAKER_03And which reminds me, and that's a great idea, as that's as needs to be done. The the way we're doing it now on the leaps is when you open lava and you have an artifact that you're looking looking. If you go to the top left where the little home button is and the artifact name is, if you press a little information icon there, it will open a window that lets you know notes and descriptions of the artifact. And a lot of the things that that the work that we do when we code the artifact goes in there, and sometimes it will tell you what it is, or it will tell you enough information for you to be able to, as an examiner, test and validate that, which is another important thing that we hammer on a lot. That glossary is important and and the description puts the leaps on it, but they're they're not the gospel if you're of the Christian tradition here, it's not ultimate truth, okay? Um, it's it's just what the developers have put in based on their what their work is, but you need to test and validate. Because if you say, hey, Briggs put that in there, they'll be like, Who the heck is that guy? Um, he's not here in this case, he's not testifying, he's not the one that did the work. You, Mr. or Mrs. Examiner, are the one that did the work. Did you validate? Did you test? Did you make sure this is right? So just keep that in that in mind, just because any tooling tells you something does not absolve you the responsibility to verify that it comports in the way as described or differently for your use case.
SPEAKER_00Yeah. Right. So uh I'll put up the link to where to go get to get heart by metadata forensics. Uh it's on their GitHub page, but I'll put it up in the show notes. Really, really cool tool. And I I like the amount of amount of artifacts it's parsing. Really cool.
SPEAKER_02No, it's good stuff.
SPEAKER_00Yeah. Um,
LevelDB Recon And Browser Artifacts
SPEAKER_00next, uh, I don't know if you guys follow Arsenal on LinkedIn, but if you do, you probably saw some blog posts or some LinkedIn posts from Um Arsenal from Mark.
SPEAKER_03And if you and if you don't, you should follow.
SPEAKER_00You should, yeah.
SPEAKER_03And not Arsenal, the football team. Oh, that's fine too. The soccer team. I'm gonna Arsenal Mark Spencer from Arsenal. It's good stuff.
SPEAKER_00Yes. So there have been some updates. Um, there was an update to Arsenal level db. So level db um is one of their tools, level db recon is one of their tools, um, and it parses level dbs. And if you don't know what a level db is, you need to know what a level db is. There's not a lot of tools that support level db, and it is a data structure that is in, I think, all of your Android devices um that is not being parsed by most tools, and you need to go find those and parse them in a tool that supports them. So I'll leave that with level db.
SPEAKER_03Yeah, let me let me say something. I will say this. It's not only in an it's in every device, it's in every device, period. If your device has a browser, it's gonna be in there, right? So, and again, what devices have a browser nowadays? It will be there. And uh, and it you need when we start talking about level DBs, we were like, oh, it's good to check it, you know, make sure. No, now it's just a necessity. You have to look at level DBs. So I'm gonna I'm not gonna steal header's thunder on this section, but uh, she'll show you a few things with the tooling and why it's that important.
SPEAKER_00Yeah, so um we've actually I think we should have shown the level db tool from Arsenal before, way, way, way back in the podcast. Um, but uh Arsenal has gotten some requests for a better content viewer in the level db. So they've done some updates to their tool, and I'm gonna show a little video. I am actually gonna just move it forward a little bit here. So we're parsing level dbs from um Arsenal's Tech Hive E01, which is available, I believe. I gotta look what site, but it's available um for testing. And I'll I'll get what site and put that in the show notes. Um, but you guys can see here that the Arsenal tool and level db recon specifically is parsing the level db files and the log files that go along with the level db is also super important. Um, and as it pars, yeah.
SPEAKER_03I'm gonna say something quickly about Arsenal. If you could pause for a second, um the the image monitor is is the best image monitor in my from our perspective. And and again, when we talk about tooling, uh it's important to say Heather and me have no remote, no uh financial contract with anybody, right? We don't we don't get paid, we don't get any influence, we get nothing. We just talk about what we use and we think it's good, right? So there's no financial ties here or nothing, okay? Um, that being said, it's a great uh the image, the image mounter is fantastic. Uh, if I need to virtualize anything, I use aim for it. I don't think there's any other better uh way as of now to do that. And the capabilities that their mounter has. I'm not gonna mention that because it's off scope for the show, but the amount of data they can get for you from those uh images and and being able to look like mount an EO1 af it's like the computer, like you being the user of the computer and manage and drive the computer, it's amazing. So uh and they build now level DBs on top of that technology, so it's it's really nice.
SPEAKER_00Thank you, Mark. I had that up on my phone earlier and I couldn't remember where it is, but that it's the NIST uh C Fred's link to the Windows on ARM disk image, the tech hive scenario. So that's where this image is coming from.
SPEAKER_03Okay, that's what you that's the test data that you're showing.
SPEAKER_00Yeah, yep. I I just couldn't remember which side it was up on, but I got it. Well, assist from the comments. Um, so the level dbs are parsed, they're in level db three con. Um, they're choosing git records. Once we choose git records here on the what happened. Am I going? I am. Okay. It's just moving, moving a little slow. There we go. I did. I think it's not playing anymore.
SPEAKER_02Oh no, it's just scroll it.
SPEAKER_00There we go. It's playing. All right, get records. Now we have a view of our level DBs in the level DB recon. And what this demonstration is gonna show is the um the user is doing a search for latitude. So when they do a search for latitude and filter the records, it's just filtering the records to um to any artifact or any record that has a latitude available. Now open in viewer. This is what I was talking about with the new content viewer. So it opened up the latitude and longitude that you were able to find using that filter in a map view. So we now have a map view in this content viewer, and it was able to auto-detect that that was a latitude and longitude and open it up in a map view. And a second, it's gonna show all of the other um file formats. I'm gonna pause here on these other file formats so we can talk a little bit about them. So it will auto-detect, um, but you can choose other data structure, other um view as options here in this view as drop-down. Did you want to say stuff about that?
SPEAKER_03Yes, I want to really highlight the uh index DB uh part there. You see, it's gonna be from the bottom, maybe the six, five or six of from the bottom up. Um, and the index DB and their protocol buffers. And this is a capability that really um sets uh this tool apart in regards to looking at level DBs. Um, a lot of your level DBs, and this is uh browser forensics, and um, we're used to thinking about browser forensics at SQLite databases, get the stuff and we're good, right? Well, the way browsers work, they will they will keep data that uh you're uh working on the browser from, for example, Google Docs or Google Sheets or any browser-based application, those applications don't save to your drive, like save as and put it on your desktop. No, it keeps a copy of whatever you're working on on a inside of level DB. And it could also be inside indexed DB. So for lack of short, I mean we don't have the time to go into the hex and bytes and where things are, but pretty much it's you got your data, it's index DB, that's how it's organized in that database. And that database physically, it's in I say physically, but the structure that holds it is a level db. So you have two levels there. You got your index DB inside the level DB. This tool is able to figure that out, or you can have protobuf inside a level DB. An example for that would be um um DFCMs, if I know if I remember correctly. So being able to kind of dig inside level DBs for these things are extremely important. I I've seen cases where um important uh document information has only resided inside level DBs because the suspect or whoever it was was using uh online document editor to work on the whatever they were writing that was important to the case. So again, when you do browser forensics, getting those SQLite databases is great. Some browsers delete everything, or the user deletes everything, but the stuff in Level DBs tends to remain there for a long time. And this is one of the many tools that you could use to get to that data and having this auto-detect slash mark whatever you need capability, I think is gonna be extremely useful.
SPEAKER_00Yeah. Um, I I love the new content viewer because level DBs can be, uh I don't know, for lack of better term, messy to look at. And the content viewer, if you look here, uh the user just chose uh to put that data in the JSON format, and so now you can see the latitude and longitude data here in the JSON format. Oh, or you can switch it to the map.
SPEAKER_03Oh, if it's indexed db, it's gonna be you'll be like, what the heck am I looking at? You know, because you're having uh a uh a database inside of a database, and you're like, I I I can read a few things, but this looks like mumbo jumbo. But no, if you deserialize the the data out if it's protobuf or actually access it to the proper um APIs and all that with indexed db, then you can actually see what the heck is in it. And I mean, this is this tool is one way of doing that.
SPEAKER_00Yes, absolutely. So that is the update to the level db recon, but it's not the only update coming from Arsenal in the last few, I guess, weeks or months. Um,
AIM BitLocker Auto-Unlock Breakthrough
SPEAKER_00so there was also an update to Arsenal Image Mounter. Um, one of the new features in Arsenal Image Mounter is BitLocker auto unlock, and I'm gonna show a little video on that too. Um, but auto unlock for auxiliary volumes as well. Windows can store auto-unlock keys for secondary BitLocker encrypted drives that a computer has been authorized to access. So, from a forensic perspective, Arsenal Image Mounter can identify those keys in an acquired system volume and use them when the corresponding encrypted drive image is mounted. So, for example, you might have an encrypted USB or an external hard drive where you don't know the recovery password. But if that computer was previously configured to automatically unlock it, the necessary key may already exist in the forensic image. So AIM can recognize that relationship and automatically unlock that secondary volume. Um, so let me let me show a little video on this.
SPEAKER_03If if if you heard that and you're like, okay, it you did not understand it because that's a crazy amazing capability.
SPEAKER_00Yeah, so this is super cool.
SPEAKER_03So yeah, go ahead. This will make it clear.
SPEAKER_00Go ahead.
SPEAKER_03Your example will make it clear.
SPEAKER_00Yeah. So we're gonna mount this e01 of the, I believe this one is the laptop. Let me make this bigger. I can't see, I need glasses.
SPEAKER_03Yeah, I know, you know, something like the ones I have, my readers. So accept the fact of your age. Sorry, go ahead.
SPEAKER_00So this is the laptop image, and the user is entering the bitlocker key to unlock the laptop image. It's an e0 one.
SPEAKER_03I like that fact. It's from it's not it's an e0 one. It's amazing that it's sticking it straight from the extraction.
SPEAKER_00So if you look, it doesn't only auto-unlock um auxiliary, like secondary USB or encrypted hard uh external hard drives. It was able to just um decrypt volume R. So uh the laptop image, it was able to automatically unlock another volume on that disk utilizing these keys that it that it uh recovers. So just paused there. So the auto unlock keys were found um for one or more volumes on Q, which is the um the volume where the keys are stored. And then another thing is gonna be this little uh bitlocker status. So the bitlocker metadata is shown here um when you choose the bitlocker status. You'll have volume information, you'll have the fact that the encrypted file system is now unlocked, you'll have the key uh information about the keys all in that little metadata box. He you now can access that um encrypted volume R that was able to auto-unlock all those confidential PDFs. Um and then when opening uh this one is opening a USB. So we're opening up a USB drive and mounting it, and it was automatically unlocked using an external key from another disk. So that original laptop image actually was able to auto-unlock that thumb drive image. And again, the the metadata status, the bitlocker status information.
SPEAKER_03Yeah, if if you're listening, take a time to go get the YouTube uh video and and watch it because it's extremely impressive how as long as you can get into that first one, any of those uh devices or volumes that have been connected there with and bit locker key kept, uh it'll it'll open them for you straight up automatically.
SPEAKER_00So now we're mounting that um external drive. And again, uh so encrypted volume G was automatically unlocked using the external key from another disk. And we now have access to volume G, which is uh an external hard drive. And go to that show bitlocker status and get that metadata, and we have the metadata related to the external hard drive. And we now have access to the external hard drive, all the personal secrets and passwords of Arsenal. Marker, are these all your your personal uh passwords and secrets that we're showing? Mark's in the chat.
SPEAKER_03So maybe, maybe he'll maybe he has his HBO account there and we can actually access burn classic, a classic burn from way, way back when.
SPEAKER_00So really hear what I want to say about this though. Um, if you have cases in your lab and you have encrypted thumb drives, you encrypted hard drives related to your case, you uh and you have a laptop image or a computer image, you potentially uh might be able to auto-recover these keys for the other devices related to your case. Go back to your offices, look at your cases, see what you haven't been able to get into. Um, this is really, really cool. Uh, Mark told me about it, I forget, like a few weeks ago, maybe. And I'm like, oh yeah, I'll check it out. Uh, when I checked it out, it took me a little while, by the way. I hate being busy, but I'm like, oh my God, I needed to look at this sooner. Like, it's really, really cool stuff that Arsenal's doing.
SPEAKER_03Yeah, no, and I appreciate the chance to be able to show it uh here on the show to make folks aware that that capability exists. So it's it's good stuff.
SPEAKER_00Yeah, definitely. Um, so oh oh, Mark's in the in the chat, they spent months building a new BitLocker library to facilitate this and some of the other things in the latest AIM. So if you don't already have AIM, make sure you go out and try it out. There is a free version, but also there's a paid version, not super expensive. So go out, get it, and unlock all of the capabilities.
SPEAKER_02Heck yeah.
SPEAKER_00All
Leapp Growth Biomes And Test Data
SPEAKER_00right, so next, we are gonna talk about the leaps, lava, and tagging. Um, it is seven o'clock. We've already been rambling for an hour, but hopefully you all stay with us because we're gonna ramble for probably a little while longer.
SPEAKER_03It's it's Sunday. It's Sunday. It is, it's Sunday.
SPEAKER_00You've got time, you've all got time.
SPEAKER_03Yeah, whatever.
SPEAKER_00But this is gonna be a longer episode because we want to make sure we hit the the most recent um updates to the leaps as well. Um, but we also didn't want to leave out any of the million things that has happened since the last time we had a podcast. So we really need to have them more often, I think.
SPEAKER_03Yeah, I wonder whose fault that is. Oh, wait, it's uh it's mine, but go ahead.
SPEAKER_00It's it might be mine too. It might be mine too. Uh, but before we get into that, I do want to give one little um one little comment about the podcast itself. On Tuesday, we're going to have been doing the podcast for three years. Can you believe it? I know it's insane.
SPEAKER_03Yeah, we and we don't look a day older from doing it. Like, we just look three years have not passed. You're going in reverse. No, it's it's it's it's been awesome. I I gotta thank you so much for uh sticking with me and putting up with me for three years on this podcast.
SPEAKER_00So uh thank you so much for picking me. So quick little thing, but like three years ago when Alexis is like, Heather, do you want to do a podcast? My immediate reaction to him was, um, you've got the wrong Heather. This is you're messaging Heather Sharpentier, not Heather Mahalik or Heather Barnhart. Um, so yeah, I I really thought he had the wrong Heather, but I'm so glad that that he picked me to be on the uh podcast.
SPEAKER_03So no, I mean you you're you both are amazing heaters, but I I'm pretty I'm pretty I was pretty clear who I was talking to. So that was that was that was that was never an issue at all.
SPEAKER_00Oh, I like that. Uh D for Dan says more episodes with more sticker give giveaways. I think we have to do a giveaway for the three-year anniversary. I'll come up with something, put it out on the I like it.
SPEAKER_03I like it. So thanks for the idea, Dan. We're gonna be doing some of that.
SPEAKER_00Definitely. So with the leaps, um, we kind of already talked about how AI has helped build artifacts faster, but there's been a lot of recent updates with the leaps. Um, we're not gonna list all of the different um updates, but a lot has been going on. And uh, we have to give a shout out to Mattia because Mattia has been kind of spearheading the push, I guess I'll say, for new artifacts. So I'm gonna just put up leaps artifacts crediting Matiya so you guys can all take a look at the list of what's been going on recently. And I think Matiya's been giving test data for all of this too, right?
SPEAKER_03Yes, so Matias his own collection of data that he works with to his testing his research, and he kindly shared uh some of his uh internal uh data sets. Uh so these data sets are not public, but I used it, tested, and validate um the artifacts built from those. So I do appreciate that. Um before I continue, because I gotta say a lot of good things about Mattia Epifani. Um he's yeah, Italian examiner, he teaches for sans. He is an amazing all-around guy, one of the best researchers in the business. Now, before I say more about him, um, I want to say that folks, if you want to contribute to the tooling, um something that will help is giving us also test data. And I understand that some of that test data might be personal, but what I suggest you might be able to do, something that James gave me the idea, is to if you're using an LLAM to create an artifact, which is totally fine, and you're using test data that's personal, have your tooling generate, use that use the data source, and then generate another data source with synthetic data for testing. All right. So let's say it's a database that has, for example, browsing history, and you cannot share that browsing history because it'll show that you were buying crazy socks last week and you don't want me to know what socks are you buying. Then then create some synthetic data that conforms to it and and then provide that then run it with the synthetic data, make sure everything is good, and then share that with us because we wanna be able to also run it and do some unit and regression tests um with your data and our data. Um, uh, because we can't just take an artifact that you send me and just add it to the lead without any testing. That's that's not gonna happen. So that's something that I'm gonna be kind of hammering down a little bit more since more people are trying to contribute. So we need test data to do that. Now, that being said, all these artifacts that Matiya shared the data with uh with me were artifacts they had we had no support at all from them. And notice he uh he gave us uh some from uh like Pinterest for iOS and Android. And what that means is that when you see Pinterest, it's one app, but you can have multiple artifacts from one application. For example, one artifact could be the messages, another artifact could be all the images in that app, another artifact could be all the um account information for who's logged in into the app and any information that's related. So in Pinterest case, we have two app, I mean two versions of the app, the iOS and Android, but that leads to a total of 14 artifacts across both um versions of the app for the different operating system. So if you add up all the individual artifacts pulled out from every app, just for the ones that Mattia gave us, it's 286 different artifacts, and which is it's insane, right? One one that's really I want to highlight is the biome slash segb files. If you're not familiar with the biome directory and the seg files, segb files within it, you have to go look at the different episodes, go into leaps.org, go anywhere, look at Chris Vance's stuff from Magnet about biomes, you need to be familiar with it. We added 36 different modules or segB data points. And I believe that we the iOS, the iLeap, you know, for you know, the lead for iOS, we are the tooling that has the most segB files in the biome support there is, period. If you want to look at biomes, thanks to Mattia and other researchers that added to that, we have the most biome uh directory artifacts in existence in a tool, and there's more, there's more coming out all times, right? So we'll continue to grow that with further research. So you want to look at and if you're like, I have no idea what BRICS is talking about. Well, let me give you a quick synopsis, a one-sentence synopsis. Biome that the biome directory contains seg B data that within it has pattern of life activity, pattern of life, and that's all you need to know. If you're trying to uh look at what the device was doing at certain points and how that relates to user activity, that's where you need to be. This is the the successor of the a lot of the knowledge C data or data streams that used to live in that database, now they live inside B uh uh streams within the biome directory. You have to look into that, and we have the larger support. I'm proud of the community, I'm proud of Matthias for doing that research, putting it out. It's a benefit for everybody that does ether forensics, and I cannot thank him enough for that.
SPEAKER_00Yeah. Uh yeah, the the biomes. Can I just say I ran it on a case? I worked today and I ran it on a case today. There are so many supported biomes now, like uh some of the biomes. That are supported. I didn't even know what they were before. Um, yeah, I had never seen them before because they weren't supported by anything, right? So if you're not having that need to dig in and find new artifacts because you've got enough for your case or whatever, you may not see them, but the leaps have the most biomes parts that I've seen by far.
SPEAKER_03It's an immense list. And again, Matthias is amazing. And and the cool thing about that is that okay, I have some artifacts that indicate something. Then you go to the biome and look at all those sec Bs, and now you have maybe 10, 15, 20 other different data sources that that confirm or or corroborate all the data points. Again, like we talked about Tim before, you don't want the smoking gun, you need all the different items to then figure out what the smoking event gun is, for lack of a better term. Right. And pattern life activity is so important in our cases. So you have to check that out.
SPEAKER_00Absolutely. So, with that being said, if you haven't run the Leaps in a while, weTC, all the great new artifacts.
DLeapp For Telegram And Wire Desktop
SPEAKER_00Um, we kind of already touched on DLEAP, but I wanted to show a report real quick um for DLEAP because Alexis and I were actually doing some testing specifically on the um telegram desktop app and the wire desktop app. And DLEAP's fairly new, so I'm sure there's a lot of people out there that haven't seen it yet. I'm gonna show it in the HTML, but we can pull it into the into Lava too. Um, just because I already have the HTML up here, but I need to you were saying before you only use lava. I I need to uh I kind of go 50-50. I look at both, so I need to move all the way over to lava. I'm not a creature, I'm not a creature that loves change right away, so I I need to slowly get there. Um we're gonna speed you up. Here's the delete for a couple of artifacts that Alexis and I actually spent some time um looking into and testing. So you can see um telegram desktop, we have the desktop accounts, a log for the application, some peers. So we have Alexis Brignoni, and I bet you can guess who Bird nerd is. That one would be me. Um what?
SPEAKER_03I never guessed. Never guessed.
SPEAKER_00We have recovered cash images. There you are in your glasses.
SPEAKER_03Yeah, thank you for showing that picture of me.
SPEAKER_00You're welcome. You're welcome. So we have the recovered, yeah, you're welcome. Um, but the wire stuff too. Uh, we spent some time uh creating the wire account info here. Um, I want to show the wire messages. So was it the wire messages or the recover and with the recovered media, yeah. Do I have them with the attachments?
SPEAKER_03I think yeah, go, go, go, go, go, the media, the media, no, the media call. The media calls. Yep.
SPEAKER_00Yep. So um we have the wire messages. So the whole whole conversation between um Jesse Pinkman, because my intern set the phones up as uh what's the show? I can't remember what the show is breaking bad. Um, and then the bird nerds group. So, of course, there's gonna be a whole bunch of birds, Sunt and Walter White. So we have the whole conversation between these players in the wire application.
SPEAKER_03Um can you scroll up really quickly to the oh yeah, just one second? I want to say a quick thing. No, no, you can put recovered media, that's fine. Okay, it I want to just a shout out to Johan. He made the uh the logo, which I like. It's like keep it on top of a second so folks can see it. The logo of the lead d Leaps is like three windows. One looks like a Mac, another one's like Linux, and another one looks like uh Windows, kind of inter like one on top of the other with a little mouse. Uh I'm sorry, um, a pointer from your mouse. And I like it because DLEAP, the idea is instead of having like a Windows version, Linux version, uh, let's put them all together and then you know the the artifacts will pick up whatever it needs to pick up for whatever operating system it is, right? So now we have one centralized way of looking at all all these non-mobile data sources or non-vehicle, non-returns from providers data source, which I think is uh a good word from for to aggregate it depending on what are you looking at. So it's pretty neat.
SPEAKER_00Yeah, so yeah, so we have the recovered media, all my crazy bird pictures.
SPEAKER_03Um, which one isn't he drinking a cup of coffee?
SPEAKER_02Yeah, yeah, yeah, yeah.
SPEAKER_00Okay, just having a little latte. Um, so if you're working computer cases, um check out the desktop apps, run them in DLEAP. This is amazing stuff. I love it.
SPEAKER_03I wanna I wanna give you a use case. So the wire one. Um, another agency, which obviously I cannot, I will not disclose, um, could not get into a wire um installation on a device, on a mobile device, but they were able to have access to the computer, and they will add wire was installed on that computer. And uh, you know, we did uh and uh uh Heather helped me with this, and we did a lot of testing on this with this data set. We got the conversation, we got everything out, and then this knowledge, we were able to give it to the agency, and that agency was able to apply it and find all the evidence that they needed to find in their case that they wouldn't found otherwise. So think about data sources and where that data might reside. And you might think, well, the conversations are done on the phone, but you never know. Maybe that phone linked to a computer, and if not the computer, it might be leaving on the provider side, or it might be a copy in the cloud from uh the Google or the Apple uh backup systems, right? So you always have to think about data, it's like rabbits, it wants to reproduce. So if it's in one place, it's gonna be in other places. I'm gonna call the the Brignoni rabbit reproduction law for data forensics.
SPEAKER_00We need a meme.
SPEAKER_03Yeah, we'll we'll find one.
SPEAKER_00So uh, so yeah, so I just wanted to show DLEAP. Um, and check it out if you haven't checked it out yet. Fairly new, so check it
Lava Viewer Workflows And Analytics
SPEAKER_00out. And actually, now we're gonna get into lava. So I want to start right from the beginning. I've had some questions. I heard it's pretty hot. Lava, uh-huh.
SPEAKER_03Get it.
SPEAKER_00Wait, you want me to do the lake?
SPEAKER_03I'm a dad. I'm a dad. I got jokes.
SPEAKER_00Um, I want to start right from the beginning because uh Alexis already kind of mentioned it at the beginning of the podcast, but I've had some questions lately, like, uh, so how do I use this new lava? Like I when I say it, they think uh the question is kind of like lava is new, replacing the leaps type of question. And it's not lava is not replacing the leaps, the leaps are still run the same way that you've always run them. You can go to the leaps.org page that I have up here and you can find the download tools and you can go and download releases for all of the different leaps um that you're used to using. You can also go to the GitHub page and you can still pull them down on the GitHub page and run Python and run them from command line like you always have. Um, nothing has changed there uh besides the number of artifacts. There's a lot, but um, but you can still do everything the way you're used to. What lava is is just a viewer. And when I say just a viewer, it's awesome. So saying just a viewer is kind of sounds minimizing, but it's way more than just a viewer.
SPEAKER_03You'll you'll see.
SPEAKER_00Yeah, you're gonna run your normal, and let me um let me now open lava. You're gonna run your normal, actually. Let me there we go. Let's do this as a as a screen instead of instead of the entire window. It'll just look better for you guys. Um so you're gonna run your leaps the way you normally do, and then you're gonna open up lava and go to open project. Um, I don't know what I have here, but let's see what I have processed. I don't even know what these are.
SPEAKER_03Um open the first one, the leap the D leap one should be the uh should be the one that we're looking at, right?
SPEAKER_00Uh oh yeah, we can open, yeah. Let's open the D-leap one.
SPEAKER_03So a little bit, a little bit, yeah. Just just the uh the history is there on the history, I think.
SPEAKER_00Oh, okay. Yeah, let's do that. Okay.
SPEAKER_03So which by the way, if you didn't see that, if you open the latest you open, it will be kept on the history. You need to open it again. You don't have to go open and find it. You can go into history and open it, which is pretty.
SPEAKER_00Well, that with that being said, I'm gonna close it because I want to show you which file you're looking for to open it, to open it in lava. So I got it from the recents because I've recently opened it. But if you just navigate to your leap output, no matter what it is, if it's iLeap, a leap, whatever, you're looking for this lava underscore data dot lava file. If you just double-click on that, it opens up your project.
SPEAKER_03So you're just a just a quick thing. We were able to see it because you only have the app up uh the app open and the dialogue did not show. Well, but but it's okay. We can show it later. We we can show that dialogue later. Yeah, let's just continue with the review and then we'll show that dialogue.
SPEAKER_00Certainly. So lava, I want to just we've we've shown lava before on the podcast, but I just want to do a quick reminder about the different settings. So the little settings wheel is up here in the right-hand corner. You have the light and the dark. Did I blind you?
SPEAKER_03Yeah, okay, thank you. I'm good.
SPEAKER_00I did that on purpose.
SPEAKER_03I'm a vampire.
SPEAKER_00There's date and time settings. You can set the date format to whatever you like for your date format. You could set your time format, same thing, um, whatever format you like for your time format. Um, and then there's uh all the different time zones. Um, I set mine to America, New York, uh, because I'm in New York. So I like everything in my local time zone. But all of the time zones are are here under time zone for you. You can change it to whatever you want. You can change your phone number settings. I don't think I can move this up.
SPEAKER_03No, no, but you can scroll the window down.
SPEAKER_00There we go. There we go. Change your phone number settings. So if you're used to seeing a plus in front, if you're used to seeing parentheses in your phone number, or you want international, uh, you can choose what phone number settings. And then there's also language. So I do use system language, but you can turn that off. And all of the languages that are supported are here: English, Spanish, French, Dutch, Portuguese, and Italian currently.
SPEAKER_03The the leaves.org in the homepage. There's a section you scroll down of all the people that collaborated um in doing the languages, like myself and Geraldine did the Spanish, and some other folks did German and Portuguese and all that. So uh again, there's a list. I don't know the name on top of my head, but you also check them out. If you are a speaker of any language that is not in this list, you can go to leaps.org and you can help us out by adding that language translation for the tool. We would appreciate that.
SPEAKER_00Exactly. So um I'm gonna go into, I'm actually gonna go in, I'm gonna go into the wire. I'm gonna go into the messages. So let's see, there we go. So I'm in the wire messages section, and this is here where you can see all of the different messages related to the wire application. I think this is set up, it is set up for conversation view as well. So up here on the top, you can have the table view or you can have the conversation view. And if in the conversation view, you get the bubbles. So we've got the actual conversation bubbles with the media there, beautiful. Yeah, with the media. You can kick it out in this little drop-down over here. Um, it currently is just a PDF export from the conversation view. I've recently requested an HTML version because I like my reports in HTML. Um, so that look for that in an upcoming version. There we go. I'm telling telling the guys I want that.
SPEAKER_03Yeah, although um just a quick, a quick two things. Um, are you gonna talk about additional columns?
SPEAKER_00Uh nope.
SPEAKER_03So we're gonna go now. So hit it. So why did I put that there? I mean, I say uh why I put it, I didn't put it. James, James did it because James is a genius. So I I've been doing a backstory. I was doing an artifact where I wanted to get the wild diff. Oh, with the wild diff, what that means is data that's in the wild file for a SQLite database um that hasn't uh that hasn't been checkpointed yet. The moment it's checkpointed, I might lose that data. All right. So what I do is uh with the coding is it looks at the concept of the database, the concepts of the wild that haven't been checkpointed, and then shows them as recovered. Okay, it's not parsing. I mean, sorry, it is parsing, but it's not carving or nothing, it's just um looking at checkpointed data in the wild file. But I wanted to tell the folks to know um, you know, that that show the uh the column that says recover from the wild, right? So now you can in that and actually just pick any of them. Let's pick a message type, let's pick message type and hit uh and uh yeah, and then go and hit apply. You'll notice that underneath of the bubble, you have the message type message. See that? So you're able to put in any column underneath the bubbles, and this is really useful because yeah, when you have a conversation where some of the entries have been recovered, now you can just go to the column that says the type of recovery, if it's recovered or not, or whatever it is. And this is not like this is not uh an artifact like that, but any of those, and you put it and it shows there, so you can put any column underneath any bubble uh it as as pertains to your the the what you want to show on your report, which I think is super useful. I think other tools kind of limit you in that sense to whatever they show you in the bubble uh format, but you can take any field. I mean, can you put them all in there for sure? You'll have super long bubbles, and I don't think that's something that might be uh good to see. As you can see here, you know, immediately time to apply it.
SPEAKER_00Oh, yeah.
SPEAKER_03Yeah, so uh but so yeah, so and it will put it there, right? If there's nothing in there, then it won't put nothing there, right? So I think it's a pretty useful uh ability to be able to add that underneath the bubble as needed. But the original reason is for that to show if uh a bubble itself was recovered or or not from uh uh checkpoint diff from the water.
SPEAKER_00I didn't know that was there.
SPEAKER_03Well, there you go.
SPEAKER_00You know, I know I love it.
SPEAKER_03If you were uh you pay more attention to the uh developer, core developer chats, you would you know when you're there whenever you want to, because you know you governed yourself. That's why.
SPEAKER_00I try and catch up. You guys talk so much. So that that's awesome.
SPEAKER_03Okay, can you and you want to show the analytics part? That's something new that uh uh Johan, no, uh that James also added.
SPEAKER_00This I saw.
SPEAKER_03Yeah, you want to talk about it or you want me to talk about it?
SPEAKER_00Yeah, go ahead.
SPEAKER_03All right, so so here's pretty good because you see it takes all the messages and then it characterizes them um through time. So if you scroll it downwards, you will see there all the activity by day and hour, and then you can actually have an idea of when these conversations tend to happen and with who and with who the most, who the top senders, the top receivers of messages, what are the conversations that have been the busiest, the movement of data, which conversations have a lot of media. So this is useful from an analytical perspective to you know characterize when the activity happens and for pattern of life is really useful, right? If you uh if your suspect talks a lot at different days, but then you see a gap in particular days where you expect uh conversations to happen, this analytical view will surface it graphically immediately. So I I really uh like this capability. It's something that uh James uh came up with, and I really appreciate him uh to put that he put that into the tooling. And we'll we will continue to add functionality uh as we as we move along. Um, the tool has evolved so much since whatever nine, eight, seven years ago. I don't even know how long this tool has been around. Um, but uh it's made so much better by the contributions, and uh James has done a great job at it.
SPEAKER_00Yeah, I didn't I didn't know that column thing was there. I'm super excited right now. Okay.
SPEAKER_01There you go.
SPEAKER_00Um, some other uh some other uh filtering that I just want to show real quick. Uh you can obviously click on any um column and clip from ascending to descending. There's a little filter on each column as well. So this is a timestamp column, so you can set a date range, but you can also filter if you wanted to filter on, I don't know, on the conversation column or the the message column and just look for a specific word.
SPEAKER_03Or sender as well, who's sending or whatever.
SPEAKER_00Yeah, who's sending, which account it is. You can come in here and just choose which one, uh, which words you'd like to filter by. Um there's export options so you can export whatever you're choosing. So I'm in the wire messages. If I will just want to export all of the wire messages, I can flip it from clipboard or file. I when I export, I want to do it to file, but you can put it in the clipboard. Um, so file has CSV, JSON, XML, HTML. I'm an HTML lover. Um, so you can choose all rows, or you can choose um filtered rows if you filtered. I didn't put any filters on, so there's nothing there.
SPEAKER_03Um, you also everything everything is there because you haven't filtered.
SPEAKER_00Yeah, right, exactly. You could remove columns. So on this column option, if I don't want to see, I don't know why you wouldn't want to see. Let's just do sender ID, conversation ID, and status. I can get rid of those.
SPEAKER_03But hit close.
SPEAKER_00Oh, yeah, I hit restart.
SPEAKER_03But after you take them out, yeah. But take out take out sender because the ones are all the way to the right, but take sender out just so people can see it.
SPEAKER_00Yeah, get rid of the timestamp too.
SPEAKER_03Yeah, but look, immediately on the screen, you can see it's not there.
SPEAKER_00Yeah, yep. So you can get rid of whatever columns you want. And then when you go back to export and you choose file, you can just do the visible columns or you can do all columns. So if you want your export to actually go back to having all STML, STML, if you're gonna you're gonna pull it out.
SPEAKER_03The STML looks really good, by the way. Okay, but the STML looks pretty nice.
SPEAKER_00Okay. Um, what else? So
Tagging And Portable Lava Subsets
SPEAKER_00the actually let me reset this. The the biggest thing that we have added, we, I didn't do anything with this, so I shouldn't say we, but the biggest thing that has been added is the tagging, in my opinion. It is something I have been waiting for like since I learned about the leaps. Even with the HTML reports, I'm always like, ah, but I don't want every single message, I only want the messages that pertain to my case. There is now, if you look over in this left-hand um column, little check boxes you can check mark, and right next to your check marks, there's this plus sign for tags. So I'm gonna add a new tag and I'm gonna call it my wire messages. I don't know why I selected all of them, but I did, and then hit okay. I've now tagged all of these messages as my wire messages. You can call them whatever you want for your case. And if you look all the way to the left up at the top, the tag rows are starting to populate over here in the top left-hand corner.
SPEAKER_03Can you do do we do word devices? Um, because we at least we have two, so we can show them.
SPEAKER_00Yeah, I'm just gonna pick a couple of those though. We're just gonna do this one and I'm gonna do a new tag. I'm just gonna call it devices.
SPEAKER_03You can select whatever color. I should hit the color. We hit okay. Hit the color, you can select any color I want. Any color you want from the from the established one to the gradients. I mean, say gradients, but there's a gradient bar you can move it around, so it's pretty neat.
SPEAKER_00So I just did that one devices, and here let's do one more as a device. Now that tag is there populated. I don't have to create a new tag, I can just click to add it to my tag.
SPEAKER_03Actually, do do a quick note so you can see the note the note thing.
SPEAKER_00Oh, go ahead.
SPEAKER_03Uh I I don't know. I don't know. Open the that that one and put a note on that one. Yeah.
SPEAKER_00So let's put here is my note. How's that? Does that say?
SPEAKER_03Yeah, yes, click.
SPEAKER_00Okay, I see. You see a little note icon that comes up.
SPEAKER_03Yes.
SPEAKER_00And it says here is my note. All right. Then when we go over to the you'll see your tagged rows. They come in sections. Um, they're uh sectioned off by artifact. So my wire devices are up on the top and my wire messages. No more having to use screen snipping as tags. Agreed. Agreed. That's yes. So now we have this here tag. Um you can manage your tags here. If you wanted to delete a section of the tag, say you just wanted you, say you had 50 different tags, you can and you only want to show two. You can get rid of them with the little uh trash bin. Um, we can also export. So from here, I'm gonna let you talk about the subset, but from here is where you can do your export of the tag. The options are lava subset, HTML report. Um, so HTML is normally what I would do, but Alexis is gonna explain to you what the lava subset is because it's pretty freaking awesome.
SPEAKER_03Yeah, so pretty much uh originally I was gonna call it you know a lava portable case, but portable case is such an overused term. So I decided with subset, um, a lava subset. I was gonna say I was uh originally even before I said I'm gonna call it obsidian, an obsidian report because lava, when it cools down after you do stuff, you know, let it sit for a while, it turns into obsidian. But yeah, uh the folks in the group did not agree. That was just like too too, I guess, too nerdy lame. So instead of an obsidian report, which I still regret I couldn't call that, we call it a lava subset. And what that does is it's literally takes those um those tags and the data and moves it out into its own um report, which is is really good because then you use lava itself to look at that subset of data, pretty much like a portable case would work um in one of the other detail forensics tooling, which is it's pretty good. This is really useful when you have data sets that are really, really data heavy that you cannot show in an HTML. You're gonna do it, you're gonna show it with the Lava subset report. And you might well, do I need Lava to open the subset report? Yes, yes, that's designed to be looked at by uh lava, so you will need that. Um, but that's just how any probable case is, right? The and uh Maybe you need to whitelist or allow list is the proper term. Allow list is executable in your environment or whatever it is, but it just follows uh you know what's kind of the procedure in in this business because that's what works. You want to say something, Heather?
SPEAKER_00Yeah, I'm gonna give you a use case for this. So um recently in my office, we have a case and it has over two million, closer to three million telegram messages. Uh, nothing processes it. Uh the tools choke. The leaps actually did process it. Yes. Woohoo! After hours and hours, it went. There are so many messages. Um, so the leaps process this, but now how do we report it? I don't, I can't even open the HTML that goes along with three million telegram messages.
SPEAKER_03Oh, it's not happening, it's not happening.
SPEAKER_00So um, it does open in lava and it opens up in lava, but now how am I gonna report that? Am I I can't do an HTML report. I mean, I'm gonna tell you that most of the messages are evidence. Um, so how am I gonna report it? We're gonna do lava subset projects. Um, we're gonna have to, and then all we'll have to do is just probably reach out to whoever the investigator and the prosecutor are and let them know they're gonna have to install lava to be able to open the subset subset project. But it is going to save us a ton of headache of creating all of these little mini HTML reports of like each conversation. And I'm gonna tell you right now, you can't even do that of each conversation because some of the full conversations have hundreds of thousands of messages. So this is kind of gonna be a not kind of, it's gonna be a lifesaver in that case in particular.
SPEAKER_03Oh, I'm really proud of the team for that. Um, and and I want to say a word about Telegram for uh for the for everything iOS, right? The one that you were running?
SPEAKER_00Uh yeah.
SPEAKER_03Yeah, I mean iOS and Android, both. Um, we took every single control message that the Telegram application exposes and we support it. We went to the source code, Telegram is open source, and we support it. And I have an article in the blog post and a little guide you can get there that explains every single control message in in Telegram. And if you don't know what that is, I'll tell you right now. Um, some applications, some implementations of Telegram, you see the messages, and then you see that, let's say, bricks and a message, but there's no message, it's like a blank. And you're like, is that a deleted message? Recover, what is it? The tool doesn't support it, and when something doesn't support it, usually they just show a blank. Well, actually, if the tool supported a control message, it will tell you what that uh message is supposed to uh do in the application. Some messages could be that somebody joined the group, or that somebody cleared the conversation, or that somebody has sent you a location. There's a there's a whole bunch. I have like four or five pages of control messages which we are supporting, and that will characterize the activity on the phone. Um, if somebody claims, uh, some cases might have happened that, well, I did not delete this information, I had nothing to do with it. Well, there is a a control message that says that the username X, Y, and C cleared you know the conversation and it it it will remain, and you can get to that. So, so that in that the the uh our parsers for A-Leap and iLeap do that. I don't see anybody doing it at the level that we do it. And again, when it gets to millions and millions and millions, a lot of tools are all the tools for choking except uh iLeap and A-Leap, which I'm really proud because now we're providing that capability to everybody to be able to do their cases. So it's it's I'm I'm super happy about it.
SPEAKER_00Yeah, so the tag the tags are amazing. This is uh honestly, I know I already said it, but this is the feature that I wanted the most.
SPEAKER_03Um, I'm gonna just show them collapsing real quick before you logo away with that. Collapse the uh the collapse one of them so you can see.
SPEAKER_00All right, hold on one second. I was gonna show that in the report, but I'll show it here too. So yeah, you can collapse these here so the screen doesn't have to be as busy. And I think you added that to the report too, correct?
SPEAKER_03Yes, you you will have to stop shaving the application, share the screen, and open the report.
SPEAKER_00Yep, I've got the report open.
SPEAKER_03So okay, yeah.
SPEAKER_00Um, let me just go to screen tire. Um, let me pop that up. Here it is. All right. So I exported when you weren't looking. I exported the tagged rows. So here's my tagged rows HTML report. I have the tagged rows, I have the source project. It talks about the tags that were used and the number of tagged rows, when it was generated, and which tool was used to generate. Um, it starts out with everything collapse. There's a collapse all and an expand all button here. You can use the little arrow down. I love this. I love the collapse all.
SPEAKER_03I we need some other tools to do that as well.
SPEAKER_00Oh my god. Yes. So this is how this is actually how I envisioned my timeline report to be. Like I want a category here called whatever for my timeline, and I want to be able to just drop down the little, the little um drop downs. I want it to say what what I'm showing, and then I want to be able to drop it down and see the artifact. Just FYI had since we're gonna build that.
SPEAKER_03If you only had access to the communications of the folks that maintain this project, you might be able to push that. Oh, wait, you already have access.
SPEAKER_00I actually started making it myself, but I'm struggling major.
SPEAKER_03Well, then keep working on it and and uh put it there and we'll we'll look into it as you already will do, we'll do, but uh so this tagged uh this tagged rose report is amazing.
SPEAKER_00I am gonna say one thing that I added to mine because I did a tagged rose report for a case, is I added my agency logo up at the top of the up at the top, but you can easily just add that into HTML, or who knows, maybe it'll be a feature coming up soon now that I'm mentioning it.
SPEAKER_03And that shouldn't be too hard because the leaves already have that capability, it's just a matter of migrating that's saying migrating, but kind of recognizing it within within lava and then put it in. So we gotta we gotta make that comment to James to kind of definitely.
SPEAKER_00Yep.
SPEAKER_03And that that shouldn't be too horrible to do.
SPEAKER_00Yeah, I wouldn't I wouldn't think. So that is lava. So for anybody who may have been confused on what lava actually is, that's what lava is, that's the capabilities of lava. Um, I foresee, even though I'm slow to make the change, I foresee people not even going to the HTML report anymore because the HTML report as is, it's everything you can't filter that to what you need for your case. But lava is giving you the capability to just choose the artifacts that are important to your case. And I think that is probably, in my opinion, the biggest, the biggest new feature for lava. Um, yeah.
SPEAKER_03Yeah, and Dan's saying it's so much cleaner, and that's something that I've been really harping about. I want the interface to be really clean, and if there's a lot of stuff, I want to have the ability to uh filter it so it gets a view that's consistent with what I need in my case. Yeah, so so I appreciate Dan pointing that out. Makes me happy because that's one of the main things I was really harping about when we were adding this functionality. I want to really streamline, really uh easy to use and easy to customize in a way that's uh intuitive. And I believe that we we achieved that purpose.
SPEAKER_00Um, all right, we've talked for an hour and 35 minutes, but I did miss one thing that I want to say.
SPEAKER_03Well, then say it. You're the owner of the time. Go ahead.
SPEAKER_00One other thing. Um, so recently we had somebody reach out to and in and in the new versions, where are my source files? Where is this data coming from? So, whichever artifact you choose, and I'm just gonna pick, let's just pick wire devices. Up on the top in Lava, there's a little I next to wire devices. If you click that, that's where you're gonna find all of your good information, your module name that was used to process it, um, the artifact name, a description, notes, uh, the author of the artifact. And then the biggest thing um that I see that that is needed um that I didn't know where to find at one point is that source path. So the wire devices are coming from the HTTPS app wire.com and in those index DB level db files. Super, super important um for your casework that you know where your data came from.
SPEAKER_03And notice the description and notes. That's uh the developer's best effort at letting you know what the artifact is about. And notice I said the developer's best effort. I mean, I put a lot of effort to make sure that the information there is accurate, but again, it's up to you as the examiner to look at that description, look at those notes, and verify that your outputs and validate those conclusions. And this is true of any tool. I don't care if you know MSAB or Celebrite or or Belkasov or whoever says that something means something. To me, that is uh informational purposes only, right? It is my verification of my outputs and my validation of that meaning that will determine uh the significance in my case. So I'm I'm gonna harp that till I have no more breath in my in my in my body that you need to go and and and don't be lazy. Be an examiner, make sure you verify all your things.
SPEAKER_00Are you saying that just because there's notes, you don't know everything?
SPEAKER_03Um I thought you knew everything. Well, I mean, well, I mean, I mean, I mean, I I know everything now. It's a correct that's up for grabs, you know. I might be making it up. I'm like I'm hallucinating like the LLMs. Uh good point. No, no, we we we have to, we have to check that out.
SPEAKER_00Test, test, test, test. I I think I've said that uh on a previous show, right? Like I we talked about the Ian Wiffin's location cheat sheet. I trust Ian's research 100%. But do I want to be up on the stand saying, well, Ian Wiffen tested this for me? And he said, No, I want to be up there and say I utilized Ian's research, but above and beyond just Ian's research, I actually got a test device, I tested it myself, and my results concur with his results.
SPEAKER_03So and that's so important because the maybe the research research that he did happened six months ago.
SPEAKER_00Yeah.
SPEAKER_03And now something has changed, right? And what are you gonna do? Just go with that six months old. Oh, which by the way, if you look, and that's how you we showed already in the informational section, it tells you when the artifact was made and when it was last updated, right? So so it's also really useful to figure out when this artifact ran last. I mean, not ran last, but was made and and modified because something could have changed in the low six months, three months, a week, a year, whatever the amount of time it is. So the tooling lets you know when the last update happened, but it also reaffirms that you need to make sure you do that testing because things change from when they were made to today.
SPEAKER_00So that just happened to me. And uh so uh what was it? Was it chat GPT? No, it was Cash App. You wrote a parser for Cash App, and so did Gerald Dean. There's two different ones. Uh, neither of one of them got my Cash App because the name of the database or the location of the database, I can't remember which, uh, changed. So literally all I had to do was take you guys um scripts and add a new location to it, and I got all my Cash App information, but something changed and it no longer worked. So yeah.
SPEAKER_03And even if it works, you gotta you gotta check. There might be some meaning that has changed on those columns. And uh you have to make sure that you you test that and make sure that you're on the right place.
SPEAKER_00Yeah.
Meme Of The Week And Closing
SPEAKER_00So to end the show, this was uh longest podcast ever. We can't leave without doing the meme of the week. I'm gonna let you explain this one since I looked at it with uh confusion yesterday. I may have gotten picked on yesterday.
SPEAKER_03Well, the thing is that I think Heather likes animals so much, and we she saw the bird, she wasn't even focusing on the meaning of the meme, she was looking at the bird and she couldn't get it. And you're like, girl, are you kidding me? This is like this is yeah, I think it's the bird, it flew over your head like the bird.
SPEAKER_01All right, so it did.
SPEAKER_03Uh I was giving a hard time. So, so so what the folks that are not listening and not watching, that's this little like like parakeet, and uh they're trying to give him a cook uh cracker, and the cracker is called lock archive, and the parakeet says, Get that thing out of my face, I don't want it, right? And then it kind of hit the touch that guy bites it to get it away from kind of get it away, and then the bite it eats part of that lock archive cracker, and when it eats it, the eyes shine, and it's a whole new universe, a whole new understanding. This is amazing. This log archive cracker is amazing. So the point I was making with that meme is that yes, a lot of data, and you're like, I don't do I really need this. I never used it before, I don't need this, but I'm telling you, the moment you taste a little bit of luck archive, right? When you when you put a little a drop, a drop of apple unified logs in your tongue, you'll be hooked. It you'll be hooked. You will not work a case that involves iOS or macOS because it's Apple Unified Log, it shows up in Mac OS, in iPad OS, and in iOS, and you'll be hooked on your investigations because there's so much data that's relevant to your cases that you you can't believe. So, yeah. So we're we're so be if you're gonna be that parakeet, be that parakeet after you bite the log archive cracker. You're gonna love it. All right, love it. Did that explanation make sense?
SPEAKER_00It absolutely makes sense, and the meme makes sense to me now. But when I looked at it, I I I just looked at it. I'm like, I don't want to do that one because I because I don't know how to explain it, but I got it.
SPEAKER_03What are the bubbles around the parakeet? Was he being washed in a washing machine? What's going on?
SPEAKER_00It looked like it was crying, I don't know. But yeah, so uh 100% agree with the meme though. The log archive is such an untapped resource of artifacts.
SPEAKER_03Yeah, so yeah, I I I I uh I try to make jokes about things that I like, and uh here you go.
SPEAKER_00I sometimes they sometimes I get it, but uh yeah, so longest podcast ever, and I think we're all done. There was plenty of other stuff to talk about, but we hit on some really great things that have happened since the last show.
SPEAKER_03I I appreciate you being here. I love doing this podcast for everybody, but mostly I do it for me because I like hanging out with you and I like talking about these things. So uh if anybody thinks it was too long, well, too bad, so sad. It was it was I I had a great time, and that's that's all that matters. I'm selfish like that.
SPEAKER_00Oh, thank you so much, everybody that was there in the chat. And until next time.
SPEAKER_03Yeah, uh, absolutely. I always ask if anything a heather has anything else good for the order, but any Heather said it all. So I think we're good to go.
SPEAKER_00All right, all right.
SPEAKER_03I think I'm gonna leave with just one uh one uh one last message here for Dan, uh good guy I've known for many, many years. Uh can you can you read it? You have a better reading voice than me. Can you read that?
SPEAKER_00Thanks, guys. Love all the updates. We're already fully implementing the leaps in our lab, especially for log analysis around crashes. Leaps are um leaps and bounds better than most tools for these.
SPEAKER_03Yeah, awesome.
SPEAKER_00I see why you wanted me to read it.
SPEAKER_03Yeah, yeah, with leaps and bounds, baby. Uh, I I love I love my jokes. All right, well, with that um with that amazing joke, I'll leave you all with the uh outro music, and we'll see each other uh in the net podcast episode, hopefully sooner rather than later.
SPEAKER_00Absolutely.
SPEAKER_03See ya. Thank you.
SPEAKER_00Bye.
SPEAKER_03Bye.