In brief

A practical guide: how on macOS to extract and brute force the account password in order to reach the keychain, tokens and desktop messengers dynamically. Static analysis is the "gold standard", but it misses protected memory areas. The talk is methodological: the Mobile Criminalist line is assessed critically.

Key points

Tools, artifacts, technologies

The terminology is "forensic examination", "the initiator of the examination". Article 57: a forensic expert is not entitled to use methods that could cause the full or partial destruction of the object or a change in its main properties and appearance (the code is not specified). Hence an examination with changes made — only with the initiator's permission. The speaker is from the Forensic Expert Centre of the Investigative Committee of Russia (SEC SK); there are no references to departmental methodologies or to regulators.

Questions from the audience

The speaker's position

The tone is that of a lecture and a methodological guide, with no polemics and no sales pitch. He treats as correct the priority of static analysis, manual double-checking and the initiator's permission before changes are made; as a problem — blind trust in automation. He admits the limitations openly: hardware encryption, the Secure Enclave, root, the difficulty of modern iPhones, the dependence on whether the plist can be pulled out.

Quotes