In brief

What it was. MOSCOW FORENSICS DAY '25 — the ninth annual digital forensics conference, 11–12 September 2025, Moscow, the "Pulsar" venue. The organizer is MKO Systems (the maker of Mobile Criminalist); the opening and the closing were led by Olga Gutman, and the talks were moderated by Dmitry Yankovoy. Day 1 was for law enforcement, day 2 for corporate information security. The recording (a splice of the YouTube streams of both days, ≈9 h 33 min) holds 19 talks and two closings; the general partner's closed-door talk and the whole evening of day 1 (the "roast", the prize draw) were not let into the stream.

What matters in substance.

The talks in one line each.

What not to believe. The Q&A was recognized worse than the talks: the lines from the audience were without a microphone, the names of those asking are by ear, and in the discussions the speakers are not labeled. The contested names were checked against the audio; some were left as recognized. The statistics come almost everywhere without sources: ×35 and ~400 cases (Moskvichev), 90/30/90% (Vyugin), 99.6% and 97% (Inkin, from the demos).


1. The conference and the recording

The event. MOSCOW FORENSICS DAY '25 (MFD '25) — the ninth annual digital forensics conference, 11–12 September 2025, Moscow, the "Pulsar" venue (3rd Yamskogo Polya St., 2, bldg. 6, "Belorusskaya" metro). The organizer is MKO Systems, in the moderator's words "a leading developer of software for computer forensic examination of mobile devices, personal computers, drones, cloud services", with training in the field of "digital forensics". The organizer's products (per the 2025 website): MK Expert Plus, MK Desktop, Forensic Kit; the flagship is "Mobile Criminalist" (MK) with the MK Brute Force, MK Scout and MK Corporate modules. The conference has been held since 2016; the next one (2026) is billed as the anniversary one, the tenth. The opening and closing of both days were led by Olga Gutman (MKO Systems); the moderator of the talks in between was Dmitry Yankovoy (MKO Systems).

Format. Two days with different audiences: 11 September — digital forensics day (talks for law enforcement officers), 12 September — information security day (for corporate security). In person plus a live stream of the open part of each day; admission by passport/service ID, filming in the hall prohibited, a professional camera operator was working, the recording was promised to the attendees. Day 1 per the program — three blocks of talks, then the "roast" (17:30–18:30), a prize draw (18:30–19:00) and informal networking (19:00–21:00). The "roast" is billed by the organizer as "the hottest part" — a session of questions for all the speakers saved up over the year and of complaints about the "Mobile Criminalist" product made straight to the CEO. The main value of the conference named from the stage is not the content of the talks but the networking of the expert community "from all over the country"; the talks, meanwhile, were sold as "real meat" and "the cream of the crop", the result of a year's work on the program.

Partners. Per the official program (logos, in the order they appear): LAN PROJECT, ACE Lab, SearchInform, ELETEK, Ester Solutions, Zero eDiscovery, Account-Best, STC Group. The general partner is Account-Best. A discrepancy with the recording: at the opening the moderator listed the partners with booths as "ACE Lab, LAN PROJECT, ELETEK, Ester Solutions, SearchInform and STC" — Zero eDiscovery, listed as a partner in the program, was not named in the speech; whether it had a booth cannot be established from the recording. The general partner Account-Best was presented as having "no booth", with a closed-door talk on UAVs (the speaker per the program is Igor Zaitsev; in the transcript of the opening, "Igor Evgenyevich", the patronymic by ear).

Audience and positioning. The stated audience is forensic experts, investigators and security-service specialists "from all over the country", in person and online. The words "law enforcement", "business" and "information security" were never spoken from the stage at the opening; the split between the days (forensics / information security) was not spelled out at the opening. The organizer casts itself as a supplier of tools for practitioners.

What is in the recording and what is not

The source of the recording is the YouTube stream of both days, spliced into a single file (https://youtu.be/4V7Wez3L_58, ≈9 h 33 min, a Whisper large-v3 transcript). Within a single speech block the timecodes are continuous; between blocks the breaks, the closed-door talk and the whole evening of day 1 are cut out.

Day 1 (11 September) — in the recording: the opening (Gutman, Yankovoy), nine talks in a row — Greshnov (ELETEK), Vakhrushina (MK Brute Force), Chikin (ACE Lab), Tushkanova (Investigative Committee, the methodology), Moskvichev (NFC), Eremin (VR-Expert), Kotova (SpyNote), Shavlovsky (macOS), Bederov (OSINT) — and the closing of the online part of day 1.

NOT in the recording:

Accuracy. The timecodes of the talks are published in no external source (the YouTube description, the program, the organizer's posts) — every timecode in this summary is derived from the recording map based on the transcript and is approximate (a drift of up to ±15 min relative to the program's schedule). The lines from the audience in the Q&A were recorded without a lapel microphone and recognized worse than the main speech — the wording of the questions is approximate in places, and the names of those asking were in most cases not established.


2. The talks

Vladimir Greshnov (ELETEK) — "Duplicators vs. manual copying: when speed and accuracy are critical"

The first talk of day 1 (the program slot 10:10–10:40). ELETEK is an official partner with a booth; the speaker is not a developer, does not command the technical details and three times sends people to the booth, to the engineer, for the specifics. Formally what is announced is a comparison of duplicators with manual copying; in substance it is a catalog tour of the product line: four hardware duplicators and two software products. There is no comparison with manual copying and no speed or accuracy figures in the speech — the title is not borne out by the content.

Key points:

Tools and artifacts: the ELETEK line (called "Element" in MKO's wrap-up post): the "Element-U" unit, the flash-drive duplicator, the SATA duplicator, the workstation, the image viewer software, the "live" acquisition software; Boot Manager, a Secure Boot bypass; the RAW/E01 formats; Astra Linux (the target OS); Android (the mobile control app); Mini ATX, Core i3, NVMe, SATA, HDD/SSD; BitLocker (detection), TPM, RAID, hidden areas, volume label, hash + verification.

Legal and organizational context: the speaker named no laws, articles, methodologies or agencies; the Russian word for "forensic examination" was never spoken, the terminology is "data acquisition", "officers". The procedurally significant properties he emphasized: the evidence medium stays unchanged (the unit's own OS without booting the native one, the read-only mode with the padlock, the hardware write blocker in the SATA duplicator), hash calculation, automatic reports. The products were built in response to field operatives' requests and to questions from the exhibitions; ELETEK has a booth with the engineer who develops them.

From the Q&A: RAID — "Element-U" images it, but reassembling the array is left as the user's problem. A RAM dump — they do not do it, they are "on the verge of starting to work on that" and want to implement it (a remark from the audience: "That's bad."). Encrypted disks — a sector-by-sector copy can be made, but the data cannot be viewed with ELETEK's tools. Clone vs. image — the person asking argued that an image is better than a clone (for an image computing a hash makes sense, for a clone it is "pointless"); the speaker: the basic mode of all the units is a sector-by-sector copy to a file, and the clone is a concession to practitioners. Secure Boot and TPM — there is a Secure Boot bypass in "Element-U", and the speaker could not answer about the behavior with TPM and sent the question to the booth.

The speaker's position: the correct basic mode is a sector-by-sector copy to a file (an image), and cloning is an add-on made on request; features are being moved to automatic operation for an untrained operator. All the limitations were acknowledged only in answer to questions, never on his own initiative.

Unclear: of the six products, only the name "Element-U" was spoken (and only in the Q&A) — the rest are named descriptively. The phrase about the hardware write blocker, "unlike on our largest workstation", literally means that the workstation does not have one; it may be a slip of the tongue. The attribution of the lines in the clone/image argument is missing from the transcript; they are assigned to the person asking by the logic of the dialogue. "Yuri Mikhailovich" from the audience — by the recording map this may be the day 2 speaker Yuri Barkalov, unconfirmed.


Valeria Vakhrushina (MKO Systems) — "Dictionary or mask: how MK Brute Force works"

The second talk of day 1 (program 10:45–11:15). The speaker is MKO's marketing director and at the same time the head of development of the MK Brute Force module (a "split personality as a marketer"). An overview product talk about password cracking inside Mobile Criminalist. The main point: cracking a password is engineering, not magic; any tool comes down to two methods (a dictionary or a mask), and "a mask head-on" must not be used.

Key points:

Tools and artifacts: MK Brute Force (three methods: dictionary / mask / dictionary based on personal data), hashcat (7.0 awaited), Mobile Criminalist, MK Scout, the built-in password manager; GPU/CPU; zip/office, Telegram Desktop passcode, BitLocker, NTLM, Android/iTunes/HiSuite backups, Apple Notes; FBE/FDE; the demo password MFD2025.

Legal and organizational context: no Criminal Code articles, laws or departmental methodologies were mentioned in the talk. What was stated was a ban on building AI into Mobile Criminalist: "building artificial intelligence… is prohibited. The legislation would object"; the speaker did not name the specific provision (having a law degree, she "won't answer this question from a legal standpoint"). The justification goes through architecture, not law: MK does not analyze or accumulate the user's data, the vendor gets nothing back, and training an AI requires data to come back — "and that would not be good". Organizationally (a line from the moderator): a reminder about the recording and a ban on filming in the hall.

From the Q&A: Ilya (a staffer with a microphone) — support for cracking a physical Android image in the free app: FBE/FDE are not in the free version; if the hash is not supported and the attack does not start — write to support, specifying the device. San Sanych — when will distributed brute-forcing come: hope for the 1st half of 2026, with no promises. The same man — AI for the inverse task (cracking passwords): no, AI is prohibited, the idea is "closer to rainbow tables", "we'll think about it". An audience member — which specific provision of the law prohibits AI: she will not answer from a legal standpoint, the substance is the policy of data not coming back. Ilya Anatolyevich — how to build a dictionary out of the device's data: through MK Brute Force's third method and the built-in password manager.

The speaker's position: the right way is meaningful hypotheses and dictionaries updated in time, so as not to be "burning electricity for nothing"; 2FA — "always". She admits the limitations honestly (a dictionary is unlikely to crack a safe password, the free version has no FBE/FDE, there is no distributed cracking yet). The style is self-ironic.

Unclear: the speaker gave the numeric estimates of combinations approximately and "googled what these numbers are called" — they are carried over verbatim, without recalculation. The file boundaries take in the moderator's lines; the meaning of "Sotochka" as a password was not explained. The names of the questioners ("Ilya", "San Sanych") are by ear.


Vyacheslav Chikin (ACE Lab, ACE NPP) — "Specifics of accelerating password brute-forcing on mobile devices"

The third talk of day 1 (the program slot 11:20–11:55), it continues the previous one's topic from the hardware side. Technical and honestly pessimistic: why brute-forcing the passwords of modern phones is almost hopeless, and what the attempt to speed it up runs into. ACE Lab is the developer of a forensic system (the product is not named).

Key points:

Tools and artifacts: scrypt (N/r/p, the "nasty thing"), SHA-256, ASICs (1024.1.1 — no use); the ACE Lab system (not named); Android FBE (2048.8.1, 2 MB/core) and FDE (32 MB/core); AMD Ryzen 9 9950X, Intel Core Ultra, NVIDIA RTX 4060 Ti; DDR5, the memory controller; Windows/Linux; assembly / the CPU cache (mentioned in the Q&A as a path not taken); dictionaries (a reference to Vakhrushina's talk).

Legal and organizational context: there is no explicit legal or procedural content — the talk is purely a hardware one; no articles of law, laws, agencies or methodologies were named. Indirectly: the talk was given on the "digital forensics day", and it is about a system for brute-forcing the passwords of seized devices.

From the Q&A: The CPU cache or RAM? — he speaks only about the CPU; to work with the cache you need code in assembly, "we haven't gone down that deep yet", they use standard functions; the cache is small and "gets eaten up very fast". Have they tried a "master password" — changing the password as in Windows instead of brute-forcing? — he had looked at the question from the hardware side; setting your own password / bypassing it — "hard — it's math"; on SHA-256 — "a very simple algorithm", but collisions for it are still not being found.

The speaker's position: a straight brute-force attack on the complex password of a modern phone is unrealistic; their system does not solve the task head-on. Many honest caveats about the research being unfinished ("our assumption is", "we're still going to look into this") — hypotheses are not passed off as facts. The tone is conversational and self-deprecating.

Unclear: the ACE Lab product is never named. "A mutation block" is the speaker's own conversational term for the way scrypt is built; how it maps onto the actual scheme (ROMix) is unclear. For the RTX 4060 Ti, "fifteen hundred passwords" — the unit "per second" comes from the context, it was not said in so many words. In the second question the person from the audience said "10.5 thousand years" instead of the speaker's "10 thousand" — a loose paraphrase.


Olga Tushkanova (Main Forensic Directorate of the Investigative Committee of Russia, GUK SK) — "A standard methodology for examining information stored on mobile devices and their components"

The fourth talk of day 1 (the program: 12:30–13:00). On the new standard methodology for the forensic examination of information in mobile devices, developed at the Investigative Committee of the Russian Federation in 2025: it was reviewed by the Investigative Committee's Scientific and Technical Council at the end of the first half of the year and recommended to the Investigative Committee's forensic expert units, and the printed version is expected "at best" by the end of the year. The speaker explains why the methodology had to be written from scratch and what is new in it. The main idea: a methodology is a formalized, reproducible algorithm with functional (rather than vendor) requirements; the contested questions (clouds, somebody else's email) are settled not by the expert acting on their own initiative but by an immediate report to the investigator.

Key points:

Tools and artifacts: the Investigative Committee's 2025 standard methodology (in press); the FSKN's 2011 methodology (FOUO) and the EKC MVD's 2014/2023 ones; methodological recommendations on Astra Linux (ready) and macOS (being written); the expert's hardware and software workstation (functional requirements); cloud service tokens, credentials for social networks and email, with cryptocurrency planned to be added; write-once and rewritable media, a cryptographic hash; examples of vendors that must not be written down by name — "CO-Systems" (= MKO Systems) and "Mobile Criminalist" / Cellebrite (in the discussion of procurement).

Legal and organizational context: the core of the talk. Federal Law 73-FZ (on state forensic expert activity — the expansion is ours), by the speaker's account, does not regulate the correction of errors in the questions. Agencies: the Investigative Committee of the Russian Federation (GUK, SEC, the Scientific and Technical Council), the EKC MVD of Russia, the FSKN, the FSB (mentioned), the courts. The Investigative Committee's Scientific and Technical Council does not develop but reviews and recommends; the methodology was written by the speaker's research department together with SEC SK. Public procurement: the methodology's functional requirements → technical specifications and contracts; standard systems are made through a state contract and development (R&D) work (in the MVD — "Special Equipment and Communications"). State secrets: clearance for experts, a certified hardware-software system into which other people's files must not be brought.

From the Q&A: Mikhail Mikhailovich — why video recording: it is a recommendation, more needed during inspections; a real case — the swapping of a Samsung phone in court. The same person — why there are no smart TVs and no smart home: "they hardly ever bring them", a methodology will be written when a real need arises. The same person — on personal data and tokens: there is no problem presenting them in the expert report, the methodology sets the procedure; the department heads at the EKC MVD are against downloading clouds as part of a forensic examination (the workload, the backlogs). From the audience — a "made-up case": OneDrive synced FOUO and state-secret material to the servers of a foreign state (FISA/CLOUD Act) — no such documents should be on a PC with internet access, a leak must be reported, and inspecting a cloud is an investigative action. San Sanych — is the Scientific and Technical Council working on a standard laboratory: the Council does not develop; a standard laboratory is an annex to a state contract, "it goes specifically through development (R&D) work".

The speaker's position: the methodology must be vendor-independent; she is against the expert accessing clouds and email on their own initiative; she is realistic about the limitations ("the expert often can't wriggle out of it", "a brick — so write it's a brick"); she is ironic about the quality of investigators' questions. She admits it is unfinished (she wants to "still manage to add" the item on cryptocurrency). The style is conversational and self-ironic.

Unclear: "from Eslava" (a vendor of bench equipment) — by ear; on the recording map, presumably ELETEK, low confidence. "73-FZ" and "Art. 57" — only the number of the law is in the transcript, the expansion is ours. In the Russian original the remark "bears responsibility for the revolution" — by sense, "for disclosure". The position in the program is "GUK SK"; the speaker herself is "head of a certain research department", and the methodology was written jointly with SEC SK; the remarks about past work at the MVD ("I acted as the functional customer") are not directly confirmed. The names of those asking are by ear.


Alexey Moskvichev (MKO Systems) — "Applying forensic methods to investigate thefts committed with NFC technology"

The fifth talk of day 1 (the program slot 13:05–13:35). About a new wave of fraud in which NFCGate, a legitimate teaching tool, and its derivatives are used to steal money by relaying the NFC data of bank cards. The trace picture in an extraction is shown on a real criminal investigation. An important caveat from the speaker himself: he works in training, the case came from a user of the software at a regional seminar, part of the data is not MKO's own examination; in the Q&A he repeatedly admits "we didn't do that examination ourselves".

Key points:

Tools and artifacts: NFCGate/NGate (4 modes, Clone requires root; TU Darmstadt, GitHub), GhostTap, SuperCard X; RAT trojans, an APK via Telegram; virtual keyloggers; MK Expert Plus (the MTK Android method); Kaspersky (standalone and the integration into the "Malicious Objects" section); decompiling the AndroidManifest (the appName "VTB Protection", the id "Darmstadt", the IP); cache4.db (Telegram); artifacts of the case (vtb1, the user id "7…", the file id "53/93", the logs of the uninstall and of the NFC service, a screenshot with the amount); Redmi Note 11S; POS limits of 3,000/1,000 rubles; Mir Pay (only in a question).

Legal and organizational context: a thin section — there is almost no legal specificity. The schemes are described through a criminal-case framing ("a real criminal investigation", the fraudster "introduced himself as a law enforcement officer"). From the audience: APKs come in for examination "at least once a month for sure", "we try to go down the same route through the EKC". No specific articles of law, laws, methodologies or positions of regulators were voiced.

From the Q&A: Traces by mode — in Relay there are traces (including on the victim's device), in Clone and Capture there are almost none (only OS artifacts and the start of the NFC service). Reading a card in a crowd (3–4 cm) — "we didn't do that examination ourselves… judging by the information we have, in principle, it is realistic"; the tag's data without the PIN is enough both for reading and, "effectively", for transactions. SuperCard X — is it legitimate — modifications are used, not the originals. Real Replay attacks — "we don't have that information… we can't give an example"; on the follow-up about the one-time cryptogram in an NFC payment the speaker gets muddled (correcting it to "not the security code — the bank card PIN"), and the answer is left hanging. Does the antivirus detect it on the phone itself? — "It would. It would on the device too." A "file — data" reference guide — "We'll try, but we're not promising."

The speaker's position: an educational/protective message (experts and security services should be the "anchor"); he honestly marks out the limits of his knowledge ("we probably don't have that much expertise here"). The weak point is technical accuracy on payment cryptography: the Replay claim about "emulating the bank card an unlimited number of times" is backed by nothing, and there are no real examples.

Unclear: the file identifier in the Telegram database, by the audio — "52…93" (in the raw transcript it sounded like "53"; checked against the audio and corrected). The trojan's name is consistently vtb1 (in the map the variant "vtb1/WTB1"). NGate vs NFCGate — by ESET's classification these are different things (NGate is malware derived from the research project NFCGate); whether the speaker distinguishes them deliberately is unclear. The statistics (×35, ~400 cases, ~100 thousand rubles, ~40 million rubles, >100 derivatives) are given without sources. Zaitsev's closed-door talk (UAVs), which came next in the program, was cut out of the recording.


Sergey Eremin (LAN PROJECT) — "Using VR-EXPERT to examine DVRs. A comparison with foreign counterparts"

The sixth talk of day 1 (the program slot 15:00–15:30, after Zaitsev's closed-door talk, which was cut out). A product presentation by the developer of the software VR-Expert (LAN PROJECT, the company is 25 years old, in 2025 entered in the Russian software registry) for extracting video from stationary and in-car DVRs. The key idea: most stationary recorders have no file system in the usual sense — the manufacturer stores the video streams and their allocation table its own way and periodically changes the structure, so a disk cannot be given "a quick look" on a workstation PC; a specialized tool is needed.

Key points:

Tools and artifacts: VR-Expert (the Russian registry, disk/image/E01, carving, signature search, HEX, logging, manual selection of the file system); the AI module (PyTorch, GPU, SQLite, Russian license plates, zones, tracking); proprietary file systems — TSFS/Tantos, TESAM/VFS-VFS2, "Dozor" (patrol police/FSIN, password bypass); FAT32; initialization in Windows 10/11 (destructive); VD-Expert (video forensic examinations, unsharp masking), Amped FIVE, Photoshop/GIMP; DVR Examiner, MD-VIDEO (GMDSOFT), SalvationData; ACE Lab equipment; DTP-Expert (OT-Kontakt); "Safe City".

Legal and organizational context: the Russian software registry is directly tied to making supplies to government bodies easier. The customers are "all law enforcement and security agencies", the piloting is "in several agencies"; the operating systems are tested against the list for the internal affairs agencies. The interface is designed for an inspection of the disk by the investigator without a specialist — the speaker rates that as "perfectly safe", but he gives no procedural caveats (admissibility, documenting the process, bringing in a specialist under the Code of Criminal Procedure). The sanctions context: supplies of foreign software are difficult, but it is still included in the alternative configuration. He did not mention specific laws, articles, Forensic Science Centre (EKC) methodologies or case law.

From the Q&A: The AI module — any source? — any video recording and static images, but "for now it doesn't go into the archive itself", the video file has to be pulled out. Determining an object's speed? — "No, we're not, and we don't plan to", that is DTP-Expert (OT-Kontakt). Searching by the detected objects? — everything is stored "in SQL" and is found with queries. A gyroscope/G-sensor? — not yet, "we'll see". GPS and visualization? — they have not worked on it, "that's a good idea".

The speaker's position: the businesslike tone of a vendor presentation; the right way is not to rely on Windows when connecting disks, the data present explicitly first and carving afterwards, to ship the software with hardware and write blockers, to keep several products in the arsenal. He acknowledges the limitations openly (carving a terabyte takes 3 weeks, Linux "through workarounds", recognition depends on quality). The claims of "being the only one" and of "having no counterparts" are the speaker's assertions and cannot be verified from the transcript.

Unclear: the names of the new file systems and recorders (TSFS, Tantos, TESAM, VFS/VFS2) are by ear, the confidence in the working map is "medium/low", the spelling may be garbled. The "Korean program" with problems on password-locked recorders is not named — by context it is MD-VIDEO. The authors of the questions are unknown; the "Alexey" in the moderator's remarks is the assistant with the microphone.


Natalia Kotova (Forensic Science Centre of the Yaroslavl Regional Police, EKC UMVD) — "SpyNote in action: how a mobile spyware trojan is created, deployed and examined"

The seventh talk of day 1 (scheduled 15:35–16:05). A practical talk by a young forensic expert (she graduated from the Ministry's university a year ago, has been performing examinations for a year, and is on stage for the first time): what SpyNote is, how it is built with the leaked builder, and how it is examined in phone fraud cases. The first part is a live demo of the builder, the second the examination method. She herself calls the upshot "a small practical guide".

Key points:

Tools and artifacts: the SpyNote v6.4 builder; Kaspersky (statistics); apktool, JADX, dex2jar, APKiD, strings, grep; Burp Suite, ZAP, Wireshark; MobSF (Docker, the online version); the Android Studio emulator (Android 10); INetSim (Q&A); AndroidManifest, accessibility service; frosting.db, verify_apps.db, packages.xml; the Samsung battery log, the package manager log; Sberbank's antivirus, the file 30.db; Base64, Gzip; SSL pinning/unpinning (Q&A).

Legal and organizational context: the typical questions of an examination in such cases — the presence of remote access software, call and SMS history, messenger and social network history, web page visits. Forensic correctness: samples are kept from being released onto the internet and are tested without a network. The agency — the Forensic Science Centre of the Yaroslavl Regional Police (EKC UMVD); the statistics — from Kaspersky's reports. The talk contains no references to articles of laws, methodology numbers or regulators' requirements.

From the Q&A: one question from the audience (the person asking is not named), in two parts. Crypters and obfuscators — in SpyNote obfuscation is "used quite heavily" (strange names for classes and variables); she uses an automated solution with behavioral analysis, and the task boils down to finding the IP address of the control server. Traffic encryption / SSL pinning / unpinning — samples are not let out onto the network, and the task of traffic analysis usually does not arise; she showed her own example because she had both the client and the server parts, where there was no encryption (only Gzip); the solution — a pair of virtual machines with the network emulated through INetSim. There were cases where the scammers wrote to the forensic expert through the built-in chat.

The speaker's position: the tone is emphatically modest and practical; she rates MobSF highly but names its limitations honestly; she insists on the only correct wording of the question put to the forensic expert.

Unclear: the person who asked the question in the Q&A is not named, and the remark is garbled. "verfi.app.db" in the Russian transcript, by the audio verify_apps.db — a distortion of verify_apps.db. The file 30.db and "Sberbank's antivirus" — by ear, the accuracy of the naming is not guaranteed. The SSL question is poorly recorded, and the meaning has been reconstructed from the context. A possible discrepancy: the person asking claimed that "the source code here is open, there's nothing like that", while the speaker replied that it is "used quite heavily" — the contradiction is not resolved in the transcript. The name of the agency: the speaker says "the EKC MVD of Russia for the Yaroslavl Region", while the heading has the official "the EKC UMVD of Russia for the Yaroslavl Region".


Andrey Shavlovsky (Forensic Expert Centre of the Investigative Committee of Russia, SEC SK) — "Examining information by dynamic analysis on macOS-based personal computers"

The eighth talk of day 1 (scheduled 16:10–16:40). A step-by-step manual on extracting and cracking the macOS account password in order to then examine protected data dynamically (the keychain, tokens, desktop messengers). The main point: static analysis of an image is the "gold standard", but it misses protected memory areas, so macOS examinations have to be supplemented with dynamic analysis, with the password obtained first. The running message — do not trust automated tools blindly, re-check by hand. The speaker's experience — 8 years of computer forensic examinations.

Key points:

Tools and artifacts: Keychain (an analogue of DPAPI); plist (XML/binary/JSON); dslocal, ShadowHashData; plutil, Base64; PBKDF2-SHA512 vs. NT hash/MD4; hashcat (mode 7100); MK Brute Force (no 7100), MK Expert (does not convert the hash), MK Scout (dynamic extraction of messengers/tokens); the unnamed third-party tool (loses part of the hash); wikpass.com; Fusion Drive, Secure Enclave (Q&A); virtualization.

Legal and organizational context: Article 57 (the speaker does not specify the code; by the context of forensic examination — the Code of Criminal Procedure of the Russian Federation): a forensic expert is not entitled to use methods that entail the full or partial destruction of the object or a change in its main properties. Hence: an examination with changes made is permissible only with the prior permission of the initiator of the examination. The speaker represents the Forensic Expert Centre of the Investigative Committee of Russia (SEC SK). There are no references to specific departmental methodologies, to regulators or to cooperation with other agencies.

From the Q&A: Yuri Mikhailovich — "So the disk wasn't encrypted? How did you pull the file out?": in this case it was a Fusion Drive, they managed to reassemble it, there was no encryption. The second question — on Linux the shadow file cannot be read under a user account, but on macOS it can? and will the plist be readable on a "live" system?: there are difficulties, especially on modern devices (hardware encryption, the Secure Enclave), without root you can't get in; the point is to pull out the plist itself; modern iPhones are problematic too, even when the passcode is available.

The speaker's position: a calm lecturing, methodological tone. Correct — the priority of static analysis, the mandatory manual re-checking of key results, the initiator's permission before changes are made. A problem — blind trust in automation ("their code may contain bugs"). He admits the limitations of the method openly (the Secure Enclave, the need for root, the difficulty of modern iPhones).

Unclear: "the previous speaker" who described static and dynamic analysis in detail — the phrase is garbled, no name is given (by the order of the talks, probably Kotova). The unnamed tool that loses part of the hash is one the speaker deliberately does not name. Mode 7100 sounded like "71.2.0" in the original Russian transcript. The domain wikpass.com is by ear. "Entropy" is what the speaker calls the final digest — non-standard terminology. The author of the first question, "Yuri Mikhailovich", may, by the recording map, be Yuri Barkalov, not confirmed.


Igor Bederov (T.Hunter / Internet-Rozysk) — "Identifying the owners, administrators and developers of web resources"

The last online talk of day 1 (scheduled 16:45–17:05). A short (≈17 min) overview talk, a how-to guide on OSINT research of websites: how to get from the domain, the hosting, DNS, the content, the technologies hooked up to it, web archives and external traffic to the three roles — the owner, the administrator, the developer. The speaker himself calls it a condensed version of an hour-and-a-half lecture; it is all presented as a checklist, with no depth. There were no questions from the audience.

Key points:

Tools and artifacts: a portable Opera (T.Hunter, 2,000+ sources); WHOIS and WHOIS archives, ICANN; DNSTwister, DNSTwist, IntelX, Have I Been Pwned; ping; Cloudflare; URLScan (urlscan.io), VirusTotal; DNS records; the SSL certificate, favicon; an SMTP check; dorks; metadata/EXIF (GPS); robots.txt, sitemap.xml; InfoApp (VKontakte); Yandex.Metrica; acquiring; web archives; external traffic/link seeding.

Legal and organizational context: according to the speaker, a ruling of the Supreme Court of the Russian Federation (August 2025) obliged business to detect typosquatting and online fraud on its own — the details, the date and the type of the act were not named. GDPR is the reason personal data disappeared from WHOIS. Techniques such as a request to Yandex support ("I'm the site administrator, I forgot which email is linked…") and a request to the bank about the acquiring service are presented as working ones, with no caveats about legality (pretexting, in fact); the legal basis for the bank's disclosure is not named. One of the cases was in the "invasion of privacy" category. Interaction with law enforcement is not described directly; there are no procedural references (the Code of Criminal Procedure, articles of the Criminal Code) in the talk. Organizationally: T.Hunter assembled a browser for researchers, and the slides are handed out to attendees.

From the Q&A: there were no questions from the audience. The moderator: "Igor, you've apparently fired up the audience so much that it's all perfectly clear now" — applause, and on to the "roast" (it did not make it into the recording).

The speaker's position: OSINT is an equal neighbor of forensics; the forecast: if smartphones lose the wired port, the weight will shift to data analysis. WHOIS is honestly admitted to have degraded, Cloudflare cannot always be stripped away, only ~10% of Metrica counters are public. Investigations of "political" petitions (calls to overthrow the government, to topple governors) are called an ordinary class of tasks — the tone is instrumental.

Unclear: the third tool name after DNSTwister/DNSTwist ("khipsk" in the Russian original) was not made out. "InfoApp" — by ear. The Supreme Court ruling is the speaker's retelling with no details and needs checking. The October 2021 social network is not named (from the description — Facebook/Meta, the global outage of 4.10.2021); the claim that during that outage the speaker "was going … to the IP address" is technically dubious (the outage was at the level of BGP/DNS announcements) — it is reported as his statement. "In about 70–80%" in the passage about petitions — what the share refers to is unclear from the broken syntax. The names of the WHOIS archive services, of the SSL/favicon products and of the web archives were not spoken aloud — only on the slides.


Closing of the online part of day 1 (Dmitry Yankovoy)

After Bederov's talk the moderator announces the move "toward the very final part of our evening today, namely the roast" and before it says goodbye to the online viewers: "now is the time to say goodbye to our online viewers. And we'll see you tomorrow". Those attending in person are invited "to the bar area, taking along some drinks, spirited and otherwise". The closing of day 1 proper in the recording — three sentences; the "roast" (17:30–18:30), the prize draw (18:30–19:00) and the informal networking (19:00–21:00) were deliberately not streamed and did not make it into the recording. The next substantive line in the recording (after a pause of ≈1:42 — the splice of the two days' streams) already belongs to day 2 (the lead-in to Barkalov's talk).


Yuri Barkalov (Forensics Science Centre) — "How does OSINT affect information security?"

The first talk of the second day (information security day, 12.09.2025); Dmitry Yankovoy opens and moderates it, the introductory and closing lines are not the speaker's. Barkalov (teaches at the International Institute of Computer Technologies, "retired three years") gives a talk that is polemical rather than practical: open sources have become a channel for influencing the consumer of information himself. The speech proper runs ≈26 min, followed by ≈9 min of sharp debate with Igor Bederov.

Key points:

Tools and artifacts: Yandex Metrica/cookies, Yandex Browser (the license agreement), "Alice", Microsoft (the Privacy Statement), Google (MH17), Telegram, GetContact, Fido (FidoNet, the historical first OSINT — prescriptions for narcotic-class drugs), USB tokens, flash drives, an ATM with "the new protection system", Mitnick's book (the title is not spoken in the recording), "CyberDed", NLP; legal artifacts — the Information Security Doctrine of the Russian Federation, Federal Law 152-FZ (Art. 19), Art. 272 of the Criminal Code, the Civil Code.

Legal and organizational context: Art. 272 of the Criminal Code and articles of the Civil Code (in the Russian transcript "the 1st, the 152nd, the 2nd" — probably Art. 152.1/152.2 of the Civil Code; the speaker map gives "152/137") as the framework of OSINT's legality; legal proceedings held in Russian — an argument against anglicisms in a forensic examination; Federal Law 152-FZ (the definition of personal data, Art. 19) — "somehow, I don't know why, it doesn't always work"; the fundamentals of information protection (legal, technical, organizational measures, a security policy) "exist, but for some reason aren't complied with"; the restriction of foreign messengers is supported with caveats; operational-search activities (ORD) vs OSINT — in ORD there are closed databases that "you can trust 100%", OSINT is "unreliable, reference information". The moderator's proposal of "a third day of MFD, done purely for lawyers".

From the Q&A:

The speaker's position: he provokes the discussion deliberately ("that's what I was after"); he does not deny the verification methodology, but considers it a different task and sees no solution against well-crafted disinformation. He is respectful of the practitioners of classic OSINT ("CyberDed", his students), and argues not with them but with the uncritical consumption of information. He is honest about the limits: he turned down the deepfake examination, and does not disclose what he answered the scammers.

Unclear: Bederov is not named out loud in the recording, the attribution of his lines is per the transcript's speaker map; the list of articles is garbled; "Elena Rafailovna Susova", "Ms. Yulova", "CyberDed" — by ear / not explained; some of the claims rest on slides that cannot be seen.


Alexey Shulmin (Kaspersky, GReAT) — "Librarian Likho — an APT group combining cyberespionage and financial motivation"

Scheduled 11:40–12:10. The speaker introduces himself as "a malware expert in the Advanced Threat Research Department" (the Russian name of GReAT). A walk-through of one APT group following Kaspersky's recent report "Notes of a Digital Auditor": the whole chain is built on spear phishing, batch files and legitimate utilities, without a single binary implant. The talk runs ≈27 min, the Q&A ≈9 min.

Key points:

Tools and artifacts: the report "Notes of a Digital Auditor", Obsidian, RAR spear phishing, .scr (MZ/PE), Smart Install Maker, data.cab/installer.config/runtime.cab, the PDF red herring, curl, LNK/trace.lnk, 4t Tray Minimizer (4t-niagara.com, a pseudo-British VAT number), rezet.cmd, C:\Intel, driver.exe = RAR 3.8, the unique password (traces from 2010), AnyDesk (svchost), Defender Control, powercfg ×6, schtasks ("shutdown at 5 a.m.", WakeUpAndLaunchEdge), wol.ps1, Edge, reg.exe → SYSTEM/SAM, wallet.rar, blat.exe, XMRig (Monero), ngrok, WebBrowserPassView, Mipko (MPK), SMB, Mail.ru phishing (login.php, the domain users-mail.ru, checked against the audio), directory listing, phpMyAdmin; in the Q&A — AMSI, KFA, KES, KSN, emulation of variable depth.

Legal and organizational context: the report is devoted to Ukrainian groups operating against Russia; the circumstantial evidence of origin is the mistake in the attachment name, the Ukrainian localization of Mipko, the Russian phpMyAdmin, the slogan on the 4t-niagara site. The limits of telemetry: "we don't see everything… bound by regulators' requirements, bound by all the GDPR stuff", the victim is not attributed — the mechanism is in the KSN agreement. Kaspersky is a commercial company, "not a government agency", it does not investigate incidents, "we're about Defensive, we're not about Offensive". Criminal liability: the attackers "all hope for Art. 272, 273, 274", but "work the RU, and they come for you at dawn".

From the Q&A:

The speaker's position: sarcastic, he addresses the group's operators, who "will watch the stream or the recording"; the main culprit is the user and the absence of security awareness (.pdf.exe in 2025). He criticizes the SOC (the missed dump of SAM/SYSTEM) and the level of the attackers ("an APT on batch files"), but admits: "it works". The conclusion: "First of all TI, first of all security awareness".

Unclear: the attachment name and the unique password were redacted in the talk; the domain users-mail.ru (the Russian word for "hyphen" was probably spoken aloud); the AnyDesk password "qwerty 1234566" is in question; articles 272/273/274 — the numbers without "Criminal Code".


Vladislav Azersky (F6) — "UWP in the DFIR crosshairs: what modern Windows apps are hiding"

Scheduled 12:15–12:35. A talk about applications in the UWP/MSIX format from a standpoint that is, as the speaker stresses, "not even about incident response so much, but more about computer forensics". The main point: the isolation UWP was conceived for has effectively disappeared, while the Store ecosystem has become both a delivery channel for malicious packages and a source of legitimate tooling that needs no administrator rights. Deeply technical; there were no questions from the audience.

Key points:

Tools and artifacts: UWP, Metro/Modern Apps, Desktop Bridge, MSIX/APPX, AppxManifest.xml (runFullTrust), BlockMap, MSIX Packaging Tool, Advanced Installer, MakeAppx, SignTool, Trusted Root, the PowerShell cmdlet (Organization ID), ms-appinstaller, Microsoft Threat Intelligence, the CVE (the number was not named), Perimeter 81, the FIN7 framework (PSF), StateRepository-Deployment (SQLite), a second SQLite database, event 9545, the App Installer log, winget, Python/Julia, ngrok/localtunnel, portable browsers, "SHRDP agents" (probably SSH/RDP), TeamViewer/RAT, VS Code/code.exe, the PowerShell log, SIEM, Purple Teaming, Yandex/Google (SEO poisoning), Microsoft Teams.

Legal and organizational context: there is no legal content — the talk is technical (no laws, articles or agencies are mentioned). The organizational context: the vendor's stance (Microsoft disabled ms-appinstaller, but itself opened the way for unsigned packages in Windows 11); corporate policies (a ban on untrusted packages and on MSIX for unprivileged users); monitoring (detection rules, event 9545 and the "four events" in a SIEM / log management). The talk sits in the information security day and is addressed to corporate security teams.

From the Q&A: there were no questions from the audience — the moderator joked "As always, you've broken my whole audience" and announced a break until 13:10.

The speaker's position: the isolation of UWP is a formality after Desktop Bridge/runFullTrust; Microsoft's decision to allow unsigned packages is presented both as a weakening and as a gift to the forensic expert (a ready-made Organization ID). Honest caveats (he found no description of the CVE, on the scale of the MSIX threat "there aren't that many cases") — he does not inflate the threat. He names the trend confidently: tunnels "in almost all cases" with ransomware, the legitimate Store has become a source of post-exploitation.

Unclear: event 9545 is flagged as unconfirmed in the recording map (in the raw transcript "95.45"); "SHRDP agents" — probably SSH/RDP; the wording about Perimeter 81 is syntactically unclear; some of the names stayed only on the slides (the name of the second SQLite database, the name of the FIN7 framework, the cmdlet and the parameter).


Nikita Vyugin (MKO Systems) — "The value of security tools: what we wouldn't have if we had everything"

Scheduled 13:10–13:40. Not a technical survey but a "warm-up" one (the speaker's own definition) of the standard security tool line-up — antivirus, DLP, EDR/XDR, SIEM, SOAR, SOC, DFIR — all on the same pattern: what it is, at what scale it is needed, the nuances of deployment, what is lost without it. The occasion — a post in Dmitry Boroshchuk's Telegram channel about "maturity" in information security. The talk ≈37 min, the Q&A ≈9 min.

Key points:

Tools and artifacts: antivirus, BYOD, DLP, EDR/XDR, SIEM, SOAR, SOC, DFIR, TI feeds, a cheat sheet (a slide), Dmitry Boroshchuk's Telegram channel, MK Enterprise (in the moderator's joke and in the question from the audience — so it was pronounced; the official name of the product is "MK Corporate"); from the Q&A — Nextcloud/ownCloud (a budget "controlled environment"), an access control system, 2FA, a backup checking system, hardening, "the Golden Rules book".

Legal and organizational context: the speaker names no specific laws or agencies. Regulators and standards — repeatedly "basic levels of compliance", "if you're under regulators… no arguing with it" (with no names). Supply chain: regulations between companies — "these days that's not rare". The legal arena: a big company needs digital evidence, DFIR reports "are read by law enforcement" and make their visit faster. Internal to the organization: deployments agreed with all the departments, SOAR — "through negotiations and agreements"; personal data as an example for DLP (Federal Law 152-FZ is not named).

From the Q&A:

The speaker's position: he positions himself as a security marketer against marketing tinsel; formally he was "really angry" at Boroshchuk's post, but in substance he agrees with it and closes on its thesis. The refrain — "count". Against selling through fear. He explicitly labels the estimates (90% antivirus, 30% DLP, 90% DFIR retrospection) as subjective.

Unclear: the attribution of the lines in the first Q&A is not marked up (who named the "four areas" — the speaker or the moderator); "Igor Evgenievich" — the recording map assumes Igor Zaitsev, not confirmed; "the Kaspersky representative" = Shulmin, but he did not speak directly before Vyugin; the talk has two different Dmitrys (Boroshchuk and Yankovoy); the figures are estimates by ear.


Maxim Sukhanov (CICADA8) — "The role of reverse engineering in understanding artifacts: when documentation is the enemy and the decompiler is a friend"

Scheduled 13:45–14:15. A talk about what a forensic expert (and a DFIR specialist) should rely on when justifying the interpretation of an artifact: someone else's results (the vendor's documentation) or one's own experiment. The main idea — a vendor's documentation cannot be trusted blindly, it systematically diverges from the code for four different reasons. There were no questions from the audience.

Key points:

Tools and artifacts: Microsoft documentation (for developers), NTFS ($STANDARD_INFORMATION, $FILE_NAME), VSS/shadow copies ("scoped shadow copy", copy-on-write, 16 KB vs 4 KB), srtasks.exe, MFT, a hex editor, Chrome history, the FAT specification, EFI System Partition, Prefetch ("OP-/OB-…pf"), OperationStart/OperationEnd, the Microsoft blog about ASP.NET, ntoskrnl.exe (PfSnBeginScenario, PfSnEndProcessTrace, PfSnSetPrefetcherInformation, PfSnOperationProcess, PrefetcherInformationClass, PrefetcherBootControl), Windows debug symbols, a decompiler (not named), Process Hacker (GitHub), Python, home-made NTFS/registry parsers, professional Telegram chats.

Legal and organizational context: no laws, articles, agencies or methodologies were mentioned. The procedural angle is in the framing of the problem: a forensic expert has to justify the interpretation of an artifact; the speaker disputes the view from the Telegram chats (~a year ago) that "I trust the documentation" is an acceptable justification. The organizational side: Microsoft explained the scoped shadow copy to customers in private and never reflected it publicly. Interaction with law enforcement was not discussed.

From the Q&A: there were no questions from the audience — the moderator: "I think you've broken my audience again."

The speaker's position: blind trust in documentation is a problem, not a solution; the justification has to be one's own experiment, and the best source of truth is the code. Skepticism toward any text by someone else, Microsoft blogs included. He is honest about the limitations: the $STANDARD_INFORMATION example is an extreme one; three of the four hypotheses about the OP files are "made up". The tone is purely technical, with a promise never once to say the word "business" (kept).

Unclear: the prefix of the prefetch files — "OP" in the transcript, "OB" in the recording map; the names of the kernel functions are by ear/from the slides; in the Russian original the phrase "no fewer than 32 requests… aren't saved" contradicts the sense (it should be "fewer than"); "Operation Based Prefetching" is called "Operation Recorder API" in the recording map; the name of the decompiler was never said.


Konstantin Titkov (Gazprombank) — "How not to end up needing forensics, and what to do if it can't be avoided"

Scheduled 14:20–14:50 (the official page names no company; "Gazprombank" comes from MKO's wrap-up post). A managerial and organizational talk about what to do when the defenses have not worked and the infrastructure has been encrypted, stolen or wiped. The speaker heads the cybersecurity center for Gazprombank's subsidiaries and is an ambassador of Cyberdom; he presents response recommendations written with colleagues and published together with Cyberdom. It logically continues Vyugin's talk.

Key points:

Tools and artifacts: DFIR, compromise assessment, TI feeds, SOC/managed EDR/EDR/IT monitoring, EDR/antiviruses/firewalling, the SANS guide, the 3-2-1 scheme, the backup system (the anti-pattern — the backup system in a flat network/domain), BitLocker, VM snapshots, storage arrays/SAN/LAN, forensic data in RAM, logs, the attacker's artifacts (persistence points, tunnels, web shells, accounts), online banking, "trophy" software, rotation of all the passwords, outbound traffic, test environments, paper originals, GitHub (the anecdote about 6 backups), a Telegram channel, the recommendations with Cyberdom (a QR code).

Legal and organizational context: CII → GosSOPKA/the NKTsKI; law enforcement → the complaint materials + the DFIR report → the crime report register (KUSP) → a possible seizure → a criminal case → a certificate recognizing the company as the victim (needed, for instance, to explain the failure to file financial statements on time); the ransom and anti-money-laundering/counter-terrorist-financing rules / financing of terrorism; personal data — Roskomnadzor within 24 h / the report within 72 h (per the speaker, "including about a fake leak", with no legal instrument cited); FinCERT; GDPR ("maybe someone also complies with GDPR, I don't know"); the goals of the investigation (to prosecute vs. to avoid publicity); the CEO's role.

From the Q&A:

The speaker's position: the order "kick out → clean up → recover" is not open to discussion; he criticizes panic, changing the passwords before the cleanup, connecting the backups to the infected network; he bets on cheap preparation. Realistic caveats: DFIR lasts days even when you have prepared; remote DFIR works only when there are competent hands on site; the 72 h for the report do not match the timeline of a real investigation. Trends: a shift of attacks to Thursday, a dwell time of 3–9 months, "a second ransom", endless repeated fake leaks.

Unclear: the companies in the July 2025 cases and the source of the news about the airline are not named; the Roskomnadzor notification deadlines are per the speaker, with no legal provision cited; "6 billion people" and "the story with GitHub" are from memory; a number of phrases were garbled by Whisper.


Scheduled 15:35–16:05. The talk is not about forensic artifacts but about designing the interfaces of investigation tools: the co-founder and UI/UX designer of the Zero eDiscovery platform explains why "design" means engineering and not decoration, and how an overloaded interface slows down data analysis. It is addressed to law enforcement officers and forensic examiners who work in somebody else's (vendor) systems.

Key points:

Tools and artifacts: Zero eDiscovery (the speaker's platform; "Zero and Discovery" in the raw Russian transcript), Word/Excel (overload + the Alt shortcuts), Yandex/VK products, Google (minimalism), the Mail.ru search (a counterexample), Yandex (search), Google Workspace (a counterexample of "common fate"), an email client, logs/tabular data (indexing, highlighting), dashboards/templates/relationship graphs, hotkeys; concepts — Hick's law, 7±2, the Gestalt principles, ergonomics; "STS"/technical means of customs control (the phrase is garbled); from the Q&A — the overloaded interface of Drozd's product, configurable filters/columns, "an end-to-end identifier for a piece of intercepted data".

Legal and organizational context: no laws, articles, agencies or methodologies are mentioned. Organizational: the target audience is law enforcement, forensics, computer forensics; the "user — vendor" model (formulate the requirements, "do not put up with" it); Drozd's counterposition — the developer will adapt only to a client "with tens of millions a year in support fees"; collaborative use of systems (different views among colleagues break communication) — an argument for uniformity of UX.

From the Q&A:

The speaker's position: design = engineering; UI/UX is not about beauty, aesthetics are secondary; overloaded interfaces are a systemic problem of products built by "people who aren't specialists". He puts the user in the position of the customer. He partly concedes to Drozd ("a very valid, very fair remark"), but insists on uniformity for the sake of collaboration. He himself calls the slide with the example "a lot of text here and little meaning".

Unclear: the questioner is named by first name only, the identification with Drozd is by the recording map and by context; the closure principle was not covered; figure-ground is reduced to "similarity and proximity, just… deeper"; the quantitative estimates ("by tens or hundreds of times", "6–7 functions", "by the hundredth line") are guesses; the phrase about "STS"/customs is garbled; the dates (Workspace ~2018/2020, Mail ~2005) are approximate.


Alexey Drozd (SearchInform) — "Using steganography in various channels to identify the source of a data leak"

Scheduled 16:10–16:40. A talk by a DLP vendor on why a security officer needs steganography: not as a way for an insider to exfiltrate data (insiders bypass DLP with a primitive substitution of characters that regexes fail to catch), but as "straw" laid down in advance so that after a leak — within those very 24/72 hours — the circle of suspects can be narrowed. Addressed to information security practitioners fighting leaks and to vendors thinking about document labeling.

Key points:

Tools and artifacts: DLP (the product is not named), regular expressions, LLMs/neural nets (the market expects them), copy /b, Ctrl+F, data-centric security, a connection graph, DCAP, a DLP agent, a keylogger, HTTPS interception, API integrations (Google Workspace, VK, Yandex 360, M365/Graph API), VDI, watermarks on monitors, Print Screen/photo/printout, EveryTag, labels on the file's address / in the metadata, Microsoft RMS, ABAC, the watermarks of deepfake generators; from the Q&A — Canarytokens / the "zero pixel" / IP logger (criticized), audio watermarks (since the 90s).

Legal and organizational context: "24 hours to respond, 72 hours to report something to someone" are named as common knowledge, with no reference to a law or a regulator (apparently the deadlines for personal data leaks; this is not spelled out in the transcript); Federal Law 152-FZ and Roskomnadzor were not mentioned. The methodological frame is the "incident lifeline" with its "point of no return". Industry self-regulation — a "global agreement" among the makers of deepfake software (the participants are not named). Interaction with law enforcement, articles of the Criminal Code or the Code of Administrative Offenses, forensic methodologies — were not mentioned at all (the talk is about corporate information security, not about forensic examination).

From the Q&A:

The speaker's position: a demonstrative refusal to sell ("I didn't come here to sell you some of our elephants"), an open listing of weaknesses, his own solutions included (the agent on macOS and in the cloud, watermarks dying from overexposure). Skepticism toward a universal solution — different channels require different things, and anything "universal" exists only at the level of labels plus encryption (RMS in essence). Prevention comes first; he explicitly invites counterarguments.

Unclear: the Russian original says "nontransparent" — by the sense, "transparent"; the "global agreement" is probably a worldwide or industry-wide one; the 24/72-hour deadlines — the norm and the regulator are not named; which VK service is meant is not specified; the content of the slides (the DCAP and EveryTag screenshots) is not described; what kind of hash it is and how it is matched is not covered.


Oleg Bezik (Digital Research Laboratory) — "Automated government systems under the forensic computer expert's microscope: problems and solutions"

Scheduled 16:45–17:15. A talk on forensic computer examinations (SKTE) of custom-built automated systems, primarily government ones (Gosuslugi, GAS "Pravosudie", GAS "Legal Statistics"), appointed in disputes over development contracts worth from 150 million to several billion rubles. The speaker is the founder and CEO of the Digital Research Laboratory, a forensic expert since 2014. The second half of the segment is a tough discussion with a former employee of the EKC MVD.

Key points:

Tools and artifacts: Gosuslugi, GAS "Pravosudie", GAS "Legal Statistics", the Moscow DIT methodology, COCOMO, their own source code comparison software (since 2025, unnamed), their own examination algorithm, a checklist memo (PDF), PMI (test programme and procedure), the objects (the ToR, the detailed ToRs, manuals, source code on flash drives and discs, the deployed system); from the discussion — SAP, banking systems, the handheld terminal, Microsoft Windows, aircraft simulators, the state information system of Rosreestr (acceptance under Federal Law 44-FZ with code hashes, load tests).

Legal and organizational context: forensic examination as a way of bringing specialized knowledge into court proceedings; an SKTE, a multidisciplinary and a valuation examination; the commercial (arbitrazh) courts, sometimes "criminal cases"; the questions are put by the court (the expert does not set them — a disputed point: the EKC holds that one may file a motion to change them, Bezik — "I've never come across that"); the parties have the right to be present; payment — "The court pays us, not a party"; the contract documents (the ToR, the detailed ToR, the PMI, acceptance); Federal Law 44-FZ (Barannikov — acceptance of the state information system of Rosreestr, code with hashes); the absence of agreed methodologies; the institutional position of the EKC (the expert checks discrepancies rather than testing the whole system); Interpolitex, Muzalevsky (RTM Group, per the recording map), R&D.

From the Q&A / discussion:

The speaker's position: the examination answers the court's questions as they are put; custom-built systems with a detailed ToR and a test programme and procedure can be checked in full; he dismisses the SAP/Windows argument as being about off-the-shelf products. He honestly names the limits ("I'm not an appraiser") and the weak points (the methodology is not packaged, the forensic experts work as testers, the examinations are long and expensive). The end of the argument: "I think we're speaking different languages".

Unclear: the transcript does not label the speakers in the discussion (the remarks are attributed by context); the second question from the audience is heavily garbled by Whisper (in the Russian original "postavlena na voyenny uchet"); it is not clear from the recording whether Bezik's team calculates the percentage by the number of requirements; "Denis Aleksandrovich" and "Volokitin" were not identified; "milestones"/"function points" is a distortion in the Russian original; "Bauman MVTU" — probably from a slide.


Mikhail Inkin (STC, Speech Technology Center) — "From audio and video data to evidence: AI analytics, biometrics, and spoofing and deepfake detection"

The closing talk of the conference (scheduled 17:20–17:50; STC was a partner). The head of a project group at STC shows how the company's products cover the chain "a bulk set of raw audio → search and analytics → forensic phonoscopic examination → minutes of the proceedings". A vendor presentation with demos; the Q&A turned out more substantive than the talk itself.

Key points:

Tools and artifacts: AVIS, IKAR Lab (ElevenLabs 99.6% in the demo; the video deepfake module 97%; classical modules — phase, resampling, background noise, DC offset; manual documenting of the features; manual transcription), Nestor AI, GigaChat, freely available LLMs, NIST, CHiME Challenge, ElevenLabs, Multi-Tacotron (named by a questioner), Zoom, server GPUs, their own speech-to-text models; video deepfake techniques (face swap, puppet-master, lip-sync, synthesis of facial elements, a face mask, real-time face swap, a photo being "animated"); ultrasonic microphone jammers ("a myth").

Legal and organizational context: the speaker named no laws, articles of law or agencies. Phonoscopic examination has been a type of forensic examination for 30+ years in Russia and abroad; the principle that "the conclusions of the automated system need expert confirmation", manual modules so the features can go into the expert report. The data sources — lawful interception of telephony, microphone recordings, seized devices (collection is out of scope). The division: AVIS — search, IKAR Lab — evidence. Identifying the synthesis vendor — as circumstantial evidence (the link to a site the suspect visited). Deployment — always in the customers' closed networks, on-prem, offline, role-based access. Nestor AI — a "strictly formatted record" of official sessions.

From the Q&A:

The speaker's position: the tone of a vendor presentation; the concrete metrics come only from the demos (99.6%, 97%, 98%), and no external or independent assessments and no conditions (the datasets, the thresholds) were given. On principle: the automation does not replace the expert, the classical methods "live on". The trend: synthesis is indistinguishable by ear and the number of algorithms is growing — synthesis detectors are unreliable, the question to pose is authenticity. Honest caveats (he has not tested synthesis of facial elements, the 98% is on his own datasets, as the SNR drops the accuracy drops).

Unclear: the sentence is self-contradictory (probably "mask" instead of "detect"); the Russian original's "sesomo-avtomaticheskom" is garbled; of the 4 vendors only ElevenLabs is named; the "in-tolerance probability" — whether such frames are excluded is not clear; the question about prompt injection is answered in terms of the customer's interests, not those of an attacker who controls the recording; the playbacks (synthesis of 1979, 2000s, Biden, the Alba video) are not transcribed in the file; the questioners are not named, and the patronymic of "Olga" varies (Alexandrovna / Svetlanovna).


Conference closing

A lead-in by moderator Dmitry Yankovoy ("the way we opened is probably how we should close") and an invitation to the stage for Olga Gutman (MKO Systems; "Olga Vasilyevna" — by ear). Gutman's speeches at the opening and at the closing are her only appearances in the recording; her position is not named in the transcripts. The closing block is extremely short and ceremonial.

Key points:

Stance and tone: warm, grateful rhetoric with no figures and no substantive assessment of the talks ("the most interesting, useful, the most important"); not a single critical or problematic statement about the industry, the conference or the products. Prize draws, gifts and prizes are not mentioned at the closing (per the program the draw took place on day 1 after the stream was switched off).

Unclear: the patronymic "Vasilyevna" and Gutman's position are not confirmed in the recording; "records" is an evaluative word with no figures; "Lera" is Valeria Vakhrushina per the recording map (a conjecture); the Saint Petersburg announcement is syntactically garbled (no title, no format, no organizer named).


3. Cross-cutting themes

  1. Password cracking: physics against the expert, a dictionary against "a mask head-on". The theme tied together three talks of day 1. Vakhrushina reduced any cracking to two methods — a dictionary or a mask — showed that "a mask head-on" cannot be used (a 10-character password: 141 trillion / 3 quadrillion / a quintillion combinations), and demonstrated it on a ZIP archive: a full mask — 7.5 hours, a partial one (3 random characters + 4 fixed digits) — the password MFD2025 in 11 seconds. Chikin explained why cracking phone passwords is almost hopeless: the main algorithm is memory-dependent scrypt (Android FBE 2048.8.1 = 2 MB per core, the older FDE = 32 MB per core), the wall is the DDR5 memory controller, ASICs are no use; the result — ~20,000 passwords/s, an 8-character password = "10 thousand years". Shavlovsky showed the same arithmetic on macOS: salted PBKDF2-SHA512 is an order of magnitude stronger than the Windows NT hash (MD4, unsalted), hashcat mode 7100, plain brute force "can run into years". The overall conclusion — brute force is a lost cause, only meaningful dictionaries work, and MK Brute Force/hashcat 7.0 and dictionaries built from personal data only lower the threshold.

  2. Import substitution, the Russian software registry and its flip side. Greshnov (ELETEK) puts the emphasis on viewing E01 on Astra Linux; Eremin (LAN PROJECT) links the entry of VR-Expert into the Russian software registry (2025) directly to easier government procurement — and in the same breath honestly rounds out the delivery with foreign software (SalvationData, MD-VIDEO/GMDSOFT) and ACE Lab equipment, while describing unsharp masking as the mechanism carried over from Amped FIVE into VD-Expert. MKO Systems builds the whole stack (MK, MK Brute Force on hashcat). Sanctions run in the background: for Eremin supplies of foreign software are "difficult", and DVR Examiner is compared in "the version … available in Russia". Import substitution here is pragmatic, not ideological.

  3. Phone and banking fraud: NFC, RAT trojans, Telegram as the delivery channel. Moskvichev went through NFC thefts (NFCGate/N-Gate out of a teaching project at TU Darmstadt, the related SuperCard X and GhostTap with "Chinese people behind" them), the classic and the reverse scheme ("into a safe account"), a case of 230 thousand RUB (a Redmi Note 11S, the vtb1 trojan from Telegram, a manifest with the appName "VTB Protection"); the statistics — growth ×35 in 2025, ~400 cases in Russia, an average amount of ~100 thousand RUB. Kotova showed SpyNote (a RAT for Android, in Kaspersky's top-10 verdicts, the v6.4 builder that leaked in 2022), where the APK is delivered through a messenger. Barkalov and Titkov mentioned the same social engineering schemes (a "safe account", panic). Telegram is the channel running through all of it: APK delivery, a social engineering message "on behalf of the head of the Interior Ministry institute", extortion.

  4. Do not trust blindly: neither the tool nor the vendor's documentation. Sukhanov (CICADA8) is the central voice: Microsoft's documentation systematically diverges from the code (NTFS timestamps marked "reserved"; "scoped" shadow copies from Windows 8 on → zeros instead of user files after a ransomware attack; the FAT specification written from the Windows 95 code; the prefetch "OP-…pf" from the out-of-date constant PrefetcherBootControl=5), and the right path is "straight from the code", through a decompiler of ntoskrnl.exe and a black box. Shavlovsky: an unnamed tool lost part of the hash during a conversion — "software tools can make mistakes, that is, their code may contain bugs". Inkin: "the conclusions of any automatic system need expert confirmation". Eremin: initializing a recorder's disk in Windows 10/11 overwrites about 40 MB and destroys the video stream table.

  5. AI and neural networks: from an outright ban to industrial use. Vakhrushina: "building artificial intelligence into Mobile Criminalist is prohibited. The legislation would object" — justified through the policy of not returning data to the vendor. Eremin: an AI module on PyTorch (object detection, license plates, a 30-minute video in 3 minutes on a GPU). Inkin: LLM summaries of a body of audio (AVIS), deepfake detection (97%), identification of the synthesis vendor (ElevenLabs 99.6%), GigaChat. Barkalov sees degradation: a lawyer brought in questions for a forensic examination generated by "Alice". Drozd: the market expects LLMs to "solve" the primitive bypassing of DLP. The common denominator — reproducibility and admissibility matter more than "magic".

  6. OSINT: a method, a surveillance tool and the subject of a clash of worldviews. Bederov spoke entirely about the method of deanonymizing sites (WHOIS and its archives against GDPR, bypassing Cloudflare, Yandex.Metrica, acquiring services, file metadata, petitions), a portable OSINT browser built on Opera with more than 2,000 sources. Barkalov spoke about how "OSINT isn't what it used to be": if there is intelligence, there is counterintelligence too (disinformation, "brainwashing the population through open sources"), the frame being the Information Security Doctrine of the Russian Federation. Their argument (day 2) was left unresolved: Bederov insisted that OSINT is a methodology for verifying open, lawful and re-checkable information fit to serve as evidence; Barkalov — that well-crafted disinformation cannot be verified. The moderator moved the argument to a day "purely for lawyers".

  7. The procedural rigor of forensic examination: methodologies, questions, the limits of authority. Tushkanova (GUK SK) presented the standard methodology of the Investigative Committee of Russia of 2025 (an evolution from the FSKN's 2011 one marked FOUO → EKC MVD 2014/2023): functional requirements for the hardware-software system, motions for the password/PIN/PUK and for the user's presence for biometrics, writing to rewritable media with a cryptographic hash, and cloud tokens once found mean not "got into the email account, downloaded all they needed" but notifying the investigator immediately. Shavlovsky limits himself by Art. 57 (not to destroy the object without the permission of the party that ordered the examination). Kotova: the only correct wording of the question is "the presence of files detected by antivirus software". Bezik took the theme to its limit: forensic computer examinations (SKTE) of government systems against the ToR / detailed ToR and the test program and procedure, the court puts the questions and the court pays. Federal Law 73-FZ comes up in Tushkanova's talk and in the debates.

  8. Incident response, the "maturity" of information security and the price of tools. Vyugin (MKO) went through the whole line-up (antivirus, DLP, EDR/XDR, SIEM, SOAR, SOC, DFIR) with the refrain "you need to count… don't fall for bare advertising"; the criteria are reasonableness (consulting all the departments) and maturity (not "to buy any tools for millions upon millions" but to understand what for); DLP cuts "up to 30% of data leaks", not the "90–100 in the marketing brochures". Titkov (Gazprombank): a security incident ≠ an IT failure, first kick the attacker out, then fix things; the ransom must not be paid (the keys will not work, anti-money-laundering and counter-terrorist-financing rules, the risk of "financing of terrorism"); the stages per SANS, a dwell time of 3–9 months, compromise assessment as a "light version of DFIR". In the argument with the moderator it was said that hardening "costs nothing" apart from the specialist's time, and the pentester Dmitriev had seen the "Golden Rules" followed at 1 company out of 200.

  9. Targeted attacks and "living off legitimate utilities" (LotL). Shulmin (Kaspersky, GReAT) went through Librarian Likho: the whole chain on batch files and legitimate utilities (RAR 3.8 with the strings wiped, blat.exe, AnyDesk under the name svchost, Defender Control, powercfg, schtasks, reg.exe → SAM/SYSTEM, XMRig), with no binary implants, a night mode of 01:00–05:00 (the tasks "WakeUpAndLaunchEdge"/"shutdown at 5 a.m."); spear phishing delivers 90–95% of the threats. Azersky (F6) showed the same logic for UWP/MSIX: malicious packages with a stolen signature (and in Windows 11 unsigned ones), the 2023 campaigns through ms-appinstaller, FIN7 with PSF, and a "legitimate" toolkit from the Microsoft Store with no admin rights through winget (Python/Julia → a reverse shell, ngrok/localtunnel, a VS Code tunnel). Both agree: what has to be detected is the illegitimate use of the legitimate.

  10. Insiders, leaks and protecting data "from the source". Drozd (SearchInform): insiders bypass DLP not with steganography but with a primitive substitution of characters (5 → the word "five" spelled out in Russian) that regexes do not catch; steganography is what the security officer needs after a leak (24/72 hours) in order to narrow the circle — watermarks on monitors, unique copies (EveryTag), labels + encryption (ABAC, "reinventing that Microsoft RMS"). Barkalov: "the main threat is the insider threat, it's the human being"; the case of an insider with flash drives. Vyugin: DLP as control over the leak channels. Drozd's overall conclusion — "the best incident is the one that never happened", catch them at the stage of intent.

  11. The scale of the data and the role of the interface: how not to drown in the volume. Pavlov (Zero eDiscovery) argued that an overloaded UI directly slows the analysis down (Hick's law, a cognitive load of 7±2, Gestalt principles); indexing and color highlighting of logs 10 thousand lines long speed the work up "by tens, if not hundreds of times". Eremin: carving a terabyte disk takes about 3 weeks, the AI module compresses a 30-minute video down to 3 minutes. Inkin: LLM summaries of bodies of audio instead of listening to all of it. Bezik: millions of lines of code, "boxes of paper", 1,041 requirements in a single examination, a panel of 3–4 experts, timelines of 1–2 years.

  12. Video, audio, biometrics and deepfakes as a new evidentiary modality. Eremin — the forensics of DVRs (proprietary file systems, cracking Dozor passwords, AI detection of objects and license plates). Inkin — phonoscopy (waveform/spectrogram/cepstrogram, formants, the fundamental frequency), spoofing detection with a sliding window and identification of the synthesis vendor, a module for detecting video deepfakes; voice synthesis has become a mass threat ("most listeners actually can't tell a synthesized voice from the voice of a real person", the case of Biden's voice in 2024, the Jessica Alba deepfake). Both themes come down to one principle — the classical methods and manual documenting of the features supplement the automation.

  13. Anti-forensics, the destruction of data and the shift from encryption to wiping. Chikin: changing the phone's state erases the key, with the risk of a wipe if the wrong actions are taken. Titkov: attackers delete the backups that get connected, a dwell time of 3–9 months, "wiping is what is going on now", the data is destroyed deliberately; the vulnerable architecture of the backup system in a flat network. Sukhanov: after a ransomware attack the shadow copies that survive (Windows 8 and later) hold "a mess of zero bytes". Greshnov: documents disguised by a swapped extension, the countermeasure being acquisition by signatures. A verifiable copy with checksums and a cryptographic hash in the expert report (Tushkanova, Greshnov) is the cross-cutting answer to the threat to integrity.


4. Indexes

4.1 Technologies, tools, artifacts

Alphabetical; in parentheses — the talk(s); then — as mentioned. The talks are abbreviated by surname: Greshnov, Vakhrushina, Chikin, Tushkanova, Moskvichev, Eremin, Kotova, Shavlovsky, Bederov, Barkalov, Shulmin, Azersky, Vyugin, Sukhanov, Titkov, Pavlov, Drozd, Bezik, Inkin.

4.2 Attack vectors and cases

4.3 Laws, agencies, regulatory requirements