# Conference summary MOSCOW FORENSICS DAY ’25 The whole conference in one document: cross-cutting themes, indexes of tools, artifacts and legal norms, and a “what not to believe” section. The per-talk summaries go into more detail. Summary · https://2025.moscow-forensics-day.workers.dev/en/summary/conference Summaries by talk: https://2025.moscow-forensics-day.workers.dev/en/summary/ --- ## In brief **What it was.** MOSCOW FORENSICS DAY '25 — the ninth annual digital forensics conference, 11–12 September 2025, Moscow, the "Pulsar" venue. The organizer is MKO Systems (the maker of Mobile Criminalist); the opening and the closing were led by Olga Gutman, and the talks were moderated by Dmitry Yankovoy. Day 1 was for law enforcement, day 2 for corporate information security. The recording (a splice of the YouTube streams of both days, ≈9 h 33 min) holds 19 talks and two closings; the general partner's closed-door talk and the whole evening of day 1 (the "roast", the prize draw) were not let into the stream. **What matters in substance.** - **Brute-force password cracking has lost.** Vakhrushina, Chikin and Shavlovsky converge from three sides: a mask "head-on" is pointless, memory-dependent scrypt turns an 8-character password into ≈10,000 years, and PBKDF2-SHA512 with a salt in macOS is stronger than a Windows hash. Only meaningful dictionaries work. Neither MKO Systems nor ACE Lab has distributed cracking — both promise it "down the line". - **Trust neither the tool nor the documentation blindly.** Sukhanov showed four divergences between Microsoft's documentation and the code (shadow copies being "scoped", the FAT specification, the myth of "boot" prefetch files): the justification has to come from the decompiled code. Shavlovsky stated **from the stage** that MK Brute Force does not support the hashcat mode needed and that a third-party tool lost part of the hash — the organizer did not rebut it. - **AI — from an outright ban to industrial use.** Vakhrushina: "building artificial intelligence into Mobile Criminalist is prohibited", and she could not name the legal justification. Eremin, Inkin and Drozd, by contrast, build products on it; Inkin, for his part, says honestly that synthesis detectors are unreliable and that the question to pose is the authenticity of the recording. - **The attack lives off the legitimate.** Shulmin (the APT Librarian Likho: not a single binary implant — curl, AnyDesk disguised as svchost, tasks for the window 01:00–05:00) and Azersky (the Microsoft Store and winget as a source of post-exploitation with no administrator rights) describe one and the same logic: what has to be detected is the illegitimate use of the legitimate. - **Procedural strictness versus convenience.** Tushkanova (cloud tokens once found are a reason to notify the investigator, not to "get into" them), Shavlovsky, Kotova, Bezik. Against that background Bederov, without a single caveat about lawfulness, describes pretexting with Yandex support and a request to the bank about the acquiring service. - **Day 2 was about money and organization, not about artifacts.** Vyugin: DLP delivers up to 30% of leaks instead of the promised 90–100%. Titkov: first kick the attacker out, then fix things; do not pay the ransom; a dwell time of 3–9 months. Bezik: disputes over state contracts worth billions, while agreed methodologies for examining automated systems simply do not exist. **The talks in one line each.** - **Greshnov (ELETEK)** — a catalog of the six products of the "Element" line instead of the comparison announced: there is no RAM dump, and encryption detection covers BitLocker only. - **Vakhrushina (MKO Systems)** — MK Brute Force: a mask "head-on" takes 7.5 hours against 11 seconds with a partial one; the core is hashcat. - **Chikin (ACE Lab)** — why scrypt cannot be sped up: it hits the memory controller wall, and mining ASICs are no use. - **Tushkanova (GUK SK)** — the Investigative Committee's standard methodology: the equipment requirements are functional, not by vendor. - **Moskvichev (MKO Systems)** — the forensics of NFC thefts: a 35-fold growth, a case for 230 thousand rubles, the teaching tool NFCGate and >100 derivatives. - **Eremin (LAN PROJECT)** — DVRs: usually there is no file system, and carving a one-terabyte disk takes ≈3 weeks. - **Kotova (Forensic Science Centre of the Yaroslavl Regional Police)** — SpyNote v6.4: a method through two antivirus tools, the antivirus verdict as proof that "it was there". - **Shavlovsky (SEC SK)** — dynamic analysis on macOS: the path to PBKDF2-SHA512 and to hashcat mode 7100. - **Bederov (T.Hunter)** — deanonymizing the owners of web resources: WHOIS has degraded, Cloudflare cannot always be stripped away, ~10% of Metrica counters are public. - **Barkalov (Forensics Science Centre)** — the polemic "OSINT isn't what it used to be"; the argument with Bederov about OSINT as a methodology of verification is left unresolved. - **Shulmin (Kaspersky GReAT)** — the APT Librarian Likho: the password of the archives, with traces going back to 2010, as a valuable IOC. - **Azersky (F6)** — UWP/MSIX in the DFIR crosshairs: the isolation disappeared with Desktop Bridge, "Living off the Store". - **Vyugin (MKO Systems)** — the value of security tools: from antivirus to DFIR with the refrain "count". - **Sukhanov (CICADA8)** — when documentation is the enemy and the decompiler is a friend. - **Titkov (Gazprombank)** — how not to end up needing forensics: a security incident is not an IT failure. - **Pavlov (Zero eDiscovery)** — the role of the interface: logs as "a wall of white lines", and indexing would speed the work up tens of times over. - **Drozd (SearchInform)** — steganography for identifying the source of a leak; an insider changes a digit into a word and DLP's regexes go blind. - **Bezik (Digital Research Laboratory)** — the examination of government automated systems: 1,041 requirements, timeframes of 1–2 years. - **Inkin (STC)** — AVIS, "IKAR Lab", the spoofing detector; all the metrics come from the demos only. - **The closing (Gutman)** — four minutes of thanks without a single figure; announcements of Astana, Novosibirsk and Saint Petersburg. **What not to believe.** The Q&A was recognized worse than the talks: the lines from the audience were without a microphone, the names of those asking are by ear, and in the discussions the speakers are not labeled. The contested names were checked against the audio; some were left as recognized. The statistics come almost everywhere without sources: ×35 and ~400 cases (Moskvichev), 90/30/90% (Vyugin), 99.6% and 97% (Inkin, from the demos). --- ## 1. The conference and the recording **The event.** MOSCOW FORENSICS DAY '25 (MFD '25) — the ninth annual digital forensics conference, 11–12 September 2025, Moscow, the "Pulsar" venue (3rd Yamskogo Polya St., 2, bldg. 6, "Belorusskaya" metro). The organizer is MKO Systems, in the moderator's words "a leading developer of software for computer forensic examination of mobile devices, personal computers, drones, cloud services", with training in the field of "digital forensics". The organizer's products (per the 2025 website): MK Expert Plus, MK Desktop, Forensic Kit; the flagship is "Mobile Criminalist" (MK) with the MK Brute Force, MK Scout and MK Corporate modules. The conference has been held since 2016; the next one (2026) is billed as the anniversary one, the tenth. The opening and closing of both days were led by Olga Gutman (MKO Systems); the moderator of the talks in between was Dmitry Yankovoy (MKO Systems). **Format.** Two days with different audiences: 11 September — digital forensics day (talks for law enforcement officers), 12 September — information security day (for corporate security). In person plus a live stream of the open part of each day; admission by passport/service ID, filming in the hall prohibited, a professional camera operator was working, the recording was promised to the attendees. Day 1 per the program — three blocks of talks, then the "roast" (17:30–18:30), a prize draw (18:30–19:00) and informal networking (19:00–21:00). The "roast" is billed by the organizer as "the hottest part" — a session of questions for all the speakers saved up over the year and of complaints about the "Mobile Criminalist" product made straight to the CEO. The main value of the conference named from the stage is not the content of the talks but the networking of the expert community "from all over the country"; the talks, meanwhile, were sold as "real meat" and "the cream of the crop", the result of a year's work on the program. **Partners.** Per the official program (logos, in the order they appear): LAN PROJECT, ACE Lab, SearchInform, ELETEK, Ester Solutions, Zero eDiscovery, Account-Best, STC Group. The general partner is Account-Best. **A discrepancy with the recording:** at the opening the moderator listed the partners with booths as "ACE Lab, LAN PROJECT, ELETEK, Ester Solutions, SearchInform and STC" — Zero eDiscovery, listed as a partner in the program, was not named in the speech; whether it had a booth cannot be established from the recording. The general partner Account-Best was presented as having "no booth", with a closed-door talk on UAVs (the speaker per the program is Igor Zaitsev; in the transcript of the opening, "Igor Evgenyevich", the patronymic by ear). **Audience and positioning.** The stated audience is forensic experts, investigators and security-service specialists "from all over the country", in person and online. The words "law enforcement", "business" and "information security" were never spoken from the stage at the opening; the split between the days (forensics / information security) was not spelled out at the opening. The organizer casts itself as a supplier of tools for practitioners. ### What is in the recording and what is not The source of the recording is the YouTube stream of both days, spliced into a single file (https://youtu.be/4V7Wez3L_58, ≈9 h 33 min, a Whisper large-v3 transcript). Within a single speech block the timecodes are continuous; between blocks the breaks, the closed-door talk and the whole evening of day 1 are cut out. **Day 1 (11 September) — in the recording:** the opening (Gutman, Yankovoy), nine talks in a row — Greshnov (ELETEK), Vakhrushina (MK Brute Force), Chikin (ACE Lab), Tushkanova (Investigative Committee, the methodology), Moskvichev (NFC), Eremin (VR-Expert), Kotova (SpyNote), Shavlovsky (macOS), Bederov (OSINT) — and the closing of the online part of day 1. **NOT in the recording:** - **The closed-door talk by Igor Zaitsev (Account-Best, "UAVs on the line of contact and in rear areas", program 13:40–14:15)** — the general partner, the talk was not let into the stream: the moderator warns outright that "we can't show the next talk in the stream", and in the recording there is nothing between this announcement and the next talk. The file contains neither video nor audio of the talk. - **The "roast" (17:30–18:30), the prize draw (18:30–19:00) and the informal networking (19:00–21:00) of day 1** — were not streamed. The online stream of day 1 was deliberately closed right after Bederov: the moderator says goodbye to the online viewers and invites those attending in person "to the bar area". Not one second of the "roast" is in the recording; the only evidence of what it contained is a line at the closing of day 2 saying that "kind words of gratitude" to the product's developers were spoken there. - **The breaks** (day 1 12:00–12:30, the break 14:20–15:00) are cut out — the timecodes at these points are continuous. **Accuracy.** The timecodes of the talks are published in no external source (the YouTube description, the program, the organizer's posts) — every timecode in this summary is derived from the recording map based on the transcript and is approximate (a drift of up to ±15 min relative to the program's schedule). The lines from the audience in the Q&A were recorded without a lapel microphone and recognized worse than the main speech — the wording of the questions is approximate in places, and the names of those asking were in most cases not established. --- ## 2. The talks ### Vladimir Greshnov (ELETEK) — "Duplicators vs. manual copying: when speed and accuracy are critical" The first talk of day 1 (the program slot 10:10–10:40). ELETEK is an official partner with a booth; the speaker is not a developer, does not command the technical details and three times sends people to the booth, to the engineer, for the specifics. Formally what is announced is a comparison of duplicators with manual copying; in substance it is a catalog tour of the product line: four hardware duplicators and two software products. There is no comparison with manual copying and no speed or accuracy figures in the speech — the title is not borne out by the content. **Key points:** - An acquisition unit for PCs/laptops that needs no opening of the case (named **"Element-U"** in the Q&A): it is connected to the computer, loads its own OS through the Boot Manager, mounts all internal and USB drives and acquires the data. - What is new in "Element-U": file-by-file acquisition not only by masks (mp3, mp4 and so on) but also **by signatures** — if the extension of a .docx was removed or changed to .mp3, the signature search determines the true type and acquires the file. - Added: "parallel copying of drives" — previously the disks were imaged strictly sequentially, now you can select a particular drive and image it first or image only that one. - The compact flash-drive duplicator — built at the request of field operatives for the discreet and quick imaging of a flash drive "during an operation": up to 2 h of battery life in copying mode, a sector-by-sector copy by default or all the files, control through an Android app, LED indicators; one drive at a time. - The SATA duplicator (2.5-inch HDD/SSD, 3.5-inch HDD) — "one of our newest" products, pass-through copying, a **hardware write blocker**, no internal memory (an option), automatic start of copying, the same Android app. - The workstation — the largest duplicator: a 7-inch touchscreen display, Mini ATX, Intel Core i3, 8 GB RAM (up to 16–32), a 2 TB NVMe (up to 4 TB), powered from a power bank; modes: sector-by-sector / disk-to-disk clone / file containers / a choice of files. - In response to questions from the exhibitions, a choice of block size for sector-by-sector copying was added: **64 KB – 8 MB**. - The hash calculation was reworked: previously there was only a "fixed verification", now hashes can be calculated separately, during the copying, or a verification can be run (the specific hashing algorithms are not named). - An automatic check of the disk for hidden areas, with a warning when a job is added (previously it required a "trained" user; it can be disabled in the settings). - The encryption notification: implemented **for BitLocker only** — for a "BitLocker-encrypted" disk only a sector-by-sector copy is available; "other types of encryption" are being worked on. - A reports feature (the mode, the source/destination disks, success, the hash) and a "status drawer" with a padlock: evidence drives are connected read-only, trusted ones are marked with a volume label for writing. - The software image viewer: the RAW and E01 formats, recovery of deleted files/partitions, "detect deleted operating systems"; the focus of the latest releases is running on **Astra Linux** (viewing E01 on Astra was implemented on request). - Software for "live" acquisition from a switched-on PC: masks and signatures, Windows and Linux; Astra Linux is in the plans. - A limitation stated by the speaker: the workstation itself, unlike the SATA duplicator, has no hardware write blocker — the "read-only" mode is provided in software. **Tools and artifacts:** the ELETEK line (called "Element" in MKO's wrap-up post): the "Element-U" unit, the flash-drive duplicator, the SATA duplicator, the workstation, the image viewer software, the "live" acquisition software; Boot Manager, a Secure Boot bypass; the RAW/E01 formats; Astra Linux (the target OS); Android (the mobile control app); Mini ATX, Core i3, NVMe, SATA, HDD/SSD; BitLocker (detection), TPM, RAID, hidden areas, volume label, hash + verification. **Legal and organizational context:** the speaker named no laws, articles, methodologies or agencies; the Russian word for "forensic examination" was never spoken, the terminology is "data acquisition", "officers". The procedurally significant properties he emphasized: the evidence medium stays unchanged (the unit's own OS without booting the native one, the read-only mode with the padlock, the hardware write blocker in the SATA duplicator), hash calculation, automatic reports. The products were built in response to field operatives' requests and to questions from the exhibitions; ELETEK has a booth with the engineer who develops them. **From the Q&A:** *RAID* — "Element-U" images it, but reassembling the array is left as the user's problem. *A RAM dump* — they do not do it, they are "on the verge of starting to work on that" and want to implement it (a remark from the audience: "That's bad."). *Encrypted disks* — a sector-by-sector copy can be made, but the data cannot be viewed with ELETEK's tools. *Clone vs. image* — the person asking argued that an image is better than a clone (for an image computing a hash makes sense, for a clone it is "pointless"); the speaker: the basic mode of all the units is a sector-by-sector copy to a file, and the clone is a concession to practitioners. *Secure Boot and TPM* — there is a Secure Boot bypass in "Element-U", and the speaker could not answer about the behavior with TPM and sent the question to the booth. **The speaker's position:** the correct basic mode is a sector-by-sector copy to a file (an image), and cloning is an add-on made on request; features are being moved to automatic operation for an untrained operator. All the limitations were acknowledged only in answer to questions, never on his own initiative. *Unclear:* of the six products, only the name "Element-U" was spoken (and only in the Q&A) — the rest are named descriptively. The phrase about the hardware write blocker, "unlike on our largest workstation", literally means that the workstation does not have one; it may be a slip of the tongue. The attribution of the lines in the clone/image argument is missing from the transcript; they are assigned to the person asking by the logic of the dialogue. "Yuri Mikhailovich" from the audience — by the recording map this may be the day 2 speaker Yuri Barkalov, unconfirmed. --- ### Valeria Vakhrushina (MKO Systems) — "Dictionary or mask: how MK Brute Force works" The second talk of day 1 (program 10:45–11:15). The speaker is MKO's marketing director and at the same time the head of development of the MK Brute Force module (a "split personality as a marketer"). An overview product talk about password cracking inside Mobile Criminalist. The main point: cracking a password is engineering, not magic; any tool comes down to two methods (a dictionary or a mask), and "a mask head-on" must not be used. **Key points:** - The most popular passwords: qwerty, password, guest, admin/admin. The Russian specifics of 2023–2024: "Baltika 9", "Sotochka", home and cell phone numbers. - Two cracking methods: a **dictionary** (a pre-loaded set of strings — popular or leaked passwords, or a self-made one; faster, but it is unlikely to crack a "safe" password) and a **mask**. A dictionary is indispensable for PINs and patterns on phones. - A trend: people use "AI" to generate dictionaries out of leaks; MK has made an analogue without AI — **a "dictionary based on personal data"**: when the method is selected, the built-in password manager opens with all the data from the extraction (personal data, the first part of emails, phone numbers, surnames), and a dictionary is built on that basis. - "A mask head-on" should not be used: a set of 26 lowercase + 26 uppercase Latin letters + 10 digits + "33, I think, special characters". Estimates of the number of combinations for a 10-character password (her wording, approximate): lowercase only — 141 trillion; plus uppercase — >3 quadrillion; plus digits — >a quintillion. - MK uses hashcat mask commands (for example `?a` — any character, a fixed value at the beginning or the end). The tactic: "first we run through a dictionary, then we add a mask". - A demo on a zip archive: the hash is recognized automatically. A run through a pre-loaded dictionary (100 thousand popular passwords, no mutations) — not a single password matched. - A mask demo (a 7-character password): a "head-on" mask over the whole set — **7.5 hours**; a partly custom-written mask (3 random characters + 4 fixed digits) — the password **MFD2025** obtained in **11 seconds** on what is not "the fanciest graphics card"; a realistic variant (3 letters + 4 digits to crack) — ~51 minutes. - The "heaviness" of the hash matters: a zip is cracked fast, whereas Telegram Local Passcode and Huawei HiSuite use different encryption methods — there it takes "much longer" (the topic of the next talk). - MK Brute Force is built on **hashcat** ("one of the fastest solutions on the market"); **hashcat 7.0** has come out — "we'll soon build it". The module's goal is a GUI on top of the interface-less hashcat, lowering the barrier to entry. - Supported types: archives and office documents (loaded right into MK Brute Force, the hash is recognized); Telegram Desktop passcode, BitLocker, NTLM — through **MK Scout** (it passes the hash automatically); Android/iTunes/HiSuite backups and Apple Notes — through Mobile Criminalist (the modal window "Crack"). - There is a free version (mobile via a QR code + desktop from the website); FBE/FDE are not supported in it ("my pain point"). - Distributed cracking is NOT implemented yet; the target is the first half of 2026, "I'm not promising anything" (first they will update the core to hashcat 7.0, then distributed cracking). **Tools and artifacts:** MK Brute Force (three methods: dictionary / mask / dictionary based on personal data), hashcat (7.0 awaited), Mobile Criminalist, MK Scout, the built-in password manager; GPU/CPU; zip/office, Telegram Desktop passcode, BitLocker, NTLM, Android/iTunes/HiSuite backups, Apple Notes; FBE/FDE; the demo password MFD2025. **Legal and organizational context:** no Criminal Code articles, laws or departmental methodologies were mentioned in the talk. What was stated was a **ban on building AI into Mobile Criminalist**: "building artificial intelligence… is prohibited. The legislation would object"; the speaker did not name the specific provision (having a law degree, she "won't answer this question from a legal standpoint"). The justification goes through architecture, not law: MK does not analyze or accumulate the user's data, the vendor gets nothing back, and training an AI requires data to come back — "and that would not be good". Organizationally (a line from the moderator): a reminder about the recording and a ban on filming in the hall. **From the Q&A:** *Ilya (a staffer with a microphone)* — support for cracking a physical Android image in the free app: FBE/FDE are not in the free version; if the hash is not supported and the attack does not start — write to support, specifying the device. *San Sanych* — when will distributed brute-forcing come: hope for the 1st half of 2026, with no promises. *The same man* — AI for the inverse task (cracking passwords): no, AI is prohibited, the idea is "closer to rainbow tables", "we'll think about it". *An audience member* — which specific provision of the law prohibits AI: she will not answer from a legal standpoint, the substance is the policy of data not coming back. *Ilya Anatolyevich* — how to build a dictionary out of the device's data: through MK Brute Force's third method and the built-in password manager. **The speaker's position:** the right way is meaningful hypotheses and dictionaries updated in time, so as not to be "burning electricity for nothing"; 2FA — "always". She admits the limitations honestly (a dictionary is unlikely to crack a safe password, the free version has no FBE/FDE, there is no distributed cracking yet). The style is self-ironic. *Unclear:* the speaker gave the numeric estimates of combinations approximately and "googled what these numbers are called" — they are carried over verbatim, without recalculation. The file boundaries take in the moderator's lines; the meaning of "Sotochka" as a password was not explained. The names of the questioners ("Ilya", "San Sanych") are by ear. --- ### Vyacheslav Chikin (ACE Lab, ACE NPP) — "Specifics of accelerating password brute-forcing on mobile devices" The third talk of day 1 (the program slot 11:20–11:55), it continues the previous one's topic from the hardware side. Technical and honestly pessimistic: why brute-forcing the passwords of modern phones is almost hopeless, and what the attempt to speed it up runs into. ACE Lab is the developer of a forensic system (the product is not named). **Key points:** - Previously, in ~70% of cases phones had a pattern lock or a short PIN; with the arrival of biometrics users set long, complex passwords — and forget them. - The opening case: the speaker's son forgot an 8-character password, the speaker hooked up the phone, which the system supports — "I struggled a whole day and still haven't cracked it". - The password character set is 95 (digits, English letters in both cases, ~33 special characters). On some phones extra symbols are entered into the password (periods, little hearts, accented letters — "Gen Z are actively using this"), but in brute-forcing they are normalized (a heart → "E", a period → quotes) — this has to be built into the masks. - Two algorithms in the devices: **SHA-256** (ASICs exist for it, "everything's clear") and **scrypt** — the main one in phones and the main problem. - The main "nasty thing" about scrypt is that it is memory-dependent, hard to speed up and to parallelize. Two bottlenecks: (1) heavy use of memory — thousands of GPU cores "fighting over memory"; (2) random requests "piling up" in the memory controller even on a top-end CPU. - The scrypt parameters: **N** (the cost factor, the main one), **r** (the block size, usually 8), **p** (parallelization). Doubling N increases the time not twofold but roughly **4-fold**. - Mining ASICs (Dogecoin and others) run on scrypt **1024.1.1** = only 130 KB of memory — no use for forensics. - Android with file-based encryption (**FBE**, modern phones) — scrypt **2048.8.1**, 2 MB of memory per core. Full-disk encryption (**FDE**, older phones) — **32 MB** per core, which is why brute-forcing takes much longer on older phones. - The tests: on Linux, CPU brute-forcing is roughly twice as fast as on Windows; on the GPU there is no difference. The **Ryzen 9 9950X** and the **Core Ultra**, with different core counts, gave the same result (the wall is the memory controller, DDR5). The **RTX 4060 Ti** — ~1,500 passwords/s. - The bottom line: on "a more or less decent machine" ~**20,000 passwords/s** → brute-forcing an 8-character password ≈ **10,000 years**. "Some people count in exponents; we prefer to count in years. Or in millennia, for now." - Their system is "gradually" starting to support parallelization; going forward — spreading a single job across several (up to 10) machines. **Tools and artifacts:** scrypt (N/r/p, the "nasty thing"), SHA-256, ASICs (1024.1.1 — no use); the ACE Lab system (not named); Android FBE (2048.8.1, 2 MB/core) and FDE (32 MB/core); AMD Ryzen 9 9950X, Intel Core Ultra, NVIDIA RTX 4060 Ti; DDR5, the memory controller; Windows/Linux; assembly / the CPU cache (mentioned in the Q&A as a path not taken); dictionaries (a reference to Vakhrushina's talk). **Legal and organizational context:** there is no explicit legal or procedural content — the talk is purely a hardware one; no articles of law, laws, agencies or methodologies were named. Indirectly: the talk was given on the "digital forensics day", and it is about a system for brute-forcing the passwords of seized devices. **From the Q&A:** *The CPU cache or RAM?* — he speaks only about the CPU; to work with the cache you need code in assembly, "we haven't gone down that deep yet", they use standard functions; the cache is small and "gets eaten up very fast". *Have they tried a "master password" — changing the password as in Windows instead of brute-forcing?* — he had looked at the question from the hardware side; setting your own password / bypassing it — "hard — it's math"; on SHA-256 — "a very simple algorithm", but collisions for it are still not being found. **The speaker's position:** a straight brute-force attack on the complex password of a modern phone is unrealistic; their system does not solve the task head-on. Many honest caveats about the research being unfinished ("our assumption is", "we're still going to look into this") — hypotheses are not passed off as facts. The tone is conversational and self-deprecating. *Unclear:* the ACE Lab product is never named. "A mutation block" is the speaker's own conversational term for the way scrypt is built; how it maps onto the actual scheme (ROMix) is unclear. For the RTX 4060 Ti, "fifteen hundred passwords" — the unit "per second" comes from the context, it was not said in so many words. In the second question the person from the audience said "10.5 thousand years" instead of the speaker's "10 thousand" — a loose paraphrase. --- ### Olga Tushkanova (Main Forensic Directorate of the Investigative Committee of Russia, GUK SK) — "A standard methodology for examining information stored on mobile devices and their components" The fourth talk of day 1 (the program: 12:30–13:00). On the new standard methodology for the forensic examination of information in mobile devices, developed at the Investigative Committee of the Russian Federation in 2025: it was reviewed by the Investigative Committee's Scientific and Technical Council at the end of the first half of the year and recommended to the Investigative Committee's forensic expert units, and the printed version is expected "at best" by the end of the year. The speaker explains why the methodology had to be written from scratch and what is new in it. The main idea: a methodology is a formalized, reproducible algorithm with functional (rather than vendor) requirements; the contested questions (clouds, somebody else's email) are settled not by the expert acting on their own initiative but by an immediate report to the investigator. **Key points:** - The definition: a methodology is "a formalized algorithm of the expert's actions, ensuring the reproducibility and reliability of the results"; methodological recommendations are an advisory document on how to apply it. - The history of the mobile methodologies (with a caveat about incomplete knowledge): the FSKN's 2011 recommendations marked FOUO → the 2014 standard methodology of the Forensic Science Centre of the Ministry of Internal Affairs (EKC MVD) → its barely updated 2023 revision → the new 2025 standard methodology of the Investigative Committee of Russia. For computer information, methodological recommendations on Astra Linux have already been written and ones on macOS are being written. - The first innovation — from "mobile phones" to "mobile devices": keypad phones, smartphones, tablets, smartwatches, smart bands. A description of the technical encryption of data has been added. - **The equipment requirements are functional, not by vendor product names**: writing down specific names is "a road to nowhere" (in six months they will change). The functional requirements for the expert's hardware and software workstation: ports and adapters (Bluetooth, Wi-Fi), connection cables, blocking registration on cellular networks, electrical power, the removal and reading of memory chips ("Why, how, which product? I won't say. The capability has to be there."), reading SIM cards, decoding the user partitions, SIM cards that cannot be registered, an ultrasonic bath and drying equipment, video recording, report generation. - The measures ensuring the preservation and integrity of information are divided into software and hardware ones, and into those for powered-on and for powered-off devices. - **Fault diagnosis** — now "a serious appendix" with five types: (1) does not power on; (2) no image; (3) does not respond to the buttons; (4) no response to the touchscreen; (5) no communication through the connection port / does not initialize in the OS of the bench equipment. For each one, the causes and "what to do"; "a brick — so write it's a brick" is one or two items. - **The expert's motions** (with templates): for the value of the password for access to the memory; for the SIM card's PIN and PUK codes; "the coolest one" — for the user to be present at the forensic examination in order to pass biometric identification. If it is not provided, "the expert often can't wriggle out of it"; the investigator's questioning of the owner and "the operational way" of obtaining it remain. - Two extraction methods: low-level (full access to the file system) and the extraction of publicly accessible data. The stages of extraction are listed as what the expert may run into (photographing and video-recording the screen, connection to the hardware and software workstation, a service mode, an agent program, downgrading the OS/software version, reading the SIM). - **The media for the results**: the methodology on computer information requires write-once media, but the volumes have grown — the new methodology regulates writing to rewritable ones (SSDs / external HDDs): an explanatory note and the expert's signature on paper adhesive tape, on an area with no individualizing features; in the expert report — the make, the model, the serial number, the size in bytes and the **cryptographic hash** of the written information. - **The most problematic question** (a meeting was held with the EKC MVD for the sake of a single common approach) — what to do with cloud service tokens and email passwords that are found. The decision: finding tokens has become an official stage of the examination; on finding them the expert **notifies the investigator immediately**, attaches the information to the expert report and points out that the data can be extracted from the cloud during investigative actions (an inspection is an investigative action, not a forensic examination). The expert logging into the email or the cloud on their own is "exceeding our authority". - A provision has been added: errors in the investigator's questions (semantic, stylistic, spelling) **may** be edited by the expert in the introductory part, indicating the reasons ("may", not must). **Tools and artifacts:** the Investigative Committee's 2025 standard methodology (in press); the FSKN's 2011 methodology (FOUO) and the EKC MVD's 2014/2023 ones; methodological recommendations on Astra Linux (ready) and macOS (being written); the expert's hardware and software workstation (functional requirements); cloud service tokens, credentials for social networks and email, with cryptocurrency planned to be added; write-once and rewritable media, a cryptographic hash; examples of vendors that must not be written down by name — "CO-Systems" (= MKO Systems) and "Mobile Criminalist" / Cellebrite (in the discussion of procurement). **Legal and organizational context:** the core of the talk. **Federal Law 73-FZ** (on state forensic expert activity — the expansion is ours), by the speaker's account, does not regulate the correction of errors in the questions. Agencies: the Investigative Committee of the Russian Federation (GUK, SEC, the Scientific and Technical Council), the EKC MVD of Russia, the FSKN, the FSB (mentioned), the courts. The Investigative Committee's Scientific and Technical Council does not develop but reviews and recommends; the methodology was written by the speaker's research department together with SEC SK. Public procurement: the methodology's functional requirements → technical specifications and contracts; standard systems are made through a state contract and development (R&D) work (in the MVD — "Special Equipment and Communications"). State secrets: clearance for experts, a certified hardware-software system into which other people's files must not be brought. **From the Q&A:** *Mikhail Mikhailovich* — why video recording: it is a recommendation, more needed during inspections; a real case — the swapping of a Samsung phone in court. *The same person* — why there are no smart TVs and no smart home: "they hardly ever bring them", a methodology will be written when a real need arises. *The same person* — on personal data and tokens: there is no problem presenting them in the expert report, the methodology sets the procedure; the department heads at the EKC MVD are against downloading clouds as part of a forensic examination (the workload, the backlogs). *From the audience* — a "made-up case": OneDrive synced FOUO and state-secret material to the servers of a foreign state (FISA/CLOUD Act) — no such documents should be on a PC with internet access, a leak must be reported, and inspecting a cloud is an investigative action. *San Sanych* — is the Scientific and Technical Council working on a standard laboratory: the Council does not develop; a standard laboratory is an annex to a state contract, "it goes specifically through development (R&D) work". **The speaker's position:** the methodology must be vendor-independent; she is against the expert accessing clouds and email on their own initiative; she is realistic about the limitations ("the expert often can't wriggle out of it", "a brick — so write it's a brick"); she is ironic about the quality of investigators' questions. She admits it is unfinished (she wants to "still manage to add" the item on cryptocurrency). The style is conversational and self-ironic. *Unclear:* "from Eslava" (a vendor of bench equipment) — by ear; on the recording map, presumably ELETEK, low confidence. "73-FZ" and "Art. 57" — only the number of the law is in the transcript, the expansion is ours. In the Russian original the remark "bears responsibility for the revolution" — by sense, "for disclosure". The position in the program is "GUK SK"; the speaker herself is "head of a certain research department", and the methodology was written jointly with SEC SK; the remarks about past work at the MVD ("I acted as the functional customer") are not directly confirmed. The names of those asking are by ear. --- ### Alexey Moskvichev (MKO Systems) — "Applying forensic methods to investigate thefts committed with NFC technology" The fifth talk of day 1 (the program slot 13:05–13:35). About a new wave of fraud in which NFCGate, a legitimate teaching tool, and its derivatives are used to steal money by relaying the NFC data of bank cards. The trace picture in an extraction is shown on a real criminal investigation. An important caveat from the speaker himself: he works in training, the case came from a user of the software at a regional seminar, part of the data is not MKO's own examination; in the Q&A he repeatedly admits "we didn't do that examination ourselves". **Key points:** - NFC is short-range wireless communication (RFID), with a range of 3–4 cm; it is used in mobile wallets, access control systems, and transport. - In 2025 there was a **35-fold growth in NFC crime** against the 2nd half of 2024 (global statistics). In Russia the first reports came in August 2024 (~40 million rubles stolen); in 2025 — ~400 such cases, mostly via NFCGate/NGate, with an average amount of ~100 thousand rubles. - **NFCGate / NGate** — a legitimate teaching project of TU Darmstadt (Darmstadt, Germany), the sources on GitHub; the speaker uses NGate and NFCGate as synonyms. Related malware: **GhostTap** ("gostap" in the Russian original, Chinese developers; 4–6 sets of card details per device, the devices traded on Telegram "for hundreds of dollars") and **SuperCard X** (also "Chinese people", disguised as a legitimate app). - The four NFCGate modes: **Clone** (instant reproduction of the tag, requires root); **Relay** (relaying the signal over the network between the reader and the "tag" anywhere in the world at all; the constraint in Russia is the contactless payment limits of 3,000 rubles, on some terminals 1,000 rubles); **Capture** (passive collection of traffic, pentesting); **Replay** (repeated emulation of the card). - **More than 100 unique derivatives** built on NFCGate have been found, disguised as apps of government agencies and of banking. - Two schemes: **the classic one** (the victim is talked into holding their own card up to the NFC of their own phone and entering the PIN, and the data is relayed to the suspect standing at an ATM) and **the reverse one** (the "safe account": the malware relays the signal of the suspect's card to the victim's phone, and the victim is guided to an ATM to deposit money). - The PIN is obtained in three ways: social engineering, virtual keyloggers, a pop-up window in a modified version of the app. - **A real case:** a call on Telegram from "a law enforcement officer" under the pretext of "keeping the money safe" → an APK → instructions → advice to delete the app → **230 thousand rubles** stolen. The device — a **Redmi Note 11S**. - The extraction was done with **"Mobile Criminalist Expert Plus"** (an advanced file system extraction, the MTK Android method). The trojan file **`vtb1`** was found (created/modified on 22.01.25 at 10:20), sitting in the Telegram directory. - From the Telegram database (`cache4.db`) the date the message with the file was received was established — **22.01.25 10:20:44**, matching the modification date. Decompiling the manifest: the application identifier **"Darmstadt"**, the appName **"VTB Protection"**, the hidden IP address of the server. - The app was uninstalled twice on **23.01.25 (11:16 and 11:41)**; in the file system directory — the start of the NFC system service; in the mobile banking directory — an image file recording the withdrawal of 230 thousand rubles. - Prevention of "carding": install apps only from official stores, do not enter card details on suspicious resources, if given a link to install a banking app call the hotline first, and block the card quickly if it is compromised. **Tools and artifacts:** NFCGate/NGate (4 modes, Clone requires root; TU Darmstadt, GitHub), GhostTap, SuperCard X; RAT trojans, an APK via Telegram; virtual keyloggers; MK Expert Plus (the MTK Android method); Kaspersky (standalone and the integration into the "Malicious Objects" section); decompiling the AndroidManifest (the appName "VTB Protection", the id "Darmstadt", the IP); `cache4.db` (Telegram); artifacts of the case (`vtb1`, the user id "7…", the file id "53/93", the logs of the uninstall and of the NFC service, a screenshot with the amount); Redmi Note 11S; POS limits of 3,000/1,000 rubles; Mir Pay (only in a question). **Legal and organizational context:** a thin section — there is almost no legal specificity. The schemes are described through a criminal-case framing ("a real criminal investigation", the fraudster "introduced himself as a law enforcement officer"). From the audience: APKs come in for examination "at least once a month for sure", "we try to go down the same route through the EKC". No specific articles of law, laws, methodologies or positions of regulators were voiced. **From the Q&A:** *Traces by mode* — in Relay there are traces (including on the victim's device), in Clone and Capture there are almost none (only OS artifacts and the start of the NFC service). *Reading a card in a crowd (3–4 cm)* — "we didn't do that examination ourselves… judging by the information we have, in principle, it is realistic"; the tag's data without the PIN is enough both for reading and, "effectively", for transactions. *SuperCard X — is it legitimate* — modifications are used, not the originals. *Real Replay attacks* — "we don't have that information… we can't give an example"; on the follow-up about the one-time cryptogram in an NFC payment the speaker gets muddled (correcting it to "not the security code — the bank card PIN"), and the answer is left hanging. *Does the antivirus detect it on the phone itself?* — "It would. It would on the device too." *A "file — data" reference guide* — "We'll try, but we're not promising." **The speaker's position:** an educational/protective message (experts and security services should be the "anchor"); he honestly marks out the limits of his knowledge ("we probably don't have that much expertise here"). The weak point is technical accuracy on payment cryptography: the Replay claim about "emulating the bank card an unlimited number of times" is backed by nothing, and there are no real examples. *Unclear:* the file identifier in the Telegram database, by the audio — "52…93" (in the raw transcript it sounded like "53"; checked against the audio and corrected). The trojan's name is consistently `vtb1` (in the map the variant "vtb1/WTB1"). NGate vs NFCGate — by ESET's classification these are different things (NGate is malware derived from the research project NFCGate); whether the speaker distinguishes them deliberately is unclear. The statistics (×35, ~400 cases, ~100 thousand rubles, ~40 million rubles, >100 derivatives) are given without sources. Zaitsev's closed-door talk (UAVs), which came next in the program, was cut out of the recording. --- ### Sergey Eremin (LAN PROJECT) — "Using VR-EXPERT to examine DVRs. A comparison with foreign counterparts" The sixth talk of day 1 (the program slot 15:00–15:30, after Zaitsev's closed-door talk, which was cut out). A product presentation by the developer of the software VR-Expert (LAN PROJECT, the company is 25 years old, in 2025 entered in the Russian software registry) for extracting video from stationary and in-car DVRs. The key idea: most stationary recorders have no file system in the usual sense — the manufacturer stores the video streams and their allocation table its own way and periodically changes the structure, so a disk cannot be given "a quick look" on a workstation PC; a specialized tool is needed. **Key points:** - The key threat to preservation: an officer connects the recorder's disk to a workstation bench, Windows offers to "initialize it", he agrees — "The information becomes inaccessible." Under XP/7 a small part of the boot sector used to be overwritten, whereas **Windows 10/11 write roughly the first 40 megabytes**, which is exactly where the video stream allocation table sits. - Most recorders **have no file system as such**: the device itself knows which sectors the stream lies in; every manufacturer builds the structure its own way and periodically changes it. - In the week before the talk, feedback from the piloting turned up two new varieties of file system: **TSFS** (LAN PROJECT's internal classification) on **Tantos** recorders and a **TESAM** recorder with a file system built on **VFS/VFS2**; support will be added in the next release. - Per the speaker, LAN PROJECT's programs are the only ones that work with **"Dozor"** video recorders (patrol police, FSIN), including cracking and bypassing passwords. - The sources are a physical disk and images (E01 included); first the extraction of the data present explicitly, then **carving** of the deleted data. The carving is "very deep" and slow — **a one-terabyte disk takes ~3 weeks**; a second, signature-based algorithm for finding the video stream has been added. - The result is laid out by camera, by date and time; there is a video viewer, a frame-by-frame breakdown, a report, a built-in HEX viewer, logging of actions. The interface was deliberately simplified so that a non-specialist (the investigator themselves) could inspect the disk. - Changes in the version: the UI was simplified, logging was added, manual selection of the file system, support for E01 and **FAT32** (ordinary car dash cams — originally "the program's original concept didn't call for it"). - **A new AI module** for video analysis: it is not tied to VR-Expert's data, it imports any video and static images; PyTorch, its own models and the user's, GPU; the classes are people, bicycles, cars, motorcycles, buses, trucks; license plate recognition (Russian ones only so far), an unsharp mask filter; the results go into **SQLite**; detection zones and an object tracking feature. - The AI's performance: a 30-minute video with one object — 25 minutes on the CPU against roughly 3 minutes on the GPU; "There are no miracles" — when little information was captured in the recording, there is nothing to extract. - Plans: models for electric vehicles and "weapons", filtering by color, face search, image categorization, recognition of the date and time from the screen; full Linux/Windows cross-platform support by the end of the year (for now the engine on Linux runs "through workarounds"); support for RAID inside recorders. - Car dash cams: 90% of the tasks are recorders after a road traffic accident with the last file's recording unfinished (the stream is written before the metadata). - The comparison with the foreign products (the speaker's assertions, not an independent check): on extraction/recovery/speed — parity; **MD-VIDEO** (GMDSOFT, "Hancom is now called GMDSOFT") has no explicit support for proprietary formats; the version of **DVR Examiner** available in Russia has no AI; the HEX viewer, the Russian interface and the Russian software registry entry are "only in ours". - The delivery model is a hardware-software kit (software + hardware, disk imagers, write blockers, storage media); optionally ACE Lab equipment for "worn-out" disks and foreign software (SalvationData, MD-VIDEO). In 2025 the company obtained an educational license; it has a lab of its own. **Tools and artifacts:** VR-Expert (the Russian registry, disk/image/E01, carving, signature search, HEX, logging, manual selection of the file system); the AI module (PyTorch, GPU, SQLite, Russian license plates, zones, tracking); proprietary file systems — TSFS/Tantos, TESAM/VFS-VFS2, "Dozor" (patrol police/FSIN, password bypass); FAT32; initialization in Windows 10/11 (destructive); VD-Expert (video forensic examinations, unsharp masking), Amped FIVE, Photoshop/GIMP; DVR Examiner, MD-VIDEO (GMDSOFT), SalvationData; ACE Lab equipment; DTP-Expert (OT-Kontakt); "Safe City". **Legal and organizational context:** the Russian software registry is directly tied to making supplies to government bodies easier. The customers are "all law enforcement and security agencies", the piloting is "in several agencies"; the operating systems are tested against the list for the internal affairs agencies. The interface is designed for an inspection of the disk by the investigator without a specialist — the speaker rates that as "perfectly safe", but he gives no procedural caveats (admissibility, documenting the process, bringing in a specialist under the Code of Criminal Procedure). The sanctions context: supplies of foreign software are difficult, but it is still included in the alternative configuration. He did not mention specific laws, articles, Forensic Science Centre (EKC) methodologies or case law. **From the Q&A:** *The AI module — any source?* — any video recording and static images, but "for now it doesn't go into the archive itself", the video file has to be pulled out. *Determining an object's speed?* — "No, we're not, and we don't plan to", that is DTP-Expert (OT-Kontakt). *Searching by the detected objects?* — everything is stored "in SQL" and is found with queries. *A gyroscope/G-sensor?* — not yet, "we'll see". *GPS and visualization?* — they have not worked on it, "that's a good idea". **The speaker's position:** the businesslike tone of a vendor presentation; the right way is not to rely on Windows when connecting disks, the data present explicitly first and carving afterwards, to ship the software with hardware and write blockers, to keep several products in the arsenal. He acknowledges the limitations openly (carving a terabyte takes 3 weeks, Linux "through workarounds", recognition depends on quality). The claims of "being the only one" and of "having no counterparts" are the speaker's assertions and cannot be verified from the transcript. *Unclear:* the names of the new file systems and recorders (TSFS, Tantos, TESAM, VFS/VFS2) are by ear, the confidence in the working map is "medium/low", the spelling may be garbled. The "Korean program" with problems on password-locked recorders is not named — by context it is MD-VIDEO. The authors of the questions are unknown; the "Alexey" in the moderator's remarks is the assistant with the microphone. --- ### Natalia Kotova (Forensic Science Centre of the Yaroslavl Regional Police, EKC UMVD) — "SpyNote in action: how a mobile spyware trojan is created, deployed and examined" The seventh talk of day 1 (scheduled 15:35–16:05). A practical talk by a young forensic expert (she graduated from the Ministry's university a year ago, has been performing examinations for a year, and is on stage for the first time): what SpyNote is, how it is built with the leaked builder, and how it is examined in phone fraud cases. The first part is a live demo of the builder, the second the examination method. She herself calls the upshot "a small practical guide". **Key points:** - SpyNote is a family of RAT trojans for Android; per Kaspersky's reports it has been in the top 10 verdicts for several years, and its popularity is growing. In **2022** the source code of the builder of one of its versions leaked online. - Most often it is used to intercept SMS messages with confirmation codes; the cover stories are a doctor's appointment booking, an antivirus, a parcel tracker; on the devices only the icons and the names change. - The **v6.4** builder is downloaded "without any VPN or SMS registration", an old version, "possibly the very one that leaked"; it builds working APKs (different from "the ones seen in the wild"), and binding with another APK is available. - Modules: viewing SMS (sending is not provided for), call history, contacts; a file manager without root; a covert camera that works with the screen locked; a **keylogger** (keyboard input, navigation, notifications); remote screen lock, factory reset, setting a lock screen password "without any user confirmation. I tested it myself"; geolocation, calls, microphone, chat, terminal, accounts. - The only correct wording of the question put to the forensic expert — **the presence of files detected by antivirus software**, "and nothing else, no malicious viruses". - The method: a physical image or a full file system → scanning with **at least two different antivirus tools** → static and dynamic analysis if an APK is found → studying the timeline. - Decompilation tools: apktool, JADX, dex2jar; APKiD (obfuscation, protection means, build tools); strings, grep. Traffic: Burp Suite/ZAP for HTTP, Wireshark for TCP (SpyNote exchanges data with the C2 over TCP). - "A find of mine" — **MobSF** (Mobile Security Framework): open-source, automated static and semi-automated dynamic analysis, a GUI, deployment via Docker, an online version for static work. Drawbacks: it does not search by IP, and it finds URLs only by regex. - From the manifest one extracts the package name, the version, permissions, an activity (Intent-filter MAIN+LAUNCHER), services (in the example — an **accessibility service**, which gives access to the contents of the screen), receivers for system events; what they are for has to be looked up in the code of the classes. - SpyNote performs its functions only on command from the C2; the host and port are set at build time and stored in the resource strings. A test **without network access** ("the forensically correct way") yields a DNS query for the C2 domain; the traffic is compressed with **Gzip** (not encrypted); in the SpyNote log — the keylogger's data in **Base64**. - The forensics of installation artifacts: the data in `/data/data`; the installation details — from the **frosting.db** and **verify_apps.db** databases; the main file — **packages.xml** (the initiator and the installer app). Artifacts differ across vendors: on Samsung — a battery usage log; the Android package manager log contains more. - If neither the file nor the app is on the device — a built-in antivirus helps (Sberbank's, for example): the file **30.db** records the verdict, the package name and the time — it can be proved that the malware "was there", without the malware itself. **Tools and artifacts:** the SpyNote v6.4 builder; Kaspersky (statistics); apktool, JADX, dex2jar, APKiD, strings, grep; Burp Suite, ZAP, Wireshark; MobSF (Docker, the online version); the Android Studio emulator (Android 10); INetSim (Q&A); AndroidManifest, accessibility service; frosting.db, verify_apps.db, packages.xml; the Samsung battery log, the package manager log; Sberbank's antivirus, the file 30.db; Base64, Gzip; SSL pinning/unpinning (Q&A). **Legal and organizational context:** the typical questions of an examination in such cases — the presence of remote access software, call and SMS history, messenger and social network history, web page visits. Forensic correctness: samples are kept from being released onto the internet and are tested without a network. The agency — the Forensic Science Centre of the Yaroslavl Regional Police (EKC UMVD); the statistics — from Kaspersky's reports. The talk contains no references to articles of laws, methodology numbers or regulators' requirements. **From the Q&A:** one question from the audience (the person asking is not named), in two parts. *Crypters and obfuscators* — in SpyNote obfuscation is "used quite heavily" (strange names for classes and variables); she uses an automated solution with behavioral analysis, and the task boils down to finding the IP address of the control server. *Traffic encryption / SSL pinning / unpinning* — samples are not let out onto the network, and the task of traffic analysis usually does not arise; she showed her own example because she had both the client and the server parts, where there was no encryption (only Gzip); the solution — a pair of virtual machines with the network emulated through INetSim. There were cases where the scammers wrote to the forensic expert through the built-in chat. **The speaker's position:** the tone is emphatically modest and practical; she rates MobSF highly but names its limitations honestly; she insists on the only correct wording of the question put to the forensic expert. *Unclear:* the person who asked the question in the Q&A is not named, and the remark is garbled. "verfi.app.db" in the Russian transcript, by the audio verify_apps.db — a distortion of `verify_apps.db`. The file 30.db and "Sberbank's antivirus" — by ear, the accuracy of the naming is not guaranteed. The SSL question is poorly recorded, and the meaning has been reconstructed from the context. A possible discrepancy: the person asking claimed that "the source code here is open, there's nothing like that", while the speaker replied that it is "used quite heavily" — the contradiction is not resolved in the transcript. The name of the agency: the speaker says "the EKC MVD of Russia for the Yaroslavl Region", while the heading has the official "the EKC UMVD of Russia for the Yaroslavl Region". --- ### Andrey Shavlovsky (Forensic Expert Centre of the Investigative Committee of Russia, SEC SK) — "Examining information by dynamic analysis on macOS-based personal computers" The eighth talk of day 1 (scheduled 16:10–16:40). A step-by-step manual on extracting and cracking the macOS account password in order to then examine protected data dynamically (the keychain, tokens, desktop messengers). The main point: static analysis of an image is the "gold standard", but it misses protected memory areas, so macOS examinations have to be supplemented with dynamic analysis, with the password obtained first. The running message — do not trust automated tools blindly, re-check by hand. The speaker's experience — 8 years of computer forensic examinations. **Key points:** - **Static analysis** (a system that is not running, "as is") is called the "gold standard" — it ensures preservation, repeatability, reproducibility; the problem is that it misses protected memory areas. **Dynamic** — the examination of a running object. - On Windows the method is established: the password hash (a weak one) is pulled out of the registry, guessed, the copy is virtualized, browser data and tokens are extracted. - macOS is a proprietary OS; the key mechanism is the **Keychain (the key chain)**, access only by password or biometrics; the speaker calls it an analogue of Windows DPAPI. - Settings, accounts and logs are stored in **plist files** (the formats are XML / binary / JSON; binary by default — more compact and faster). - The account data is in the system directory **`dslocal`**, a separate binary plist per user; the section of interest is **`ShadowHashData`**. - The order: access to the file → conversion of the binary plist into XML with the **`plutil`** command (the bash terminal) → decoding `ShadowHashData` from **Base64** → the password hash. - The hash is encoded with **PBKDF2-SHA512** (salt + iterations + the "entropy"/the final digest). By contrast, Windows — the **NT hash** based on the outdated **MD4**, with no salt and no iterations, a brute force speed that is "very high". - **The salt prevents rainbow tables**: two users with the same password have different hashes — which is why macOS hashes are cryptographically stronger than Windows ones and take longer to guess. - Preparing the hash for brute forcing is done with special scripts (input: the plist with `ShadowHashData`, output: the hashcat format). - **hashcat** is given the file with the hash and the algorithm — mode **7100**; guessing by mask or by dictionary. - **MK Brute Force** is called "an excellent program", but at the time of the talk it **does not support mode 7100**, so it could not be tried on a macOS hash. **"Mobile Criminalist Expert"** does not convert the macOS hash ("maybe they've fixed it by now"). One unnamed third-party tool did convert the hash, but displayed it **incompletely** — a brute force on it is impossible (an illustration of how unreliable automation is). - Brute forcing is better done on a GPU cluster; simple brute force "can run into years, which nobody needs", so custom dictionaries are needed; the resource **wikpass.com** is recommended. - Once the password has been established — virtualization of the copy, or (if that failed) an examination of the object with changes made, but in a forensic examination only with the initiator's permission. With the password, the keychain, tokens and desktop messengers are decrypted — dynamically, including through **"Mobile Criminalist Scout"**. **Tools and artifacts:** Keychain (an analogue of DPAPI); plist (XML/binary/JSON); `dslocal`, `ShadowHashData`; `plutil`, Base64; PBKDF2-SHA512 vs. NT hash/MD4; hashcat (mode 7100); MK Brute Force (no 7100), MK Expert (does not convert the hash), MK Scout (dynamic extraction of messengers/tokens); the unnamed third-party tool (loses part of the hash); wikpass.com; Fusion Drive, Secure Enclave (Q&A); virtualization. **Legal and organizational context:** **Article 57** (the speaker does not specify the code; by the context of forensic examination — the Code of Criminal Procedure of the Russian Federation): a forensic expert is not entitled to use methods that entail the full or partial destruction of the object or a change in its main properties. Hence: an examination with changes made is permissible only with the prior permission of the initiator of the examination. The speaker represents the Forensic Expert Centre of the Investigative Committee of Russia (SEC SK). There are no references to specific departmental methodologies, to regulators or to cooperation with other agencies. **From the Q&A:** *Yuri Mikhailovich* — "So the disk wasn't encrypted? How did you pull the file out?": in this case it was a **Fusion Drive**, they managed to reassemble it, there was no encryption. *The second question* — on Linux the `shadow` file cannot be read under a user account, but on macOS it can? and will the plist be readable on a "live" system?: there are difficulties, especially on modern devices (hardware encryption, the **Secure Enclave**), **without root you can't get in**; the point is to pull out the plist itself; modern iPhones are problematic too, even when the passcode is available. **The speaker's position:** a calm lecturing, methodological tone. Correct — the priority of static analysis, the mandatory manual re-checking of key results, the initiator's permission before changes are made. A problem — blind trust in automation ("their code may contain bugs"). He admits the limitations of the method openly (the Secure Enclave, the need for root, the difficulty of modern iPhones). *Unclear:* "the previous speaker" who described static and dynamic analysis in detail — the phrase is garbled, no name is given (by the order of the talks, probably Kotova). The unnamed tool that loses part of the hash is one the speaker deliberately does not name. Mode 7100 sounded like "71.2.0" in the original Russian transcript. The domain wikpass.com is by ear. "Entropy" is what the speaker calls the final digest — non-standard terminology. The author of the first question, "Yuri Mikhailovich", may, by the recording map, be Yuri Barkalov, not confirmed. --- ### Igor Bederov (T.Hunter / Internet-Rozysk) — "Identifying the owners, administrators and developers of web resources" The last online talk of day 1 (scheduled 16:45–17:05). A short (≈17 min) overview talk, a how-to guide on OSINT research of websites: how to get from the domain, the hosting, DNS, the content, the technologies hooked up to it, web archives and external traffic to the three roles — the owner, the administrator, the developer. The speaker himself calls it a condensed version of an hour-and-a-half lecture; it is all presented as a checklist, with no depth. There were no questions from the audience. **Key points:** - The three roles: **the owner** (domain/hosting), **the administrator** (communicates with users, posts content), **the developer** (the engine, the technologies hooked up to it). - The "anchor" tool is a portable OSINT build of the **Opera** browser from T.Hunter: runs from a USB stick, sessions on the stick, privacy settings, **more than 2,000 sources** (cryptocurrency, social networks, websites, Telegram, security departments, forensics); the sources can be exported as HTML into any browser. - **WHOIS** has degraded: domain names are "registered extremely sloppily", the data is not verified; after **GDPR** the owner in the output is "a private person". The way out is historical **WHOIS archives**, where personal data may have survived. - "A bit off-topic": according to the speaker, in August (2025) the Supreme Court of the Russian Federation obliged business entities to detect typosquatting and online fraud on their own. The tools: **DNSTwister, DNSTwist** (+ a third name not made out) — searching for similar domains; **IntelX, Have I Been Pwned** — leaks involving the domain; all of it free. - The hosting is determined by anything from the built-in ping to external services. **Cloudflare** is "actively used by offenders" to hide the actual location; "you can't always" strip the protection away. - Bypassing Cloudflare: services that indexed the resource before it was put in place (**URLScan, VirusTotal**); "leaks of Cloudflare itself"; DNS analysis; the technologies on the site (verification in Yandex/Google, acquiring services); reuse of the **SSL certificate and favicon**. - **DNS records** hold information about the linked servers. The October 2021 case: the outage of a social network "banned and designated terrorist in Russia" — the speaker was getting in "to the hosting, to the IP address". Part of the infrastructure of drug-trafficking and disinformation sites is physically located in Russia and visible through DNS. - Linked contacts are looked for in the body of the site and in external leaks: archived WHOIS from scraping; advertising that uses the site; "millions-strong leaks" (email address patterns, employee names, passwords). Guessing addresses by pattern (office@, admin@, support@, hr@, pr@) + a check with an **SMTP request**. - External files are found through VirusTotal and **dorks**; what matters most is the **metadata (EXIF)**. A 2025 case: a "harassment" site by one businessman against another, pictures taken on an iPhone → **GPS in the metadata → the home address** of the suspect. - Hyperlinks: internal ones — through robots.txt and sitemap.xml (hidden pages); external ones — social networks and file-sharing services (a file-sharing service is linked to an email by OSINT methods → the administrator). If there is a VKontakte group, the **InfoApp** application gives the data of the group's administrators. - The site's technologies (acquiring services, chatbots, analytics counters, advertising IDs) are "a huge minus" for the owner's privacy. **Yandex.Metrica**: ~10% of counters are public (the moment of installation gives away the installer); Yandex support, asked "I'm the site administrator, I forgot which email is linked…", discloses the email by the counter ID. - **Acquiring** is tied to a bank: with an acquiring service installed, "you can contact the bank" and find out the recipient, his login and registration data. - **Web archives** give the old code, the technologies, old contacts, links "and even files". **External traffic**: sites hosting petitions are "almost always" inflated by bots, but the author does the first seeding himself → the external traffic shows who first posted the links → his page and his groups. **Tools and artifacts:** a portable Opera (T.Hunter, 2,000+ sources); WHOIS and WHOIS archives, ICANN; DNSTwister, DNSTwist, IntelX, Have I Been Pwned; ping; Cloudflare; URLScan (urlscan.io), VirusTotal; DNS records; the SSL certificate, favicon; an SMTP check; dorks; metadata/EXIF (GPS); robots.txt, sitemap.xml; InfoApp (VKontakte); Yandex.Metrica; acquiring; web archives; external traffic/link seeding. **Legal and organizational context:** according to the speaker, a ruling of the Supreme Court of the Russian Federation (August 2025) obliged business to detect typosquatting and online fraud on its own — the details, the date and the type of the act were not named. GDPR is the reason personal data disappeared from WHOIS. Techniques such as a request to Yandex support ("I'm the site administrator, I forgot which email is linked…") and a request to the bank about the acquiring service are presented as working ones, with no caveats about legality (pretexting, in fact); the legal basis for the bank's disclosure is not named. One of the cases was in the "invasion of privacy" category. Interaction with law enforcement is not described directly; there are no procedural references (the Code of Criminal Procedure, articles of the Criminal Code) in the talk. Organizationally: T.Hunter assembled a browser for researchers, and the slides are handed out to attendees. **From the Q&A:** there were no questions from the audience. The moderator: "Igor, you've apparently fired up the audience so much that it's all perfectly clear now" — applause, and on to the "roast" (it did not make it into the recording). **The speaker's position:** OSINT is an equal neighbor of forensics; the forecast: if smartphones lose the wired port, the weight will shift to data analysis. WHOIS is honestly admitted to have degraded, Cloudflare cannot always be stripped away, only ~10% of Metrica counters are public. Investigations of "political" petitions (calls to overthrow the government, to topple governors) are called an ordinary class of tasks — the tone is instrumental. *Unclear:* the third tool name after DNSTwister/DNSTwist ("khipsk" in the Russian original) was not made out. "InfoApp" — by ear. The Supreme Court ruling is the speaker's retelling with no details and needs checking. The October 2021 social network is not named (from the description — Facebook/Meta, the global outage of 4.10.2021); the claim that during that outage the speaker "was going … to the IP address" is technically dubious (the outage was at the level of BGP/DNS announcements) — it is reported as his statement. "In about 70–80%" in the passage about petitions — what the share refers to is unclear from the broken syntax. The names of the WHOIS archive services, of the SSL/favicon products and of the web archives were not spoken aloud — only on the slides. --- ### Closing of the online part of day 1 (Dmitry Yankovoy) After Bederov's talk the moderator announces the move "toward the very final part of our evening today, namely the roast" and **before it says goodbye to the online viewers**: "now is the time to say goodbye to our online viewers. And we'll see you tomorrow". Those attending in person are invited "to the bar area, taking along some drinks, spirited and otherwise". The closing of day 1 proper in the recording — three sentences; the "roast" (17:30–18:30), the prize draw (18:30–19:00) and the informal networking (19:00–21:00) were deliberately not streamed and did not make it into the recording. The next substantive line in the recording (after a pause of ≈1:42 — the splice of the two days' streams) already belongs to day 2 (the lead-in to Barkalov's talk). --- ### Yuri Barkalov (Forensics Science Centre) — "How does OSINT affect information security?" The first talk of the second day (information security day, 12.09.2025); Dmitry Yankovoy opens and moderates it, the introductory and closing lines are not the speaker's. Barkalov (teaches at the International Institute of Computer Technologies, "retired three years") gives a talk that is polemical rather than practical: open sources have become a channel for influencing the consumer of information himself. The speech proper runs ≈26 min, followed by ≈9 min of sharp debate with Igor Bederov. **Key points:** - He dislikes English-language terms: "legal proceedings in the Russian Federation are held in Russian"; closer to him is "computer/competitive intelligence", and explaining an English term to a judge is an extra task. - The main thesis — **"OSINT isn't what it used to be"**: since there is intelligence, there is counterintelligence too, "And what is counterintelligence? It's disinformation"; open sources have become a channel for "brainwashing the population". He flags this as a personal opinion. - He divides OSINT into professional (analysis of information security incidents) and "civilian" — "any of you" is at once a consumer and a supplier of information; "the first civilian OSINT" was the grannies at the entrance, who have now been "replaced by young people who sit on social media". - The frame of the talk — **the Information Security Doctrine of the Russian Federation**: protecting information includes protecting society from information that is harmful; the example of the rumor "there's a currency reform tomorrow" from "an assistant to some janitor" at Sberbank — NLP, social engineering, creating panic. - A personal social engineering case: a Telegram message "on behalf of the head of the Interior Ministry institute" about a forthcoming call from "an FSB representative" → a call asking him to describe how information security is organized at the institute → "we'll soon invite you to Lubyanka". - Scammers only need "some tiny bit" — a name, passport details; the "safe account" scheme is absurd ("put it under the bed, under the pillow"), but "people get brainwashed… it's human psychology"; he quotes the song about fools from "Buratino". - **The classics of information security matter more than tools**: "the main threat is the insider threat, it's the human being"; the case — 64 million stolen from an organization with money, versus an organization with tokens where "there's nothing to steal"; attackers know in advance where there is something to steal. - The only method of protecting an organization from OSINT that he can see is **counterintelligence**: "Launch some disinfo, see who leaks what", concealing information about the informatization object. - He criticizes the platforms' "closed OSINT": the Yandex Metrica and Yandex Browser agreements, the Microsoft Privacy Statement; the cookies test ("clear the cookies — type the password again"). He adds the caveat that he is not accusing Yandex of trading in data. - He refers to Tushkanova: "the most malicious system is Microsoft", "Microsoft itself doesn't deny it"; a Bill Gates quote to the effect that "we'll decide that for him". - MH17 ("flight 17"): "their investigation was done through Google", they assumed that "people post correct information" — "where did they get the information from, who posted it?". - An AI case: a lawyer brought an order appointing a forensic examination whose questions had been generated by "Alice"; an example of uncritical consumption of AI content. The refusal to examine a deepfake — because of the recording quality. - An unresolved problem: open information has to be checked, but "what if it's well-crafted disinformation"? Planting disinfo is easy — GetContact from 10 different numbers. **Tools and artifacts:** Yandex Metrica/cookies, Yandex Browser (the license agreement), "Alice", Microsoft (the Privacy Statement), Google (MH17), Telegram, GetContact, Fido (FidoNet, the historical first OSINT — prescriptions for narcotic-class drugs), USB tokens, flash drives, an ATM with "the new protection system", Mitnick's book (the title is not spoken in the recording), "CyberDed", NLP; legal artifacts — the Information Security Doctrine of the Russian Federation, Federal Law 152-FZ (Art. 19), Art. 272 of the Criminal Code, the Civil Code. **Legal and organizational context:** Art. 272 of the Criminal Code and articles of the Civil Code (in the Russian transcript "the 1st, the 152nd, the 2nd" — probably Art. 152.1/152.2 of the Civil Code; the speaker map gives "152/137") as the framework of OSINT's legality; legal proceedings held in Russian — an argument against anglicisms in a forensic examination; Federal Law 152-FZ (the definition of personal data, Art. 19) — "somehow, I don't know why, it doesn't always work"; the fundamentals of information protection (legal, technical, organizational measures, a security policy) "exist, but for some reason aren't complied with"; the restriction of foreign messengers is supported with caveats; operational-search activities (ORD) vs OSINT — in ORD there are closed databases that "you can trust 100%", OSINT is "unreliable, reference information". The moderator's proposal of "a third day of MFD, done purely for lawyers". **From the Q&A:** - *How does OSINT differ from operational-search activities?* "It's the depth of immersion"; in ORD there are databases, "closed, special information" that can be trusted; OSINT — unreliable open sources. - *Why is everyone using OSINT so fiercely?* "Because it's been hyped"; everyone likes it. - *How is OSINT useful methodologically for information protection?* Open sources cannot be fully trusted; for information security — look at what has been posted about you, and defend yourself with disinformation about your own system. - **Olga Tushkanova**: there is "a third level" — a specialist sees that about their own field "they write rubbish", and realizes the rest is the same; OSINT is either trusting the databases or getting "orienting information". → "the main thing is analytics". - **Igor Bederov** (not named out loud in the recording): OSINT is a methodology for collecting, analyzing and **verifying** information that is open, lawfully obtained and re-verifiable, and usable in court as an evidentiary basis. → Barkalov: "But we're not in the West, thank God"; on verification — "I won't even argue with that… But that's exactly where the problem lies" (the GetContact example with 10 different numbers). **The speaker's position:** he provokes the discussion deliberately ("that's what I was after"); he does not deny the verification methodology, but considers it a different task and sees no solution against well-crafted disinformation. He is respectful of the practitioners of classic OSINT ("CyberDed", his students), and argues not with them but with the uncritical consumption of information. He is honest about the limits: he turned down the deepfake examination, and does not disclose what he answered the scammers. *Unclear: Bederov is not named out loud in the recording, the attribution of his lines is per the transcript's speaker map; the list of articles is garbled; "Elena Rafailovna Susova", "Ms. Yulova", "CyberDed" — by ear / not explained; some of the claims rest on slides that cannot be seen.* --- ### Alexey Shulmin (Kaspersky, GReAT) — "Librarian Likho — an APT group combining cyberespionage and financial motivation" Scheduled 11:40–12:10. The speaker introduces himself as "a malware expert in the Advanced Threat Research Department" (the Russian name of GReAT). A walk-through of one APT group following Kaspersky's recent report "Notes of a Digital Auditor": the whole chain is built on spear phishing, batch files and legitimate utilities, without a single binary implant. The talk runs ≈27 min, the Q&A ≈9 min. **Key points:** - The group Librarian Likho (formerly Librarian Ghouls, the "Ghouls cluster"/cybercrime) was "renamed" once they realized: the main motivation is cyberespionage, the financial one is secondary; other vendors call it **Rare Wolf / Rezet** (the name comes from the batch file rezet.cmd). - The report "Notes of a Digital Auditor" — ~330 pages of "technical meat", free as a PDF via a QR code, an English version on request; it splits the Ukrainian groups operating against Russia into three clusters (hacktivists, cyberespionage, "everyone else"); graphs in Obsidian, IOCs. - Attribution: there is a sponsor behind the APT — "some large agency", the resources are "essentially unlimited". The targets are Russia, Belarus, Kazakhstan; industrial enterprises, research institutes, design bureaus, think tanks, big universities. - The **KISS** principle: "we've got clumsy paws", or a bet on legitimate tools being hard to detect. - The vector is spear phishing with a RAR attachment, "payment order…", with the author's own mistake in the name (circumstantial evidence); inside it a **.scr = MZ/PE** launched through ShellExecute; built with **Smart Install Maker**. - Inside data.cab: a PDF dummy (the speaker insists — **red herring**, not decoy: a payment slip for 600 rubles for insurance), a legitimate **curl** (they carry it with them), a malicious **LNK** — the only thing that really gets detected. - The toolkit goes into the hidden system folder **C:\Intel** (in the speaker's view, that gives them away instead); driver.exe unpacks as **RAR 3.8** with its strings zeroed out; the **unique password** of the archives, with traces going back to 2010, is an interesting IOC. - **AnyDesk disguised as svchost** — "the core of the whole attack", installation mode with a password for windowless access; **Defender Control** (the D switch) turns Defender off; **powercfg** ×6 so the machine does not fall asleep. - The night mode: the task **"shutdown at 5 a.m."** and **wol.ps1** → the task **WakeUpAndLaunchEdge** (waking the machine at 01:00 through the genuine Edge); the window is 01:00–05:00, "4 hours, enough to scoop up absolutely everything", and in the morning the victim notices nothing. - A dump of **SYSTEM/SAM** through reg.exe; **wallet.rar** with crypto wallets + registry backups → exfiltration by e-mail through **blat.exe**; the **XMRig** miner (Monero) with a malicious pool. - The rest of the toolkit: **ngrok, WebBrowserPassView, Mipko Professional Keylogger** (a Russian product, Pskov; the distribution carries a Ukrainian localization, "a hypothesis"); lateral movement by batch files over **SMB**. - The infrastructure: phishing under **Mail.ru**, "an exact match" (login.php, sign-in via Gosuslugi), an open **directory listing** with the toolkit, **phpMyAdmin** in Russian by default — "that's the kind of evidence … left about themselves". - The trend: spear phishing now delivers 90–95% of threats (a year ago — 80%); the tricks with the password in the email body → over a separate channel; a case from another investigation — an implant takes the file "logins and passwords.xlsx" from the desktop at a large organization. **Tools and artifacts:** the report "Notes of a Digital Auditor", Obsidian, RAR spear phishing, .scr (MZ/PE), Smart Install Maker, data.cab/installer.config/runtime.cab, the PDF red herring, curl, LNK/trace.lnk, 4t Tray Minimizer (4t-niagara.com, a pseudo-British VAT number), rezet.cmd, C:\Intel, driver.exe = RAR 3.8, the unique password (traces from 2010), AnyDesk (svchost), Defender Control, powercfg ×6, schtasks ("shutdown at 5 a.m.", WakeUpAndLaunchEdge), wol.ps1, Edge, reg.exe → SYSTEM/SAM, wallet.rar, blat.exe, XMRig (Monero), ngrok, WebBrowserPassView, Mipko (MPK), SMB, Mail.ru phishing (login.php, the domain users-mail.ru, checked against the audio), directory listing, phpMyAdmin; in the Q&A — AMSI, KFA, KES, KSN, emulation of variable depth. **Legal and organizational context:** the report is devoted to Ukrainian groups operating against Russia; the circumstantial evidence of origin is the mistake in the attachment name, the Ukrainian localization of Mipko, the Russian phpMyAdmin, the slogan on the 4t-niagara site. The limits of telemetry: "we don't see everything… bound by regulators' requirements, bound by all the GDPR stuff", the victim is not attributed — the mechanism is in the KSN agreement. Kaspersky is a commercial company, "not a government agency", it does not investigate incidents, "we're about Defensive, we're not about Offensive". Criminal liability: the attackers "all hope for Art. 272, 273, 274", but "work the RU, and they come for you at dawn". **From the Q&A:** - *Why batch files and not implants?* Two hypotheses ("paws" + hard to detect); all of it is something Kaspersky is "very good at detecting"; PowerShell after AMSI is transparent. - *A lightweight solution for Astra / Russian operating systems?* "I'm not a product manager, I'm a techie"; there is KFA and there are trials. - *Why nothing was said about the victim — what system, was there any protection?* "We don't see everything" (regulators, GDPR); "where did you get the idea that it wasn't detected?"; Defender is simply switched off when the privileges are there, and copying files is legitimate activity. - *Send an official request to VK/Mail.ru about the password?* He does not know whether it is possible; "it's not our job". **The speaker's position:** sarcastic, he addresses the group's operators, who "will watch the stream or the recording"; the main culprit is the user and the absence of security awareness (.pdf.exe in 2025). He criticizes the SOC (the missed dump of SAM/SYSTEM) and the level of the attackers ("an APT on batch files"), but admits: "it works". The conclusion: "First of all TI, first of all security awareness". *Unclear: the attachment name and the unique password were redacted in the talk; the domain users-mail.ru (the Russian word for "hyphen" was probably spoken aloud); the AnyDesk password "qwerty 1234566" is in question; articles 272/273/274 — the numbers without "Criminal Code".* --- ### Vladislav Azersky (F6) — "UWP in the DFIR crosshairs: what modern Windows apps are hiding" Scheduled 12:15–12:35. A talk about applications in the UWP/MSIX format from a standpoint that is, as the speaker stresses, "not even about incident response so much, but more about computer forensics". The main point: the isolation UWP was conceived for has effectively disappeared, while the Store ecosystem has become both a delivery channel for malicious packages and a source of legitimate tooling that needs no administrator rights. Deeply technical; there were no questions from the audience. **Key points:** - History: Metro Apps (Windows 8, isolated containers) → UWP (Windows 10) → **Desktop Bridge (build 1607)**: Win32 is packaged as UWP with permissions for the system APIs — "…the isolation was gone. And that's a very important point." - **MSIX** (an evolution of APPX) — an archive-installer; three key files: **AppxManifest.xml** (the **runFullTrust** permission = access to everything), a mandatory signature with the certificate inside the package, **BlockMap** (the hashes of all the files — useful to the forensic expert). - Four types of application; "most malicious MSIX applications are signed precisely with a developer certificate" — attackers compromise a company and sign their own package with its certificates. - Building: **MSIX Packaging Tool**, **Advanced Installer**, or **MakeAppx** + a hand-written manifest + **SignTool** (a self-signed certificate has to be imported into Trusted Root — admin rights are needed). - In Windows 11 unsigned packages are installed with a PowerShell cmdlet; the indicator is a **fixed Organization ID** in the Publisher field. - The campaigns of mid-2023 (Microsoft Threat Intelligence): financially motivated groups distributed MSIX through the **ms-appinstaller** handler (later disabled); the channels were phishing, **SEO poisoning**, malvertising, phishing in Teams. - "A certain CVE" — a bypass of signature validation (the publisher did not match the developer of **Perimeter 81**); the speaker honestly notes that he found no detailed description of it, and that "there aren't that many cases". - The **FIN7** technique: an MSIX with an embedded framework (per the recording map — PSF) that runs a PS1 or a batch file before the main application, via config JSON. - DFIR artifacts: the application directory; the SQLite database **StateRepository-Deployment** (the source URL or the full path of the MSIX, the file hashes — installed ones only); a second SQLite database (the Organization ID of unsigned packages); the event log — **event 9545** (an unsigned package via PowerShell); the **App Installer** log (GUI vs ms-appinstaller); traces of **winget**. - "Living off the Store" without admin rights through winget: the **Python/Julia** interpreters → a reverse shell; the **ngrok/localtunnel** tunnels (in ransomware cases, "recently added" to the Store); portable browsers; SSH/RDP agents; a RAT (TeamViewer); **VS Code** (code.exe → a tunnel after authenticating with GitHub). - Recommendations: prohibit untrusted packages and the installation of MSIX by unprivileged users; detection rules for the cmdlet; collection of event 9545 and of four more events in a SIEM. **Tools and artifacts:** UWP, Metro/Modern Apps, Desktop Bridge, MSIX/APPX, AppxManifest.xml (runFullTrust), BlockMap, MSIX Packaging Tool, Advanced Installer, MakeAppx, SignTool, Trusted Root, the PowerShell cmdlet (Organization ID), ms-appinstaller, Microsoft Threat Intelligence, the CVE (the number was not named), Perimeter 81, the FIN7 framework (PSF), StateRepository-Deployment (SQLite), a second SQLite database, event 9545, the App Installer log, winget, Python/Julia, ngrok/localtunnel, portable browsers, "SHRDP agents" (probably SSH/RDP), TeamViewer/RAT, VS Code/code.exe, the PowerShell log, SIEM, Purple Teaming, Yandex/Google (SEO poisoning), Microsoft Teams. **Legal and organizational context:** there is no legal content — the talk is technical (no laws, articles or agencies are mentioned). The organizational context: the vendor's stance (Microsoft disabled ms-appinstaller, but itself opened the way for unsigned packages in Windows 11); corporate policies (a ban on untrusted packages and on MSIX for unprivileged users); monitoring (detection rules, event 9545 and the "four events" in a SIEM / log management). The talk sits in the information security day and is addressed to corporate security teams. **From the Q&A:** there were no questions from the audience — the moderator joked "As always, you've broken my whole audience" and announced a break until 13:10. **The speaker's position:** the isolation of UWP is a formality after Desktop Bridge/runFullTrust; Microsoft's decision to allow unsigned packages is presented both as a weakening and as a gift to the forensic expert (a ready-made Organization ID). Honest caveats (he found no description of the CVE, on the scale of the MSIX threat "there aren't that many cases") — he does not inflate the threat. He names the trend confidently: tunnels "in almost all cases" with ransomware, the legitimate Store has become a source of post-exploitation. *Unclear: event 9545 is flagged as unconfirmed in the recording map (in the raw transcript "95.45"); "SHRDP agents" — probably SSH/RDP; the wording about Perimeter 81 is syntactically unclear; some of the names stayed only on the slides (the name of the second SQLite database, the name of the FIN7 framework, the cmdlet and the parameter).* --- ### Nikita Vyugin (MKO Systems) — "The value of security tools: what we wouldn't have if we had everything" Scheduled 13:10–13:40. Not a technical survey but a "warm-up" one (the speaker's own definition) of the standard security tool line-up — antivirus, DLP, EDR/XDR, SIEM, SOAR, SOC, DFIR — all on the same pattern: what it is, at what scale it is needed, the nuances of deployment, what is lost without it. The occasion — a post in Dmitry Boroshchuk's Telegram channel about "maturity" in information security. The talk ≈37 min, the Q&A ≈9 min. **Key points:** - Two criteria for judging the tools: **reasonableness** (choose them by consulting all the departments — the business, the security service, economic security, the lawyers, HR) and **maturity** (not the "willingness to buy… for millions upon millions", but an understanding of why and how to integrate them). - **Antivirus** — "the most, most, most basic level"; always needed ("at least one digital device"), blocks ~90% of simple threats. The nuances: false positives, a false sense of security, the weak integration of the basic versions, the BYOD hole, quarantine gets in the way of an investigation. - **DLP** — needed when there is a risk of leaking trade secrets/personal data even on 15 machines (the "tyrant of a boss" case); extremely sensitive to configuration and classification; the real effect — up to 30% of leaks, not the "90–100%" of the brochures; "not plug-and-play". - **EDR** — an agent on the endpoint (process behavior, the network, scripts) for the risk zone of sophisticated attacks; **XDR** — an extension to the network, email and clouds, correlation, "often applies machine learning". Growth in scale = growth in licenses: "count, calculate". - **SIEM** — "an alarm system": it collects and stores events, but "doesn't respond… on its own, not SOAR, not some kind of artificial intelligence"; "garbage in, garbage out"; rules for each infrastructure; the example — 6 thousand machines for 6 IT specialists. - **SOAR** — playbooks, automation of the response; to be integrated only "through negotiations… between all the departments"; the risk of automatic actions ("business goes down"); "not artificial intelligence", it follows whatever playbooks have been written; it offloads the SOC. - **SOC** — an organizational unit (people + infrastructure + tools), 24/7, TI feeds; expensive, burnout, a staff shortage. - **DFIR** — "doesn't protect anything, but you have to resort to it"; retrospective in ~90% of cases; RAM as a time-critical source; with ~3 incidents a year — outsourcing; the reports "are read by law enforcement as well". - The conclusion: "don't fall for bare advertising"; count the scale, the licenses, the people, the time and the lost profit; "security has probably never been better… but without proper configuration — maybe even go bankrupt". **Tools and artifacts:** antivirus, BYOD, DLP, EDR/XDR, SIEM, SOAR, SOC, DFIR, TI feeds, a cheat sheet (a slide), Dmitry Boroshchuk's Telegram channel, MK Enterprise (in the moderator's joke and in the question from the audience — so it was pronounced; the official name of the product is "MK Corporate"); from the Q&A — Nextcloud/ownCloud (a budget "controlled environment"), an access control system, 2FA, a backup checking system, hardening, "the Golden Rules book". **Legal and organizational context:** the speaker names no specific laws or agencies. Regulators and standards — repeatedly "basic levels of compliance", "if you're under regulators… no arguing with it" (with no names). Supply chain: regulations between companies — "these days that's not rare". The legal arena: a big company needs digital evidence, DFIR reports "are read by law enforcement" and make their visit faster. Internal to the organization: deployments agreed with all the departments, SOAR — "through negotiations and agreements"; personal data as an example for DLP (Federal Law 152-FZ is not named). **From the Q&A:** - *What should the less rich do (at the bare minimum "what you described comes to those same 5–10 million")? How much does hardening cost?* (the moderator) → Four areas: identification (2FA), perimeter control, a backup system with checking, control of users inside the perimeter; if there is no DLP/SIEM/EDR — the "forensics story" after the fact; the pentester Sasha Dmitriev: out of 200 pentests one company went by the "Golden Rules" (0.5%). The moderator: "hardening costs nothing" apart from the specialist's time; "can you guarantee that those basic methods will actually be followed?" → **"Alas"**. - *Why doesn't MKO "trade in fear" the way the Kaspersky representative does?* ("Igor Evgenievich"; the integrator has been deploying MK Corporate for ~3 years, nobody has dropped it, but the inflow of new clients is lower) → Scaring people is "bad form", "from a business-ethics standpoint… not good"; those who bought out of fear do not renew the license; the decision has to be a weighed one; "the time will come anyway when they'll have to turn to DFIR". **The speaker's position:** he positions himself as a security marketer against marketing tinsel; formally he was "really angry" at Boroshchuk's post, but in substance he agrees with it and closes on its thesis. The refrain — "count". Against selling through fear. He explicitly labels the estimates (90% antivirus, 30% DLP, 90% DFIR retrospection) as subjective. *Unclear: the attribution of the lines in the first Q&A is not marked up (who named the "four areas" — the speaker or the moderator); "Igor Evgenievich" — the recording map assumes Igor Zaitsev, not confirmed; "the Kaspersky representative" = Shulmin, but he did not speak directly before Vyugin; the talk has two different Dmitrys (Boroshchuk and Yankovoy); the figures are estimates by ear.* --- ### Maxim Sukhanov (CICADA8) — "The role of reverse engineering in understanding artifacts: when documentation is the enemy and the decompiler is a friend" Scheduled 13:45–14:15. A talk about what a forensic expert (and a DFIR specialist) should rely on when justifying the interpretation of an artifact: someone else's results (the vendor's documentation) or one's own experiment. The main idea — a vendor's documentation cannot be trusted blindly, it systematically diverges from the code for four different reasons. There were no questions from the audience. **Key points:** - Two approaches to justification: cite an article/book/documentation, or run an expert experiment. The documentation option is the one examined — "why that's a problem, not a solution". - Vendors "can deceive people" (in quotation marks, with no malice) — four reasons, each with a Windows case. - **Case 1 (NTFS):** in Microsoft's documentation for `$STANDARD_INFORMATION` and `$FILE_NAME` the timestamps are marked as reserved — blind trust yields the conclusion "there are no timestamps". The reason is a "valid" one: the vendor is protecting its internal structures "from so-called clumsy hands". "The maximum degree" of mismatch. - **Case 2 (shadow copies, VSS):** from Windows 8 on the copies are "scoped" — with ransomware running over the network the copies survive, but instead of user files they hold "a mess of zero bytes". By the documentation this should not happen. The **srtasks.exe** process walks the MFT and, by extension, excludes user files from copy-on-write (a granularity of 16 KB against a 4 KB cluster — part of the data does survive after all). Microsoft explained this to at least two customers in private; the keyword is **scoped**. On server versions of Windows there is no scoping. - **Case 3 (FAT):** the vendor documents an implementation other than the one it has — the FAT specification (used to format the EFI System Partition) was written from the code of Windows 95/98/ME, while the FAT driver in NT/XP/10/11 does not follow it; third-party drivers (Linux) are forced to modify the logic of the error check. - **Case 4 (Prefetch):** the internet takes the files "OP-…pf" to be "boot" files because of the out-of-date constant **PrefetcherBootControl** (=5) from old Windows SDK headers that found their way into **Process Hacker** on GitHub. In fact the file is created by calls to the **OperationStart/OperationEnd** API ("Operation Based Prefetching") and has nothing to do with booting. - The correct method is "the hardest route, straight from the code": searching for strings in the System32 binaries → debug symbols → a decompiler on the kernel (**ntoskrnl.exe**, the PfSn… functions, the PrefetcherInformationClass=5 parameter) → black-box testing (a Python wrapper around OperationStart/OperationEnd). - The regularities of Prefetch: the trace is created on OperationStart and ends on OperationEnd; within one process there is one trace; the threshold is 32 page faults. **Tools and artifacts:** Microsoft documentation (for developers), NTFS ($STANDARD_INFORMATION, $FILE_NAME), VSS/shadow copies ("scoped shadow copy", copy-on-write, 16 KB vs 4 KB), srtasks.exe, MFT, a hex editor, Chrome history, the FAT specification, EFI System Partition, Prefetch ("OP-/OB-…pf"), OperationStart/OperationEnd, the Microsoft blog about ASP.NET, ntoskrnl.exe (PfSnBeginScenario, PfSnEndProcessTrace, PfSnSetPrefetcherInformation, PfSnOperationProcess, PrefetcherInformationClass, PrefetcherBootControl), Windows debug symbols, a decompiler (not named), Process Hacker (GitHub), Python, home-made NTFS/registry parsers, professional Telegram chats. **Legal and organizational context:** no laws, articles, agencies or methodologies were mentioned. The procedural angle is in the framing of the problem: a forensic expert has to justify the interpretation of an artifact; the speaker disputes the view from the Telegram chats (~a year ago) that "I trust the documentation" is an acceptable justification. The organizational side: Microsoft explained the scoped shadow copy to customers in private and never reflected it publicly. Interaction with law enforcement was not discussed. **From the Q&A:** there were no questions from the audience — the moderator: "I think you've broken my audience again." **The speaker's position:** blind trust in documentation is a problem, not a solution; the justification has to be one's own experiment, and the best source of truth is the code. Skepticism toward any text by someone else, Microsoft blogs included. He is honest about the limitations: the $STANDARD_INFORMATION example is an extreme one; three of the four hypotheses about the OP files are "made up". The tone is purely technical, with a promise never once to say the word "business" (kept). *Unclear: the prefix of the prefetch files — "OP" in the transcript, "OB" in the recording map; the names of the kernel functions are by ear/from the slides; in the Russian original the phrase "no fewer than 32 requests… aren't saved" contradicts the sense (it should be "fewer than"); "Operation Based Prefetching" is called "Operation Recorder API" in the recording map; the name of the decompiler was never said.* --- ### Konstantin Titkov (Gazprombank) — "How not to end up needing forensics, and what to do if it can't be avoided" Scheduled 14:20–14:50 (the official page names no company; "Gazprombank" comes from MKO's wrap-up post). A managerial and organizational talk about what to do when the defenses have not worked and the infrastructure has been encrypted, stolen or wiped. The speaker heads the cybersecurity center for Gazprombank's subsidiaries and is an ambassador of Cyberdom; he presents response recommendations written with colleagues and published together with Cyberdom. It logically continues Vyugin's talk. **Key points:** - The main thesis: **a security incident is not an IT failure** (a deliberate, adaptive attack); the standard IT recovery plan does not work. The order: first kick the attacker out (all the persistence points, tunnels, web shells, accounts), then fix things — otherwise he destroys the backups that get connected and raises the ransom. - July 2025 cases (not named): a federal beverage producer + a retail chain, a pharmacy chain (customers lost), an airline (2 weeks on, fuel still calculated by hand from the statistics of past flights). - **Against paying the ransom**: the keys may not work; they may not be handed over at all "in the .ru zone"; the bank will refuse on anti-money-laundering/counter-terrorist-financing grounds; the payment may be classified as financing of terrorism. - Emergency actions: check and cancel the payment orders in online banking; do not power off and do not reboot (forensic data in memory); isolate the backup system and the backups; take snapshots of the VMs; examine the outbound traffic; consider network isolation. - A 24/7 mode; the roles of HR (overtime), PR (the regulator/customers/the press), IT (the source of recovery, contractors), security (the DFIR company); the logistics of the experts; leave cancelled; communications outside the affected infrastructure. - CII entities — "must first of all" report to GosSOPKA / an accredited center / the NKTsKI. - The stages from the **SANS** guide: preparation (logs, disks, BitLocker, licenses for "trophy" software), identification (the ladder TI feeds → SOC → managed EDR → your own EDR → IT monitoring → a Telegram channel), containment (do not reboot, disconnect from the LAN and from the SAN; the "particularly cunning" ones encrypt when the C2 is lost), cleanup (remove all the backdoors, restore the security tools, change **all** the passwords everywhere), recovery (3-2-1 with integrity checking; otherwise test environments or manual entry of the paper originals, ~2 weeks), the report. - **Compromise assessment** — "light DFIR" (logs + traffic → a probabilistic conclusion); the grounds — a **dwell time of 3–9 months** per vendors' reports. - Double extortion (a second ransom for deletion, the data being sold anyway); repeated "fake" leaks — a new permanent workload; notifying Roskomnadzor within 24 h and the report within 72 h; the NKTsKI (CII), FinCERT (the Central Bank). - Preparing in advance, "calmly, for free": printed-out phone numbers of employees and of their relatives, reserves of installation packages/licenses, protection of the backup system itself, a DFIR partner chosen in advance, command-and-staff exercises. **Tools and artifacts:** DFIR, compromise assessment, TI feeds, SOC/managed EDR/EDR/IT monitoring, EDR/antiviruses/firewalling, the SANS guide, the 3-2-1 scheme, the backup system (the anti-pattern — the backup system in a flat network/domain), BitLocker, VM snapshots, storage arrays/SAN/LAN, forensic data in RAM, logs, the attacker's artifacts (persistence points, tunnels, web shells, accounts), online banking, "trophy" software, rotation of all the passwords, outbound traffic, test environments, paper originals, GitHub (the anecdote about 6 backups), a Telegram channel, the recommendations with Cyberdom (a QR code). **Legal and organizational context:** CII → GosSOPKA/the NKTsKI; law enforcement → the complaint materials + the DFIR report → the crime report register (KUSP) → a possible seizure → a criminal case → a certificate recognizing the company as the victim (needed, for instance, to explain the failure to file financial statements on time); the ransom and anti-money-laundering/counter-terrorist-financing rules / financing of terrorism; personal data — Roskomnadzor within 24 h / the report within 72 h (per the speaker, "including about a fake leak", with no legal instrument cited); FinCERT; GDPR ("maybe someone also complies with GDPR, I don't know"); the goals of the investigation (to prosecute vs. to avoid publicity); the CEO's role. **From the Q&A:** - *Which is there more of — cases where the encryption has already happened, or cases where the attack was spotted while it was still being prepared?* → The question is better put to those who get called in to do DFIR; there is **"survivorship bias"** — the businesses that did not recover "don't come to these conferences"; the task is to prepare so as to recover fast; start by printing out whatever will be unrecoverable after the encryption. There were no other questions. **The speaker's position:** the order "kick out → clean up → recover" is not open to discussion; he criticizes panic, changing the passwords before the cleanup, connecting the backups to the infected network; he bets on cheap preparation. Realistic caveats: DFIR lasts days even when you have prepared; remote DFIR works only when there are competent hands on site; the 72 h for the report do not match the timeline of a real investigation. Trends: a shift of attacks to Thursday, a dwell time of 3–9 months, "a second ransom", endless repeated fake leaks. *Unclear: the companies in the July 2025 cases and the source of the news about the airline are not named; the Roskomnadzor notification deadlines are per the speaker, with no legal provision cited; "6 billion people" and "the story with GitHub" are from memory; a number of phrases were garbled by Whisper.* --- ### Nikita Pavlov (Zero eDiscovery) — "The role of the user interface in digital investigations: how UI convenience and intuitiveness speed up data analysis and search" Scheduled 15:35–16:05. The talk is not about forensic artifacts but about designing the interfaces of investigation tools: the co-founder and UI/UX designer of the Zero eDiscovery platform explains why "design" means engineering and not decoration, and how an overloaded interface slows down data analysis. It is addressed to law enforcement officers and forensic examiners who work in somebody else's (vendor) systems. **Key points:** - "Design" in the English sense means engineering, not "decoration"; most interfaces are built by "people who aren't specialists" with no school of design, "everything is piled into one heap". - **Hick's law**: "the more choices, the longer the decision"; in Word/Excel people use "at most 6 or 7 functions". - UI/UX is "not about beauty" (the analogy with military hardware — it is beautiful because nothing is superfluous); user experience ≈ the ergonomics of physical objects, user interface is the software implementation; the goal of both is productivity. - **A cognitive load of 7±2** objects at a time; the search-engine example: the minimalist Google versus the overloaded Mail.ru search ("never changed at all since 2005 or so"); now "everyone already works in Yandex". - **Gestalt principles**: proximity (related elements next to each other), similarity (color/shape), closure (skipped), common fate ("this button was here the last time I was here"; the counterexample is the 2018–2020 redesign of Google Workspace, users "were lost"), figure-ground. - A practical example: incident logs — "a wall of white lines on black", and by the hundredth line the brain is overloaded; indexing and a search by "concrete points" would cut the work "by tens, if not hundreds of times". - Color highlighting by rules: red means alerts, green is good, orange "needs attention"; a hierarchy of components speeds up perception (the analogy — the sheet of paper you need is put on top). - **A checklist of requirements for the vendor**: (a) unified search; (b) templates and dashboards (customization to fit the tasks); (c) visualization of relationships (affiliated persons, corruption schemes); (d) hotkeys (the Alt shortcuts in Excel); (e) unambiguous button colors (red means delete, green means create, blue means neutral); (f) feedback from the system ("it at least showed a spinner"). - The main call: "formulate and voice your requirements for the interfaces" and "not to put up with" bad interfaces. **Tools and artifacts:** Zero eDiscovery (the speaker's platform; "Zero and Discovery" in the raw Russian transcript), Word/Excel (overload + the Alt shortcuts), Yandex/VK products, Google (minimalism), the Mail.ru search (a counterexample), Yandex (search), Google Workspace (a counterexample of "common fate"), an email client, logs/tabular data (indexing, highlighting), dashboards/templates/relationship graphs, hotkeys; concepts — Hick's law, 7±2, the Gestalt principles, ergonomics; "STS"/technical means of customs control (the phrase is garbled); from the Q&A — the overloaded interface of Drozd's product, configurable filters/columns, "an end-to-end identifier for a piece of intercepted data". **Legal and organizational context:** no laws, articles, agencies or methodologies are mentioned. Organizational: the target audience is law enforcement, forensics, computer forensics; the "user — vendor" model (formulate the requirements, "do not put up with" it); Drozd's counterposition — the developer will adapt only to a client "with tens of millions a year in support fees"; collaborative use of systems (different views among colleagues break communication) — an argument for uniformity of UX. **From the Q&A:** - **Alexey** (by context — Drozd, SearchInform): the checklist has no "customization" item; what matters more is being able to arrange filters and columns in your own order ("in 99% of cases some four main columns are enough for me"); for a client that is not large the developer "is unlikely to adapt". → Pavlov: the "templates and dashboards" item is exactly about this, but he does not champion customization as an idea — UX should be "close to uniform" (the example of "look at the second column" from a colleague with a different setup); in collaborative products you must be "very careful". Drozd: the problem is solved by an end-to-end ID of a piece of data, over a single incident "there aren't 10 people poring… at once"; the argument was postponed. **The speaker's position:** design = engineering; UI/UX is not about beauty, aesthetics are secondary; overloaded interfaces are a systemic problem of products built by "people who aren't specialists". He puts the user in the position of the customer. He partly concedes to Drozd ("a very valid, very fair remark"), but insists on uniformity for the sake of collaboration. He himself calls the slide with the example "a lot of text here and little meaning". *Unclear: the questioner is named by first name only, the identification with Drozd is by the recording map and by context; the closure principle was not covered; figure-ground is reduced to "similarity and proximity, just… deeper"; the quantitative estimates ("by tens or hundreds of times", "6–7 functions", "by the hundredth line") are guesses; the phrase about "STS"/customs is garbled; the dates (Workspace ~2018/2020, Mail ~2005) are approximate.* --- ### Alexey Drozd (SearchInform) — "Using steganography in various channels to identify the source of a data leak" Scheduled 16:10–16:40. A talk by a DLP vendor on why a security officer needs steganography: not as a way for an insider to exfiltrate data (insiders bypass DLP with a primitive substitution of characters that regexes fail to catch), but as "straw" laid down in advance so that after a leak — within those very 24/72 hours — the circle of suspects can be narrowed. Addressed to information security practitioners fighting leaks and to vendors thinking about document labeling. **Key points:** - Insiders do gravitate toward real steganography but use it rarely (you can't install just any software, an engine of your own is "not for average minds"); they get no further than `copy /b` and file concatenation. - They prefer "cryptography" in the sense of primitive encoding: the banal example — use Ctrl+F to replace the digit "5" with the word "five", and personal data stops being caught by regular expressions. "100500 ways" that not a single DLP will see through without neural nets. - Why a security officer needs steganography — to "lay down some straw": to find the point to dig from, to "narrow the circle a bit" on the "incident lifeline" (the methodology of last year's talk). - **Approach No. 1 — "information-system-based"** (data-centric security): every action is intercepted together with its attributes (content + who was CC'd, attachments, IP, MAC); better to draw a graph than a table (a fan-out mailing = a "bush"). Integration at the driver level (**DCAP**) is needed. The agent is "very good on Windows, almost as good on various Unix-likes, not very good yet on macOS, and practically useless if we're dealing with cloud logic". - Cloud editors: a keylogger yields "gibberish" when the editing is non-linear, HTTPS interception — only state deltas ("PL", "AN"); the whole document — only via **API** (Google Workspace, VK, Yandex 360, M365/Graph API), but "you can't integrate with everyone out there". - **Approach No. 2 — "user-session-based"**: watermarks on all monitors at the driver level (against photographing the screen); they show up on a screenshot (the username, the machine name, date, time). An example from "colleagues in the trade" — **EveryTag**: a unique copy of a document thanks to shifts in line spacing, paragraph indents and margins → a hash is extracted from a photo or printout → the user. - **Four unsolved problems**: (1) formats (with audio, "what do you do there? Unclear"); (2) architecture (a unique copy for every user — client-server logic); (3) detecting the marks — the "Achilles' heel": an overexposed photo kills the watermark; (4) retyping the document by hand — "What do you do? Nothing". - The third approach — labels in the file plus encryption (the logic of **Microsoft RMS**): a file leaves the perimeter only in encrypted form, and if it reached the wrong recipient it cannot be used; this is the **ABAC** model, onto which encryption is "bolted" — "reinventing that Microsoft RMS which once existed, and it turns out there's demand for it again now". - An analogy — the watermarks of deepfake generators in the audio spectrum, which detectors "detect well". - The bottom line: steganography is "not such a scary thing", but "just a supplement", not a panacea; the best incident is the one that never happened, and the insider is to be caught "on takeoff". **Tools and artifacts:** DLP (the product is not named), regular expressions, LLMs/neural nets (the market expects them), `copy /b`, Ctrl+F, data-centric security, a connection graph, DCAP, a DLP agent, a keylogger, HTTPS interception, API integrations (Google Workspace, VK, Yandex 360, M365/Graph API), VDI, watermarks on monitors, Print Screen/photo/printout, EveryTag, labels on the file's address / in the metadata, Microsoft RMS, ABAC, the watermarks of deepfake generators; from the Q&A — Canarytokens / the "zero pixel" / IP logger (criticized), audio watermarks (since the 90s). **Legal and organizational context:** "24 hours to respond, 72 hours to report something to someone" are named as common knowledge, with no reference to a law or a regulator (apparently the deadlines for personal data leaks; this is not spelled out in the transcript); Federal Law 152-FZ and Roskomnadzor were not mentioned. The methodological frame is the "incident lifeline" with its "point of no return". Industry self-regulation — a "global agreement" among the makers of deepfake software (the participants are not named). Interaction with law enforcement, articles of the Criminal Code or the Code of Administrative Offenses, forensic methodologies — were not mentioned at all (the talk is about corporate information security, not about forensic examination). **From the Q&A:** - *(an addition)* Watermarks for audio have existed "almost since the 90s". The speaker did not answer it separately. - *What is your view of Canarytokens / the "zero pixel"?* → Negative: an active beacon "phones home to some service like an IP logger" when the file is opened and gives the security officer away; use it "wisely", and the feature must be one you can switch off. **The speaker's position:** a demonstrative refusal to sell ("I didn't come here to sell you some of our elephants"), an open listing of weaknesses, his own solutions included (the agent on macOS and in the cloud, watermarks dying from overexposure). Skepticism toward a universal solution — different channels require different things, and anything "universal" exists only at the level of labels plus encryption (RMS in essence). Prevention comes first; he explicitly invites counterarguments. *Unclear: the Russian original says "nontransparent" — by the sense, "transparent"; the "global agreement" is probably a worldwide or industry-wide one; the 24/72-hour deadlines — the norm and the regulator are not named; which VK service is meant is not specified; the content of the slides (the DCAP and EveryTag screenshots) is not described; what kind of hash it is and how it is matched is not covered.* --- ### Oleg Bezik (Digital Research Laboratory) — "Automated government systems under the forensic computer expert's microscope: problems and solutions" Scheduled 16:45–17:15. A talk on forensic computer examinations (SKTE) of custom-built automated systems, primarily government ones (Gosuslugi, GAS "Pravosudie", GAS "Legal Statistics"), appointed in disputes over development contracts worth from 150 million to several billion rubles. The speaker is the founder and CEO of the Digital Research Laboratory, a forensic expert since 2014. The second half of the segment is a tough discussion with a former employee of the EKC MVD. **Key points:** - An automated system is a hardware and software complex; government automated systems automate a function of a government body (GAS "Pravosudie" — court proceedings, GAS "Legal Statistics" — the work of prosecutors). Development runs on a state contract; "very often relationships like that end badly". - Contract values of 150 million – several billion rubles; disputes go to the commercial (arbitrazh) courts, "sometimes it even gets to criminal cases"; an SKTE is appointed "99% of the time, even 99.99%" (judges do not understand the development of complex automated systems). - Appraisers are brought in (the cost of the work done properly, or of "finishing the system"); the examination becomes multidisciplinary. The speaker notes three times: "I'm not an appraiser". - The goals of the examination ("We think like a judge"): does the software meet the ToR; if not — what does not work and why; are there critical defects; the cost of what was done and of the rework. - The court's standard questions: compliance with the requirements of the contract / the ToR / the detailed ToR; the cost of what was actually done; critical defects; whether they are remediable; the value of the work of inadequate quality. - A critical defect is "all the functions are implemented, the buttons are blinking (like Nikita was telling us, everything's green and red), but the one report that matters most … doesn't get generated" → "a pretty toy that costs a lot of money". An irremediable defect is one whose fixing is impossible or pointless ("another contract just like this one, for another billion rubles"). - **Pain point No. 1**: agreed, publicly available methodologies for examining automated systems "simply don't exist"; their own algorithm (a database of the objects → checking that the deliverables are complete → checking compliance with the ToR) is not packaged. Every automated system is a "unique palace", hence the valuation problem too ("one developer can do it for 100 thousand, … a third for a billion"). - **Pain point No. 2**: the enormous volume of objects — boxes of paper documentation (the ToR, the detailed ToRs, manuals, explanatory notes), source code on flash drives and discs, "millions of lines of code". The current case — **1,041 requirements**; the forensic experts are "testers of sorts". - Timeframes of 1–2 years, "really expensive", a panel of 3–4 people travels to the customer's office; the record is 9 people in the room (2 forensic experts + 7 representatives, "argued, quarrelled, told each other to go to hell"). - Cost estimation — the **Moscow DIT** and **COCOMO** methodologies (by quantitative indicators, lines of code); the "classic" scheme "it cost 100 million, 87 percent was done → 87 million" is one he often comes across. - Tips: take stock of the objects at hand (documentation, source code, the deployed system + contracts); prepare the questions for the expert in advance; hire only professional forensic experts; a PDF checklist at the link. **Tools and artifacts:** Gosuslugi, GAS "Pravosudie", GAS "Legal Statistics", the Moscow DIT methodology, COCOMO, their own source code comparison software (since 2025, unnamed), their own examination algorithm, a checklist memo (PDF), PMI (test programme and procedure), the objects (the ToR, the detailed ToRs, manuals, source code on flash drives and discs, the deployed system); from the discussion — SAP, banking systems, the handheld terminal, Microsoft Windows, aircraft simulators, the state information system of Rosreestr (acceptance under Federal Law 44-FZ with code hashes, load tests). **Legal and organizational context:** forensic examination as a way of bringing specialized knowledge into court proceedings; an SKTE, a multidisciplinary and a valuation examination; the commercial (arbitrazh) courts, sometimes "criminal cases"; the questions are put by the court (the expert does not set them — a disputed point: the EKC holds that one may file a motion to change them, Bezik — "I've never come across that"); the parties have the right to be present; payment — "The court pays us, not a party"; the contract documents (the ToR, the detailed ToR, the PMI, acceptance); Federal Law 44-FZ (Barannikov — acceptance of the state information system of Rosreestr, code with hashes); the absence of agreed methodologies; the institutional position of the EKC (the expert checks discrepancies rather than testing the whole system); Interpolitex, Muzalevsky (RTM Group, per the recording map), R&D. **From the Q&A / discussion:** - **A former employee of the EKC MVD**: "don't take on all the testing. That's a road to nowhere"; at the EKC they moved away from testing (SAP, banking systems); the expert's job is to check the specific discrepancies; complex subject areas (Windows, banking software, simulators) cannot be assessed without specialists in the field; **a percentage based on the number of requirements is incorrect without the weight of the modules**; one should file a motion to reformulate the questions and save money (200–500 thousand instead of 5 million). → Bezik: the examination follows the court's questions as they are put; this is about systems built "from scratch" with a detailed ToR and a test programme and procedure (GAS "Legal Statistics"); changing the questions is not his business. - **Sergey Barannikov** (a forensic expert): examinations like these arise under Federal Law 44-FZ; the customer brings experts in at acceptance (documentation, code with hashes, load tests) so as not to "go to prison for accepting God knows what". → "Congratulations on having taken part in work like that". - **Andrey**: are the cost questions handled in a multidisciplinary format with economists, or in-house by IT experts? → Mostly in a multidisciplinary format; for valuation what is needed is specifically an appraiser, "not an economist as such". - *Unnamed*: what formulas to use to cost a "super-high-quality" development — "there's no formula"; what happens to the system during a dispute that drags on for years → there is no answer in the recording. **The speaker's position:** the examination answers the court's questions as they are put; custom-built systems with a detailed ToR and a test programme and procedure can be checked in full; he dismisses the SAP/Windows argument as being about off-the-shelf products. He honestly names the limits ("I'm not an appraiser") and the weak points (the methodology is not packaged, the forensic experts work as testers, the examinations are long and expensive). The end of the argument: "I think we're speaking different languages". *Unclear: the transcript does not label the speakers in the discussion (the remarks are attributed by context); the second question from the audience is heavily garbled by Whisper (in the Russian original "postavlena na voyenny uchet"); it is not clear from the recording whether Bezik's team calculates the percentage by the number of requirements; "Denis Aleksandrovich" and "Volokitin" were not identified; "milestones"/"function points" is a distortion in the Russian original; "Bauman MVTU" — probably from a slide.* --- ### Mikhail Inkin (STC, Speech Technology Center) — "From audio and video data to evidence: AI analytics, biometrics, and spoofing and deepfake detection" The closing talk of the conference (scheduled 17:20–17:50; STC was a partner). The head of a project group at STC shows how the company's products cover the chain "a bulk set of raw audio → search and analytics → forensic phonoscopic examination → minutes of the proceedings". A vendor presentation with demos; the Q&A turned out more substantive than the talk itself. **Key points:** - STC has been on the market for 35+ years, with 5000+ projects; its algorithms take part in **NIST** and the **CHiME Challenge**; it has LLM expertise (GigaChat, freely available models, tuning for the customer). - Voice biometrics — automated and manual methods; the systems are **language-independent and text-independent**; the principle that "the conclusions of any automatic system need expert confirmation". 70+ parts of the body are involved in producing the voice; phonoscopy has been a forensic examination for 30+ years. - Three products: **AVIS** (search and analytics), **IKAR Lab** (for forensic examination, once "IKAR Lab 3"), **Nestor AI** (minutes). - **AVIS**: automatically extracts gender, language, recognized text (18 languages — Russian, CIS, Arabic and others), biometric search, translation, cluster and statistical analysis, graphs of links and topics, keyword search highlighted on the waveform; LLM digests of the bulk set, summarization of a conversation, detection of code words and slang. - **IKAR Lab**: assessing whether a recording is usable, noise cleaning, extracting the text, speaker separation, identification (auditory / acoustic / phonetic / spectrographic / automatic), searching for editing. **The spoofing detector**: an overall score + a second-by-second one over a sliding window (they forge part of the recording). New versions identify the **synthesis vendor** — "99.6% ElevenLabs" in the demo, 4 vendors today. - Detecting synthesis is non-trivial: the algorithms "are advancing by leaps and bounds", "dozens or maybe even hundreds" of new ones a year; in forensics the question is posed more broadly — the **authenticity of the recording** (classical methods: analysis of phase, background noise, resampling, DC offset). - The history of synthesis: a mechanical "yes"/"no" of the late nineteenth century → "the first mass-market device" of 1979 → 2000s synthesis (no emotion or breathing) → a synthesized voice of Biden in the US campaign of 2024 ("smear campaigning"). Synthesis copies breathing, pauses, intonation. - A fraud demo (a playback): "…got into an accident on the M4 highway… A Beemer slammed into me… I urgently need money" — a synthesized voice; "most listeners can't tell a synthesized voice from the voice of a real person". - Multimodality (video): a puzzle for the room (Jessica Alba — a real person vs. synthesis), the vote "roughly even". **The video deepfake detection module**: a frame-by-frame probability, a mask of "the neural network's attention" (it does not mean the area is fake), the "in-tolerance probability" (frames with excessive head turns); 97% on the fake. - **Nestor AI**: minutes of official sessions, streaming audio and files (Zoom, a dictaphone), a "strictly formatted record" split by speaker, their number and gender, LLM abstracts, an AI agent with tunable prompts. **Tools and artifacts:** AVIS, IKAR Lab (ElevenLabs 99.6% in the demo; the video deepfake module 97%; classical modules — phase, resampling, background noise, DC offset; manual documenting of the features; manual transcription), Nestor AI, GigaChat, freely available LLMs, NIST, CHiME Challenge, ElevenLabs, Multi-Tacotron (named by a questioner), Zoom, server GPUs, their own speech-to-text models; video deepfake techniques (face swap, puppet-master, lip-sync, synthesis of facial elements, a face mask, real-time face swap, a photo being "animated"); ultrasonic microphone jammers ("a myth"). **Legal and organizational context:** the speaker named no laws, articles of law or agencies. Phonoscopic examination has been a type of forensic examination for 30+ years in Russia and abroad; the principle that "the conclusions of the automated system need expert confirmation", manual modules so the features can go into the expert report. The data sources — lawful interception of telephony, microphone recordings, seized devices (collection is out of scope). The division: AVIS — search, IKAR Lab — evidence. Identifying the synthesis vendor — as circumstantial evidence (the link to a site the suspect visited). Deployment — always in the customers' closed networks, on-prem, offline, role-based access. Nestor AI — a "strictly formatted record" of official sessions. **From the Q&A:** - *Which video deepfake techniques are detected?* → He has not tested synthesis of facial elements himself; face masks and real-time face swap — yes; lip-sync / a photo being "animated" — 98% on STC's own datasets, for other data "you have to look, test on the data". - *Why identify the vendor if underneath it is Multi-Tacotron anyway?* → Additional circumstantial evidence (the link between the suspect and a site). - *Prompt injection through audio (an inaudible "system prompt")?* → Unlikely, "the customer is interested in the data being clean"; the usual request is to fine-tune for a narrow group's slang. - *Protecting the product against leaks (it can be seen as a weapon)?* → A closed network, on-prem, role-based access. - *How effective is noise cleaning when the microphone is jammed with ultrasound?* → Such jammers against good microphones are "something of a myth"; the lower the SNR, the lower the accuracy of the automation (compensated for by manual and linguistic methods). - *The delivery model for Nestor?* → A hardware and software system: microphones + software, or software alone. - *Transcription speed?* → Depends on the hardware; on server GPUs the speed-up is "a thousand or even tens of thousands of times" (roughly 1000 sec of speech in 1 sec). - *Who needs forensic examinations in other languages?* → Manual transcription by a native speaker; IKAR Lab is exported to a number of countries. **The speaker's position:** the tone of a vendor presentation; the concrete metrics come only from the demos (99.6%, 97%, 98%), and no external or independent assessments and no conditions (the datasets, the thresholds) were given. On principle: the automation does not replace the expert, the classical methods "live on". The trend: synthesis is indistinguishable by ear and the number of algorithms is growing — synthesis detectors are unreliable, the question to pose is authenticity. Honest caveats (he has not tested synthesis of facial elements, the 98% is on his own datasets, as the SNR drops the accuracy drops). *Unclear: the sentence is self-contradictory (probably "mask" instead of "detect"); the Russian original's "sesomo-avtomaticheskom" is garbled; of the 4 vendors only ElevenLabs is named; the "in-tolerance probability" — whether such frames are excluded is not clear; the question about prompt injection is answered in terms of the customer's interests, not those of an attacker who controls the recording; the playbacks (synthesis of 1979, 2000s, Biden, the Alba video) are not transcribed in the file; the questioners are not named, and the patronymic of "Olga" varies (Alexandrovna / Svetlanovna).* --- ### Conference closing A lead-in by moderator Dmitry Yankovoy ("the way we opened is probably how we should close") and an invitation to the stage for Olga Gutman (MKO Systems; "Olga Vasilyevna" — by ear). Gutman's speeches at the opening and at the closing are her only appearances in the recording; her position is not named in the transcripts. The closing block is extremely short and ceremonial. **Key points:** - "Well, these two days have flown by"; Gutman: "it was incredibly interesting to listen to all the speakers". - Thanks for attending in person and online; the statistics: "we set some truly incredible records for live-stream viewership. All the detailed figures will be available later in our post-event release" — **not a single number** (not views, not attendees, not speakers) was spoken. - Thanks addressed by name: to the speakers ("for the most interesting talks"), to the partners ("for co-organizing"), to the organizing team (called up on stage, the photographer singled out), a group photo. - "A big omission": the product development teams had never been thanked — "You didn't see the roast yesterday, but believe me, so many kind words of gratitude were said for creating our product… We bow deeply to you" — the only evidence in the recording of what the "roast" contained. - "With that, the Moscow Forensics Day 2025 conference is declared closed". - Announcements ("we're not saying goodbye for the rest of this half-year", the dates read out with the prompt "Lera here is actively prompting me"): **Saint Petersburg — October 7** (no title or format named), **Astana — September 24** ("a partner event"), **Novosibirsk — October 2** ("the Legal Week"); a year from now — the anniversary conference (no date, no venue). - The end of the recording: "Once again, thank you very much for your attention over these two days. It was awesome! Goodbye!". **Stance and tone:** warm, grateful rhetoric with no figures and no substantive assessment of the talks ("the most interesting, useful, the most important"); not a single critical or problematic statement about the industry, the conference or the products. Prize draws, gifts and prizes are not mentioned at the closing (per the program the draw took place on day 1 after the stream was switched off). *Unclear: the patronymic "Vasilyevna" and Gutman's position are not confirmed in the recording; "records" is an evaluative word with no figures; "Lera" is Valeria Vakhrushina per the recording map (a conjecture); the Saint Petersburg announcement is syntactically garbled (no title, no format, no organizer named).* --- ## 3. Cross-cutting themes 1. **Password cracking: physics against the expert, a dictionary against "a mask head-on".** The theme tied together three talks of day 1. **Vakhrushina** reduced any cracking to two methods — a dictionary or a mask — showed that "a mask head-on" cannot be used (a 10-character password: 141 trillion / 3 quadrillion / a quintillion combinations), and demonstrated it on a ZIP archive: a full mask — 7.5 hours, a partial one (3 random characters + 4 fixed digits) — the password MFD2025 in 11 seconds. **Chikin** explained why cracking phone passwords is almost hopeless: the main algorithm is memory-dependent scrypt (Android FBE 2048.8.1 = 2 MB per core, the older FDE = 32 MB per core), the wall is the DDR5 memory controller, ASICs are no use; the result — ~20,000 passwords/s, an 8-character password = "10 thousand years". **Shavlovsky** showed the same arithmetic on macOS: salted PBKDF2-SHA512 is an order of magnitude stronger than the Windows NT hash (MD4, unsalted), hashcat mode 7100, plain brute force "can run into years". The overall conclusion — brute force is a lost cause, only meaningful dictionaries work, and MK Brute Force/hashcat 7.0 and dictionaries built from personal data only lower the threshold. 2. **Import substitution, the Russian software registry and its flip side.** **Greshnov (ELETEK)** puts the emphasis on viewing E01 on Astra Linux; **Eremin (LAN PROJECT)** links the entry of VR-Expert into the Russian software registry (2025) directly to easier government procurement — and in the same breath honestly rounds out the delivery with foreign software (SalvationData, MD-VIDEO/GMDSOFT) and ACE Lab equipment, while describing unsharp masking as the mechanism carried over from Amped FIVE into VD-Expert. **MKO Systems** builds the whole stack (MK, MK Brute Force on hashcat). Sanctions run in the background: for Eremin supplies of foreign software are "difficult", and DVR Examiner is compared in "the version … available in Russia". Import substitution here is pragmatic, not ideological. 3. **Phone and banking fraud: NFC, RAT trojans, Telegram as the delivery channel.** **Moskvichev** went through NFC thefts (NFCGate/N-Gate out of a teaching project at TU Darmstadt, the related SuperCard X and GhostTap with "Chinese people behind" them), the classic and the reverse scheme ("into a safe account"), a case of 230 thousand RUB (a Redmi Note 11S, the `vtb1` trojan from Telegram, a manifest with the appName "VTB Protection"); the statistics — growth ×35 in 2025, ~400 cases in Russia, an average amount of ~100 thousand RUB. **Kotova** showed SpyNote (a RAT for Android, in Kaspersky's top-10 verdicts, the v6.4 builder that leaked in 2022), where the APK is delivered through a messenger. **Barkalov** and **Titkov** mentioned the same social engineering schemes (a "safe account", panic). Telegram is the channel running through all of it: APK delivery, a social engineering message "on behalf of the head of the Interior Ministry institute", extortion. 4. **Do not trust blindly: neither the tool nor the vendor's documentation.** **Sukhanov (CICADA8)** is the central voice: Microsoft's documentation systematically diverges from the code (NTFS timestamps marked "reserved"; "scoped" shadow copies from Windows 8 on → zeros instead of user files after a ransomware attack; the FAT specification written from the Windows 95 code; the prefetch "OP-…pf" from the out-of-date constant PrefetcherBootControl=5), and the right path is "straight from the code", through a decompiler of ntoskrnl.exe and a black box. **Shavlovsky**: an unnamed tool lost part of the hash during a conversion — "software tools can make mistakes, that is, their code may contain bugs". **Inkin**: "the conclusions of any automatic system need expert confirmation". **Eremin**: initializing a recorder's disk in Windows 10/11 overwrites about 40 MB and destroys the video stream table. 5. **AI and neural networks: from an outright ban to industrial use.** **Vakhrushina**: "building artificial intelligence into Mobile Criminalist is prohibited. The legislation would object" — justified through the policy of not returning data to the vendor. **Eremin**: an AI module on PyTorch (object detection, license plates, a 30-minute video in 3 minutes on a GPU). **Inkin**: LLM summaries of a body of audio (AVIS), deepfake detection (97%), identification of the synthesis vendor (ElevenLabs 99.6%), GigaChat. **Barkalov** sees degradation: a lawyer brought in questions for a forensic examination generated by "Alice". **Drozd**: the market expects LLMs to "solve" the primitive bypassing of DLP. The common denominator — reproducibility and admissibility matter more than "magic". 6. **OSINT: a method, a surveillance tool and the subject of a clash of worldviews.** **Bederov** spoke entirely about the method of deanonymizing sites (WHOIS and its archives against GDPR, bypassing Cloudflare, Yandex.Metrica, acquiring services, file metadata, petitions), a portable OSINT browser built on Opera with more than 2,000 sources. **Barkalov** spoke about how "OSINT isn't what it used to be": if there is intelligence, there is counterintelligence too (disinformation, "brainwashing the population through open sources"), the frame being the Information Security Doctrine of the Russian Federation. Their argument (day 2) was left unresolved: Bederov insisted that OSINT is a methodology for verifying open, lawful and re-checkable information fit to serve as evidence; Barkalov — that well-crafted disinformation cannot be verified. The moderator moved the argument to a day "purely for lawyers". 7. **The procedural rigor of forensic examination: methodologies, questions, the limits of authority.** **Tushkanova (GUK SK)** presented the standard methodology of the Investigative Committee of Russia of 2025 (an evolution from the FSKN's 2011 one marked FOUO → EKC MVD 2014/2023): functional requirements for the hardware-software system, motions for the password/PIN/PUK and for the user's presence for biometrics, writing to rewritable media with a cryptographic hash, and cloud tokens once found mean not "got into the email account, downloaded all they needed" but notifying the investigator immediately. **Shavlovsky** limits himself by Art. 57 (not to destroy the object without the permission of the party that ordered the examination). **Kotova**: the only correct wording of the question is "the presence of files detected by antivirus software". **Bezik** took the theme to its limit: forensic computer examinations (SKTE) of government systems against the ToR / detailed ToR and the test program and procedure, the court puts the questions and the court pays. Federal Law 73-FZ comes up in Tushkanova's talk and in the debates. 8. **Incident response, the "maturity" of information security and the price of tools.** **Vyugin (MKO)** went through the whole line-up (antivirus, DLP, EDR/XDR, SIEM, SOAR, SOC, DFIR) with the refrain "you need to count… don't fall for bare advertising"; the criteria are reasonableness (consulting all the departments) and maturity (not "to buy any tools for millions upon millions" but to understand what for); DLP cuts "up to 30% of data leaks", not the "90–100 in the marketing brochures". **Titkov (Gazprombank)**: a security incident ≠ an IT failure, first kick the attacker out, then fix things; the ransom must not be paid (the keys will not work, anti-money-laundering and counter-terrorist-financing rules, the risk of "financing of terrorism"); the stages per SANS, a dwell time of 3–9 months, compromise assessment as a "light version of DFIR". In the argument with the moderator it was said that hardening "costs nothing" apart from the specialist's time, and the pentester Dmitriev had seen the "Golden Rules" followed at 1 company out of 200. 9. **Targeted attacks and "living off legitimate utilities" (LotL).** **Shulmin (Kaspersky, GReAT)** went through Librarian Likho: the whole chain on batch files and legitimate utilities (RAR 3.8 with the strings wiped, blat.exe, AnyDesk under the name svchost, Defender Control, powercfg, schtasks, reg.exe → SAM/SYSTEM, XMRig), with no binary implants, a night mode of 01:00–05:00 (the tasks "WakeUpAndLaunchEdge"/"shutdown at 5 a.m."); spear phishing delivers 90–95% of the threats. **Azersky (F6)** showed the same logic for UWP/MSIX: malicious packages with a stolen signature (and in Windows 11 unsigned ones), the 2023 campaigns through ms-appinstaller, FIN7 with PSF, and a "legitimate" toolkit from the Microsoft Store with no admin rights through winget (Python/Julia → a reverse shell, ngrok/localtunnel, a VS Code tunnel). Both agree: what has to be detected is the illegitimate use of the legitimate. 10. **Insiders, leaks and protecting data "from the source".** **Drozd (SearchInform)**: insiders bypass DLP not with steganography but with a primitive substitution of characters (5 → the word "five" spelled out in Russian) that regexes do not catch; steganography is what the security officer needs after a leak (24/72 hours) in order to narrow the circle — watermarks on monitors, unique copies (EveryTag), labels + encryption (ABAC, "reinventing that Microsoft RMS"). **Barkalov**: "the main threat is the insider threat, it's the human being"; the case of an insider with flash drives. **Vyugin**: DLP as control over the leak channels. Drozd's overall conclusion — "the best incident is the one that never happened", catch them at the stage of intent. 11. **The scale of the data and the role of the interface: how not to drown in the volume.** **Pavlov (Zero eDiscovery)** argued that an overloaded UI directly slows the analysis down (Hick's law, a cognitive load of 7±2, Gestalt principles); indexing and color highlighting of logs 10 thousand lines long speed the work up "by tens, if not hundreds of times". **Eremin**: carving a terabyte disk takes about 3 weeks, the AI module compresses a 30-minute video down to 3 minutes. **Inkin**: LLM summaries of bodies of audio instead of listening to all of it. **Bezik**: millions of lines of code, "boxes of paper", 1,041 requirements in a single examination, a panel of 3–4 experts, timelines of 1–2 years. 12. **Video, audio, biometrics and deepfakes as a new evidentiary modality.** **Eremin** — the forensics of DVRs (proprietary file systems, cracking Dozor passwords, AI detection of objects and license plates). **Inkin** — phonoscopy (waveform/spectrogram/cepstrogram, formants, the fundamental frequency), spoofing detection with a sliding window and identification of the synthesis vendor, a module for detecting video deepfakes; voice synthesis has become a mass threat ("most listeners actually can't tell a synthesized voice from the voice of a real person", the case of Biden's voice in 2024, the Jessica Alba deepfake). Both themes come down to one principle — the classical methods and manual documenting of the features supplement the automation. 13. **Anti-forensics, the destruction of data and the shift from encryption to wiping.** **Chikin**: changing the phone's state erases the key, with the risk of a wipe if the wrong actions are taken. **Titkov**: attackers delete the backups that get connected, a dwell time of 3–9 months, "wiping is what is going on now", the data is destroyed deliberately; the vulnerable architecture of the backup system in a flat network. **Sukhanov**: after a ransomware attack the shadow copies that survive (Windows 8 and later) hold "a mess of zero bytes". **Greshnov**: documents disguised by a swapped extension, the countermeasure being acquisition by signatures. A verifiable copy with checksums and a cryptographic hash in the expert report (Tushkanova, Greshnov) is the cross-cutting answer to the threat to integrity. --- ## 4. Indexes ### 4.1 Technologies, tools, artifacts *Alphabetical; in parentheses — the talk(s); then — as mentioned. The talks are abbreviated by surname: Greshnov, Vakhrushina, Chikin, Tushkanova, Moskvichev, Eremin, Kotova, Shavlovsky, Bederov, Barkalov, Shulmin, Azersky, Vyugin, Sukhanov, Titkov, Pavlov, Drozd, Bezik, Inkin.* - **4t Tray Minimizer / 4t-niagara.com** (Shulmin) — a legitimate window-hiding utility; installed "noisily" through the registry; the developer poses as a British company (a VAT number), and the slogan gives away the real authors. - **Advanced Installer / MSIX Packaging Tool** (Azersky) — the two main tools for packaging a regular application as UWP; the Packaging Tool is installed from the Store. - **The VR-Expert AI module** (Eremin) — PyTorch, their own models and users' models, a GPU (a 30-minute video: 25 minutes on the CPU → about 3 minutes on the GPU); classes of people/bicycles/cars/motorcycles/buses/trucks, Russian license plates, zones and object tracking, the results in SQLite; it takes any video and static images. - **AMSI** (Shulmin) — after it came along, PowerShell code is visible: "you might as well hand us your code directly, we'll detect it". - **AndroidManifest.xml** (Kotova, Moskvichev) — permissions, an activity with the intent-filter MAIN+LAUNCHER, services (an accessibility service among them), receivers; Moskvichev — decompilation of the `vtb1` manifest (the appName "VTB Protection", the identifier "Darmstadt", the hidden server IP). - **AnyDesk (disguised as svchost)** (Shulmin) — "the core of the whole attack"; installation mode with the password "qwerty 1234566" for access without a permission prompt. - **APKiD** (Kotova) — detection of obfuscation, of protection tools (anti-VM among them) and of build tools. - **apktool / JADX / dex2jar** (Kotova) — decompilation of an APK; JADX shows the code and the manifest. - **AppxManifest.xml / AppxBlockMap / the package signature** (Azersky) — the key files of MSIX; runFullTrust removes the isolation; BlockMap — the hashes of all the files in the package (it helps the forensic expert). - **APPX / MSIX** (Azersky) — the previous and the current package formats; APPX was "tied purely" to UWP isolation, "but that was dropped later". - **AVIS** (Inkin) — STC's search and analytics suite: the speaker's gender and language, speech recognition in 18 languages, biometric search, translation into Russian, keywords highlighted on the waveform, graphs of connections and topics, LLM summaries, detection of code words and slang. - **Astra Linux** (Greshnov — viewing E01, the target platform; Tushkanova — methodological recommendations on the trace picture; Shulmin's Q&A — a request for a lightweight solution for it). - **Base64** (Kotova — the keylogger's blocks in the SpyNote log; Shavlovsky — the encoding of ShadowHashData). - **BitLocker** (Greshnov — detection, a sector-by-sector copy only; Vakhrushina — cracking the hash through MK Scout; Titkov — decrypt it on the seized disks while preparing). - **blat.exe** (Shulmin) — a legitimate SMTP sender; the email exfiltration channel ("in the transcript once as blat.executable"). - **Boot Manager / Secure Boot / TPM** (Greshnov) — booting the Element-U unit's own OS; there is a Secure Boot bypass; the speaker does not know the behavior with TPM. - **Burp Suite / OWASP ZAP** (Kotova) — proxies for analyzing HTTP traffic; in the Q&A — SSL pinning/unpinning, a substituted certificate. - **`cache4.db`** (Moskvichev) — the Telegram database from which the date of receipt of `vtb1` was established (22.01.25 10:20:44). - **Cloudflare** (Bederov) — "actively used by offenders" to hide their hosting; bypassed through URLScan, VirusTotal, DNS, "leaks of Cloudflare itself", the reuse of the SSL certificate and of the favicon. - **COCOMO / the Moscow DIT methodology** (Bezik) — estimating the cost of software by quantitative indicators (lines of code, "milestones"); they give similar results. - **`copy /b`** (Drozd) — the limit of the typical insider's "home-grown" steganography. - **curl** (Shulmin) — legitimate, "we bring our own"; detecting it would be "shooting yourself in the foot"; the installer is deleted afterwards. - **`data.cab` / `installer.config` / `runtime.cab`** (Shulmin) — the contents of Smart Install Maker: the payload / the installation commands / an "empty" cab (36 bytes of headers, its purpose unknown). - **DCAP (Data-Centric Audit and Protection)** (Drozd) — recording the user's actions with a file at the driver level; it is responsible for "access". - **Defender Control** (Shulmin) — a third-party utility (three switches); called with the D switch to turn Windows Defender off. - **DFIR (Digital Forensic Incident Response)** (Vyugin, Titkov) — retrospection (~90% of cases after the fact), RAM as a critical source; with ~3 incidents a year — outsource it; the reports are read by law enforcement; it is carried out per the SANS guide. - **DLP** (Vyugin — the effect is "up to 30%", not "90–100%", not plug-and-play; Drozd — a vendor; the agent is good on Windows/*nix, weak on macOS, useless in the cloud). - **DNSTwister / DNSTwist** (Bederov) — a free search for typosquatting domains, for their activity and for the presence of a site or email. - **Docker** (Kotova) — the container for deploying MobSF. - **Dozor (DVRs)** (Eremin) — widespread in the patrol police and the FSIN; LAN PROJECT are "the only ones" who crack and bypass their passwords. - **DVR Examiner / MD-VIDEO (GMDSOFT) / SalvationData / Amped FIVE** (Eremin) — the foreign counterparts; the version of DVR Examiner available in Russia has no AI; "the Korean program" does not handle password-locked recorders correctly. - **E01 / RAW** (Greshnov — the image viewer, E01 on Astra Linux; Eremin — support for E01 images). - **EDR / XDR** (Vyugin — an "overseer" on the endpoint / an extended one covering the network, email and clouds; Titkov — the rungs of detection, managed EDR). - **ElevenLabs** (Inkin) — the synthesis vendor, identified by IKAR Lab's anti-spoofing with a probability of 99.6%. - **EveryTag** (Drozd) — a Russian solution: a unique copy of a document on every request, through shifts in line spacing, indents and margins; from a screenshot or a photo a hash is extracted → the user. - **FBE / FDE** (Chikin — scrypt 2048.8.1 (2 MB per core) / the old FDE 32 MB per core; Vakhrushina — not supported in the free version of MK Brute Force). - **FISA / CLOUD Act** (Tushkanova's Q&A) — the synchronization of OneDrive to the servers of a foreign state. - **frosting.db / verify_apps.db / packages.xml** (Kotova) — the forensic artifacts of installation: the date and time, the displayed name, the initiator and the installer application. - **GetContact** (Barkalov) — "a wonderful tool" (sarcastically) for planting disinformation from 10 different numbers. - **GhostTap / SuperCard X** (Moskvichev) — malware related to NFCGate ("Chinese developers" behind it): 4–6 sets of card details linked to a device, the devices traded on Telegram "for hundreds of dollars". - **GigaChat (Sber)** (Inkin) — an LLM that STC has experience working with and tuning to a customer's task. - **GIMP / Photoshop** (Eremin) — the manual alternative to unsharp masking. - **Google Workspace / Google Docs** (Pavlov — the 2018–2020 redesign as a counterexample; Drozd — integration via the API as the only way to get a whole cloud document). - **hashcat** (Vakhrushina — the base of MK Brute Force, the integration of 7.0 is awaited; Chikin — the cracking engine; Shavlovsky — mode 7100 for the macOS hash). - **HiSuite (Huawei)** (Vakhrushina) — a backup for which cracking is supported; a "heavy" hash. - **IKAR Lab (IKAR Lab 3)** (Inkin) — STC's expert phonoscopy suite: noise reduction, speaker separation, the search for editing, spoofing detection (overall and second by second with a sliding window), identification of the synthesis vendor, the classical modules (phase, resampling, background noise, DC offset), a video deepfake detection module, manual documenting of the features. - **INetSim** (Kotova) — network emulation for dynamic analysis without letting the sample out onto the internet. - **InfoApp (VKontakte)** (Bederov) — obtaining the profile data of the administrators of a VK group (the spelling is by ear). - **IntelX / Have I Been Pwned** (Bederov) — a free check for leaks involving the domain. - **Keychain ("svyazka klyuchey" in Russian)** (Shavlovsky) — the macOS store of keys and passwords, access by password or biometrics; called an analogue of Windows DPAPI. - **keylogger / Mipko Professional (MPK)** (Shulmin — a Russian keylogger with a Ukrainian localization in the distribution; Kotova — the Keylogger module in SpyNote). - **Librarian Likho / Librarian Ghouls (Rare Wolf, Rezet)** (Shulmin) — an APT group; the alias Rezet comes from the batch file rezet.cmd; Kaspersky's report "Notes of a Digital Auditor" (~330 pages). - **LLM / neural networks** (Vakhrushina — building them into MK is prohibited; Drozd — the market is waiting for them to "solve this kind of primitive trick"; Inkin — summaries, summarization, detection of code words). - **MakeAppx / SignTool** (Azersky) — creating a package without a GUI + signing it with a self-signed certificate (importing it into Trusted Root requires admin rights). - **Mobile Criminalist (MK) / MK Expert Plus / MK Scout / MK Corporate** (Vakhrushina, Moskvichev, Shavlovsky, Vyugin) — MKO's flagship and product line; MK Expert Plus was used for a file system extraction (the MTK Android method); MK Scout passes hashes on (Telegram passcode, BitLocker, NTLM) and extracts keychain/tokens/messengers; MK Corporate — the corporate product (in the recording and in the transcript "MK Enterprise"). - **MK Brute Force / MK Brute Force FREE** (Vakhrushina) — password cracking built on hashcat; three methods (a dictionary, a mask, a dictionary built from personal data); the free version via a QR code, without FBE/FDE; per Shavlovsky — it does not support mode 7100. - **MobSF (Mobile Security Framework)** (Kotova) — an open-source security assessment of applications; automated static and semi-automated dynamic analysis, a GUI, deployment through Docker; no search by IP, URL — only by regex. - **MTK / MediaTek** (Moskvichev — the successful extraction method "MTK Android"; Chikin — the context of the crypto chip). - **NFCGate / N-Gate** (Moskvichev) — a legitimate teaching project of TU Darmstadt (GitHub); four modes, Clone/Relay/Capture/Replay (Clone requires root); repurposed into a tool for theft; >100 derivatives. - **ngrok / localtunnel** (Azersky — tunnels from the Store, "recently added", installed with winget; Shulmin — ngrok in Librarian Likho's toolkit). - **ntoskrnl.exe / debug symbols / decompiler** (Sukhanov) — the kernel as the only place left with the prefetch name template after the filtering; the PfSn… functions, the parameter PrefetcherInformationClass=5. - **OperationStart / OperationEnd, Prefetch "OP-…pf"** (Sukhanov) — "Operation Based Prefetching": the files are created by API calls, not at boot; verified with a Python wrapper. - **Opera (T.Hunter's portable OSINT build)** (Bederov) — running from a USB stick, the sessions on the stick, 2000+ sources, export to HTML. - **PBKDF2-SHA512 / NT hash (MD4)** (Shavlovsky) — the macOS password hash (salt + iterations + "entropy") against the weak Windows NT hash with no salt; the salt kills rainbow tables. - **plist / plutil / dslocal / ShadowHashData** (Shavlovsky) — macOS configuration files (XML / binary / JSON), conversion with `plutil`, the account's hash in the `dslocal` directory, the `ShadowHashData` section. - **powercfg / schtasks** (Shulmin) — 6 calls to powercfg against the machine falling asleep; the tasks "shutdown at 5 a.m." and "WakeUpAndLaunchEdge" (waking at 01:00). - **Process Hacker (GitHub)** (Sukhanov) — the source of the out-of-date constant PrefetcherBootControl=5 from an old Windows SDK, which gave rise to the myth of a "boot prefetch". - **Python / Julia (from the Microsoft Store)** (Azersky) — interpreters, installed with winget without admin rights → a reverse shell. - **QR code** (Vakhrushina — the free MK Brute Force; Shulmin — the report "Notes of a Digital Auditor"; Titkov — the recommendations with Cyberdom; Bezik — the PDF checklist; Eremin — support). - **RAID** (Greshnov — Element-U images it, reassembly is up to the user; Eremin — support for RAID in recorders is in development). - **RAR 3.8 (driver.exe)** (Shulmin) — an ancient version with the console output strings filled with zeroes; the unique password of the archives, with traces going back to 2010 — an IOC. - **`reg.exe` → SAM / SYSTEM** (Shulmin) — a dump of the registry hives, the backups go out in the exfiltration; "if this got past the SOC…". - **Redmi Note 11S** (Moskvichev) — the device from a real NFC theft case. - **reverse shell / RAT (TeamViewer)** (Azersky) — interpreters and legitimate RATs from the Store as the attacker's tool. - **scrypt / SHA-256 / ASIC** (Chikin) — scrypt as a "nasty thing" (memory-dependent, N.r.p, doubling N ≈ ×4 the time); for SHA-256 there are ASICs (mining scrypt 1024.1.1 = 130 KB, no use for forensics). - **Smart Install Maker** (Shulmin) — a simple self-extracting installer for the payload; the unpacker is written in Python. - **SIEM / SOAR / SOC** (Vyugin) — "an alarm system" (it does not respond by itself, garbage in — garbage out) / automation playbooks (the risk of automatic actions) / an organizational unit working 24/7 (expensive, burnout). - **SpyNote v6.4** (Kotova) — a family of RATs for Android; a builder (the icon/host/port, binding with an APK); the SMS/camera/keylogger/remote reset modules. - **SQLite / StateRepository-Deployment** (Azersky — the database with the source URL/path of the MSIX and the hashes of the files; a second database with the Organization ID; Eremin — storage of the results of the AI analysis). - **Multi-Tacotron** (Inkin's Q&A) — in the questioner's view, the base model underneath the audio deepfakes of different vendors (an argument against "identifying the vendor"). - **Telegram** (Moskvichev — delivery of the APK, the database; Barkalov — social engineering "on behalf of the head of the Interior Ministry institute"; Shulmin — the report via a QR code; Sukhanov, Vyugin — Dmitry Boroshchuk's channel as the occasion; Titkov — extortion and "repeated leaks"). - **TI feeds (Threat Intelligence)** (Shulmin, Vyugin, Titkov) — "to know your enemy", shift-left, the SOC's toolkit. - **TSFS (Tantos) / TESAM / VFS-VFS2** (Eremin) — the new proprietary file systems of DVRs, found a week before the talk (the spelling is by ear). - **Unisoc / Kirin / Exynos / Qualcomm** (Chikin) — processors; the context of crypto chips and of the cracking parameters. - **VD-Expert / DTP-Expert (OT-Kontakt)** (Eremin) — video-technical forensic examinations and speed determination; LAN PROJECT hands the second task to a partner. - **VirusTotal / URLScan (urlscan.io)** (Bederov) — they indexed the resource before Cloudflare; VirusTotal also for finding a site's external files; Shulmin — the attackers "naively" check their "little creations" on services like these. - **VR-Expert** (Eremin) — LAN PROJECT's software for extracting video from recorders; in the Russian software registry (2025); carving a terabyte ~3 weeks, a signature search, a HEX viewer, cross-platform. - **VS Code / code.exe** (Azersky) — creating a tunnel after authenticating with GitHub ("no longer a problem for attackers"). - **`wallet.rar`** (Shulmin) — an archive with everything related to electronic money, + the SAM/SYSTEM backups → to the attackers. - **WHOIS / WHOIS archives** (Bederov) — the primary source, degraded after GDPR ("a private person"); bypassed through the historical archives. - **winget** (Azersky) — installation from the Store without administrator rights; a trace in the log. - **Wireshark** (Kotova) — analysis of SpyNote's TCP exchange with the C2 (Gzip, DNS → IP → TCP). - **`wol.ps1`** (Shulmin) — a PowerShell script that creates a wake-up task through the launch of the genuine Edge. - **XMRig / Monero** (Shulmin) — a legitimate miner with a malicious pool and controller; "Utilization at 110–146%". - **Yandex.Metrica** (Bederov — ~10% of the counters are public, Yandex support discloses the email address by the identifier; Barkalov — criticized as "closed OSINT", the collection of personal data and cookies). - **watermarks on monitors / labels in the file / RMS / ABAC** (Drozd) — marking at the driver level (the name, the machine, the date), unique copies, labels + encryption when data leaves the perimeter (the ABAC model, "reinventing Microsoft RMS"). - **Gestalt principles / Hick's law / the cognitive load of 7±2** (Pavlov) — the basis of interface design; indexing and color highlighting of logs speed analysis up "by tens, if not hundreds of times". - **GAS "Pravosudie" / GAS "Legal Statistics" / Gosuslugi / the Rosreestr state information system** (Bezik) — examples of automated government systems as objects of an SKTE. - **Cyberdom** (Titkov) — the platform together with which the response recommendations were published; the speaker — an ambassador. - **Nextcloud / ownCloud** (Vyugin's Q&A) — a budget "controlled environment" for users instead of DLP. - **Nestor AI** (Inkin) — STC's suite for taking the minutes of sessions: streaming audio and files (Zoom, a dictaphone), the minutes split by speaker, LLM abstracts. - **PMI / TZ / ChTZ** (Bezik) — the test program and procedure, the terms of reference and the detailed terms of reference as the basis for checking the requirements. - **Smartphones/tablets/smartwatches/bands, keypad phones** (Tushkanova) — the broadened range of objects of the standard methodology; the expert's hardware and software workstation with functional requirements (removing and reading memory chips, SIM cards that cannot be registered, an ultrasonic bath). - **steganography** (Drozd) — "not a panacea", a supplement to DLP/DCAP; the unsolved problems: formats (audio), architecture, detection (overexposure kills the mark), retyping by hand. - **Element-U and the Element line (ELETEK)** (Greshnov) — a unit for acquisition from a PC without taking it apart (its own OS, a Secure Boot bypass, acquisition by masks and signatures), a USB flash-drive copier (2 hours on battery, an Android app, LEDs), a SATA copier with a hardware write blocker, a workstation (Mini-ATX, Core i3, a 2 TB NVMe, a block of 64 KB–8 MB, detection of hidden areas/BitLocker), a viewer for RAW/E01 images, "live" acquisition software. ### 4.2 Attack vectors and cases - **NFC thefts (the classic and the reverse scheme)** — Moskvichev — a social-engineering call → a "specially secured" application (NFCGate in Relay Mode) → the victim holds their card up and enters the PIN → relaying to an accomplice at an ATM; the reverse scheme — the signal of the suspect's card to the victim's phone, "deposit money into a 'safe account'". - **A real NFC case for 230 thousand rubles** — Moskvichev — a call on Telegram from "a law enforcement officer" → an APK → instructions → deleting the app; a Redmi Note 11S, the `vtb1` trojan (received 22.01.25 10:20:44, deleted twice on 23.01.25), the manifest with "Darmstadt" and "VTB Protection", the server IP established. - **A SpyNote infection through a messenger** — Kotova — an APK under a cover story (a doctor's appointment booking, an antivirus, a parcel tracker), binding with another APK; the modules SMS/camera (even with the screen locked)/keylogger/remote factory reset; traces in /data/data, frosting.db, packages.xml, the Samsung battery log, the file 30.db of Sberbank's antivirus. - **Brute-forcing a mobile password is practically impossible** — Chikin — ~20,000 passwords/s → an 8-character password ≈ 10,000 years; the type of encryption (FBE 2 MB vs. FDE 32 MB per core) sets the cost of the attack. - **Cracking the password of a macOS account** — Shavlovsky — extracting the plist from `dslocal` → `ShadowHashData` → Base64 → brute-forcing PBKDF2-SHA512 in hashcat (7100); the case — the disk turned out to be a Fusion Drive, they reassembled it; the barrier — the Secure Enclave, without root the plist cannot be pulled out. - **Disguising documents by changing or removing the extension** — Greshnov — .docx → .mp3 or no extension at all; the countermeasure — acquisition by signatures; encrypted disks (BitLocker) — only a sector-by-sector copy, with no viewing. - **Ruining a DVR's disk by initializing it in Windows** — Eremin — Windows 10/11 overwrites about 40 MB at the start of the disk (the video stream allocation table); recovery only by carving or a signature search; a shifted file system (a disk moved from a PC into a recorder) is saved by specifying the file system manually. - **The Librarian Likho attack chain** — Shulmin — spear phishing (a RAR named "payment order" → .scr = MZ/PE, Smart Install Maker) → a PDF red herring + curl + an LNK → C:\Intel, RAR 3.8, AnyDesk under the name svchost, Defender Control, powercfg, the tasks "shutdown at 5 a.m."/"WakeUpAndLaunchEdge" → the window 01:00–05:00 → a dump of SAM/SYSTEM, wallet.rar, XMRig → lateral movement over SMB. - **The Librarian Likho infrastructure** — Shulmin — phishing impersonating Mail.ru (login.php, sign-in through Gosuslugi), an open directory listing, a Russian-language phpMyAdmin; the evidence of origin: the author's mistake in the attachment's name, the Ukrainian localization of Mipko. - **The case of "logins and passwords.xlsx" on the desktop** — Shulmin — on command the implant takes the file with employee passwords from a large organization ("that wasn't deception"). - **Malicious MSIX packages** — Azersky — signing with a stolen developer certificate; in Windows 11 — unsigned ones through a PowerShell cmdlet (the indicator — a fixed Organization ID, event 9545); the 2023 campaigns through ms-appinstaller (SEO poisoning, malvertising, phishing in Teams); FIN7 with PSF (config.json → a PS1 script or a batch file). - **Living off the Store through winget** — Azersky — the Python/Julia interpreters → a reverse shell; the ngrok/localtunnel tunnels "in almost all cases" with ransomware; portable browsers for internal resources; a VS Code tunnel through GitHub. - **Encryption or wiping of the infrastructure** — Titkov — the July 2025 cases (a beverage producer, a pharmacy chain, an airline — fuel calculated by hand for 2 weeks); a dwell time of 3–9 months; the deletion of connected backups; "particularly cunning" malware encrypts when it loses contact with the C2; a mass password change before the cleanup signals to the attacker. - **Double extortion and "repeat leaks"** — Titkov — a second ransom for deleting the data (they do not delete it); regular publications of old data enriched with generated data, passed off as a new breach. - **Shadow copies full of zeros after ransomware** — Sukhanov — from Windows 8 on, the "scoped shadow copy": user files in the surviving copies — zero bytes (Microsoft replied to customers privately); part of the data survives because of the 16 KB granularity against a 4 KB cluster. - **Bypassing DLP by a primitive substitution of characters** — Drozd — "5" → "five" through "find and replace", and regexes go blind; cloud editors cannot be reconstructed either with a keylogger or from HTTPS interception; a photo of the screen taken on a smartphone under legitimate access; an overexposed shot kills the watermark; retyping by hand — "What do you do? Nothing". - **OSINT deanonymization of sites** — Bederov — WHOIS → the archives (against GDPR), bypassing Cloudflare, file metadata; a 2025 case (a harassment site, pictures taken on an iPhone → GPS → the home address); October 2021 (the Meta outage, getting in by the hosting IP); petitions (the author's own first seeding). - **Social engineering and HUMINT** — Barkalov — a Telegram message "on behalf of the head of the Interior Ministry institute" → a call from "an FSB representative"; the ATM case (a conversation with the developer of its protection → the spots to drill, "I started a computer inside without tripping the alarm"); 64 million stolen from an organization that had money in its account; an insider with flash drives; planting disinformation in GetContact from 10 numbers. - **Voice cloning and deepfakes** — Inkin — voice synthesis from a sample ("I just got into an accident on the M4 highway… I urgently need money"); partial forgery of a recording (detection with a sliding window); Biden's voice in the 2024 US campaign; the video deepfake of Jessica Alba (the room split, the detector — 97%); face swap / puppet-master / lip-sync / "animating" a photo (98% on STC's own datasets); prompt injection through an inaudible audio signal (a hypothesis from the audience). ### 4.3 Laws, agencies, regulatory requirements - **The standard methodology for examining information in mobile devices (Investigative Committee of Russia, 2025)** — Tushkanova — reviewed by the Investigative Committee's Scientific and Technical Council, recommended to the Investigative Committee's forensic units; the evolution: the FSKN's 2011 methodological recommendations (FOUO) → the EKC MVD of Russia standard methodology 2014 → the 2023 revision → the Investigative Committee of Russia 2025. - **Federal Law 73-FZ (on state forensic expert activity)** — Tushkanova (the correction of errors in the investigator's questions is not regulated; liability for disclosure), Bezik (the context of the forensic examination); the day 1 debates. - **Art. 57 (the expert may not destroy or alter an object without the initiator's permission)** — Shavlovsky (the code is not specified; from the context, the Code of Criminal Procedure of the Russian Federation). - **Art. 272 / 273 / 274 of the Criminal Code of the Russian Federation** — Shulmin (the attackers' hope; they "get very, very long sentences"); Art. 272 of the Criminal Code — Barkalov (the framework of OSINT's legality). - **Federal Law 152-FZ "On Personal Data" (Art. 19), Art. 152.1/152.2 of the Civil Code of the Russian Federation, the Information Security Doctrine of the Russian Federation** — Barkalov (protecting society from harmful information; the articles are garbled in the recording). - **A ruling of the Supreme Court of the Russian Federation (August 2025) on typosquatting** — Bederov — it obliges business entities to detect typosquatting and online fraud on their own; the details of the act were not named. - **Federal Law 44-FZ / the acceptance of state contracts** — Bezik and Barannikov — the acceptance of the Rosreestr state information system with a step-by-step check of the documentation and of the code "with hashes", load tests; state contracts for the development of automated systems, 150 million – billions of RUB. - **FIS GosSOPKA / NKTsKI / FinCERT / CII (from the context, Federal Law 187-FZ)** — Titkov — CII entities "must first of all" report to GosSOPKA/NKTsKI; those supervised by the Central Bank — FinCERT. - **Roskomnadzor: notification of a personal data leak within 24 h / a report within 72 h** — Titkov — "including about a fake leak"; the statute was not named. - **AML/CFT; the ransom as financing of terrorism** — Titkov — the bank may refuse to make the payment to the attackers; a payment that has gone through may be classified as financing of terrorism. - **The crime report register (KUSP), recognition as the victim, seizure** — Titkov — the procedure after an incident (the complaint + the DFIR report → registration in the KUSP → a possible seizure → a criminal case → a certificate of recognition as the victim). - **FISA / CLOUD Act** — Tushkanova (Q&A) — OneDrive on the servers of a foreign state; a leak of FOUO material/state secrets — a duty to report it; the inspection of a cloud — an investigative action. - **GDPR** — Bederov (the disappearance of personal data from WHOIS), Shulmin (the anonymization of KSN telemetry), Titkov ("maybe someone also complies"). - **Operational-search activities (ORD) / countering foreign technical intelligence** — Barkalov (OSINT differs from ORD by "the depth of immersion", closed databases), Bederov (OSINT as an evidentiary methodology). - **EKC MVD of Russia / SEC SK / GUK SK / the Investigative Committee's Scientific and Technical Council / the FSB** — Tushkanova (a meeting on cloud data, the development of the methodology, similar councils at the MVD/FSB), Moskvichev (the EKC as the recipient of the forensic examination), Bezik (a discussion with a former EKC MVD employee). - **State secrets: clearance for experts, a certified hardware-software system, a state contract / development (R&D) work** — Tushkanova — a certified classified system with no extraneous files; standard systems through development (R&D) work (in the MVD — "Special Equipment and Communications"). - **The Russian software registry** — Eremin — VR-Expert was added in 2025; this is linked to easier supply to government agencies. - **The personal data law / the check material** — Bederov (indirectly), Tushkanova — citing tokens in the expert report, the order and the procedure. - **The wording of the question put to the forensic expert** — Kotova ("the presence of files detected by antivirus software. And nothing else"); Bezik (the court puts the questions, the expert may not change them — the dispute with the EKC MVD); Tushkanova (the right to edit errors in the investigator's questions).