European Magnet User Summit Event Details – Rome
Thanks for signing up for our European Magnet User Summit event, check out the event agenda below. More details to come soon!
|8:30 – 9:00||REGISTRATION|
|9:00 – 10:00||LECTURE|
MACOS: FORENSIC ARTIFACTS AND TECHNIQUES THAT ARE ESSENTIAL FOR MAC INVESTIGATIONS
|10:15 – 11:15||KEYNOTE|
|11:15 – 12:30||LUNCH & ASK THE EXPERT STATIONS|
|12:30 – 14:00||LAB|
Bring Your Own Computer
|14:15 – 15:15||LECTURE|
Thinking DFIRENTLY: UTILIZING TECHNOLOGY TO WORK SMARTER THAN EVER
We’re in a critical time for digital forensics where the ways we’re used to working cases may not be enough to keep up anymore. What can labs do differently to deal with growing amounts of digital evidence to prevent backlogs?
In this talk, Magnet Forensics will illustrate how we’re tackling the problem. This will include real examples of how organizations are handling these issues, along with helpful open source initiatives, tools, and resources you can use. She will not only help you see how your lab can work smarter with stakeholders to produce meaningful results more efficiently but how to adjust Standard Operating Procedures to be more effective
|15:15 – 15:30||ASK THE EXPERTS STATIONS & NETWORKING|
|15:30 – 17:00||LAB|
Bring Your Own Computer
MAKING MAGAK: USING GRAYKEY AND AXIOM TOGETHER TO MAXIMIZE IOS INVESTIGATIONS
David Miles, Grayshift & Trey Amick, Magnet Forensics
In this lab, students will learn how to maximize the workflow between the GrayKey and Magnet AXIOM software. Hands-on demonstrations will allow students to explore the latest versions of iOS, understand what information is available at what level of data protection, and explore file-system specific artifacts.
Students will learn how to use the extracted keychain information to bolster their investigations by tracking information that can allow access to cloud services as well as encrypted application data on the local iOS device. Coverage of file-system specific artifacts like KnowledgeC, PowerLog, and Location data will be explored so students can learn how these artifacts can lend incredible supporting evidence to a case by using real-world examples.
Note: GrayKey labs are restricted to law enforcement and government attendees only. As this will be strictly enforced, please be advised that valid government organization ID must be presented at registration check-in AND upon entrance to these restricted sessions. If you do not qualify, please select an alternate lab or lecture.
*Please note that the Grayshift BYOD Lab is for Law Enforcement only. ID badges will be checked upon arrival to the session.