The Cider Press: Extracting Forensic Artifacts from Apple Continuity - SANS DFIR Summit 2017

preview_player
Показать описание
Apple Continuity allows us to move between our devices without disruption in activity. Just think of the ultimate handoff where you can start browsing the Internet on your iPhone, continue on your Mac without the hassle of having to type a search a second time.
Essentially, your devices work together enabling you to do less. Imagine how this looks on a Mac, iPhone or Apple Watch. What will the forensic artifacts look like? Will you be able to tell which device the user conducted an activity on? What if it makes or breaks your
investigation?

Рекомендации по теме
Комментарии
Автор

I wonder if this can lead to open-source implementations of Apple's Continuity and HandOff features.

nicnl