Research
We locate the data left behind on digital devices and services, and verify whether it holds up as digital evidence. Our work is organized around the five questions below.
How much of deleted data can be recovered?
We study how deleted or damaged data leaves traces in operating systems, file systems, storage media, memory, and databases, and how those traces can be used to restore the original data.
This covers the full range of deletion traces across a system: file system metadata and unallocated-space analysis, recoverability differences across storage media (HDD, SSD, NVMe), reconstructing history from logs and journals, and recovering database records.
How did the attacker get in, and what did they leave behind?
Incident response is one of the main applications of digital forensics, commonly called DFIR (Digital Forensics and Incident Response). We apply forensic techniques to systems hit by hacking or malware to uncover the attack path and the scope of damage.
This covers analyzing malware traces in memory and on disk, reconstructing attack timelines from operating system artifacts and logs, extracting indicators of compromise (IoCs), investigating and recovering ransomware-affected systems, and preserving digital evidence so it can be used in investigations and litigation.
What traces do new apps and systems leave behind?
We analyze the artifacts that applications, operating systems, and network services leave across a system, including user devices, servers, and logs.
We identify where and in what form usage traces on mobile and PC operating systems, messenger and browser records, remote access and collaboration tools, and newly emerging software such as generative AI services store data, and develop analysis methods that put these findings to use in investigations.
How do we acquire data that lives off the device?
Cloud services and synced data cannot be fully understood by examining a single device alone. We study cloud platform structures and the procedures that make it possible to actually acquire digital evidence in the field.
This covers methods for collecting and analyzing logs, metadata, and user data from IaaS, PaaS, and SaaS cloud services, cloud storage, collaboration platforms, and cloud databases, as well as the practical limitations of investigations, such as jurisdiction and access rights, and how to address them.
How do we prove that analysis results can be trusted?
We verify the reliability of analysis tools and procedures themselves, and study how to detect anti-forensic attempts that interfere with analysis or erase traces.
This covers verifying the accuracy of analysis tool results, ensuring the integrity of digital evidence through hashing and imaging procedures, standardizing procedures from collection through analysis, and detecting anti-forensic techniques such as data hiding, deletion, and tampering.