CINXE.COM
iOS KnowledgeC.db Notifications · DFIR Review
<!DOCTYPE html><html lang="en" data-reactroot=""><head><meta charSet="utf-8"/><link rel="alternate" type="application/rss+xml" title="iOS KnowledgeC.db Notifications RSS Feed" href="https://dfir.pubpub.org/rss.xml"/><title>iOS KnowledgeC.db Notifications · DFIR Review</title><meta property="og:title" content="iOS KnowledgeC.db Notifications"/><meta name="twitter:title" content="iOS KnowledgeC.db Notifications · DFIR Review"/><meta name="twitter:image:alt" content="iOS KnowledgeC.db Notifications · DFIR Review"/><meta name="citation_title" content="iOS KnowledgeC.db Notifications"/><meta name="dc.title" content="iOS KnowledgeC.db Notifications"/><meta property="og:site_name" content="DFIR Review"/><meta name="citation_journal_title" content="DFIR Review"/><meta property="og:url" content="https://dfir.pubpub.org/pub/g2v1z97i/release/1"/><meta property="og:type" content="article"/><meta name="citation_pdf_url" content="https://dfir.pubpub.org/pub/g2v1z97i/download/pdf"/><meta property="og:image" content="https://assets.pubpub.org/3yqqvtl4/71553968763873.png"/><meta property="og:image:url" content="https://assets.pubpub.org/3yqqvtl4/71553968763873.png"/><meta property="og:image:width" content="500"/><meta name="twitter:image" content="https://assets.pubpub.org/3yqqvtl4/71553968763873.png"/><link rel="icon" type="image/png" sizes="256x256" href="https://assets.pubpub.org/c8g3oakn/41553968740088.png"/><meta name="citation_author" content="Scott Koenig"/><meta name="dc.creator" content="Scott Koenig"/><meta property="article:published_time" content="Thu Nov 03 2022 11:43:49 GMT+0000 (Coordinated Universal Time)"/><meta property="dc.date" content="2022-10-3"/><meta name="citation_publication_date" content="2022/11/3"/><meta property="dc.publisher" content="PubPub"/><link rel="canonical" href="https://dfir.pubpub.org/pub/g2v1z97i"/><meta property="fb:app_id" content="924988584221879"/><meta name="twitter:card" content="summary"/><meta name="twitter:site" content="@pubpub"/><meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no"/><meta name="google-site-verification" content="jmmJFnkSOeIEuS54adOzGMwc0kwpsa8wQ-L4GyPpPDg"/><link rel="stylesheet" type="text/css" href="/dist/main.8953e10b2e394e83bb73.css"/><link rel="search" type="application/opensearchdescription+xml" title="DFIR Review" href="/opensearch.xml"/></head><body class="pub-body-wrapper active-pub-g2v1z97i"><script>0</script><div id="root"><div id="app" class=""><style type="text/css">:root { --community-accent-dark: #2D2E2F; --community-accent-dark-faded-30: rgb(63, 63, 63); --community-accent-dark-faded: rgba(45, 46, 47, 0.050000000000000044); }</style><style> .accent-background { background-color: #2D2E2F; } .accent-color { color: #FFFFFF; } .accent-background.header-component, .accent-background.nav-bar-component, .accent-background.footer-component, .accent-background.nav-item-background, .accent-background.image-wrapper{ background-color: #2D2E2F; } .accent-color.header-component, .accent-color.nav-bar-component, .accent-color.footer-component, .accent-color.nav-item { color: #FFFFFF; } .bp3-button.bp3-intent-primary:not(.bp3-outlined) { background-color: rgba(45, 46, 47, 0.6); color: #FFFFFF; } .bp3-button.bp3-intent-primary:not(.bp3-outlined):hover:not(.bp3-disabled) { background-color: rgba(45, 46, 47, 0.8); color: #FFFFFF; } .bp3-button.bp3-intent-primary:not(.bp3-outlined):active:not(.bp3-disabled), .bp3-button.bp3-intent-primary.bp3-active:not(.bp3-disabled) { background-color: #2D2E2F; color: #FFFFFF; } .bp3-button.bp3-intent-primary.bp3-outlined { border-color: #2D2E2F; color: #2D2E2F; } .bp3-button.bp3-intent-primary.bp3-outlined:hover:not(.bp3-disabled) { background-color: rgba(45, 46, 47, 0.09999999999999998); color: #2D2E2F; } .bp3-button.bp3-intent-primary.bp3-outlined:active:not(.bp3-disabled), .bp3-button.bp3-intent-primary.bp3-active:not(.bp3-disabled) { background-color: rgba(45, 46, 47, 0.19999999999999996); color: #2D2E2F; } .bp3-tree-node.bp3-tree-node-selected > .bp3-tree-node-content { background-color: #2D2E2F; } .bp3-tag.bp3-intent-primary { background: #2D2E2F; color: #FFFFFF; } .bp3-tag.bp3-minimal.bp3-intent-primary { background-color: rgba(45, 46, 47, 0.09999999999999998); color: inherit; } .accent-color .bp3-button:not([class*="bp3-intent-primary"]), .accent-color .bp3-button:not([class*="bp3-intent-success"]), .accent-color .bp3-button:not([class*="bp3-intent-warning"]), .accent-color .bp3-button:not([class*="bp3-intent-danger"]), .accent-color .bp3-button[class*="bp3-icon"]::before { color: inherit; } .accent-color a, .accent-color a:hover { color: inherit; } .bp3-tab[aria-selected="true"], .bp3-tab:not([aria-selected="true"]):hover { box-shadow: inset 0 -3px 0 rgba(45, 46, 47, 0.09999999999999998); } .bp3-tab[aria-selected="true"] { box-shadow: inset 0 -3px 0 #2D2E2F; } .thread:hover:after { background-color: #2D2E2F; } .bp3-slider-progress.bp3-intent-primary, .bp3-dark .bp3-slider-progress.bp3-intent-primary { background: #2D2E2F; } .bp3-slider-handle .bp3-slider-label { background: #2D2E2F; color: #FFFFFF; } .highlight-dot-wrapper .highlight-dot { background-color: #2D2E2F; } .changelog-callout { background: rgba(45, 46, 47, 0.09999999999999998) !important; } .changelog-callout .release-label { color: #2D2E2F; border: 1px dashed #2D2E2F; } span.citation:hover { color: #2D2E2F; } .overflow-gradient { background: linear-gradient(90deg, rgba(45, 46, 47, 0) 0%, rgba(45, 46, 47, 0) 85%, #2D2E2F 100%); } </style><a href="#main-content" tabindex="0" class="skip-link-component tab-to-show-component">Skip to main content</a><header class="header-component accent-background accent-color"><div class="main"><div class="container "><div class="row"><div class="col-12 main-content"><div class="logo-wrapper"><a href="/" aria-label="DFIR Review"><img alt="" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImhuZHdvMDAzLzYxNjc1Mzc0NjMxMDQ5LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJoZWlnaHQiOjUwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0="/></a></div><div class="global-controls-component"><a role="button" href="/search" aria-label="Search" class="bp3-button bp3-minimal mobile-aware-component__mobile" tabindex="0"><span icon="search" class="bp3-icon bp3-icon-search"><svg data-icon="search" width="16" height="16" viewBox="0 0 16 16"><path d="M15.55 13.43l-2.67-2.68a6.94 6.94 0 001.11-3.76c0-3.87-3.13-7-7-7s-7 3.13-7 7 3.13 7 7 7c1.39 0 2.68-.42 3.76-1.11l2.68 2.67a1.498 1.498 0 102.12-2.12zm-8.56-1.44c-2.76 0-5-2.24-5-5s2.24-5 5-5 5 2.24 5 5-2.24 5-5 5z" fill-rule="evenodd"></path></svg></span></a><a role="button" href="/search" aria-label="Search" class="bp3-button bp3-large bp3-minimal mobile-aware-component__desktop" tabindex="0"><span class="bp3-button-text">Search</span></a><button type="button" style="display:inline-flex;-webkit-appearance:unset" aria-expanded="false" aria-controls="id-2" aria-haspopup="menu" aria-label="Dashboard menu" class="bp3-button bp3-minimal mobile-aware-component__mobile"><span icon="settings" class="bp3-icon bp3-icon-settings"><svg data-icon="settings" width="16" height="16" viewBox="0 0 16 16"><path d="M3 1c0-.55-.45-1-1-1S1 .45 1 1v3h2V1zm0 4H1c-.55 0-1 .45-1 1v2c0 .55.45 1 1 1h2c.55 0 1-.45 1-1V6c0-.55-.45-1-1-1zm12-4c0-.55-.45-1-1-1s-1 .45-1 1v2h2V1zM9 1c0-.55-.45-1-1-1S7 .45 7 1v6h2V1zM1 15c0 .55.45 1 1 1s1-.45 1-1v-5H1v5zM15 4h-2c-.55 0-1 .45-1 1v2c0 .55.45 1 1 1h2c.55 0 1-.45 1-1V5c0-.55-.45-1-1-1zm-2 11c0 .55.45 1 1 1s1-.45 1-1V9h-2v6zM9 8H7c-.55 0-1 .45-1 1v2c0 .55.45 1 1 1h2c.55 0 1-.45 1-1V9c0-.55-.45-1-1-1zm-2 7c0 .55.45 1 1 1s1-.45 1-1v-2H7v2z" fill-rule="evenodd"></path></svg></span></button><button type="button" style="display:inline-flex;-webkit-appearance:unset" aria-expanded="false" aria-controls="id-2" aria-haspopup="menu" aria-label="Dashboard menu" class="bp3-button bp3-large bp3-minimal mobile-aware-component__desktop"><span class="bp3-button-text">Dashboard</span><span icon="caret-down" class="bp3-icon bp3-icon-caret-down"><svg data-icon="caret-down" width="16" height="16" viewBox="0 0 16 16"><desc>caret-down</desc><path d="M12 6.5c0-.28-.22-.5-.5-.5h-7a.495.495 0 00-.37.83l3.5 4c.09.1.22.17.37.17s.28-.07.37-.17l3.5-4c.08-.09.13-.2.13-.33z" fill-rule="evenodd"></path></svg></span></button><a role="button" href="/login?redirect=/pub/g2v1z97i/release/1" class="bp3-button bp3-minimal mobile-aware-component__mobile" tabindex="0"><span class="bp3-button-text">Login</span></a><a role="button" href="/login?redirect=/pub/g2v1z97i/release/1" class="bp3-button bp3-large bp3-minimal mobile-aware-component__desktop" tabindex="0"><span class="bp3-button-text">Login or Signup</span></a></div></div></div></div></div></header><nav class="nav-bar-component accent-background accent-color"><div class="container "><div class="row"><div class="col-12 "><div class="scrollable-nav"><ul class="nav-list"><li><a href="/"><span class="title">DFIR Review</span></a></li><li><a href="/blog"><span class="title">Stats</span></a></li><li><a href="/reviewers"><span class="title">Reviewers</span></a></li><li><a href="/submission-guidance"><span class="title">Submission Guidance</span></a></li><li><a href="/pub"><span class="title">Publications</span></a></li><li><a href="/about"><span class="title">Aims & Scope</span></a></li><li><a href="/review-guidance"><span class="title">Review Guidance</span></a></li><li><a href="/community"><span class="title">Community</span></a></li><li><a href="/dfrws"><span class="title">DFRWS.org</span></a></li></ul><div class="overflow-gradient"></div></div></div></div></div></nav><div id="main-content" tabindex="-1"><div id="pub-container"><div class="pub-header-background-component pub-header-theme-dark pub-header-component"><div class="background-element background-white-layer"></div><div class="background-element background-color" style="background-color:rgba(0, 0, 0, 0.0275)"></div><div class="background-element background-safety-layer"></div><div class="container pub"><div class="row"><div class="col-12 pub-header-column"><div class="pub-header-content-component"><div class="pub-header-top-area has-bottom-hairline"><div class="basic-details"><span class="metadata-pair"><b class="pub-header-themed-secondary">Published on </b>Nov 03, 2022</span><div class="show-details-placeholder"></div></div></div><div class="title-group-component"><h1 class="title"><span class="text-wrapper">iOS KnowledgeC.db Notifications</span></h1><div class="byline-component"><span class="text-wrapper"><span>by<!-- --> </span><span><a href="/user/scott-koenig" class="hoverline">Scott Koenig</a></span></span></div><div class="published-date"><span class="pub-header-themed-secondary">Published on</span><span>Nov 03, 2022</span></div></div><div class="utility-buttons-component"><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left show-header-details-button"><div class="pub-header-themed-box icon-container"><span icon="info-sign" class="bp3-icon bp3-icon-info-sign"><svg data-icon="info-sign" width="14" height="14" viewBox="0 0 16 16"><path d="M8 0C3.58 0 0 3.58 0 8s3.58 8 8 8 8-3.58 8-8-3.58-8-8-8zM7 3h2v2H7V3zm3 10H6v-1h1V7H6V6h3v6h1v1z" fill-rule="evenodd"></path></svg></span></div></button><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left cite-button"><div class="pub-header-themed-box icon-container"><span class="bp3-icon" data-icon="cite" aria-label="" aria-hidden="true"><svg width="14px" height="14px" viewBox="0 0 24 24"><g><path d="M5.56 22.286v-2.548h-2.039v-15.476h2.039v-2.548h-5.56v20.573h5.56zM24 22.286v-20.573h-5.583v2.548h2.039v15.476h-2.039v2.548h5.583z"></path><path d="M13.918 5.993l-0.421 3.1h-2.409l0.438-3.1h-1.348l-0.421 3.1h-1.702v1.23h1.516l-0.404 2.982h-1.668v1.23h1.483l-0.438 3.083h1.331l0.438-3.083h2.393l-0.438 3.083h1.348l0.421-3.083h1.719v-1.23h-1.533l0.404-2.982h1.685v-1.23h-1.483l0.421-3.1h-1.331zM10.902 10.324h2.393l-0.388 2.982h-2.409l0.404-2.982z"></path></g></svg></span></div><div class="label">Cite</div></button><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left"><div class="pub-header-themed-box icon-container"><span class="bp3-icon" data-icon="share2" aria-label="" aria-hidden="true"><svg width="14px" height="14px" viewBox="0 0 32 32"><path d="M25.524 22.54c-1.206 0-2.286 0.476-3.111 1.222l-11.317-6.587c0.079-0.365 0.143-0.73 0.143-1.111s-0.063-0.746-0.143-1.111l11.19-6.524c0.857 0.794 1.984 1.286 3.238 1.286 2.635 0 4.762-2.127 4.762-4.762s-2.127-4.762-4.762-4.762c-2.635 0-4.762 2.127-4.762 4.762 0 0.381 0.064 0.746 0.143 1.111l-11.191 6.524c-0.857-0.794-1.984-1.286-3.238-1.286-2.635 0-4.762 2.127-4.762 4.762s2.127 4.762 4.762 4.762c1.254 0 2.381-0.492 3.238-1.286l11.302 6.603c-0.079 0.333-0.127 0.683-0.127 1.032 0 2.556 2.079 4.635 4.635 4.635s4.635-2.079 4.635-4.635c0-2.556-2.079-4.635-4.635-4.635z"></path></svg></span></div><div class="label">Social</div></button><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left"><div class="pub-header-themed-box icon-container"><span class="bp3-icon" data-icon="download2" aria-label="" aria-hidden="true"><svg width="14px" height="14px" viewBox="0 0 32 32"><path d="M28.963 11.37h-7.407v-11.111h-11.111v11.111h-7.407l12.963 12.963 12.963-12.963zM3.037 28.037v3.704h25.926v-3.704h-25.926z"></path></svg></span></div><div class="label">Download</div></button><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left"><div class="pub-header-themed-box icon-container"><span class="bp3-icon" data-icon="toc" aria-label="" aria-hidden="true"><svg width="14px" height="14px" viewBox="0 0 24 24"><g><path d="M17.077 19.582h-11.538v3.033h11.538v-3.033zM24 7.451h-18.462v3.033h18.462v-3.033zM5.538 16.55h18.462v-3.033h-18.462v3.033zM5.538 1.385v3.033h18.462v-3.033h-18.462z"></path><path d="M2.769 2.769c0 0.765-0.62 1.385-1.385 1.385s-1.385-0.62-1.385-1.385c0-0.765 0.62-1.385 1.385-1.385s1.385 0.62 1.385 1.385z"></path></g></svg></span></div><div class="label">Contents</div></button></div><div class="draft-release-buttons-component"><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left mobile-aware-component__mobile"><div class="pub-header-themed-box icon-container"><span icon="history" class="bp3-icon bp3-icon-history"><svg data-icon="history" width="14" height="14" viewBox="0 0 16 16"><path d="M8 3c-.55 0-1 .45-1 1v4c0 .28.11.53.29.71l2 2a1.003 1.003 0 001.42-1.42L9 7.59V4c0-.55-.45-1-1-1zm0-3a7.95 7.95 0 00-6 2.74V1c0-.55-.45-1-1-1S0 .45 0 1v4c0 .55.45 1 1 1h4c.55 0 1-.45 1-1s-.45-1-1-1H3.54C4.64 2.78 6.23 2 8 2c3.31 0 6 2.69 6 6 0 2.61-1.67 4.81-4 5.63v-.01c-.63.23-1.29.38-2 .38-3.31 0-6-2.69-6-6 0-.55-.45-1-1-1s-1 .45-1 1c0 4.42 3.58 8 8 8 .34 0 .67-.03 1-.07.02 0 .04-.01.06-.01C12.98 15.4 16 12.06 16 8c0-4.42-3.58-8-8-8z" fill-rule="evenodd"></path></svg></span></div></button><button style="display:inline-flex;-webkit-appearance:unset" type="button" class="large-header-button-component pub-header-themed-box-hover-target mobile-aware-component__desktop" aria-expanded="false" aria-controls="id-11" aria-haspopup="menu" aria-label="Choose a historical release of this Pub"><div class="button-box pub-header-themed-box no-label"><span icon="history" class="bp3-icon bp3-icon-history"><svg data-icon="history" width="22" height="22" viewBox="0 0 20 20"><path d="M10 0C6.71 0 3.82 1.6 2 4.05V2c0-.55-.45-1-1-1s-1 .45-1 1v4c0 .55.45 1 1 1h4c.55 0 1-.45 1-1s-.45-1-1-1H3.76C5.23 3.17 7.47 2 10 2c4.42 0 8 3.58 8 8s-3.58 8-8 8-8-3.58-8-8c0-.55-.45-1-1-1s-1 .45-1 1c0 5.52 4.48 10 10 10s10-4.48 10-10S15.52 0 10 0zm0 3c-.55 0-1 .45-1 1v6c0 .28.11.53.29.71l3 3a1.003 1.003 0 001.42-1.42L11 9.59V4c0-.55-.45-1-1-1z" fill-rule="evenodd"></path></svg></span><span icon="caret-down" class="bp3-icon bp3-icon-caret-down caret"><svg data-icon="caret-down" width="10" height="10" viewBox="0 0 16 16"><path d="M12 6.5c0-.28-.22-.5-.5-.5h-7a.495.495 0 00-.37.83l3.5 4c.09.1.22.17.37.17s.28-.07.37-.17l3.5-4c.08-.09.13-.2.13-.33z" fill-rule="evenodd"></path></svg></span></div><div class="outer-label"><div class="top pub-header-themed-secondary">last released</div><div class="bottom"><time dateTime="2022-11-03T11:43:49.132Z" title="2022-11-03 11:43">3 years ago</time></div></div></button></div></div><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left details-button"><div class="pub-header-themed-box icon-container"><span icon="expand-all" class="bp3-icon bp3-icon-expand-all"><svg data-icon="expand-all" width="14" height="14" viewBox="0 0 16 16"><path d="M4 7c.28 0 .53-.11.71-.29L8 3.41l3.29 3.29c.18.19.43.3.71.3a1.003 1.003 0 00.71-1.71l-4-4C8.53 1.11 8.28 1 8 1s-.53.11-.71.29l-4 4A1.003 1.003 0 004 7zm8 2c-.28 0-.53.11-.71.29L8 12.59l-3.29-3.3a1.003 1.003 0 00-1.42 1.42l4 4c.18.18.43.29.71.29s.53-.11.71-.29l4-4A1.003 1.003 0 0012 9z" fill-rule="evenodd"></path></svg></span></div><div class="label">Show details</div></button></div></div></div><div class="pub-header-sticky-component"><div class="sticky-title">iOS KnowledgeC.db Notifications</div><div class="sticky-buttons"><button type="button" style="display:inline-flex;-webkit-appearance:unset" aria-expanded="false" aria-controls="id-13" aria-haspopup="menu" aria-label="Table of contents" class="bp3-button bp3-minimal contents-button"><span class="bp3-button-text">Contents</span></button><span class="dot">·</span><button type="button" class="bp3-button bp3-minimal"><span icon="double-chevron-up" class="bp3-icon bp3-icon-double-chevron-up"><svg data-icon="double-chevron-up" width="16" height="16" viewBox="0 0 16 16"><path d="M4 8c.28 0 .53-.11.71-.29L8 4.41l3.29 3.29c.18.19.43.3.71.3a1.003 1.003 0 00.71-1.71l-4-4C8.53 2.11 8.28 2 8 2s-.53.11-.71.29l-4 4A1.003 1.003 0 004 8zm4.71-.71C8.53 7.11 8.28 7 8 7s-.53.11-.71.29l-4 4a1.003 1.003 0 001.42 1.42L8 9.41l3.29 3.29c.18.19.43.3.71.3a1.003 1.003 0 00.71-1.71l-4-4z" fill-rule="evenodd"></path></svg></span></button></div></div></div><div class="pub-document-component"><div class="pub-grid"><div class="main-content"><main class="pub-body-component"><div class="editor ProseMirror read-only"><h1 id="synopsis">Synopsis</h1><div class="tableWrapper" id="7pnvpve7ye" data-smaller-font="false"><table><tbody><tr><td><p id="ca09dpu7kq"><strong>Forensics Question:</strong> <br/>What are the different types of notifications we will have from the KnowledgeC.db and what do they mean? </p><p id="ncf47u53que">Can we determine if the user interacted with device after a notification was received and displayed on an iPhone?</p></td><td><p id="n4x03e4rspv"></p><figure id="3z7uqe08aw" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/otm7hspl/01604324623084.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im90bTdoc3BsLzAxNjA0MzI0NjIzMDg0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im90bTdoc3BsLzAxNjA0MzI0NjIzMDg0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im90bTdoc3BsLzAxNjA0MzI0NjIzMDg0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im90bTdoc3BsLzAxNjA0MzI0NjIzMDg0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="3z7uqe08aw-figure-caption"><div><div></div></div></figcaption></figure></td></tr><tr><td><p id="tapzxzhb9k"><strong>OS Version:</strong> <br/>iOS 14.7.1 (18G82)</p><p id="n591ehow3km">iOS 14.4.2 (18D70)<br/></p></td><td><figure id="nlkqjkuo9y6" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/9636kems/61615840870473.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Ijk2MzZrZW1zLzYxNjE1ODQwODcwNDczLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Ijk2MzZrZW1zLzYxNjE1ODQwODcwNDczLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Ijk2MzZrZW1zLzYxNjE1ODQwODcwNDczLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Ijk2MzZrZW1zLzYxNjE1ODQwODcwNDczLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="nlkqjkuo9y6-figure-caption"><div><div></div></div></figcaption></figure></td></tr><tr><td><p id="zc8ryi5sxh"><strong>Tools:</strong> </p><p id="nvoaf3co3p6">Cellebrite UFED 4PC 7.47.0.247</p><p class="MsoNoSpacing" id="ncw27heev64">Cellebrite Physical Analyzer 7.48.1.3 – Does not decode KnowledgeC.db /notification/usage</p><p class="MsoNoSpacing" id="nckft86vwnj">Magnet AXIOM 5.4.0.26185</p><p class="MsoNoSpacing" id="nceajwn8y1k">ArtEx 2.0.0.4</p><p class="MsoNoSpacing" id="nbjt1sjuitt">iLEAPP 1.9.4 – Does not decode KnowledgeC.db /notification/usage</p><p class="MsoNoSpacing" id="nbuqnlrxgak">APOLLO 1.4</p></td><td><p id="n7fsdfw313q"></p></td></tr></tbody></table></div><h1 id="introduction">Introduction</h1><p id="nl0q2rww66z">Cell phone use is routine. Our cell phones are really an extension of ourselves. We carry them around not only to make calls and messages, but they are also our daily planners, to-do lists, and entertainment resources. We use them at all times of the day – the alarms in the morning, email and social media all day, listening to music, and even reading books at night in bed. They can be a distraction, but does that stop us from checking them all day, especially when a notification pops up? Sometimes we just look to see what the notification is and move on with our business. Sometimes, a notification needs to be handled right away. How do iPhones, or at least those running iOS 14, store notifications, and what happened with those notifications?</p><p class="MsoNoSpacing" id="nrwcv8qmnd4"> While using some commercial and some free forensic tools, I noticed very few of them decode the <em><strong>KnowledgeC.db/notification/usage</strong></em> data. The ones that do provide very little information about what the notification types mean.</p><p class="MsoNoSpacing" id="nkdnqwptlml"> Thanks to Sarah Edwards and several others who previously researched the <em><strong>KnowledgeC.db, </strong></em>we know it to be a great artifact. It can be used to determine a lot of device activities and a user’s pattern of life, but can we use that data to determine if a user interacted with the device after it received a notification?</p><p class="MsoNoSpacing" id="nimj8k7ahy7"> Based on previous research and publications, in conjunction this research, I believe not only can we determine if a user interacted with the device after receiving a notification, but I also believe we can determine how and when that interaction occurred.</p><p id="ndb9vfz2fs4"></p><h2 id="artifact-location"><strong>Artifact Location:</strong></h2><p class="MsoNoSpacing" id="nvib9kmh5zf">· <em><strong>private\var\mobile\Library\CoreDuet\Knowledge\</strong></em></p><p class="MsoNoSpacing" id="no3ykjo5d3i">The notification data I will be discussing is stored in the <em><strong>KnowledgeC.db ZOBJECTS </strong></em>table and<em><strong>ZSTRUCTUREDMETADATA </strong></em>table<em><strong>.</strong></em></p><p class="MsoNoSpacing" id="n0wpm4ffvv1"><em><strong> </strong></em></p><p class="MsoNoSpacing" id="nctss9ttyfv">The data I will be discussing in detail is:</p><p class="MsoNoSpacing" id="nqq1z5wzcic">· <em><strong>ZSTREAMNAME </strong></em>= <em><strong>/notification/usage</strong></em></p><p class="MsoNoSpacing" id="np1gzbdn5kk">· <em><strong>ZVALUESTRING</strong></em> = The notification types, which are listed below</p><p class="MsoNoSpacing" id="noss8wduju1">o <em><strong>Clear</strong></em></p><p class="MsoNoSpacing" id="n1ep3e7zlcw">o <em><strong>DefaultAction</strong></em></p><p class="MsoNoSpacing" id="nh6r8zh16u2">o <em><strong>Dismiss</strong></em></p><p class="MsoNoSpacing" id="n2wz4ijaj5v">o <em><strong>Hidden</strong></em></p><p class="MsoNoSpacing" id="ncnajbhqb2w">o <em><strong>IndirectClear</strong></em></p><p class="MsoNoSpacing" id="nz5je6jt39j">o <em><strong>Orb </strong></em></p><p class="MsoNoSpacing" id="n92f9lkv5vm">o <em><strong>Receive</strong></em></p><p class="MsoNoSpacing" id="nl8xdzl5yts">· <em><strong>Z_DKNOTIFICATIONUSAGEMETADATAKEY__BUNDLEID </strong></em>= the bundle or application for which the notification is related. In the database, the bundle ID is only listed with a <em><strong>Receive</strong></em> notification type.</p><p class="MsoNoSpacing" id="nreey7940hl">· <em><strong>Z_DKNOTIFICATIONUSAGEMETADATAKEY__IDENTIFIER</strong></em> = semi-unique identifier that can be used to link different notification types.</p><p class="MsoNoSpacing" id="n1x2o0s9guj"> </p><p class="MsoNoSpacing" id="ndsw39rc73x"><em><strong>Note:</strong></em> I mention the <em><strong>Z_DKNOTIFICATIONUSAGEMETADATAKEY__IDENTIFIER </strong></em>as a semi-unique identifier because in some cases, like the Do Not Disturb notifications, the identifier repeats itself, but we can still use this to link the notification types together while analyzing the data.</p><p class="MsoNoSpacing" id="ncf26m4j466"> </p><p class="MsoNoSpacing" id="nmw1qkviqn6">Here is a link to GitHub for a SQLite query that might assist with analyzing the database</p><p class="MsoNoSpacing" id="nrn879vlwka"> </p><p class="MsoNoSpacing" id="n4s7fe6zliq"><strong>Device Settings:</strong></p><p class="MsoNoSpacing" id="n5rcn1lweup">When using this data in a forensic analysis, be sure to check the device notification settings. During testing, all applications tested had all notifications turned ON. These are the settings a user can change that could restrict the notification types you might encounter during an analysis. Figure 1 shows the settings menu for the Apple Messenger Application (com.apple.MobileSMS). Please check out the resources section to review additional research.</p><p class="MsoNoSpacing" id="n66n5w4e2ij"> </p><p class="MsoNoSpacing" id="n2uvjrz1z7d"></p><figure id="nwjzs9zwm6t" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/ygt9zlof/21659644944980.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InlndDl6bG9mLzIxNjU5NjQ0OTQ0OTgwLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InlndDl6bG9mLzIxNjU5NjQ0OTQ0OTgwLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InlndDl6bG9mLzIxNjU5NjQ0OTQ0OTgwLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InlndDl6bG9mLzIxNjU5NjQ0OTQ0OTgwLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="nwjzs9zwm6t-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="navqridz0eu"> </p><p class="MsoNoSpacing" id="nojk56cev8m">Figure 1</p><p class="MsoNoSpacing" id="n2nnmze8kqg"> </p><p class="MsoNoSpacing" id="nzfg5wnwttv"><strong>Research and Testing: </strong></p><p class="MsoNoSpacing" id="nmtd1aniyc9">The following sections will demonstrate how I was able to determine each notification type and how I recreated them in testing. </p><p class="MsoNoSpacing" id="nz7vw606qax"> </p><p class="MsoNoSpacing" id="n5z8blelkkc"><em><strong>Note</strong></em>: During testing, Magnet AXIOM, ArtEx, and APOLLO parsed the <em><strong>KnowledgeC.db</strong></em> notifications. Cellebrite Physical Analyzer and iLEAPP did not. iLEAPP had a section for iOS notifications, but the data was being parsed from<em><strong>DeliveredNotifications.plist, </strong></em>not the notifications from <em><strong>KnowledgeC.db,</strong></em> review the resources for additional information. </p><p class="MsoNoSpacing" id="npmj3lacz2t"> </p><p class="MsoNoSpacing" id="n45x0gys5bq">During testing, the test device was connected to ArtEx via ArtExtraction – Live Connection. This allowed me to run multiple tests, and I did not have to repeatedly acquire full file system dumps. The acquisition methods and tools listed above were used to validate what was being displayed in ArtEx. </p><p class="MsoNoSpacing" id="nafkquv0zbs"> </p><p class="MsoNoSpacing" id="nf5u57gbgnk"><em><strong>Note:</strong></em> If you are a curious how to perform your own testing using ArtEx, here is a link to a recorded session of Cellebrite’s Ctrl + Alt + Del where ArtEx creator Ian Whiffin discusses how to use the ArtEx Live Connection to conduct research: <a href="https://www.cellebrite.com/en/using-artifact-examiner-artex-to-investigate-an-artifact-on-a-device/">https://www.cellebrite.com/en/using-artifact-examiner-artex-to-investigate-an-artifact-on-a-device/</a></p><p class="MsoNoSpacing" id="neqm92odl59"> </p><p class="MsoNoSpacing" id="nqpy1o3mdvp"><strong>Receive Notification Type:</strong></p><p class="MsoNoSpacing" id="ne9tjiiwh6n">A <em><strong>Receive</strong></em> notification type is when a notification is received and displayed on the device. Depending on user interaction and device status the notification could be viewed from the springboard, the Lock Screen and/or the Notification Center. </p><p class="MsoNoSpacing" id="nbkes9bk1j5"> </p><p class="MsoNoSpacing" id="ncfleq4ff3t">Figure 2 has an example of a <em><strong>Receive</strong></em> notification type in ArtEx. During testing, this was created by sending the test device a text message (SMS). The test device screen came on and displayed the notification. After a few seconds, the screen automatically turned OFF and went dark. I did not touch or interact with the device or the screen.</p><p class="MsoNoSpacing" id="na1392iepum"> </p><figure id="n8a1b24dgvf" data-node-type="image" data-size="94" data-align="center" data-url="https://assets.pubpub.org/f6rpcgyb/71659645034872.jpeg" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImY2cnBjZ3liLzcxNjU5NjQ1MDM0ODcyLmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImY2cnBjZ3liLzcxNjU5NjQ1MDM0ODcyLmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjE2MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImY2cnBjZ3liLzcxNjU5NjQ1MDM0ODcyLmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjI0MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImY2cnBjZ3liLzcxNjU5NjQ1MDM0ODcyLmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19" alt=""/><figcaption id="n8a1b24dgvf-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="nim2x12b5ud">Figure 2</p><p class="MsoNoSpacing" id="nee6x8svum8"> </p><p class="MsoNoSpacing" id="nikk9d4sxdn">I turned the screen ON and OFF several times, using side button. During that time, I captured a screenshot of what the notification looked like on the device, seen in Figure 3. This did not affect or change the notification as it remained visible on the Lock Screen.</p><p class="MsoNoSpacing" id="nbwha3v1omv"> </p><p class="MsoNoSpacing" id="ntw6c6leyry"></p><figure id="nic8l5g004w" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/x0iv3gaw/41659645064014.jpeg" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IngwaXYzZ2F3LzQxNjU5NjQ1MDY0MDE0LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IngwaXYzZ2F3LzQxNjU5NjQ1MDY0MDE0LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjE2MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IngwaXYzZ2F3LzQxNjU5NjQ1MDY0MDE0LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjI0MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IngwaXYzZ2F3LzQxNjU5NjQ1MDY0MDE0LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19" alt=""/><figcaption id="nic8l5g004w-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="nsp67sxlin5">Figure 3</p><p class="MsoNoSpacing" id="nk73d6i716d"> </p><p class="MsoNoSpacing" id="nlvfuqspj11">At 2:14 PM, I made a phone call to the test device, which was unanswered. When the phone call was received by the device and the InCallService application was brought into focus. A <em><strong>Receive</strong></em> notification type was created, seen in Figure 4 and Figure 5.</p><p class="MsoNoSpacing" id="nn6e0y0wiqv"> </p><p class="MsoNoSpacing" id="naia5vw25mu"></p><figure id="nm367nxwlcz" data-node-type="image" data-size="100" data-align="center" data-url="https://assets.pubpub.org/xw6lxvgp/21659645088930.jpeg" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Inh3Nmx4dmdwLzIxNjU5NjQ1MDg4OTMwLmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Inh3Nmx4dmdwLzIxNjU5NjQ1MDg4OTMwLmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjE2MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Inh3Nmx4dmdwLzIxNjU5NjQ1MDg4OTMwLmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjI0MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Inh3Nmx4dmdwLzIxNjU5NjQ1MDg4OTMwLmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19" alt=""/><figcaption id="nm367nxwlcz-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="n6bdt2jq72a">Figure 4</p><p class="MsoNoSpacing" id="nivfmie1kin"> </p><p class="MsoNoSpacing" id="nmey298z4cq"></p><figure id="n1ixmfgqi7r" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/re61xtc7/41659645110209.jpeg" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InJlNjF4dGM3LzQxNjU5NjQ1MTEwMjA5LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InJlNjF4dGM3LzQxNjU5NjQ1MTEwMjA5LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjE2MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InJlNjF4dGM3LzQxNjU5NjQ1MTEwMjA5LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjI0MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InJlNjF4dGM3LzQxNjU5NjQ1MTEwMjA5LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19" alt=""/><figcaption id="n1ixmfgqi7r-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="nb4ca3i6cki">Figure 5</p><p class="MsoNoSpacing" id="n07dmcqe7hm"> </p><p class="MsoNoSpacing" id="njj2jump1dq">At 3:35 PM, the test device received a phone call from an unknown source. The phone call was unanswered. There was not any user interaction with the screen. After the phone stopped ringing, the screen turned OFF and went dark. A <em><strong>Receive</strong></em> notification type was recorded via the <em><strong>KnowledgeC.db</strong></em>, seen in Figure 6 and Figure 7. You will notice a <em><strong>Receive</strong></em> notification type for the voicemail which followed the unanswered phone call. </p><p class="MsoNoSpacing" id="nge476zo8yy"> </p><p class="MsoNoSpacing" id="nvcg7eqbotp"><em><strong>Note:</strong></em> During testing, when I answered or declined an incoming phone call, a <em><strong>Receive</strong></em> notification type would not be logged in the <em><strong>KnowledgeC.db</strong></em>. A <em><strong>Receive</strong></em> notification type would be logged in the <em><strong>KnowledgeC.db</strong></em> when a phone call was missed/unanswered and when a voicemail was received. </p><p class="MsoNoSpacing" id="n26t3upu8d5"> </p><p class="MsoNoSpacing" id="n96eyk9n612">These are examples of a<em><strong> Receive</strong></em> notification type that occurred on an iPhone with iOS 14.7.1. These types of notifications will be recorded when a notification is received by the device and when it is displayed on the device screen. In Figure 7, we have four notifications on the test device. There has been no user interaction with the device screen or the notifications.</p><p class="MsoNoSpacing" id="nffk50w1ucl"> </p><p class="MsoNoSpacing" id="n1k8g905kpz"></p><figure id="ndmri46z5ad" data-node-type="image" data-size="100" data-align="center" data-url="https://assets.pubpub.org/7cltj7ts/41659645140886.jpeg" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjdjbHRqN3RzLzQxNjU5NjQ1MTQwODg2LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjdjbHRqN3RzLzQxNjU5NjQ1MTQwODg2LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjE2MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjdjbHRqN3RzLzQxNjU5NjQ1MTQwODg2LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjI0MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjdjbHRqN3RzLzQxNjU5NjQ1MTQwODg2LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19" alt=""/><figcaption id="ndmri46z5ad-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="nj6080qlqek">Figure 6</p><p class="MsoNoSpacing" id="naee3q9n3b2"> </p><p class="MsoNoSpacing" id="nnex9drbiyx"></p><figure id="nngdqlnb77q" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/3l3vopr9/41659645161479.jpeg" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjNsM3ZvcHI5LzQxNjU5NjQ1MTYxNDc5LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjNsM3ZvcHI5LzQxNjU5NjQ1MTYxNDc5LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjE2MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjNsM3ZvcHI5LzQxNjU5NjQ1MTYxNDc5LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjI0MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjNsM3ZvcHI5LzQxNjU5NjQ1MTYxNDc5LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19" alt=""/><figcaption id="nngdqlnb77q-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="np1tthmuosl">Figure 7</p><p class="MsoNoSpacing" id="n7oklhuvdcp"> </p><p class="MsoNoSpacing" id="neemlg2j5c9"><em><strong>Note:</strong></em> If an application is in focus on a device and new application data is received for that specific application, no <em><strong>Receive</strong></em> notification type will be recorded. If the application is running in the background, a <em><strong>Receive</strong></em> notification type will be recorded. Example: if the Apple Messenger application is in focus and additional messages are received, a <em><strong>Receive</strong></em> notification type will not be recorded in the <em><strong>KnowledgeC.db</strong></em>. </p><p class="MsoNoSpacing" id="nbih58yalp5"> </p><p class="MsoNoSpacing" id="n8r11yh7fss"><em><strong>Note:</strong></em> During testing, there was a time when I did not have mobile data service and attempted to send two photos via multimedia messenger. When I attempted to send the messages to an Android device, the iPhone testing device received notifications which indicated the messages failed. The device recorded two <em><strong>Receive</strong></em> notifications. These notifications had the same <em><strong>Z_DKNOTIFICATIONUSAGEMETADATAKEY__IDENTIFIER</strong></em>, so again, just a reminder, these identifiers are semi-unique. There is a chance to have duplicates.</p><p class="MsoNoSpacing" id="nsb48z24n4e"> </p><p class="MsoNoSpacing" id="nobq70f235z"><strong>Hidden Notification Type:</strong></p><p class="MsoNoSpacing" id="nprecnjmfmd">A <em><strong>Hidden</strong></em> notification type will be recorded when a notification is hidden from the Lock Screen notification area. This area can be viewed both when the device is locked and when a user swipes down on the screen to see the Notification Center. </p><p class="MsoNoSpacing" id="nnb0avdikh9"> </p><p class="MsoNoSpacing" id="nfh9ujqjr99">During testing this occurred a few different ways:</p><p class="MsoNoSpacing" id="nrh5ffe1t2d"> </p><p class="MsoNoSpacing" id="n9tyrmdhvbf">· If a device is locked and it receives a notification, it will be displayed on the Lock Screen. When a user unlocks the device and accesses the springboard or an application, the notifications that were displayed on the Lock Screen, will no longer be displayed, thus they are hidden, and <em><strong>Hidden</strong></em> notification types will be recorded in the <em><strong>KnowledgeC.db.</strong></em></p><p class="MsoNoSpacing" id="nuret2mgdt1"> </p><p class="MsoNoSpacing" id="ne3tn74iufk">· If a device is unlocked and the user is navigating the springboard or an application is in focus and a notification is received, a Banner Notification will be displayed on the screen. These notifications will be listed in the Lock Screen area until the device screen turns off, either by a user or a device setting.</p><p class="MsoNoSpacing" id="nofpfq5sv8z"> </p><p class="MsoNoSpacing" id="nspngs98jww"><em><strong>Note:</strong></em> Please review my previous blog about how to determine what value was set for the display auto-lock.</p><p class="MsoNoSpacing" id="nvs4jxjfl8a"><strong> </strong></p><p class="MsoNoSpacing" id="noufshjdya1">In Figure 7, there are four notifications displayed on the Lock Screen. At 4:38:56 PM, the test device was unlocked and I clicked on one of the SMS notification banners. An open button appeared to the left of the notification banner. Instead of clicking on the open button, I clicked on the home button unlocking the device. At that time all the notification banners were hidden from the Lock Screen. I checked the Lock Screen and verified that there were no notification banners visible, seen in Figure 8.</p><p class="MsoNoSpacing" id="nnbpw927pr5"></p><p class="MsoNoSpacing" id="n65mju15y6s"></p><figure id="noc99vra6rq" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/gnpge4xh/21659645179776.jpeg" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImducGdlNHhoLzIxNjU5NjQ1MTc5Nzc2LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImducGdlNHhoLzIxNjU5NjQ1MTc5Nzc2LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjE2MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImducGdlNHhoLzIxNjU5NjQ1MTc5Nzc2LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjI0MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImducGdlNHhoLzIxNjU5NjQ1MTc5Nzc2LmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19" alt=""/><figcaption id="noc99vra6rq-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="npjgujol42p"> </p><p class="MsoNoSpacing" id="nk1y1zkkzwq"> <br/>Figure 8</p><p class="MsoNoSpacing" id="nng0kokdg1f"> </p><p class="MsoNoSpacing" id="na5iz8mshgo">While reviewing the notifications in ArtEx, seen in Figure 9, I noticed there are four <em><strong>Hidden</strong></em> notifications logged at the time I unlocked the device. I researched if there was any way to link the <em><strong>Hidden</strong></em> notification type to the <em><strong>Receive</strong></em>notification type. Reminder, bundle identifications are only recorded with a <em><strong>Receive </strong></em>notification type. </p><p class="MsoNoSpacing" id="nmdc1geqi4b"> </p><p class="MsoNoSpacing" id="nsk5o05d34b"></p><figure id="naclnood97p" data-node-type="image" data-size="100" data-align="center" data-url="https://assets.pubpub.org/srbb2kft/11659645191340.jpeg" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InNyYmIya2Z0LzExNjU5NjQ1MTkxMzQwLmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InNyYmIya2Z0LzExNjU5NjQ1MTkxMzQwLmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjE2MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InNyYmIya2Z0LzExNjU5NjQ1MTkxMzQwLmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjI0MDAsImZpdCI6Imluc2lkZSIsIndpdGhvdXRFbmxhcmdlbWVudCI6dHJ1ZX19fQ== 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InNyYmIya2Z0LzExNjU5NjQ1MTkxMzQwLmpwZWciLCJlZGl0cyI6eyJyZXNpemUiOnsid2lkdGgiOjgwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19" alt=""/><figcaption id="naclnood97p-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="ngrdojbliqm">Figure 9</p><p class="MsoNoSpacing" id="nz0pk2qo0j8"> </p><p class="MsoNoSpacing" id="n7e8wc4pxlh">As seen in Figure 10, I noticed Magnet AXIOM was parsing the <em><strong>ZSTRUCTUREDMETADATA table Z_DKNOTIFICATIONUSAGEMETADATAKEY__IDENTIFIER</strong></em> with the notifications. After additional testing, I was able to determine this is the value that can be used to link related notification types together.</p><p class="MsoNoSpacing" id="n5345gexi4g"> </p><p class="MsoNoSpacing" id="nhnfc5dyyn4"></p><figure id="njbo794270x" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/awupvpuf/61659645213845.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImF3dXB2cHVmLzYxNjU5NjQ1MjEzODQ1LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImF3dXB2cHVmLzYxNjU5NjQ1MjEzODQ1LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImF3dXB2cHVmLzYxNjU5NjQ1MjEzODQ1LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImF3dXB2cHVmLzYxNjU5NjQ1MjEzODQ1LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="njbo794270x-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="nqrdcxfafyh">Figure 10</p><p class="MsoNoSpacing" id="nbju8udwww3"> </p><p class="MsoNoSpacing" id="n00ubs27g83">In Figure 11, we can see the data stored in the <em><strong>KnowledgeC.db</strong></em> when the 4 notifications were received. Then we can see when the notifications are hidden from the lock screen and when they are cleared from the Notification Center. Later I will discuss the <em><strong>IndirectClear</strong></em> notification type and describe how and why this happened, see the <em><strong>IndirectClear</strong></em> section for more details. </p><p class="MsoNoSpacing" id="nlxd8ayiq9l"> </p><p class="MsoNoSpacing" id="n3n71721igl"></p><p class="MsoNoSpacing" id="ny9rbm6r1eq">Figure 11</p><p class="MsoNoSpacing" id="n0ecpn6kas8"> </p><p class="MsoNoSpacing" id="n78niqmv8yx">In the next example, the test device received a SMS notification, Facebook Messenger notification and a Twitter notification. When the notifications were received there was no user interaction with the device. The screen turned ON and OFF on its own. After the three notifications were received, the test device was unlocked by clicking the home button and all notifications were hidden from the Lock Screen. These notifications can still be visible in the Notification Center. </p><p class="MsoNoSpacing" id="nrrdahddoe1"> </p><p class="MsoNoSpacing" id="n6b51r0flak">In Figure 12 we can see the activity for the three notifications that were received and hidden. When the notifications were hidden from the Lock Screen, <em><strong>Hidden</strong></em> notification types were recorded for each notification. Figure 12 shows how these actions look like on the device and in the <em><strong>KnowledgeC.db</strong></em>.</p><p class="MsoNoSpacing" id="n0o0pf9cd9f"> </p><p class="MsoNoSpacing" id="nw40l14lm1u"></p><p class="MsoNoSpacing" id="nfw6920arad"></p><p class="MsoNoSpacing" id="ndufa7efeqr">Figure 12</p><p class="MsoNoSpacing" id="n1r9va0ylet"> </p><p class="MsoNoSpacing" id="now02rz6m5d">The previous examples had user – device interaction. Based on the testing, <em><strong>Hidden</strong></em> notifications can be both user and non-user initiated.</p><p class="MsoNoSpacing" id="n1r0hgdvm00"> </p><p class="MsoNoSpacing" id="n4emdjcro8j">In Figure 13, the Notification Center is checked for any active notifications, which there are none. The device is unlocked, and the Facebook Messenger is brought into focus. While the application was in focus, the device received a notification for a SMS message. There was no user interaction with this notification, and it disappears from the screen on its own. Another message is received, and another Banner Notification is displayed, it also did not have any user interaction and disappears on its own.</p><p class="MsoNoSpacing" id="n5jfs5vufsq"> </p><p class="MsoNoSpacing" id="nxb16beyyq4">The Facebook Messenger application was sent to the background, and we can see the messenger application still has a badge notification count, these will only be cleared after the application data is viewed or handled within the application. When the notifications were received, the messenger application was running in the background. All the applications were closed, except for the Facebook Messenger application. While the Facebook Messenger application was in focus, a Facebook Messenger message was received. Notice the device did not display a Banner Notification, as previously seen with the SMS notifications. </p><p class="MsoNoSpacing" id="n8m0n1cgu7l"> </p><p class="MsoNoSpacing" id="ng5tmd5gd84">After the screen is turned off and the device is locked, we can only see the two SMS notifications are displayed in the Notification Center. The Facebook Messenger message did not generate a <em><strong>Receive</strong></em> notification type and will not be listed in the <em><strong>KnowledgeC.db</strong></em>.</p><p class="MsoNoSpacing" id="nnlzm4jmnig"> </p><p class="MsoNoSpacing" id="nvw4z2l6uxp"></p><p class="MsoNoSpacing" id="n3elkkpqb8l">Figure 13</p><p class="MsoNoSpacing" id="n7son2otz2m"> </p><p class="MsoNoSpacing" id="nd9uwqfcxdk"><strong>Clear Notification Type:</strong></p><p class="MsoNoSpacing" id="nxw9ovw450z">A <em><strong>Clear</strong></em> notification type occurs when a user manually swipes left on the notification banner displayed in the Lock Screen or in the Notification Center, by doing so, reveals a clear button. When the user presses the clear button for an individual notification or the clear all buttons. It removes the notification from the Lock Screen and the Notification Center.</p><p class="MsoNoSpacing" id="n81nuk1wck1"> </p><p class="MsoNoSpacing" id="n8yut1qolm7"><em><strong>Note:</strong></em> A corresponding <em><strong>IndirectClear</strong></em> notification type will also be recorded with a matching timestamp as the <em><strong>Clear</strong></em>notification type. Review the <em><strong>IndirectClear</strong></em> notification type section for more details. </p><p class="MsoNoSpacing" id="n765hxf7b7d"><strong> </strong></p><p class="MsoNoSpacing" id="nyxb0hbmphy">In Figure 14, the test device receives a notification for an incoming SMS message. Then at 7:45:55 PM, another notification is received for a second incoming SMS message.</p><p class="MsoNoSpacing" id="n392v6863tr"> </p><p class="MsoNoSpacing" id="nuai384o7x1">The user accessed the Lock Screen notifications, swiped left on the second notification, and pressed the clear button. The notification was removed from the Lock Screen and will not be displayed in the Notification Center. After analyzing the database, when the clear button is selected, that specific notification will have both a <em><strong>Clear </strong></em>notification type and an <em><strong>IndirectClear</strong></em> notification type with the same timestamp. <em><strong> </strong></em></p><p class="MsoNoSpacing" id="nxnix5ak5n1"> </p><p class="MsoNoSpacing" id="nmk6o4gr90e">The user then accessed the Lock Screen, swiped right on the notification banner, and clicked the open button. The Messenger application was brought into focus and the message was viewed within the application. After analyzing the database when the open button was selected, that specific notification would have both a <em><strong>DefaultAction</strong></em> notification type and an <em><strong>IndirectClear</strong></em> notification type with the same timestamp. Review the <em><strong>DefaultAction</strong></em> notification type section for more details. </p><p class="MsoNoSpacing" id="n6143oazdw4"> </p><p class="MsoNoSpacing" id="nt7uj3g3gep">In Figure 14 we can see what these actions look like on the device and the data recorded in the <em><strong>KnowledgeC.db</strong></em>. </p><p class="MsoNoSpacing" id="n3rt0h0z4yc"> </p><p class="MsoNoSpacing" id="n5o0mh5crt5"></p><p class="MsoNoSpacing" id="nbqwypzu1ur">Figure 14</p><p class="MsoNoSpacing" id="nn6hj6uznvt"> </p><p class="MsoNoSpacing" id="nb65prefryk"><strong>Dismiss Notification Type:</strong></p><p class="MsoNoSpacing" id="n3ntrhen6tr">If a device is unlocked and the screen is ON when a notification is received, if the user swipes up on the notification, before it disappears on its own, a <em><strong>Dismiss</strong></em> notification type will be recorded in the <em><strong>KnowledgeC.db</strong></em>.</p><p class="MsoNoSpacing" id="n518ozpr2ym"> </p><p class="MsoNoSpacing" id="n02f0stku03">In Figure 15, the test device receives a Facebook Messenger message notification. The user swiped up on the notification to dismiss it. Then a SMS message notification is received, and the user swiped up on the notification to dismiss it. The user then locks the device and views the Lock Screen and Notification Center. The two notifications that were dismissed are no longer visible in the Lock Screen notification area, but they are displayed in the Notification Center. </p><p class="MsoNoSpacing" id="ncmeswzlhgg"> </p><p class="MsoNoSpacing" id="n2hh9y0asjj">The SMS notification is cleared from the Notification Center and the Facebook Messenger notification is opened, thus bringing the Facebook Messenger application into focus. Figure 15, shows what this looks like on the device and how the data is recorded in the <em><strong>KnowledgeC.db</strong></em>.</p><p class="MsoNoSpacing" id="n740w9afpzb"> </p><p class="MsoNoSpacing" id="niwu2t4mt7a"></p><p class="MsoNoSpacing" id="njtorio4npf">Figure 15</p><p class="MsoNoSpacing" id="nuvzwpiiu9b"> </p><p class="MsoNoSpacing" id="nk8cn7v3dpj"><strong>IndirectClear Notification Type:</strong></p><p class="MsoNoSpacing" id="n6702oyyqp7">An <em><strong>IndirectClear</strong></em> notification type will occur when a notification is no longer displayed in the Notification Center. </p><p class="MsoNoSpacing" id="ndizdqcsxrp"> </p><p class="MsoNoSpacing" id="n04a9664bgk">In Figure 16 the test device as already received two notifications, one from a SMS message and another from Twitter. An additional Facebook Messenger message notification is received. At this time, the test device is locked, and the screen is turning ON when the notifications are received, then back OFF on its own after the notification has been displayed. Another Twitter notification is received and displayed. Special thanks to Kevin Pagano (@KevinPagano3) for his assistance with an additional notification during testing! An additional SMS message notification was received.</p><p class="MsoNoSpacing" id="nyknef5d7ak"> </p><p class="MsoNoSpacing" id="nlq6i6puapj">The user unlocked the device by pressing the home button. This user action then hid the notifications from the Lock Screen and a <em><strong>Hidden</strong></em> notification type was recorded for each one of the notifications that were displayed on the Lock Screen.</p><p class="MsoNoSpacing" id="nsd3nf1n71h"> </p><p class="MsoNoSpacing" id="n3ebzh19c9t">After the notifications were hidden from the Lock Screen, the user checked the Notification Center, and all the past notifications are still visible. The user entered the Notification Center and used the clear button to clear the Facebook Messenger notification. </p><p class="MsoNoSpacing" id="ndoyn70bbdm"> </p><p class="MsoNoSpacing" id="nipocgmpkie">During testing, I received a phone call from someone reminding me that my vehicle warranty was expired. After receiving the phone call notification, the device was unlocked, and the notification was hidden from the Lock Screen, then the user cleared it from the Notification Center. Then the user cleared one of the SMS notifications from the Notification Center. The user then unlocks the device and views the springboard. Notice that all the badge notification counters are still visible.</p><p class="MsoNoSpacing" id="ncarbbs4r4i"> </p><p class="MsoNoSpacing" id="n3penouqel3">In Figure 16, we can see what this looks like on the device and how the data is recorded in the <em><strong>KnowledgeC.db</strong></em>.</p><p class="MsoNoSpacing" id="ndxdm6rf6g4"> </p><p class="MsoNoSpacing" id="nt209d7jtro"></p><p class="MsoNoSpacing" id="njxaytswdzz">Figure 16</p><p class="MsoNoSpacing" id="nkbrymxc7tf"> </p><p class="MsoNoSpacing" id="ni7aebpz9xi">An <em><strong>IndirectClear</strong></em> notification type will be recorded when the application is opened which has pending data/badge notifications that have not been viewed. </p><p class="MsoNoSpacing" id="nl0gvujjxiv"> </p><p class="MsoNoSpacing" id="n5egvfdoz46"><strong>DefaultAction Notification Type:</strong></p><p class="MsoNoSpacing" id="nw5dr5wo00z">The <em><strong>DefaultAction</strong></em> notification type occurs when a notification is received and is used to open the application to view the data.</p><p class="MsoNoSpacing" id="nd25pxexrk0"> </p><p class="MsoNoSpacing" id="nb19mqmgc53">We have already seen some examples of the <em><strong>DefaultAction</strong></em> notification type, but we will review it and show how it was replicated during testing.</p><p class="MsoNoSpacing" id="nzw2558itys"> </p><p class="MsoNoSpacing" id="nh13xg2qc57">In this first example, Figure 17, the device was unlocked, and the user was navigating the springboard. The device received a SMS message notification, which was displayed on the device in a banner notification. The notification banner was clicked, and the Apple Messenger application was opened to view the data. You will notice the <em><strong>DefaultAction</strong></em> and <em><strong>IndirectClear</strong></em> notification types are logged one second apart. </p><p class="MsoNoSpacing" id="nkbjo28w85p"> </p><p class="MsoNoSpacing" id="niscm0hv4mt"></p><p class="MsoNoSpacing" id="nxgh5miojmy">Figure 17 </p><p class="MsoNoSpacing" id="n7ew61c48y0"> </p><p class="MsoNoSpacing" id="njy5k3q286f"><em><strong>Note:</strong></em> When a notification is used to bring an application into focus, the method listed for bringing the application into focus will be <em>com.apple.SpringBoard.transitionReason.externalrequest</em>. I’ll be doing more research into application in focus methods for both iOS 14 and 15 and will be writing something soon, so stay tuned.</p><p class="MsoNoSpacing" id="n8wyt1s8awu"> </p><p class="MsoNoSpacing" id="nj815thbi8m">In Figure 18, the second example, we will be reviewing the data stored in the <em><strong>KnowledgeC.db</strong></em> and attempt to determine what happened on the device, based on what we have already learned in this blog. Based on previous testing I believe:</p><p class="MsoNoSpacing" id="nytbmg6oyff"> </p><p class="MsoNoSpacing" id="nf50dk6gxnp">· On 10/1/2021 at 19:13:14 UTC, the device was unlocked, the screen was on, and the device received a Facebook Messenger notification.</p><p class="MsoNoSpacing" id="n0xbzkvoyur"> </p><p class="MsoNoSpacing" id="nqhdwglpbs8">· At 19:13:16 UTC, the device user swiped up on the notification to dismiss it.</p><p class="MsoNoSpacing" id="n2qp9jn5yqr"> </p><p class="MsoNoSpacing" id="nzxp9r9r7cn">· At 19:13:48 UTC, the notification was hidden from the Lock Screen. </p><p class="MsoNoSpacing" id="ntl675ud79m"> </p><p class="MsoNoSpacing" id="nycrqp2qg97">· At 19:14:23 UTC, the device user accessed the Notification Center and opened the notification, which then brought the Facebook Messenger into focus.</p><p class="MsoNoSpacing" id="nmkyx1xg8an"> </p><p class="MsoNoSpacing" id="n4mtas9c8uz"></p><p class="MsoNoSpacing" id="njmkmxmahxa">Figure 18</p><p class="MsoNoSpacing" id="np2bu3nrt7o"> </p><p class="MsoNoSpacing" id="nt4q0dho241">In Figure 19 and can see what these device events look like in ArtEx.</p><p class="MsoNoSpacing" id="nq6my7tk7ge"> </p><p class="MsoNoSpacing" id="ntrpuf9199c"></p><p class="MsoNoSpacing" id="nwg2vyrm1a5">Figure 19</p><p class="MsoNoSpacing" id="nax0x3f2tog"> </p><p class="MsoNoSpacing" id="njzj90iic0y"><strong>Orb Notifications: </strong></p><p class="MsoNoSpacing" id="n18c47lq8m5">I have not been able to determine exactly what <em><strong>Orb</strong></em> stands for and if anyone could provide some insight it would be appreciated.</p><p class="MsoNoSpacing" id="nn3eijxpjo4"> </p><p class="MsoNoSpacing" id="nhze6259tre">During testing, I would receive an <em><strong>Orb</strong></em> notification type in the <em><strong>KnowledgeC.db</strong></em> when a notification was received, and I interacted with the notification on the device screen. When I pressed and held the notification, the application would open in a small sub-window on the device. I could send messages or preform other actions within the application from this small sub-window. The following are some examples:</p><p class="MsoNoSpacing" id="nirjk1x5750"> </p><p class="MsoNoSpacing" id="nes2xh2s6gj"><strong>Do not Disturb Notification:</strong></p><p class="MsoNoSpacing" id="n79tjlbirwk">During testing, I received several Do Not Disturb While Driving notifications. While the notification was displayed on the Lock Screen, if I clicked on the notification a sub-window would appear and an option to select, <em><strong>I’m Not Driving</strong></em>would be displayed. When this small sub-window with this option would be displayed on the screen, I would receive an <em><strong>Orb</strong></em> notification type in the <em><strong>KnowledgeC.db</strong></em>, seen in Figure 20.</p><p class="MsoNoSpacing" id="n7x3w69je44"> </p><p class="MsoNoSpacing" id="nwxwoyof85o"></p><p class="MsoNoSpacing" id="n2w1nm35j22">Figure 20</p><p class="MsoNoSpacing" id="n87bbxbip9u"> </p><p class="MsoNoSpacing" id="nuggr7f1k6p"><strong>Apple Messenger:</strong></p><p class="MsoNoSpacing" id="nh7zrk3pg55">During testing, I was able to replicate the <em><strong>Orb</strong></em> notification type by sending a SMS message to the test device, then clicking on the notification and opening the Apple Messenger application in a small sub-window, which allowed me to interact with the application in the small sub-window, which included sending a text message, while the device was locked as seen in Figure 21.</p><p class="MsoNoSpacing" id="ni6y82udrwf"> </p><p class="MsoNoSpacing" id="nz33ltwek2g"></p><p class="MsoNoSpacing" id="nkecrlkbn46">Figure 21</p><p class="MsoNoSpacing" id="nqh68s1g08t"> </p><p class="MsoNoSpacing" id="nzbe0pewbfl"><strong>Josh Hickman Image Testing:</strong></p><p class="MsoNoSpacing" id="n3ijoca6spp">After my testing, I decided to test my knowledge of these notifications and loaded up Josh Hickman’s iPhone SE iOS 14.3 image into ArtEx.</p><p class="MsoNoSpacing" id="nop57k9woin"> </p><p class="MsoNoSpacing" id="nxf63n6a09p"><strong>Facebook Messenger:</strong></p><p class="MsoNoSpacing" id="n45idad6zqb">In Josh Hickman’s documentation there is a section for Facebook Messenger, which is displayed in Figure 22. Notice in Figure 22, his test device sends and receives several messages, media messages and video calls. </p><p class="MsoNoSpacing" id="ns7ad59bywx"> </p><p class="MsoNoSpacing" id="nv7tw5v7vdx"></p><figure id="n3jmmkm4xr9" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/a3h3obwr/01659645334113.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImEzaDNvYndyLzAxNjU5NjQ1MzM0MTEzLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImEzaDNvYndyLzAxNjU5NjQ1MzM0MTEzLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImEzaDNvYndyLzAxNjU5NjQ1MzM0MTEzLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImEzaDNvYndyLzAxNjU5NjQ1MzM0MTEzLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="n3jmmkm4xr9-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="nujyczs68rq">Figure 22</p><p class="MsoNoSpacing" id="nz6z6ik8wfd"> </p><p class="MsoNoSpacing" id="npfc2ph6kgm">Figure 23 is that same timeframe viewed in ArtEx. Notice between 14:32 though 15:18, no new notifications were being received on the device. This is because the Facebook Application was in focus, and everything is occurring in real time on the device. </p><p class="MsoNoSpacing" id="n6fmd06dafo"> </p><p class="MsoNoSpacing" id="n2npcp8ws8x">At 15:24:14 there is a Receive notification type for Google Duo (com.google.Tachyon). </p><p class="MsoNoSpacing" id="nrvqofljunr"> </p><p class="MsoNoSpacing" id="n5pbsma5tnf"></p><figure id="ngirwvo6op8" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/slwk1j4u/71659645349084.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InNsd2sxajR1LzcxNjU5NjQ1MzQ5MDg0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InNsd2sxajR1LzcxNjU5NjQ1MzQ5MDg0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InNsd2sxajR1LzcxNjU5NjQ1MzQ5MDg0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InNsd2sxajR1LzcxNjU5NjQ1MzQ5MDg0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="ngirwvo6op8-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="njl0rnrke55">Figure 23 </p><p class="MsoNoSpacing" id="ny2psc7m54g"> </p><p class="MsoNoSpacing" id="nfg439fhyzd"><strong>Google Duo:</strong></p><p class="MsoNoSpacing" id="nfp7uz3la2j">In Josh Hickman’s documentation there is a section for Google Duo, which is displayed in Figure 24. Notice in Figure 24, there is documentation that on 2/4/2021 at 15:24, a note is received, which contained a message <em>What is this??</em> </p><p class="MsoNoSpacing" id="ne1py2dxsmo"> </p><p class="MsoNoSpacing" id="nxqcjbh6yrw"></p><figure id="n6vw8u7g7ka" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/2by364ya/61659645369647.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjJieTM2NHlhLzYxNjU5NjQ1MzY5NjQ3LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjJieTM2NHlhLzYxNjU5NjQ1MzY5NjQ3LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjJieTM2NHlhLzYxNjU5NjQ1MzY5NjQ3LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjJieTM2NHlhLzYxNjU5NjQ1MzY5NjQ3LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="n6vw8u7g7ka-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="n843txpi9qa">Figure 24</p><p class="MsoNoSpacing" id="nkqaz3zs5jy"> </p><p class="MsoNoSpacing" id="ngne210d61i">Figure 25 is that same timeframe viewed in ArtEx. Notice there is a <em><strong>Receive</strong></em> notification type, followed by a <em><strong>DefaultAction</strong></em>, then an <em><strong>IndirectClear</strong></em> notification type. This indicates that when the notification was received on the device, the user used the notification to bring the application into focus. We can see in ArtEx the application started in focus at 15:24:20, which is one second after the <em><strong>DefaultAction</strong></em> notification type was logged. </p><p class="MsoNoSpacing" id="nbiyzl4b66j"> </p><p class="MsoNoSpacing" id="nr56mxe2hzo"></p><figure id="nfj9hfvz1zg" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/e5gexzku/11659645383334.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImU1Z2V4emt1LzExNjU5NjQ1MzgzMzM0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImU1Z2V4emt1LzExNjU5NjQ1MzgzMzM0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImU1Z2V4emt1LzExNjU5NjQ1MzgzMzM0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImU1Z2V4emt1LzExNjU5NjQ1MzgzMzM0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="nfj9hfvz1zg-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="n1ov6ya7m26">Figure 25</p><p class="MsoNoSpacing" id="nj89b46ii5e"> </p><p class="MsoNoSpacing" id="nr9uihukz3a"><strong>Messenger Application:</strong></p><p class="MsoNoSpacing" id="n4rhqhf3suf">In Josh Hickman’s documentation there is a section for Messages, which is displayed in Figure 26. Notice in Figure 26, there is documentation that on 2/15/2021 at 13:06 (Eastern Time) an iMessage is received. Because Josh Hickman’s device is set to Eastern Time and I am in Pacific Time, for this example I will be referencing artifacts in UTC.</p><p class="MsoNoSpacing" id="n2yo4j8jj13"> </p><p class="MsoNoSpacing" id="nz94qdcxr1f"></p><figure id="nulkplczenl" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/nv5e6s6l/11659645395392.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im52NWU2czZsLzExNjU5NjQ1Mzk1MzkyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im52NWU2czZsLzExNjU5NjQ1Mzk1MzkyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im52NWU2czZsLzExNjU5NjQ1Mzk1MzkyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im52NWU2czZsLzExNjU5NjQ1Mzk1MzkyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="nulkplczenl-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="nk8faw3xikd">Figure 26</p><p class="MsoNoSpacing" id="nul08wl9o1l"> </p><p class="MsoNoSpacing" id="njnrx87hyfy">According to Josh Hickman’s documentation his device received an iMessage at 18:06 UTC. Can we answer the following questions?</p><p class="MsoNoSpacing" id="nuhh0tq9l0l"> </p><p class="MsoNoSpacing" id="nt909dr1lyo">· Did the device display a notification on the screen for this message?</p><p class="MsoNoSpacing" id="neyx71umkwp">· Did the user interact with the screen if a notification was displayed?</p><p class="MsoNoSpacing" id="n3eyqujgzr4">· How was the notification cleared from the device?</p><p class="MsoNoSpacing" id="n5w29ub7nxo"> </p><p class="MsoNoSpacing" id="n4th7qbi22i">In Figure 27, we can see in ArtEx at 18:04:18 UTC, the device was unlocked, but notice an application was not in focus. A message was sent at 18:04:46 UTC, but was not sent from the iPhone, it was sent from a synced Mac.</p><p class="MsoNoSpacing" id="nftofxpnkty"> </p><p class="MsoNoSpacing" id="n8jxmsyqu3g">At 18:06:37 UTC, a <em><strong>Receive</strong></em> notification type was received on the device, thus because the device is unlocked, a banner notification would have been displayed on the screen. </p><p class="MsoNoSpacing" id="nsu04wipmfa"> </p><p class="MsoNoSpacing" id="n9z9zubdzrd">At 18:06:37 UTC, a <em><strong>Dismiss</strong></em> notification type was recorded, thus when the banner notification was displayed on the device, the user interacted with the screen and dismissed the banner notification.</p><p class="MsoNoSpacing" id="n16blvpxx4p"> </p><p class="MsoNoSpacing" id="n4e22bg7rf9">At 18:06:49 UTC, the Messenger application (com.apple.MobileSMS) was brought into focus via the home screen.</p><p class="MsoNoSpacing" id="ntxlzsk6hh3"> </p><p class="MsoNoSpacing" id="nwru0gqec9h">Note: If the notification was used to open the application a <em><strong>DefaultAction</strong></em> notification type would have been recorded and the method of bringing the application into focus would have been different. </p><p class="MsoNoSpacing" id="n0k105vgijh"> </p><p class="MsoNoSpacing" id="ns8tyjje0zn">At 18:06:52 UTC, a <em><strong>IndirectClear</strong></em> notification type was recorded because the application was opened, and the user viewed the message. The notification will no longer be displayed on the Lock Screen or the Notification Center.</p><p class="MsoNoSpacing" id="n6jvv1a3b57"> </p><p class="MsoNoSpacing" id="nweaixynh91">Notice in Figure 27, there are several messages being sent back and forth. Some from the synced Mac and others from the iPhone, but notifications are not being recorded. This is because the Messenger application was in focus when these messages were being sent and received.</p><p class="MsoNoSpacing" id="n30n67ehls2"> </p><p class="MsoNoSpacing" id="npzu8503onr"></p><figure id="njbxqxfwhn1" data-node-type="image" data-size="100" data-align="center" data-url="https://assets.pubpub.org/hg5sk7xp/11659645419980.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImhnNXNrN3hwLzExNjU5NjQ1NDE5OTgwLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImhnNXNrN3hwLzExNjU5NjQ1NDE5OTgwLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImhnNXNrN3hwLzExNjU5NjQ1NDE5OTgwLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImhnNXNrN3hwLzExNjU5NjQ1NDE5OTgwLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="njbxqxfwhn1-figure-caption"><div><div></div></div></figcaption></figure><p class="MsoNoSpacing" id="n12mpzt0d0j">Figure 27</p><p class="MsoNoSpacing" id="nnyyiss4tu2"> </p><p class="MsoNoSpacing" id="nrvyrb0nbxu">In Figure 28, I have combined ArtEx and the <em><strong>KnowledgeC.db</strong></em> date in a video to again show how this works together. </p><p class="MsoNoSpacing" id="nqgpstyf8lg"> </p><p class="MsoNoSpacing" id="nxaueoahhzl"></p><p class="MsoNoSpacing" id="nhglyzesroa">Figure 28 </p><p class="MsoNoSpacing" id="n8geeyhanhi"> </p><h2 id="considerations"><strong>Considerations:</strong></h2><p class="MsoNoSpacing" id="ncrm652y4j8">Most of this testing was done on a device with iOS 14.7.1, but I believe the results of this testing should be true with other versions of iOS 14.</p><p class="MsoNoSpacing" id="nuv0ei8zh0i">I plan to conduct some additional testing on how device notifications are stored if the device is connected to a vehicle with and without CarPlay. I have done some preliminary testing, and it appears to be very similar to what has already been detailed in this blog. I will add any additional information learned to this blog later. </p><h2 id="conclusion"><strong>Conclusion:</strong></h2><p class="MsoNoSpacing" id="ngawthbjcui">I believe it has been demonstrated there are certain types of notifications that can be used, in conjunction with other device data, to prove whether a user interacted with a device at a certain time. </p><p class="MsoNoSpacing" id="n34q7jbqnik"> Based on testing<em><strong> ZVALUESTRING</strong></em> is the notification types and each notification type is created when:</p><p class="MsoNoSpacing" id="nt24v90ywnj">· Clear = Notification was cleared by a user via the Lock Screen or Notification Center </p><p class="MsoNoSpacing" id="nou1lwownkm">· DefaultAction = An application is opened via a notification</p><p class="MsoNoSpacing" id="n6m6nq5ux3v">· Dismiss = Notification was dismissed by a device user when the notification was received</p><p class="MsoNoSpacing" id="npo097y033a">· Hidden = When notifications are hidden from the Lock Screen </p><p class="MsoNoSpacing" id="n4xlp1ooy49">· IndirectClear = When notifications are cleared from the Notification Center</p><p class="MsoNoSpacing" id="nt3fxgfg4ao">· Orb = Is triggered via user interaction when an application is opened in a small sub-window </p><p class="MsoNoSpacing" id="nbdn8btnrsi">· Receive = Is when a notification is received and displayed on the device</p><p class="MsoNoSpacing" id="ndzv11zbwzv"> </p><h2 id="references"><strong>References:</strong></h2><p class="MsoNoSpacing" id="n7snoay3rnt">· August 2018 – Sarah Edwards</p><p class="MsoNoSpacing" id="nf8gpz2ap0w">o <a href="https://www.mac4n6.com/blog/2018/8/5/knowledge-is-power-using-the-knowledgecdb-database-on-macos-and-ios-to-determine-precise-user-and-application-usage">https://www.mac4n6.com/blog/2018/8/5/knowledge-is-power-using-the-knowledgecdb-database-on-macos-and-ios-to-determine-precise-user-and-application-usage</a></p><p class="MsoNoSpacing" id="n7hjukup0h2"> </p><p class="MsoNoSpacing" id="nbqcwu9lzb8">o <a href="https://objectivebythesea.com/v3/talks/OBTS_v3_sEdwards.pdf">https://objectivebythesea.com/v3/talks/OBTS_v3_sEdwards.pdf</a></p><p class="MsoNoSpacing" id="ngcjlie88xu"> </p><p class="MsoNoSpacing" id="nz3a6rmt723">· August 2019 – Christopher Vance </p><p class="MsoNoSpacing" id="n2290cuwg3n">o <a href="https://blog.d204n6.com/2019/08/ios-12-delivered-notifications-and-new.html?m=1">https://blog.d204n6.com/2019/08/ios-12-delivered-notifications-and-new.html?m=1</a></p><p class="MsoNoSpacing" id="ny5v3pwosdd"> </p><p class="MsoNoSpacing" id="nfsemk0t7l4">· October 2019 – Ian Whiffin</p><p class="MsoNoSpacing" id="ns1grm844h8">o <a href="http://www.doubleblak.com/m/blogPosts.php?id=2">http://www.doubleblak.com/m/blogPosts.php?id=2</a></p><p class="MsoNoSpacing" id="n70tcjun9zd"> </p><p class="MsoNoSpacing" id="nkkrwuhkpry">· Josh Hickman’s Test Device images:</p><p class="MsoNoSpacing" id="ndnmnueny7o">o <a href="https://thebinaryhick.blog/">https://thebinaryhick.blog/</a></p><h1 id="dfir-review">DFIR Review</h1><p id="ntf0p5omsp0">Determining what notifications, if any, were displayed on a mobile device is a common question asked of forensic examiners. Taking it a step further, understanding what a user of a device did when they were presented with a notification can provide user behavior patterns. The author of this paper demonstrated their understanding of the KnowledgeC and the gaps in research associated with notifications. </p><p id="n2uhabbbx5o">Reviewers found that some of the figures in the paper were missing or could not be viewed.</p><p id="nk5sxaa4xp6">As the Notification Center may be available from the lock screen, examiners should be cautioned on attributing interactive behavior to a a specific individual without performing additional analysis.</p><h1 id="future-work-provided-by-dfir-review">Future Work (provided by DFIR Review)</h1><p id="nixk5lpcwsb">Reviewers are interested in seeing additional values for ZVALUESTRING and additional data that may be associated with device usage. Reviewers also suggested not using video attachments in the submission, if possible, as they do not publish well.</p><p id="nxykm24eus7">Future work on this topic could include testing newer iOS versions to see if anything has changed and testing if additional forensic tools can verify this information. Reviewers also suggested trying different types of applications such as email and also looking at reminders and other alerts.</p><h1 id="reviewers">Reviewers</h1><p id="n7jagjqy3ck">Jessica Hyde, David Loveall (subreviewer) (Methodology Review, Validated Review Using Reviewer Generated Datasets)</p><p id="nc9uc9crzzm">Troy Pugliese (Methodology Review)</p><p id="n0aeen54fx7">Aricia Kulm (Methodology Review)</p><p id="nfee9cdm6ig">Zheng Jie Chan (Methodology Review)</p><p id="nyg39hsr47z"></p><p id="n84np68voka"></p></div></main></div><div class="side-content"></div></div><div class="pub-bottom-component"><div class="inner"><div class="pub-bottom-section-component pub-bottom-license"><div role="none" class="top-row"><div class="left-title">License</div><div class="center-content"><div class="center-content-item"><a target="_blank" rel="license noopener noreferrer" class="license-link" href="https://creativecommons.org/licenses/by/4.0/"><img width="75" alt="" src="/static/license/cc-by.svg" class="license-image"/>Creative Commons Attribution 4.0 International License<!-- --> <!-- -->(CC-BY 4.0)</a></div></div><div class="right-icons" role="none"></div></div></div><div class="pub-bottom-section-component expanded"><div role="button" class="top-row" style="cursor:pointer"><div class="left-title">Comments</div><div class="center-content"><div class="center-content-item">0</div></div><div class="right-icons" role="none"><button type="button" aria-label="Search comments" class="bp3-button bp3-minimal"><span icon="search" class="bp3-icon bp3-icon-search"><svg fill="#2D2E2F" data-icon="search" width="14" height="14" viewBox="0 0 16 16"><path d="M15.55 13.43l-2.67-2.68a6.94 6.94 0 001.11-3.76c0-3.87-3.13-7-7-7s-7 3.13-7 7 3.13 7 7 7c1.39 0 2.68-.42 3.76-1.11l2.68 2.67a1.498 1.498 0 102.12-2.12zm-8.56-1.44c-2.76 0-5-2.24-5-5s2.24-5 5-5 5 2.24 5 5-2.24 5-5 5z" fill-rule="evenodd"></path></svg></span></button><button type="button" aria-label="Sort comments" aria-expanded="false" aria-controls="id-14" aria-haspopup="dialog" class="bp3-button bp3-minimal"><span icon="sort" class="bp3-icon bp3-icon-sort"><svg fill="#2D2E2F" data-icon="sort" width="14" height="14" viewBox="0 0 16 16"><path d="M5 12c-.28 0-.53.11-.71.29l-.29.3V9c0-.55-.45-1-1-1s-1 .45-1 1v3.59l-.29-.29A.965.965 0 001 12a1.003 1.003 0 00-.71 1.71l2 2c.18.18.43.29.71.29s.53-.11.71-.29l2-2A1.003 1.003 0 005 12zm3-9h7c.55 0 1-.45 1-1s-.45-1-1-1H8c-.55 0-1 .45-1 1s.45 1 1 1zm7 2H8c-.55 0-1 .45-1 1s.45 1 1 1h7c.55 0 1-.45 1-1s-.45-1-1-1zm0 8H8c-.55 0-1 .45-1 1s.45 1 1 1h7c.55 0 1-.45 1-1s-.45-1-1-1zm0-4H8c-.55 0-1 .45-1 1s.45 1 1 1h7c.55 0 1-.45 1-1s-.45-1-1-1z" fill-rule="evenodd"></path></svg></span></button><button type="button" aria-label="Filter comments" aria-expanded="false" aria-controls="id-15" aria-haspopup="dialog" class="bp3-button bp3-minimal"><span icon="filter" class="bp3-icon bp3-icon-filter"><svg fill="#2D2E2F" data-icon="filter" width="14" height="14" viewBox="0 0 16 16"><path d="M13.99.99h-12a1.003 1.003 0 00-.71 1.71l4.71 4.71V14a1.003 1.003 0 001.71.71l2-2c.18-.18.29-.43.29-.71V7.41L14.7 2.7a1.003 1.003 0 00-.71-1.71z" fill-rule="evenodd"></path></svg></span></button><button type="button" aria-label="Collapse this section" class="bp3-button bp3-minimal"><span icon="collapse-all" class="bp3-icon bp3-icon-collapse-all"><svg fill="#2D2E2F" data-icon="collapse-all" width="14" height="14" viewBox="0 0 16 16"><path d="M7.29 6.71c.18.18.43.29.71.29s.53-.11.71-.29l4-4a1.003 1.003 0 00-1.42-1.42L8 4.59l-3.29-3.3a1.003 1.003 0 00-1.42 1.42l4 4zm1.42 2.58C8.53 9.11 8.28 9 8 9s-.53.11-.71.29l-4 4a1.003 1.003 0 001.42 1.42L8 11.41l3.29 3.29c.18.19.43.3.71.3a1.003 1.003 0 00.71-1.71l-4-4z" fill-rule="evenodd"></path></svg></span></button></div></div><div class="section-content"><div class="pub-discussions-component"><style> .discussion-list .discussion-thread-component.preview:hover, .discussion-list .discussion-thread-component.expanded-preview { border-left: 3px solid #2D2E2F; padding-left: calc(1em - 2px); } </style><div class="discussion-list"><div class="thread-comment-component input"><div class="avatar-wrapper"><div class="avatar-component" style="width:18px;min-width:18px;height:18px;border-width:0;font-size:7px;background-color:#2D2E2F;z-index:initial;border-radius:50%"><div>?</div></div></div><a role="button" class="bp3-button bp3-small discussion-primary-button" href="/login?redirect=/pub/g2v1z97i/release/1" tabindex="0"><span class="bp3-button-text">Login to discuss</span></a></div><div class="empty-state bp3-non-ideal-state"><div class="bp3-non-ideal-state-visual"><span icon="comment" class="bp3-icon bp3-icon-comment"><svg data-icon="comment" width="60" height="60" viewBox="0 0 20 20"><desc>comment</desc><path d="M19 1H1c-.55 0-1 .45-1 1v12c0 .55.45 1 1 1h3v4a1.003 1.003 0 001.71.71l4.7-4.71H19c.55 0 1-.45 1-1V2c0-.55-.45-1-1-1zM4 10c-1.1 0-2-.9-2-2s.9-2 2-2 2 .9 2 2-.9 2-2 2zm6 0c-1.1 0-2-.9-2-2s.9-2 2-2 2 .9 2 2-.9 2-2 2zm6 0c-1.1 0-2-.9-2-2s.9-2 2-2 2 .9 2 2-.9 2-2 2z" fill-rule="evenodd"></path></svg></span></div><div class="bp3-heading">No comments here</div><div> Why not start the discussion?</div></div></div></div></div></div></div></div><div class="pub-link-controller-component"></div></div></div></div><div class="footer-component accent-background accent-color"><div class="container "><div class="row"><div class="col-12 "><div class="left"></div><div class="right"><div class="footer-title"><a href="/">DFIR Review</a></div><ul class="separated"><li><a class="link" href="/rss.xml">RSS</a></li><li><a class="link" href="/legal">Legal</a></li></ul></div></div></div></div><div class="built-on"><a href="https://www.pubpub.org">Published with<img class="logo" src="/static/logoWhite.svg" alt="PubPub logo"/></a></div></div></div></div><script crossorigin="anonymous" src="https://polyfill-fastly.io/v3/polyfill.min.js?features=default,fetch,HTMLCanvasElement.prototype.toBlob,Node.prototype.contains,Array.prototype.find,Array.from,Number.isNaN,Object.assign,Object.entries,Object.values,Promise,requestIdleCallback,String.prototype.includes,URL,URLSearchParams"></script><script id="initial-data" type="text/plain" data-json="{"communityData":{"id":"b0ac9c28-479a-496c-884c-7ae8fc26e385","subdomain":"dfir","domain":null,"title":"DFIR Review","citeAs":null,"publishAs":null,"description":"DFIR Review responds to the need for a focal point for up-to-date community-reviewed applied research and testing in digital forensics and incident response. DFIR Review concentrates on targeted studies of specific devices, digital traces, analysis methods, and criminal activity","avatar":"https://assets.pubpub.org/3yqqvtl4/71553968763873.png","favicon":"https://assets.pubpub.org/c8g3oakn/41553968740088.png","accentColorLight":"#FFFFFF","accentColorDark":"#2D2E2F","hideCreatePubButton":true,"headerLogo":"https://assets.pubpub.org/hndwo003/61675374631049.png","headerLinks":null,"headerColorType":"dark","useHeaderTextAccent":false,"hideHero":false,"hideHeaderLogo":false,"heroLogo":null,"heroBackgroundImage":null,"heroBackgroundColor":"#0558b3","heroTextColor":null,"useHeaderGradient":true,"heroImage":null,"heroTitle":"DFIR Review","heroText":"DFIR Review responds to the need for a focal point for up-to-date community-reviewed applied research and testing in digital forensics and incident response. DFIR Review concentrates on targeted studies of specific devices, digital traces, analysis methods, and criminal activity","heroPrimaryButton":{},"heroSecondaryButton":{},"heroAlign":"left","navigation":[{"id":"0f373a2c-c88d-4615-901f-9f3007392c8a","type":"page"},{"id":"b4ba8d5a-2328-4d86-ad66-f8c2c76a506f","type":"page"},{"id":"a8a6a998-952b-45ac-9dde-1e1fef976417","type":"page"},{"id":"6a7dd0ce-1852-4aa8-b858-dd9e4fcc23e7","type":"page"},{"id":"c9d33e1b-70ca-4f00-935e-8b048a2db8aa","type":"page"},{"id":"b1a5d079-3ee0-4434-a65f-c1b0cc624b45","type":"page"},{"id":"2bd22226-03c8-4300-b555-73eb1d6a582d","type":"page"},{"id":"9a0a763a-139f-4380-8620-47bf9e307106","type":"page"},{"id":"a7126096-fe0b-49af-a377-e69d372934d0","type":"page"}],"hideNav":false,"navLinks":null,"footerLinks":null,"footerLogoLink":null,"footerTitle":null,"footerImage":null,"website":"","facebook":"","twitter":"","instagram":null,"mastodon":null,"linkedin":null,"bluesky":null,"github":null,"email":"","socialLinksLocation":null,"issn":null,"isFeatured":null,"viewHash":"qz0cilrt","editHash":"bqi37oih","premiumLicenseFlag":false,"defaultPubCollections":[],"analyticsSettings":null,"spamTagId":"16a43a5f-d437-4a0a-9721-4781fc993f4e","organizationId":null,"scopeSummaryId":"aa45c5c8-46a9-480c-912b-0ace04e252d4","createdAt":"2019-03-23T18:09:32.984Z","updatedAt":"2023-02-02T21:50:33.149Z","scopeSummary":{"id":"aa45c5c8-46a9-480c-912b-0ace04e252d4","collections":1,"pubs":41,"discussions":8,"reviews":0,"submissions":0,"createdAt":"2021-04-26T16:49:17.482Z","updatedAt":"2025-03-18T02:21:15.927Z"},"spamTag":{"id":"16a43a5f-d437-4a0a-9721-4781fc993f4e","status":"confirmed-not-spam","statusUpdatedAt":"2025-03-25T17:07:04.197Z","fields":{},"spamScore":0,"spamScoreComputedAt":"2023-02-02T21:50:33.162Z","spamScoreVersion":1,"createdAt":"2022-12-07T19:10:59.508Z","updatedAt":"2025-03-25T17:07:04.197Z"},"collections":[{"id":"4d6cbcc5-a3fc-459d-820d-1d4a5f7362d7","title":"Papers","slug":"dsthj493","avatar":null,"isRestricted":true,"isPublic":true,"viewHash":"w3mlztuf","editHash":"k7ll8o5q","metadata":null,"kind":"tag","doi":null,"readNextPreviewSize":"choose-best","layout":{"blocks":[{"id":"m5nt3cew","type":"collection-header","content":{}},{"id":"82wrvv3v","type":"pubs","content":{"sort":"collection-rank","pubPreviewType":"medium"}}],"isNarrow":false},"layoutAllowsDuplicatePubs":false,"pageId":"0f373a2c-c88d-4615-901f-9f3007392c8a","communityId":"b0ac9c28-479a-496c-884c-7ae8fc26e385","scopeSummaryId":"1db60c83-a461-4697-a639-fb7d951333bb","crossrefDepositRecordId":null,"createdAt":"2019-03-30T17:19:53.991Z","updatedAt":"2021-04-26T16:48:52.977Z","members":[]}],"pages":[{"id":"b1a5d079-3ee0-4434-a65f-c1b0cc624b45","title":"Aims & Scope","slug":"about","description":"DFIR Review Aims & Scope","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"e8ydkitt","layout":[{"id":"wpmh8voe","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"heading","attrs":{"id":"dfir-review---aims-scope","rtl":null,"level":1,"fixedId":"","textAlign":null},"content":[{"text":"DFIR Review - Aims & Scope","type":"text"}]},{"type":"paragraph","attrs":{"id":"nk8u9egeeah","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Rapid review and dissemination of up-to-date results of applied research and testing is necessary to keep pace with changes in technology and cybercrime. The Internet-of-Things (IoT) and smartphone applications are prime examples of the unprecedented proliferation of new devices and digital traces. New versions of operating systems can also have data structures that contain valuable information from a forensic perspective. When a new type of digital trace is found to be relevant to a legal matter, it may be the first time it has been studied from a forensic perspective. New approaches to analysing digital traces can help develop insights in an investigation. Often this type of material is shared via blogs by active practitioners who are the first to tackle new devices, uncover new digital traces, and encounter new forms of criminal activity. Currently, these posts do not undergo community review or vetting, and are not presented or published in a formalized forum for long term reference. The faster this knowledge can be produced, reviewed, and shared among the DFIR community, the better able we will be to deal with new devices, digital traces, and criminal activities. DFIR Review aims to take the up-to-date rapid content created by practitioners and distributed regularly via blogs and provide review such that the findings can be cited and stored in a referenceable format so that it may be used by others including for reference in legal and other matters while crediting the originating source such as a practitioner blog.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n3ng0n83wot","rtl":null,"class":null,"textAlign":null}},{"type":"heading","attrs":{"id":"review","rtl":null,"level":3,"fixedId":"","textAlign":null},"content":[{"text":"Review","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nljdv0w59dg","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Submissions to DFIR Review will be reviewed rapidly by a panel of qualified members of the community to include practitioners, researchers, graduate students and others working in the digital forensics field. Submissions will be accepted or rejected on the basis of reviewer responses following these criteria:","type":"text"}]},{"type":"paragraph","attrs":{"id":"nxkaguaiv0n","rtl":null,"class":"rtecenter","textAlign":null},"content":[{"text":"Reviewer Guidance","type":"text","marks":[{"type":"link","attrs":{"href":"review-guidance","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"ne057aizup3","rtl":null,"class":null,"textAlign":null},"content":[{"text":"For accepted submissions, reviewers will provide a detailed response including comments, further research concepts that may not have been explored, as well as validation and/or verification of initial research. The intent is that this response material will be presented along with the submission on DFIR Review.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nj7lk5w62hk","rtl":null,"class":null,"textAlign":null}},{"type":"heading","attrs":{"id":"presentation","rtl":null,"level":3,"fixedId":"","textAlign":null},"content":[{"text":"Presentation","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nmlms51diln","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Accepted submissions will be made available on the DFRWS website open access under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/). Accepted submissions will be organized along with reviewer response materials. Although authors can revise accepted materials on the basis of reviewer feedback, this is not a requirement for publication, taking into account that practitioners may not have time to rework a submission or perform additional research. Authors can post their work on their personal website or blog with a reference to the publication in DFIR Review. In this way, DFIR Review is the system of record for the work, and authors can disseminate their work with a reference to the publication in DFIR Review.","type":"text"}]},{"type":"paragraph","attrs":{"id":"naicemtgxdg","rtl":null,"class":null,"textAlign":null}},{"type":"heading","attrs":{"id":"submissions","rtl":null,"level":3,"fixedId":"","textAlign":null},"content":[{"text":"Submissions","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n5ghelqimur","rtl":null,"class":null,"textAlign":null},"content":[{"text":"DFIR Review welcomes submissions that provide up-to-date knowledge in digital forensics and incident response, as well as test results that validate or update prior studies. The DFIR Review community will actively encourage authors to submit their work, and will assist authors throughout the submission process as needed. Topics of interest include:","type":"text"}]},{"type":"bullet_list","attrs":{"id":"n8yhzvlmrlq","rtl":null},"content":[{"type":"list_item","content":[{"type":"paragraph","attrs":{"id":"nn3ihqrnag2","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Forensic treatment of new devices, including Internet-of-Things","type":"text"}]}]},{"type":"list_item","content":[{"type":"paragraph","attrs":{"id":"nedidix8y5q","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Forensic analysis of new smartphone apps or updated versions (inclusion of open source tools encouraged)","type":"text"}]}]},{"type":"list_item","content":[{"type":"paragraph","attrs":{"id":"nlt1vg7bgka","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Forensic analysis of new data structures on operating systems","type":"text"}]}]},{"type":"list_item","content":[{"type":"paragraph","attrs":{"id":"nhoxhzvfab7","rtl":null,"class":null,"textAlign":null},"content":[{"text":"New methods of analysing digital traces to find patterns, links and other insights","type":"text"}]}]},{"type":"list_item","content":[{"type":"paragraph","attrs":{"id":"n4emu4f3xwp","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Insights into new ways that criminals are using technology, emphasizing technical elements and potential solutions","type":"text"}]}]},{"type":"list_item","content":[{"type":"paragraph","attrs":{"id":"nvo51ty1z6o","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Validation and testing of new forensic tool features (inclusion of test data preferred)","type":"text"}]}]}]},{"type":"paragraph","attrs":{"id":"ny6tg2u0pg2","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Submit via EasyChair: ","type":"text"},{"text":"https://easychair.org/conferences/?conf=dfirr2023","type":"text","marks":[{"type":"link","attrs":{"href":"https://easychair.org/conferences/?conf=dfirr2023","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"n09z0jhp5vv","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Submission implies that the work will not have been published elsewhere (except in as an abstract, academic thesis, preprint or personal blog), and publication in a virtual proceedings is approved by all authors and tacitly or explicitly by the responsible authorities where the work was carried out. Authors of high impact work will be encouraged to further develop their work and submit it to DFRWS conferences and other DFIR community events and publications.","type":"text"}]},{"type":"paragraph","attrs":{"id":"ncgh3dca42r","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Inquiries can be directed to DFIR@dfrws.org","type":"text"}]},{"type":"paragraph","attrs":{"id":"nwbwbuygrva","rtl":null,"class":null,"textAlign":null}},{"type":"heading","attrs":{"id":"copyright-and-rights","rtl":null,"level":3,"fixedId":"","textAlign":null},"content":[{"text":"Copyright and Rights","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n1kp4gmi6mu","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Authors will retain copyright of their work in DFIR Review. Authors will grant DFRWS the non-exclusive right to include the material in any form throughout the world, in all languages, for all time, effective when and if the work is accepted for publication.","type":"text"}]}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2019-03-30T17:21:31.710Z"},{"id":"a7126096-fe0b-49af-a377-e69d372934d0","title":"DFRWS.org","slug":"dfrws","description":"DFRWS community support and activities.","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"m6xca1m0","layout":[{"id":"jcfro4os","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"heading","attrs":{"id":"dfrws","level":1},"content":[{"text":"DFRWS","type":"text","currIndex":0}],"currIndex":0},{"type":"paragraph","attrs":{"class":null},"content":[{"text":"DFIR Review is part of DFRWS, a non-profit, volunteer organization dedicated to bringing together everyone with a legitimate interest in digital forensics to address the emerging challenges of our field. DFRWS organizes digital forensic conferences, challenges, and international collaboration to help drive the direction of research and development.","type":"text","currIndex":0}],"currIndex":1},{"type":"paragraph","attrs":{"class":null},"currIndex":2},{"type":"paragraph","attrs":{"class":null},"content":[{"text":"Additional information about DFRWS conferences and publications: ","type":"text","currIndex":0},{"text":"www.DFRWS.org","type":"text","marks":[{"type":"link","attrs":{"href":"https://www.dfrws.org","title":null,"target":null}}],"currIndex":1}],"currIndex":3}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2019-03-31T06:36:38.964Z"},{"id":"c9d33e1b-70ca-4f00-935e-8b048a2db8aa","title":"Publications","slug":"pub","description":"Published work and reviews.","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"54wh5ywg","layout":[{"id":"amkwtrbk","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"heading","attrs":{"id":"dfir-review---publications","level":1},"content":[{"text":"DFIR Review - Publications","type":"text","currIndex":0}],"currIndex":0},{"type":"paragraph","attrs":{"class":null},"content":[{"text":"Reviewed and accepted work addressing emerging challenges in digital forensics, incident response, and cyber-investigation. ","type":"text","currIndex":0}],"currIndex":1}]},"align":"left"}},{"id":"gruw36cv","type":"pubs","content":{"size":"medium","limit":0,"title":"","pubIds":[],"pubPreviewType":"medium"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2019-03-31T06:32:20.073Z"},{"id":"a8a6a998-952b-45ac-9dde-1e1fef976417","title":"Reviewers","slug":"reviewers","description":"Thank you page acknowledging our reviewers","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"aj895cs6","layout":[{"id":"n102ug0t","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"paragraph","attrs":{"id":"fta2auwwsi","class":null},"content":[{"text":"Thank you to all of the volunteer reviewers who contribute their time to conduct thorough reviews of DFIR Review. Please see the bios of selected reviewers below.","type":"text"}]},{"type":"paragraph","attrs":{"id":"0pl4vgpemk","class":null}},{"type":"paragraph","attrs":{"id":"3rcmkxfsl1","class":null},"content":[{"text":"Addisu Afework","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"efzsdtbd9a","class":null},"content":[{"text":"Addisu Afework is a Digital Forensics researcher in a governmental agency. Since 2017, he has been performing digital forensics research on smart home IoT devices. Before studying his MSc in Legal Informatics and Digital Forensics Science, he was working in the cybersecurity field since 2009 as a cybersecurity engineer. Currently, he is working on developing tools and procedures in the digital forensics investigation area. Addisu is interested in researching and developing tools and methods to assist digital forensic investigators to easily and efficiently conduct investigations. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"p0ks0nrivq","class":null}},{"type":"paragraph","attrs":{"id":"ms99wbnrut","class":null},"content":[{"text":"Timothy Bollé","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"uld75x0t2x","class":null},"content":[{"text":"Timothy Bollé is a PhD Student in Digital Forensic and Investigation at the University of Lausanne, under the supervision of Dr. Eoghan Casey. He received his BSc and MSc in forensic science, from the School of Criminal Sciences at the University of Lausanne. During his master, he performed research and development in collaboration with Swiss police to detect repetitions in online fraud. His area of expertise includes research and development in digital forensic science, specializing in machine learning. His PhD research focuses on effective use of machine learning to support forensic analysis of digital evidence. Alongside his PhD and teaching activities, he performed practical case work through the forensic science laboratory that is part the School of Criminal Sciences. When he is not in front of his computer, he enjoys to look at the various astronomical objects through his telescope. He his currently working on his thesis and on developing correlation systems to find links across different cases for a European project. You can reach him at timothy.bolle@unil.ch.","type":"text"}]},{"type":"paragraph","attrs":{"id":"maarbjqhfa","class":null}},{"type":"paragraph","attrs":{"id":"0kxc8cughk","class":null},"content":[{"text":"Ali Hadi","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"sl2qlnesfh","class":null},"content":[{"text":"Ali Hadi is a Senior Cybersecurity Specialist with 14+ years of industrial experience in Information Technology (IT), currently working as a full time professor and researcher for the Computer & Digital Forensics Dept. at Champlain College, USA. He provides consulting in several areas of Cybersecurity including digital forensics and incident response, malware analysis, cyber threat hunting, and penetration testing. He is also an author, speaker, and freelance instructor. His research interests include digital forensics, incident response, cyber threat hunting, and malware analysis.","type":"text"}]},{"type":"paragraph","attrs":{"id":"unbzsbrrog","class":null}},{"type":"paragraph","attrs":{"id":"1dwltx7xjj","class":null},"content":[{"text":"Jessica Hyde","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"vavo0ol12x","class":null},"content":[{"text":"Jessica Hyde is an experienced forensic examiner in both the commercial and government sectors. She is currently the Director of Forensics at Magnet Forensics and an Adjunct Professor teaching Mobile Forensics in the graduate program at George Mason University, where she achieved an MS in Computer Forensics. Jessica is the host of Cache Up, a weekly podcast where she interviews digital forensics practitioners. She is also involved in several community efforts including as Chair of DFIR Review, 1st Vice President of the New York Metro High Tech Crime International Association Chapter, advisory board for Cyber Sleuths Lab, and a member of the Editorial Board for the Forensic Science International: Digital Investigations Journal. Her previous roles included performing forensic examinations as a Sr. Mobile Exploitation Analyst for Basis Technology, Senior at EY, and Senior Electrical Engineer at American Systems. Jessica is also proud to be a veteran of the United States Marine Corps.","type":"text"}]},{"type":"paragraph","attrs":{"id":"4r8m1leg9d","class":null}},{"type":"paragraph","attrs":{"id":"cnx7uh53hc","class":null},"content":[{"text":"Alex O. Ogbole","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"w1olaw9uge","class":null},"content":[{"text":"He is an Investigator and Digital Forensic Analyst with the Economic and Financial Crimes Commission (EFCC) Nigeria. He has over a decade’s experience in digital forensics, evidence management, and investigation of financial and cyber-related criminal cases. He holds a bachelor’s degree in computer sciences and a master’s degree (in-view) in Legal Informatics and Forensic Science from Hallym University Chuncheon, South Korea. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"rny1zjjden","class":null}},{"type":"paragraph","attrs":{"id":"ev024rb2ea","class":null},"content":[{"text":"Elénore Ryser","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"f9j3x9kxtz","class":null},"content":[{"text":"Elénore Ryser has a MSc in Forensic Science and is a PhD student at the University of Lausanne. Her main areas of research cover a typology of digital traces, the evaluation of digital traces and communication of digital forensic results as well as geo-localisation evidences. In 2019, she received a grant from the Société Académique Vaudoise to support her PhD research.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nv29rz80i96","class":null}},{"type":"paragraph","attrs":{"id":"n4f1d0jonc3","class":null},"content":[{"text":"Brett Shavers","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nblu5btvwzi","class":null},"content":[{"text":"Brett Shavers is a digital forensics examiner whose experience spans a law enforcement career investigating cybercrime and serving as a consultant, expert witness, and special master in civil litigation cases. Brett has well over 1,000 hours of formal digital forensics training from a variety of U.S. federal agencies and forensic software companies. He has provided private consultation to government agencies and law firms in sensitive legal matters ranging from internal employee matters to class action litigation. Brett has also taught digital forensics and investigative techniques to dozens of law enforcement agencies internationally and at graduate-level educational programs. He is an award-winning author of several respected digital forensics books such as Placing the Suspect Behind the Keyboard, Hiding Behind the Keyboard, and the X-Ways Forensics Practitioner’s Guide. Brett also manages the DFIR Training website, www.dfir.training as a free resource for the DFIR community. You can find Brett at www.dfir.training and ","type":"text"},{"text":"www.brettshavers.com","type":"text","marks":[{"type":"link","attrs":{"href":"http://www.brettshavers.com/","title":null,"target":"_blank"}}]},{"text":".","type":"text"}]},{"type":"paragraph","attrs":{"id":"niceabdzcj5","class":null}},{"type":"paragraph","attrs":{"id":"wjfgouj9bd","class":null},"content":[{"text":"Hannes Spichiger","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"0tgf0rrgvw","class":null},"content":[{"text":"Hannes Spichiger is a PhD Student at the University of Lausanne interested in questions of reliability and uncertainty related to digital evidence. His thesis is focused on the localisation of persons based on mobile phone traces. In addition to his research activity, he works part time as a specialist for digital investigation at the Neuchâtel Police force in Switzerland. His technical specialisation is mostly centred around the analysis of mobile phones.","type":"text"}]},{"type":"paragraph","attrs":{"id":"x1d7u0dcoo","class":null}},{"type":"paragraph","attrs":{"id":"dgm9r38f2u","class":null},"content":[{"text":"Joe Walsh","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"u7n29eiqth","class":null},"content":[{"text":"Joe Walsh teaches digital forensics and computer security courses at DeSales University. Prior to accepting this position, he worked as a senior security consultant for a computer security firm where he was responsible for performing security assessments, conducting penetration testing, and responding to computer security incidents. He has been a police officer for thirteen years. Joe is a former member of the Internet Crimes Against Children (ICAC) task force and the FBI Child Exploitation Task Force, where he was responsible for conducting online undercover investigations and forensic examinations of digital evidence. He has been recognized in court as an expert in computer crime and digital forensics. Joe has a bachelor’s degree in Computer Information Systems and earned his master’s degree in Criminal Justice with a concentration in Digital Forensics at DeSales University. He recently completed his second master's degree in Information Systems with a concentration in Cybersecurity and is currently pursuing a Ph.D. in Information Systems with a specialization in Information Systems Cyber Security.","type":"text"}]},{"type":"paragraph","attrs":{"id":"316deb0ade","class":null}}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2021-01-07T20:03:12.970Z"},{"id":"9a0a763a-139f-4380-8620-47bf9e307106","title":"Community","slug":"community","description":"Organizers, reviewers and other community members","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"faat8dm3","layout":[{"id":"0orzouf3","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{},"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"heading","attrs":{"id":"dfir-review---community","rtl":null,"level":1,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"DFIR Review - Community","type":"text"}]},{"type":"paragraph","attrs":{"id":"njvmqvwrc72","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"The DFIR Review community is part of the Digital Forensic Research Conference (","type":"text"},{"text":"DFRWS.org","type":"text","marks":[{"type":"link","attrs":{"href":"https://www.dfrws.org","title":null,"target":null,"pubEdgeId":null}}]},{"text":"). The following individuals are involved with the coordination of DFIR Review and performing reviews of submitted work.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nmhcg32xrcr","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"type":"heading","attrs":{"id":"organizing-committee","rtl":null,"level":3,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Organizing Committee","type":"text"}]},{"type":"table","attrs":{"id":"nl858e11jp1","size":null,"align":null,"hideLabel":false,"smallerFont":false,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nob2cd5m6pw","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Chair","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nluano1hjzi","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Jessica Hyde (George Mason University & Hexordia)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nevuw0krmqk","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Vice Chair","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"n9rt66lkf8r","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Eoghan Casey (University of Lausanne & Digital Forensics Solutions)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"ncp0cp7e75w","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Program Chair","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"njo8hz6z3fc","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Elénore Ryser (University of Lausanne)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"n9qm9vvhvke","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Program Vice Chairs","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nm0e0289thf","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Holger Morgenstern (Albstadt-Sigmaringen University)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nfwuwcdtt5p","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Publication Co-Chairs","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"n3xjynkt6hp","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Joseph Walsh (DeSales University)","type":"text"}]},{"type":"paragraph","attrs":{"id":"nyue3ejt816","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Johannn Polewczyk (University of Lausanne)","type":"text"},{"type":"hard_break","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"text":"Stephen Boyce (Marymount University & Magnet Forensics)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"n3z0ooxd4e9","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Industry Practitioner Liaisons","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nl0vizkjnsc","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Brett Shavers (DFIR Training)","type":"text"},{"type":"hard_break","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"text":"Tony Knutson (SANS Institute, Kroll)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nn4f52e3b48","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Government Practitioner Liaison","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nsqzhip8skn","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Open","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"n7d817t277l","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Communications Chair","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nlweyvguct0","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Prashanth Kumar Reddy Malise (George Mason University)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nb3g91k5nvm","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Academia Liaison","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nvyh6n6hw1i","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Mark McKinnon (Davenport University)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nb8y6poo5ut","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"DFRWS Liaison","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nxdbp7wyl5g","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Daryl Pfeif (Digital Forensics Solutions)","type":"text"}]}]}]}]},{"type":"paragraph","attrs":{"id":"nqeycm08v59","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"type":"heading","attrs":{"id":"gold-reviewers","rtl":null,"level":3,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Gold Reviewers","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n8i5812w1z4","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Addisu Afework Birhanu","type":"text"}]},{"type":"paragraph","attrs":{"id":"n1kh4iysins","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Jessica Hyde","type":"text"}]},{"type":"heading","attrs":{"id":"silver-reviewers","rtl":null,"level":3,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Silver Reviewers","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n6fdc4jxn5f","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Timothy Bollé","type":"text"}]},{"type":"paragraph","attrs":{"id":"n7o01htwz3d","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Yohannes Yemane Brhan","type":"text"}]},{"type":"paragraph","attrs":{"id":"nj5kt6d91wk","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Lisa Brown","type":"text"}]},{"type":"paragraph","attrs":{"id":"nrc1291xnwq","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Eric Eppley","type":"text"}]},{"type":"paragraph","attrs":{"id":"nzkiahta6tk","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Ali Hadi","type":"text"}]},{"type":"paragraph","attrs":{"id":"n8zwsae7fd4","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Anthony Knutson","type":"text"}]},{"type":"paragraph","attrs":{"id":"ndqp4i8u6ib","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Nickolas Ligman","type":"text"}]},{"type":"paragraph","attrs":{"id":"nebcnn9kssg","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Johann Polewczyk","type":"text"}]},{"type":"paragraph","attrs":{"id":"neui5xdpmvn","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Francesco Servida","type":"text"}]},{"type":"paragraph","attrs":{"id":"nk4y4uj79rp","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Linda Shou","type":"text"}]},{"type":"heading","attrs":{"id":"reviewers","rtl":null,"level":3,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviewers","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n9s3lh9ajpy","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Zheng Jie Chan","type":"text"}]},{"type":"paragraph","attrs":{"id":"n8elkug24sb","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Amanda Chung","type":"text"}]},{"type":"paragraph","attrs":{"id":"n2aabge5wje","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Manon Fischer","type":"text"}]},{"type":"paragraph","attrs":{"id":"npnfnj8l2wd","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Joshua I. James","type":"text"}]},{"type":"paragraph","attrs":{"id":"no912s063do","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Selena Ley","type":"text"}]},{"type":"paragraph","attrs":{"id":"njxapqpjwad","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Prashanth Malise","type":"text"}]},{"type":"paragraph","attrs":{"id":"nwsmf4uk2w9","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Doug Metz","type":"text"}]},{"type":"paragraph","attrs":{"id":"nxnafg3l6oq","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Sungmi Park","type":"text"}]},{"type":"paragraph","attrs":{"id":"n0g52jkbwup","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Elénore Ryser","type":"text"}]},{"type":"paragraph","attrs":{"id":"nggzzzcdghx","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Bradley Schatz","type":"text"}]},{"type":"paragraph","attrs":{"id":"n3f48kee4la","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Aurèle Scoundrianos","type":"text"}]},{"type":"paragraph","attrs":{"id":"nxfzzfjv0bj","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Brett Shavers","type":"text"}]},{"type":"paragraph","attrs":{"id":"nhm88qaxmrz","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Hannes Spichiger","type":"text"}]},{"type":"paragraph","attrs":{"id":"nit2iq3d23w","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Adrien Vincart","type":"text"}]},{"type":"paragraph","attrs":{"id":"n4k32e401lj","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Ryan Wesley","type":"text"}]},{"type":"paragraph","attrs":{"id":"nqk71vxqngp","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Mike Williamson","type":"text"}]},{"type":"paragraph","attrs":{"id":"nsa2fmswdj9","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Sara Pierce","type":"text"}]},{"type":"paragraph","attrs":{"id":"nq1yf68ueg1","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Rishitha Reddy Munugala","type":"text"}]},{"type":"paragraph","attrs":{"id":"nbu3tm23f7c","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Saarthik Tannan","type":"text"}]},{"type":"paragraph","attrs":{"id":"nrp61pupf81","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Madison Brumbelow ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ni74qzjo8sp","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Utta Von Nuremburg","type":"text"}]},{"type":"paragraph","attrs":{"id":"npl1u0vkavz","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Kristin Ibanez","type":"text"}]},{"type":"paragraph","attrs":{"id":"n9qfsttvt14","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Charina Marrion","type":"text"}]},{"type":"paragraph","attrs":{"id":"nud0ag5mn1t","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Jad Saliba","type":"text"}]},{"type":"paragraph","attrs":{"id":"nao5nk4co3i","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Alexander Brunner","type":"text"}]},{"type":"paragraph","attrs":{"id":"nyr4o65w4ru","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Rishi Krishnan","type":"text"}]},{"type":"paragraph","attrs":{"id":"n108kjc0y31","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"type":"paragraph","attrs":{"id":"ndtssgtyvl1","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2019-03-30T18:15:15.380Z"},{"id":"2bd22226-03c8-4300-b555-73eb1d6a582d","title":"Review Guidance","slug":"review-guidance","description":"Criteria and guidelines for evaluating DFIR Review submissions.","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"pbpqub3l","layout":[{"id":"d93kbyyg","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{},"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"heading","attrs":{"id":"dfir-review---guidance","rtl":null,"level":1,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"DFIR Review - Guidance","type":"text"}]},{"type":"paragraph","attrs":{"id":"ic90m4lbu1","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"The following guidance is intended for reviewers to use in both assessing and drafting their review. Please be cognizant that comments will be included in the publication of the submission. If upon assignment you recognize that you are not suited to perform the review (i.e. schedule conflicts, not an area of expertise, etc.), please send an email to the TPC as soon as possible so that another reviewer may be assigned.","type":"text"}]},{"type":"paragraph","attrs":{"id":"x3lj85fcgz","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"type":"heading","attrs":{"id":"categories-of-review","rtl":null,"level":4,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Categories of Review","type":"text","marks":[{"type":"strong"}]}]},{"type":"table","attrs":{"id":"4ru0p1lqtj","size":null,"align":null,"hideLabel":false,"smallerFont":false,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[183],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"h48sq7n1wm","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Methodology Review","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[369],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"ipmaixvsto","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"This review is a read through and verification that the concepts and methods expressed in the submission are sound. This is the lowest level review. This method should only be used when it is the only available method to the reviewer or the content is not suitable for a higher level review.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"image","attrs":{"id":"qcaisrdf1j","url":"https://assets.pubpub.org/0osmcztc/31554327656996.png","href":null,"size":49,"align":"center","altText":"","caption":"","hideLabel":false,"suggestionId":null,"fullResolution":false,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[183],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"w1yn0ety3k","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Verified Review using Author Provided Datasets","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[369],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"wh4ugfxa51","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"This review requires verifying the technical details of the submission with a set of data provided by the author. It is expected that this review category is the minimum requirement when data is provided by the author.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"image","attrs":{"id":"6h80l2c4aj","url":"https://assets.pubpub.org/n6fvj3o0/71554327672214.png","href":null,"size":49,"align":"center","altText":"","caption":"","hideLabel":false,"suggestionId":null,"fullResolution":false,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[183],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"3hzixhujhp","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Validated Review using Reviewer Generated Datasets","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[369],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"32ay6jab2m","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"This is the “gold standard” for DFIR Review. When possible, this is the preferred method of review. When conducting this type of review, please ensure you include the OS/app/HW versions you are validating with in your review. It is completely acceptable to extend beyond the initial review with your learnings.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"image","attrs":{"id":"phzkvuu9h9","url":"https://assets.pubpub.org/3q7iw5tx/21554327684657.png","href":null,"size":49,"align":"center","altText":"","caption":"","hideLabel":false,"suggestionId":null,"fullResolution":false,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}}]}]}]},{"type":"heading","attrs":{"id":"reviewer-confidence","rtl":null,"level":4,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviewer Confidence","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nf351r1fcb","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"This is where the reviewer states their confidence with the material under review and their ability to provide a review. If you feel that you are a 1 or a 2, it is suggested that you email the Technical Program Committee and inform them that you are not comfortable performing the review so someone with more experience in that area of forensics can be assigned the review.","type":"text"}]},{"type":"paragraph","attrs":{"id":"sldjxeoggf","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"type":"heading","attrs":{"id":"review-guidelines","rtl":null,"level":4,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Review Guidelines","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"w6q8pl05jo","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews will be published along with the accepted article in addition to the name of the reviewer and the category or review performed.","type":"text"}]},{"type":"bullet_list","attrs":{"id":"gcirgi18cz","rtl":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"7bgjwn9p5u","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should be comprehensive and should highlight the reviewer's knowledge of the subject matter in the article.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"zv1bwwy5vu","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should provide practitioners, lawyers, and judges with assurance that the article is reliable and complete.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"89jgh2k4o2","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews can state how the article can be useful in a digital investigation, and any associated limitations or risks.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"eghi9j8xnu","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should state if an article is trivial or not useful for addressing questions in a digital investigation.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"t5p53ll9u1","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should state if the article misses important details.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"5ekmydmqjo","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should explain the basis of the review (testing performed, prior knowledge from a case, etc.) including details regarding verification/validation via use of the author provided data sets or creation of data sets by the reviewer. When validating with reviewer generated data, please provide details as to OS, app, hardware used for the testing as applicable.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"z6ky625z73","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should highlight related questions that could be explored in future research.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"7lh03rosl2","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should describe technical details of any testing performed, such as:","type":"text"}]}]}]},{"type":"paragraph","attrs":{"id":"swk3tzi33s","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"\"","type":"text"},{"text":"Using Autopsy version 4.10, I confirmed that the digital trace described in this article was present on Windows 10. In addition, I confirmed that the trace was compatible with the activity/interpretation presented in this article.","type":"text","marks":[{"type":"em"}]},{"text":"\"","type":"text"}]},{"type":"paragraph","attrs":{"id":"udcf2whdll","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"type":"paragraph","attrs":{"id":"iqbm1mbg29","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"If we cannot repeat the steps that are presented in the article, we should state this, such as:","type":"text"}]},{"type":"paragraph","attrs":{"id":"4dh6aj6gdw","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"\"","type":"text"},{"text":"After performing the specified action in the article on a Windows 10 system, I examined the XYZ.dat file using a hex viewer but did not find the digital traces described in this article. However, I did not observe the digital traces described in this article. The traces I observed showed that the specified action occurred, but did not include additional details presented in the article (consider providing a screenshot of observed trace).","type":"text","marks":[{"type":"em"}]},{"text":"\"","type":"text"}]},{"type":"paragraph","attrs":{"id":"1kc9evklwj","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"OR","type":"text"}]},{"type":"paragraph","attrs":{"id":"psxmh1n0vy","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"\"","type":"text"},{"text":"Although it was not possible to perform testing on the same type of system (vehicle), I tested the XYZ application independently on an Android ABC device and obtained results that were compatible with those presented in this article","type":"text","marks":[{"type":"em"}]},{"text":"\"","type":"text"}]},{"type":"bullet_list","attrs":{"id":"m8ullauqum","rtl":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"ce971rvguk","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should highlight related questions that could be explored in future research.","type":"text"}]}]}]},{"type":"paragraph","attrs":{"id":"s0guqkqk5o","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"An explanation video covering reviewer guidance and process is available here: ","type":"text"},{"text":"https://bit.ly/DFIRReviewGuidance","type":"text","marks":[{"type":"link","attrs":{"href":"https://bit.ly/DFIRReviewGuidance","title":null,"target":null,"pubEdgeId":null}}]}]},{"type":"paragraph","attrs":{"id":"fjuk3m4tav","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Review Rubric","type":"text","marks":[{"type":"strong"}]}]},{"type":"table","attrs":{"id":"qnvm4c1qr7","size":null,"align":null,"hideLabel":false,"smallerFont":false,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[127],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"cbj5z74dxf","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Criteria","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"cs0j5hsmz9","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reject","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nw5poar7ge","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Revise","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"qx7lgaafyc","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Accept","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[127],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"wluzvqh811","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Content and Organization ","type":"text","marks":[{"type":"strong"}]},{"type":"hard_break","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"marks":[{"type":"strong"}]},{"text":"(Weight 60%)","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"0ega3gnx7y","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Substantial omission of details. Serious factual errors. Poorly organized.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"avvu5uu7a0","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Omission of minor pertinent details. Small factual errors. Overall organization good, but individual sections lack coherence/ depth or good content presented in a disorganized fashion. Excessive information not pertinent to subject.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"yfqnghf4xm","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Follows the submission guidelines, providing all pertinent details. No factual errors. Well organized in pursuit of a clearly defined objectives.","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[127],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"1rss3h1sxg","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Use of Sources* ","type":"text","marks":[{"type":"strong"}]},{"type":"hard_break","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"marks":[{"type":"strong"}]},{"text":"(Weight 30%)","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"991l6a92jl","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Little use of supporting sources, mostly generalities. Overuse of links to or quotations from other texts/websites.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"yudc6vs551","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Scanty use of supporting sources. Minor misuse of sources, or selection of inappropriate sources. Incomplete details.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"d6vk3vkb08","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Drawing on several details from sources (rather than general concepts) and/or multiple sources. Appropriate use and choice of sources.","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[127],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"4kgfimc5z6","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Grammar and Language ","type":"text","marks":[{"type":"strong"}]},{"type":"hard_break","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"marks":[{"type":"strong"}]},{"text":"(Weight 10%)","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"ou57jqf397","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Substantial grammar and/or typographical errors that confuse clarity and sense. Misuse of vocabulary; excessive repetition in expression.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"c4txjy47gu","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Some grammatical/ typographical errors, but without effect on sense. Repetitious use of vocabulary or expression.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"x6tw7j8ey8","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Few to no grammatical errors or typos.","type":"text"}]}]}]}]},{"type":"paragraph","attrs":{"id":"4sabm68tbt","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"* Submissions should contain sufficient details to repeat the process and determine whether or not the results are compatible with those described in the submission. All testing or other sources should be described in the review. Sources includes not just citations but testing that is thoroughly described. Author created testing is a source.","type":"text"}]},{"type":"paragraph","attrs":{"id":"38b1mux24u","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Review Timelines","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"y4f99cyjje","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Submissions are accepted on a per month basis and reviewed in the next month. For example submissions between Feb 1st and 28th will be assigned in early March for review completion by mid-March. If you are unable to provide a timely review, please notify the Program Chair(s) as quickly as possible so the review may be re-assigned. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"1nzt6o5m4i","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Format for text block of review","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"mk4xniq6no","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Please format your comments such that you indicate the type(s) of reviews followed by comments in 3 categories.","type":"text"}]},{"type":"paragraph","attrs":{"id":"whauqposzg","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Type of Review: ","type":"text","marks":[{"type":"em"}]},{"text":"Methodology Review and Verified Review using Author Provided Datasets (Please indicate if this is a Methodology Review, Verified Review using Author Provided Datasets, or Validated using Reviewer Generated Datasets).","type":"text"}]},{"type":"paragraph","attrs":{"id":"sh8nj7v7jg","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Omissions and Questions about the work:","type":"text","marks":[{"type":"em"}]}]},{"type":"ordered_list","attrs":{"id":"wi04ywbezr","rtl":null,"order":1,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"xf0lyd67r1","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"What is meant by x?","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"ks3ok21n17","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Was y tested?","type":"text"}]}]}]},{"type":"paragraph","attrs":{"id":"6xmhxxtf0m","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Future work:","type":"text","marks":[{"type":"em"}]}]},{"type":"ordered_list","attrs":{"id":"x9fzln9kcl","rtl":null,"order":1,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"m1r3g3hsla","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Future work could include validation on z platform","type":"text"}]}]}]},{"type":"paragraph","attrs":{"id":"a0v8xdv8ll","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Formatting suggestions and typographical errors:","type":"text","marks":[{"type":"em"}]}]},{"type":"ordered_list","attrs":{"id":"e48yaa32ms","rtl":null,"order":1,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"ad5eow1jiq","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Figure 3 is labeled incorrectly as Figure 4","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"bve6ohp2en","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"community is misspelled on page 3","type":"text"}]},{"type":"paragraph","attrs":{"id":"2d4e4d9mo2","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}}]}]},{"type":"paragraph","attrs":{"id":"t3gknsknon","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Questions?","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"xvrj74tpko","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Contact us at dfirreview@dfrws.org","type":"text"}]}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2019-03-30T17:24:56.535Z"},{"id":"b4ba8d5a-2328-4d86-ad66-f8c2c76a506f","title":"Stats","slug":"blog","description":"Blog post with stats for DFIR Review","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"fnjtgcsg","layout":[{"id":"xpwsx1ff","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"paragraph","attrs":{"id":"n3uvj3mojvp","class":null},"content":[{"text":"DFIR Review – Year in Review 2020 Statistics","type":"text","marks":[{"type":"strong"}]},{"text":" (cross-posted from https://www.dfir.training/dfir-blog/dfir-review-year-in-review)","type":"text"}]},{"type":"paragraph","attrs":{"id":"n6juf9nhy7l","class":null},"content":[{"text":"Feb 7, 2021","type":"text"}]},{"type":"paragraph","attrs":{"id":"nylv7n651m3","class":"MsoNormal"},"content":[{"text":"Hi! We at DFIR Review wanted to take a moment to share some of the great things all the volunteers at DFIR Review have been doing over the last year and all the great peer-reviewed posts available at ","type":"text"},{"text":"dfir.pubpub.org","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/","title":null,"target":null}}]},{"text":".","type":"text"}]},{"type":"paragraph","attrs":{"id":"nq2vfwvfnix","class":"MsoNormal"},"content":[{"text":"For those who are unfamiliar, DFIR Review is a project under ","type":"text"},{"text":"DFRWS","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfrws.org/","title":null,"target":null}}]},{"text":" that conducts peer review of content and blogs, regardless of if they have already been posted. The goal of this project is to provide verification, validation, and review of digital forensics content that is rapidly shared by practitioners. This allows for the review process to take place while the content is still available to the community.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n630v13lo3j","class":"MsoNormal"},"content":[{"text":"In 2020, DFIR Review published 11 pieces including the following:","type":"text"}]},{"type":"paragraph","attrs":{"id":"njquwnpvnyq","class":"MsoListParagraphCxSpFirst"},"content":[{"text":"· ","type":"text"},{"text":"Google Search Bar & Search Term History – Are You Finding Everything by Joshua Hickman","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/wpbdig8l","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nw3nmuneafp","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"OK Computer…er…Google. Dissecting Google Assistant (Part 1) by Joshua Hickman","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/eivkytr1","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nuqku8khss8","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"OK Computer…er…Google. Dissecting Google Assistant (Part Deux) by Joshua Hickman","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/eivkytr1","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"np1z3kyai28","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"Chromebook Forensic Acquisition by Daniel Dickerman","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/inkjsqrh","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"na2dtd9t866","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"Parsing Google’s Now Playing History on Pixel Devices by Kevin Pagano","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/xbvsrjt5","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"n827jpi13ne","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"Windows 10 Jump List and Link File Artifacts – Saved, Copied, and Moved by Larry Jones","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/wfuxlu9v","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nmw1m3fbfx8","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"Tinkering with TikTok Timestamps by Ryan Benson","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/9llea7yp","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nzabtw21n2t","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"How Android Bluetooth Connections Can Determine if a Driver had Their Hands on the Wheel During an Accident by Heather Mahalik","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/6ysxvhvc","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nty3qc3v9ab","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"Can Google Takeout Location Data Be Trusted? By Ross Donnelly","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/d39u7lg1","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nyi40hf6d43","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"How to Use iOS Bluetooth Connections to Solve Crimes Faster by Heather Mahalik and Matt Goeckel","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/frknihlg","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"njuk6qfjsy8","class":"MsoListParagraphCxSpLast"},"content":[{"text":"· ","type":"text"},{"text":"Can You Track Processes Accessing the Camera and Microphone on Windows 10? By Zachary Stanford","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/nm5b39ae","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"ng9zp1lfo6h","class":"MsoNormal"},"content":[{"text":"The magic behind this cadre of publications is the ","type":"text"},{"text":"DFIR Review Community","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/community","title":null,"target":null}}]},{"text":" and ","type":"text"},{"text":"reviewers","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/reviewers","title":null,"target":null}}]},{"text":". We have a community of over 30 reviewers who have completed 100 reviews. Our community is truly global with contributions from 15 countries across 4 continents!","type":"text"}]},{"type":"paragraph","attrs":{"id":"noi6sl2ie5l","class":"MsoNormal"}},{"type":"paragraph","attrs":{"id":"ngkvtiqievw","class":"MsoNormal"},"content":[{"text":"Thank you to everyone who has contributed be it as an author, reviewer, or organizing committee. We hope to be able to share even more throughout 2021. Have content you want to submit to DFIR Review? Check out our ","type":"text"},{"text":"submission guidance","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/submission-guidance","title":null,"target":null}}]},{"text":". If you are interested in being a reviewer, please feel free to email us at ","type":"text"},{"text":"dfirreview@dfrws.org","type":"text","marks":[{"type":"link","attrs":{"href":"mailto:dfirreview@dfrws.org","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nm5w5cylpe4","class":null}},{"type":"paragraph","attrs":{"id":"nply4zgf0ih","class":null},"content":[{"text":"Slide-deck of the stats","type":"text","marks":[{"type":"link","attrs":{"href":"https://www.dfir.training/dfir-review-year-in-review-2020/file","title":null,"target":null}}]}]}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2021-02-07T19:35:12.262Z"},{"id":"6a7dd0ce-1852-4aa8-b858-dd9e4fcc23e7","title":"Submission Guidance","slug":"submission-guidance","description":"","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"2o9h9at6","layout":[{"id":"zd5ru333","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"heading","attrs":{"id":"dfir-review---submission-guidance","rtl":null,"level":1,"fixedId":"","textAlign":null},"content":[{"text":"DFIR Review - Submission Guidance","type":"text"}]},{"type":"paragraph","attrs":{"id":"mpox5nedvm","rtl":null,"class":null,"textAlign":null}},{"type":"paragraph","attrs":{"id":"333wqr8yd8","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Thank you for your interest in submitting to DFIRReview. Please submit via ","type":"text"},{"text":"https://easychair.org/conferences/?conf=dfirr2023","type":"text","marks":[{"type":"link","attrs":{"href":"https://easychair.org/conferences/?conf=dfirr2023","title":null,"target":null}}]},{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ni3c4l2wcr","rtl":null,"class":null,"textAlign":null},"content":[{"text":"The following guidance is intended for submitters to utilize in formatting their files submitted to DFIR Review. As DFIR Review is designed for the review of already relieved works, it is suggested that articles be posted in advance as blogs. Author names are not blind to reviewers as submissions for this project are typically already in the public view.","type":"text"}]},{"type":"paragraph","attrs":{"id":"34xpelqcy8","rtl":null,"class":null,"textAlign":null},"content":[{"text":"DFIRReview accepts submissions for an entire month at a time. At the beginning of the next month those papers are assigned for a review period. For example, Reviews submitted between Jan 1 and Jan 31 will be reviewed in February with a decision to the author expected by the end of February","type":"text"}]},{"type":"paragraph","attrs":{"id":"e6jc08o2jj","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Please add the following headers to your blog post with the content filled in and submit your attachment as a .docx file. This will help ensure the best possible publication of your content:","type":"text"}]},{"type":"paragraph","attrs":{"id":"t9p2x2zcx4","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Synopsis:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"ljaq43noa3","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Forensics Question: ","type":"text","marks":[{"type":"strong"}]},{"text":"What is the goal of your paper? What are you trying to answer?","type":"text"}]},{"type":"paragraph","attrs":{"id":"alb8fp1l75","rtl":null,"class":null,"textAlign":null},"content":[{"text":"OS Version:","type":"text","marks":[{"type":"strong"}]},{"text":" Include the applicable Operating System and/or Application versions applies to your content","type":"text"}]},{"type":"paragraph","attrs":{"id":"8l222dkh42","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Tools:","type":"text","marks":[{"type":"strong"}]},{"text":" Please list any and all tools used to create, test, and/or validate your content.","type":"text"}]},{"type":"paragraph","attrs":{"id":"gk0ulcc0n9","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Thank you!","type":"text"}]},{"type":"paragraph","attrs":{"id":"lr8118ce91","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Questions?","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"z50oi5bfgm","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Contact us at dfirreview@dfrws.org","type":"text"}]}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2020-05-28T21:59:19.835Z"},{"id":"0f373a2c-c88d-4615-901f-9f3007392c8a","title":"DFIR Review","slug":"","description":"DFIR Review responds to the need for a focal point for up-to-date community-reviewed applied research and testing in digital forensics and incident response. DFIR Review concentrates on targeted studies of specific devices, digital traces, analysis methods, and criminal activity.","avatar":"https://assets.pubpub.org/3ej3id6s/11553968629226.png","isPublic":true,"isNarrowWidth":null,"viewHash":"dfgao2b3","layout":[{"id":"yjymbe9d","type":"banner","content":{"text":"We are actively seeking reviewers! Interested? Email us at dfirreview@dfrws.org ","align":"center","buttonUrl":"","buttonText":"","buttonType":"none","showButton":false,"backgroundSize":"full","backgroundColor":"#3275d8","backgroundImage":"","backgroundHeight":"narrow","defaultCollectionIds":[]}},{"id":"kqa6nus3","type":"banner","content":{"text":"Submit topics of interest for research","align":"center","buttonUrl":"https://bit.ly/DFIRReviewRequests","buttonText":"Research Request","buttonType":"link","showButton":true,"backgroundSize":"full","backgroundColor":"#3275d8","backgroundImage":"","backgroundHeight":"narrow","defaultCollectionIds":[]}},{"id":"bzmjons3","type":"pubs","content":{"sort":"creation-date","limit":0,"title":"","pubIds":[],"collectionIds":[],"pubPreviewType":"medium"}},{"id":"xw3itri0","type":"pubs","content":{"limit":8,"title":"Featured Posts","pubIds":[],"collectionIds":[],"pubPreviewType":"medium"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2019-03-23T18:09:32.990Z"}]},"loginData":{"id":null},"locationData":{"hostname":"dfir.pubpub.org","path":"/pub/g2v1z97i/release/1","params":{"pubSlug":"g2v1z97i","releaseNumber":"1"},"query":{},"queryString":"?","isDashboard":false,"isBasePubPub":false,"isProd":true,"isDuqDuq":false,"isQubQub":false,"appCommit":"6d87aaeef578ba6bd8c8ce36fb866b505dd22469"},"scopeData":{"elements":{"activeTargetType":"pub","activeTargetName":"Pub","activeTarget":{"id":"b2d0adf2-a290-4094-804c-c9eac7297bc9","slug":"g2v1z97i","title":"iOS KnowledgeC.db Notifications","htmlTitle":null,"description":null,"htmlDescription":null,"avatar":null,"customPublishedAt":null,"doi":null,"labels":null,"downloads":null,"metadata":null,"viewHash":"uumywdhz","editHash":"90hd8nib","reviewHash":"muvdiwos","commentHash":"ry21hvpc","draftId":"da208dc1-c175-4dc3-a7c9-19556046fe84","communityId":"b0ac9c28-479a-496c-884c-7ae8fc26e385","crossrefDepositRecordId":null,"scopeSummaryId":"80404ffd-e950-4360-9a02-44679dacf8c6","createdAt":"2022-04-11T17:27:40.839Z","updatedAt":"2022-11-17T22:41:03.381Z","collectionPubs":[],"releases":[{"id":"c4147c98-309b-462c-ada4-9b70ff4b4e85","historyKey":1415}],"submission":null},"activePub":{"id":"b2d0adf2-a290-4094-804c-c9eac7297bc9","slug":"g2v1z97i","title":"iOS KnowledgeC.db Notifications","htmlTitle":null,"description":null,"htmlDescription":null,"avatar":null,"customPublishedAt":null,"doi":null,"labels":null,"downloads":null,"metadata":null,"viewHash":"uumywdhz","editHash":"90hd8nib","reviewHash":"muvdiwos","commentHash":"ry21hvpc","draftId":"da208dc1-c175-4dc3-a7c9-19556046fe84","communityId":"b0ac9c28-479a-496c-884c-7ae8fc26e385","crossrefDepositRecordId":null,"scopeSummaryId":"80404ffd-e950-4360-9a02-44679dacf8c6","createdAt":"2022-04-11T17:27:40.839Z","updatedAt":"2022-11-17T22:41:03.381Z","collectionPubs":[],"releases":[{"id":"c4147c98-309b-462c-ada4-9b70ff4b4e85","historyKey":1415}],"submission":null},"activeCollection":null,"activeIds":{"pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","collectionId":null,"communityId":"b0ac9c28-479a-496c-884c-7ae8fc26e385"},"inactiveCollections":[],"activeCommunity":{"id":"b0ac9c28-479a-496c-884c-7ae8fc26e385","subdomain":"dfir","domain":null,"title":"DFIR Review","citeAs":null,"publishAs":null,"description":"DFIR Review responds to the need for a focal point for up-to-date community-reviewed applied research and testing in digital forensics and incident response. DFIR Review concentrates on targeted studies of specific devices, digital traces, analysis methods, and criminal activity","avatar":"https://assets.pubpub.org/3yqqvtl4/71553968763873.png","favicon":"https://assets.pubpub.org/c8g3oakn/41553968740088.png","accentColorLight":"#FFFFFF","accentColorDark":"#2D2E2F","hideCreatePubButton":true,"headerLogo":"https://assets.pubpub.org/hndwo003/61675374631049.png","headerLinks":null,"headerColorType":"dark","useHeaderTextAccent":false,"hideHero":false,"hideHeaderLogo":false,"heroLogo":null,"heroBackgroundImage":null,"heroBackgroundColor":"#0558b3","heroTextColor":null,"useHeaderGradient":true,"heroImage":null,"heroTitle":"DFIR Review","heroText":"DFIR Review responds to the need for a focal point for up-to-date community-reviewed applied research and testing in digital forensics and incident response. DFIR Review concentrates on targeted studies of specific devices, digital traces, analysis methods, and criminal activity","heroPrimaryButton":{},"heroSecondaryButton":{},"heroAlign":"left","navigation":[{"id":"0f373a2c-c88d-4615-901f-9f3007392c8a","type":"page"},{"id":"b4ba8d5a-2328-4d86-ad66-f8c2c76a506f","type":"page"},{"id":"a8a6a998-952b-45ac-9dde-1e1fef976417","type":"page"},{"id":"6a7dd0ce-1852-4aa8-b858-dd9e4fcc23e7","type":"page"},{"id":"c9d33e1b-70ca-4f00-935e-8b048a2db8aa","type":"page"},{"id":"b1a5d079-3ee0-4434-a65f-c1b0cc624b45","type":"page"},{"id":"2bd22226-03c8-4300-b555-73eb1d6a582d","type":"page"},{"id":"9a0a763a-139f-4380-8620-47bf9e307106","type":"page"},{"id":"a7126096-fe0b-49af-a377-e69d372934d0","type":"page"}],"hideNav":false,"navLinks":null,"footerLinks":null,"footerLogoLink":null,"footerTitle":null,"footerImage":null,"website":"","facebook":"","twitter":"","instagram":null,"mastodon":null,"linkedin":null,"bluesky":null,"github":null,"email":"","socialLinksLocation":null,"issn":null,"isFeatured":null,"viewHash":"qz0cilrt","editHash":"bqi37oih","premiumLicenseFlag":false,"defaultPubCollections":[],"analyticsSettings":null,"spamTagId":"16a43a5f-d437-4a0a-9721-4781fc993f4e","organizationId":null,"scopeSummaryId":"aa45c5c8-46a9-480c-912b-0ace04e252d4","createdAt":"2019-03-23T18:09:32.984Z","updatedAt":"2023-02-02T21:50:33.149Z"}},"memberData":[],"activePermissions":{"activePermission":null,"canView":false,"canEdit":false,"canManage":false,"canAdmin":false,"canAdminCommunity":false,"canManageCommunity":false,"canViewCommunity":false,"canEditCommunity":false,"isSuperAdmin":false,"canCreateReviews":false,"canCreateDiscussions":true,"canViewDraft":false,"canEditDraft":false},"activeCounts":{"reviews":0,"submissions":0},"scope":{"pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","communityId":"b0ac9c28-479a-496c-884c-7ae8fc26e385"},"facets":{"CitationStyle":{"props":{"citationStyle":{"sources":[{"scope":{"kind":"root"},"value":"apa","facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"83f6269e-9991-4638-9c35-fe33e4e64b66","value":"apa"}],"value":"apa"},"inlineCitationStyle":{"sources":[{"scope":{"kind":"root"},"value":"count","facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"83f6269e-9991-4638-9c35-fe33e4e64b66","value":"count"}],"value":"count"}},"value":{"citationStyle":"apa","inlineCitationStyle":"count"},"stack":[{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"value":{"citationStyle":"apa","inlineCitationStyle":"count"},"facetBindingId":"83f6269e-9991-4638-9c35-fe33e4e64b66"}]},"License":{"props":{"kind":{"sources":[{"scope":{"kind":"root"},"value":"cc-by","facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"db28dd45-5551-433b-8c3c-21632d7b7516","value":"cc-by"}],"value":"cc-by"},"copyrightSelection":{"sources":[{"scope":{"kind":"root"},"value":{"choice":"infer-from-scope","year":null},"facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"db28dd45-5551-433b-8c3c-21632d7b7516","value":{"choice":"infer-from-scope","year":null}}],"value":{"choice":"infer-from-scope","year":null}}},"value":{"kind":"cc-by","copyrightSelection":{"choice":"infer-from-scope","year":null}},"stack":[{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"value":{"kind":"cc-by","copyrightSelection":{"choice":"infer-from-scope","year":null}},"facetBindingId":"db28dd45-5551-433b-8c3c-21632d7b7516"}]},"NodeLabels":{"props":{"image":{"sources":[{"scope":{"kind":"root"},"value":{"enabled":false,"text":"Image"},"facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"65fda716-3a80-4fff-990e-d083a0a5f50b","value":{"enabled":false,"text":"Figure"}}],"value":{"enabled":false,"text":"Figure"}},"video":{"sources":[{"scope":{"kind":"root"},"value":{"enabled":false,"text":"Video"},"facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"65fda716-3a80-4fff-990e-d083a0a5f50b","value":{"enabled":false,"text":"Video"}}],"value":{"enabled":false,"text":"Video"}},"audio":{"sources":[{"scope":{"kind":"root"},"value":{"enabled":false,"text":"Audio"},"facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"65fda716-3a80-4fff-990e-d083a0a5f50b","value":{"enabled":false,"text":"Audio"}}],"value":{"enabled":false,"text":"Audio"}},"table":{"sources":[{"scope":{"kind":"root"},"value":{"enabled":false,"text":"Table"},"facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"65fda716-3a80-4fff-990e-d083a0a5f50b","value":{"enabled":false,"text":"Table"}}],"value":{"enabled":false,"text":"Table"}},"math":{"sources":[{"scope":{"kind":"root"},"value":{"enabled":false,"text":"Equation"},"facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"65fda716-3a80-4fff-990e-d083a0a5f50b","value":{"enabled":false,"text":"Equation"}}],"value":{"enabled":false,"text":"Equation"}},"iframe":{"sources":[{"scope":{"kind":"root"},"value":{"enabled":false,"text":"Iframe"},"facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"65fda716-3a80-4fff-990e-d083a0a5f50b","value":{"enabled":false,"text":"Iframe"}}],"value":{"enabled":false,"text":"Iframe"}}},"value":{"image":{"enabled":false,"text":"Figure"},"video":{"enabled":false,"text":"Video"},"audio":{"enabled":false,"text":"Audio"},"table":{"enabled":false,"text":"Table"},"math":{"enabled":false,"text":"Equation"},"iframe":{"enabled":false,"text":"Iframe"}},"stack":[{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"value":{"image":{"enabled":false,"text":"Figure"},"video":{"enabled":false,"text":"Video"},"audio":{"enabled":false,"text":"Audio"},"table":{"enabled":false,"text":"Table"},"math":{"enabled":false,"text":"Equation"},"iframe":{"enabled":false,"text":"Iframe"}},"facetBindingId":"65fda716-3a80-4fff-990e-d083a0a5f50b"}]},"PubEdgeDisplay":{"props":{"defaultsToCarousel":{"sources":[{"scope":{"kind":"root"},"value":true,"facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"3fdd11f1-c1a0-40f5-9d83-2edc54e9228f","value":true}],"value":true},"descriptionIsVisible":{"sources":[{"scope":{"kind":"root"},"value":true,"facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"3fdd11f1-c1a0-40f5-9d83-2edc54e9228f","value":true}],"value":true}},"value":{"defaultsToCarousel":true,"descriptionIsVisible":true},"stack":[{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"value":{"defaultsToCarousel":true,"descriptionIsVisible":true},"facetBindingId":"3fdd11f1-c1a0-40f5-9d83-2edc54e9228f"}]},"PubHeaderTheme":{"props":{"backgroundImage":{"sources":[{"scope":{"kind":"root"},"value":null,"facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"ebbddf8d-ad8c-49db-9ac2-193f7687e596","value":""}],"value":""},"backgroundColor":{"sources":[{"scope":{"kind":"root"},"value":"community","facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"ebbddf8d-ad8c-49db-9ac2-193f7687e596","value":"light"}],"value":"light"},"textStyle":{"sources":[{"scope":{"kind":"root"},"value":"light","facetBindingId":null},{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"facetBindingId":"ebbddf8d-ad8c-49db-9ac2-193f7687e596","value":"dark"}],"value":"dark"}},"value":{"backgroundImage":"","backgroundColor":"light","textStyle":"dark"},"stack":[{"scope":{"kind":"pub","id":"b2d0adf2-a290-4094-804c-c9eac7297bc9"},"value":{"backgroundImage":"","backgroundColor":"light","textStyle":"dark"},"facetBindingId":"ebbddf8d-ad8c-49db-9ac2-193f7687e596"}]}}},"featureFlags":{"releaseDiscussionsDialog":false,"activityDigestSubscribeToggle":true,"notifications":true,"submissions":true,"surveySummer22":false,"reviews":false,"comments":false,"htmlPubHeaderValues":false,"minimal-header":false,"minimal-footer":false,"customScripts":false,"collapsible-header":false,"two-column-footer":false,"suggestedEdits":false,"collapsible-header-bpc":false,"customAnalyticsProvider":false,"newAnalytics":true,"bodyContributors":false,"noCookieBanner":false},"initialNotificationsData":{"hasNotifications":false,"hasUnreadNotifications":false},"dismissedUserDismissables":{}}"></script><script id="view-data" type="text/plain" data-json="{"pubData":{"subscription":null,"id":"b2d0adf2-a290-4094-804c-c9eac7297bc9","slug":"g2v1z97i","title":"iOS KnowledgeC.db Notifications","htmlTitle":null,"description":null,"htmlDescription":null,"avatar":null,"customPublishedAt":null,"doi":null,"labels":null,"downloads":null,"metadata":null,"viewHash":null,"editHash":null,"reviewHash":null,"commentHash":null,"draftId":"da208dc1-c175-4dc3-a7c9-19556046fe84","communityId":"b0ac9c28-479a-496c-884c-7ae8fc26e385","crossrefDepositRecordId":null,"scopeSummaryId":"80404ffd-e950-4360-9a02-44679dacf8c6","createdAt":"2022-04-11T17:27:40.839Z","updatedAt":"2022-11-17T22:41:03.381Z","members":[{"id":"176a3ecf-b9d6-48d2-b1f9-9c88d01bbd13","permissions":"manage","isOwner":true,"subscribedToActivityDigest":false,"userId":"adb58dcd-f040-4ef1-98de-ba664b2246fa","pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","collectionId":null,"communityId":null,"organizationId":null,"createdAt":"2022-04-11T17:27:40.883Z","updatedAt":"2022-04-11T17:27:40.883Z"}],"draft":null,"submission":null,"crossrefDepositRecord":null,"scopeSummary":{"id":"80404ffd-e950-4360-9a02-44679dacf8c6","collections":0,"pubs":0,"discussions":0,"reviews":0,"submissions":0,"createdAt":"2022-04-11T17:27:40.853Z","updatedAt":"2022-04-11T17:27:40.853Z"},"inboundEdges":[],"outboundEdges":[],"discussions":[],"releases":[{"id":"c4147c98-309b-462c-ada4-9b70ff4b4e85","noteContent":null,"noteText":null,"pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","userId":"30aa145b-85e3-45f0-af37-2431daffd78a","docId":"c4e95f31-2a68-49e0-bec4-5ea5b72bc8d4","historyKey":1415,"historyKeyMissing":false,"createdAt":"2022-11-03T11:43:49.132Z","updatedAt":"2022-11-03T11:43:49.132Z"}],"reviews":[],"collectionPubs":[],"attributions":[{"id":"c7cdbdf9-6d0f-4ce6-b83b-3fbd75ecebb1","name":null,"avatar":null,"title":null,"order":0.5,"isAuthor":true,"roles":null,"affiliation":null,"orcid":null,"userId":"2b028128-c5e1-47da-8c59-af7b26d83970","pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","createdAt":"2022-04-11T17:29:37.997Z","updatedAt":"2022-04-11T17:29:37.997Z","user":{"id":"2b028128-c5e1-47da-8c59-af7b26d83970","firstName":"Scott","lastName":"Koenig","fullName":"Scott Koenig","avatar":"https://assets.pubpub.org/f088ur44/01599601723720.jpg","slug":"scott-koenig","initials":"SK","title":"DFIR Examiner","orcid":""}}],"exports":[{"id":"ecd0ddae-cdc7-4319-b6fe-4a6d2337502e","format":"epub","url":"https://assets.pubpub.org/l533bwtn/b2d0adf2-a290-4094-804c-c9eac7297bc9.epub","historyKey":1415,"pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","workerTaskId":"0993e005-1803-4114-9113-93cddeede790","createdAt":"2022-11-03T11:43:49.769Z","updatedAt":"2022-11-03T11:44:14.481Z"},{"id":"2911a13d-c7cc-4b09-a35e-ee3042d7f483","format":"docx","url":"https://assets.pubpub.org/b72k9c3c/b2d0adf2-a290-4094-804c-c9eac7297bc9.docx","historyKey":1415,"pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","workerTaskId":"472d0793-409d-42d9-95b5-c0cfbb63c02a","createdAt":"2022-11-03T11:43:49.770Z","updatedAt":"2022-11-03T11:44:15.967Z"},{"id":"52c1a70c-24bd-41de-b854-bc3bfb369ebc","format":"odt","url":"https://assets.pubpub.org/k0a3lwgr/b2d0adf2-a290-4094-804c-c9eac7297bc9.odt","historyKey":1415,"pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","workerTaskId":"7a8c3da1-6701-4e6f-90c7-4e1f74222475","createdAt":"2022-11-03T11:43:50.164Z","updatedAt":"2022-11-03T11:44:16.098Z"},{"id":"d3a71496-0c38-49a3-bcb4-0844baa8f2ac","format":"html","url":"https://assets.pubpub.org/8oixmger/b2d0adf2-a290-4094-804c-c9eac7297bc9.html","historyKey":1415,"pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","workerTaskId":"136fb4b5-d143-4081-b6ff-a3469ded0fa8","createdAt":"2022-11-03T11:43:49.767Z","updatedAt":"2022-11-03T11:44:09.761Z"},{"id":"4291c1a4-be44-48e6-a262-a85364dfbfc4","format":"json","url":"https://assets.pubpub.org/4tl1p4rx/b2d0adf2-a290-4094-804c-c9eac7297bc9.json","historyKey":1415,"pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","workerTaskId":"32a07912-5299-4f6d-88bd-564e0e2c729d","createdAt":"2022-11-03T11:43:50.131Z","updatedAt":"2022-11-03T11:44:10.055Z"},{"id":"921d4a25-ee6b-47f9-834a-c99bffba7a4d","format":"plain","url":"https://assets.pubpub.org/ybtzg5an/b2d0adf2-a290-4094-804c-c9eac7297bc9.txt","historyKey":1415,"pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","workerTaskId":"1cb64280-cc82-4a0a-b243-8a895387c594","createdAt":"2022-11-03T11:43:50.164Z","updatedAt":"2022-11-03T11:44:11.077Z"},{"id":"a324a518-0fb2-48a2-ac78-3867f8dd65f4","format":"markdown","url":"https://assets.pubpub.org/9p2fqxsb/b2d0adf2-a290-4094-804c-c9eac7297bc9.md","historyKey":1415,"pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","workerTaskId":"9a3829bd-eee6-4e65-949c-eab01691a16b","createdAt":"2022-11-03T11:43:49.767Z","updatedAt":"2022-11-03T11:44:11.497Z"},{"id":"59197573-daae-43fe-a3d9-a673965da4ad","format":"tex","url":"https://assets.pubpub.org/fadqgydj/b2d0adf2-a290-4094-804c-c9eac7297bc9.tex","historyKey":1415,"pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","workerTaskId":"8784e277-5044-4489-918a-596b19bbe581","createdAt":"2022-11-03T11:43:50.126Z","updatedAt":"2022-11-03T11:44:11.748Z"},{"id":"cc71c962-066f-462e-bda9-5bc213bfdd36","format":"jats","url":"https://assets.pubpub.org/2f19h3ii/b2d0adf2-a290-4094-804c-c9eac7297bc9.xml","historyKey":1415,"pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","workerTaskId":"9ef53a39-e6e2-451b-96c3-67ade2e6dfc5","createdAt":"2022-11-03T11:43:50.175Z","updatedAt":"2022-11-03T11:44:16.850Z"},{"id":"f300b55d-4fc7-404f-8da9-bacf92f24186","format":"pdf","url":"https://s3.amazonaws.com/assets.pubpub.org/8plrdb64p0xjvy9xb8zj7aiha5mwp3q0.pdf","historyKey":1415,"pubId":"b2d0adf2-a290-4094-804c-c9eac7297bc9","workerTaskId":"88e95829-d123-4a2b-9161-58d86290d633","createdAt":"2022-11-03T11:43:49.770Z","updatedAt":"2022-11-03T11:44:21.076Z"}],"isRelease":true,"releaseNumber":1,"initialStructuredCitations":{},"citationData":{"pub":{"default":"<div class=\"csl-bib-body\"> <div data-csl-entry-id=\"temp_id_12530990288487698\" class=\"csl-entry\">Koenig, S. (2022). iOS KnowledgeC.db Notifications. <i>DFIR Review</i>. Retrieved from https://dfir.pubpub.org/pub/g2v1z97i</div></div>","apa":"<div class=\"csl-bib-body\"> <div data-csl-entry-id=\"temp_id_12530990288487698\" class=\"csl-entry\">Koenig, S. (2022). iOS KnowledgeC.db Notifications. <i>DFIR Review</i>. https://dfir.pubpub.org/pub/g2v1z97i</div></div>","harvard":"<div class=\"csl-bib-body\"> <div data-csl-entry-id=\"temp_id_12530990288487698\" class=\"csl-entry\">Koenig, S. (2022) 'iOS KnowledgeC.db Notifications', <i>DFIR Review</i> [Preprint]. Available at: https://dfir.pubpub.org/pub/g2v1z97i.</div></div>","vancouver":"<div class=\"csl-bib-body\"> <div data-csl-entry-id=\"temp_id_12530990288487698\" class=\"csl-entry\"> <div class=\"csl-left-margin\">1. </div><div class=\"csl-right-inline\">Koenig S. iOS KnowledgeC.db Notifications. DFIR Review [Internet]. 2022 Nov 3; Available from: https://dfir.pubpub.org/pub/g2v1z97i</div> </div></div>","bibtex":"@article{Koenig2022iOS,\n\tauthor = {Koenig, Scott},\n\tjournal = {DFIR Review},\n\tyear = {2022},\n\tmonth = {nov 3},\n\tnote = {https://dfir.pubpub.org/pub/g2v1z97i},\n\tpublisher = {},\n\ttitle = {iOS {KnowledgeC}.db {Notifications}},\n}\n\n"}},"siblingEdges":[],"initialDoc":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"heading","attrs":{"id":"synopsis","rtl":null,"level":1,"fixedId":"","textAlign":null},"content":[{"text":"Synopsis","type":"text"}]},{"type":"table","attrs":{"id":"7pnvpve7ye","hideLabel":false},"content":[{"type":"table_row","content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null},"content":[{"type":"paragraph","attrs":{"id":"ca09dpu7kq","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Forensics Question:","type":"text","marks":[{"type":"strong"}]},{"text":" ","type":"text"},{"type":"hard_break"},{"text":"What are the different types of notifications we will have from the KnowledgeC.db and what do they mean? ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ncf47u53que","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Can we determine if the user interacted with device after a notification was received and displayed on an iPhone?","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null},"content":[{"type":"paragraph","attrs":{"id":"n4x03e4rspv","rtl":null,"class":null,"textAlign":null}},{"type":"image","attrs":{"id":"3z7uqe08aw","url":"https://assets.pubpub.org/otm7hspl/01604324623084.png","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}}]}]},{"type":"table_row","content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null},"content":[{"type":"paragraph","attrs":{"id":"tapzxzhb9k","rtl":null,"class":null,"textAlign":null},"content":[{"text":"OS Version:","type":"text","marks":[{"type":"strong"}]},{"text":" ","type":"text"},{"type":"hard_break"},{"text":"iOS 14.7.1 (18G82)","type":"text"}]},{"type":"paragraph","attrs":{"id":"n591ehow3km","rtl":null,"class":null,"textAlign":null},"content":[{"text":"iOS 14.4.2 (18D70)","type":"text"},{"type":"hard_break"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null},"content":[{"type":"image","attrs":{"id":"nlkqjkuo9y6","url":"https://assets.pubpub.org/9636kems/61615840870473.png","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}}]}]},{"type":"table_row","content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null},"content":[{"type":"paragraph","attrs":{"id":"zc8ryi5sxh","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Tools:","type":"text","marks":[{"type":"strong"}]},{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nvoaf3co3p6","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Cellebrite UFED 4PC 7.47.0.247","type":"text"}]},{"type":"paragraph","attrs":{"id":"ncw27heev64","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Cellebrite Physical Analyzer 7.48.1.3 – Does not decode KnowledgeC.db /notification/usage","type":"text"}]},{"type":"paragraph","attrs":{"id":"nckft86vwnj","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Magnet AXIOM 5.4.0.26185","type":"text"}]},{"type":"paragraph","attrs":{"id":"nceajwn8y1k","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"ArtEx 2.0.0.4","type":"text"}]},{"type":"paragraph","attrs":{"id":"nbjt1sjuitt","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"iLEAPP 1.9.4 – Does not decode KnowledgeC.db /notification/usage","type":"text"}]},{"type":"paragraph","attrs":{"id":"nbuqnlrxgak","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"APOLLO 1.4","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null},"content":[{"type":"paragraph","attrs":{"id":"n7fsdfw313q","rtl":null,"class":null,"textAlign":null}}]}]}]},{"type":"heading","attrs":{"id":"introduction","rtl":null,"level":1,"fixedId":"","textAlign":null},"content":[{"text":"Introduction","type":"text"}]},{"type":"paragraph","attrs":{"id":"nl0q2rww66z","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Cell phone use is routine. Our cell phones are really an extension of ourselves. We carry them around not only to make calls and messages, but they are also our daily planners, to-do lists, and entertainment resources. We use them at all times of the day – the alarms in the morning, email and social media all day, listening to music, and even reading books at night in bed. They can be a distraction, but does that stop us from checking them all day, especially when a notification pops up? Sometimes we just look to see what the notification is and move on with our business. Sometimes, a notification needs to be handled right away. How do iPhones, or at least those running iOS 14, store notifications, and what happened with those notifications?","type":"text"}]},{"type":"paragraph","attrs":{"id":"nrwcv8qmnd4","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" While using some commercial and some free forensic tools, I noticed very few of them decode the ","type":"text"},{"text":"KnowledgeC.db/notification/usage","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" data. The ones that do provide very little information about what the notification types mean.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nkdnqwptlml","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" Thanks to Sarah Edwards and several others who previously researched the ","type":"text"},{"text":"KnowledgeC.db, ","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":"we know it to be a great artifact. It can be used to determine a lot of device activities and a user’s pattern of life, but can we use that data to determine if a user interacted with the device after it received a notification?","type":"text"}]},{"type":"paragraph","attrs":{"id":"nimj8k7ahy7","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" Based on previous research and publications, in conjunction this research, I believe not only can we determine if a user interacted with the device after receiving a notification, but I also believe we can determine how and when that interaction occurred.","type":"text"}]},{"type":"paragraph","attrs":{"id":"ndb9vfz2fs4","rtl":null,"class":null,"textAlign":null}},{"type":"heading","attrs":{"id":"artifact-location","rtl":null,"level":2,"fixedId":"","textAlign":null},"content":[{"text":"Artifact Location:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nvib9kmh5zf","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· ","type":"text"},{"text":"private\\var\\mobile\\Library\\CoreDuet\\Knowledge\\","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"no3ykjo5d3i","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"The notification data I will be discussing is stored in the ","type":"text"},{"text":"KnowledgeC.db ZOBJECTS ","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":"table and","type":"text"},{"text":"ZSTRUCTUREDMETADATA ","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":"table","type":"text"},{"text":".","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n0wpm4ffvv1","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nctss9ttyfv","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"The data I will be discussing in detail is:","type":"text"}]},{"type":"paragraph","attrs":{"id":"nqq1z5wzcic","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· ","type":"text"},{"text":"ZSTREAMNAME ","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":"= ","type":"text"},{"text":"/notification/usage","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"np1gzbdn5kk","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· ","type":"text"},{"text":"ZVALUESTRING","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" = The notification types, which are listed below","type":"text"}]},{"type":"paragraph","attrs":{"id":"noss8wduju1","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"o ","type":"text"},{"text":"Clear","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n1ep3e7zlcw","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"o ","type":"text"},{"text":"DefaultAction","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nh6r8zh16u2","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"o ","type":"text"},{"text":"Dismiss","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n2wz4ijaj5v","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"o ","type":"text"},{"text":"Hidden","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"ncnajbhqb2w","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"o ","type":"text"},{"text":"IndirectClear","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nz5je6jt39j","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"o ","type":"text"},{"text":"Orb ","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n92f9lkv5vm","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"o ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nl8xdzl5yts","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· ","type":"text"},{"text":"Z_DKNOTIFICATIONUSAGEMETADATAKEY__BUNDLEID ","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":"= the bundle or application for which the notification is related. In the database, the bundle ID is only listed with a ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nreey7940hl","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· ","type":"text"},{"text":"Z_DKNOTIFICATIONUSAGEMETADATAKEY__IDENTIFIER","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" = semi-unique identifier that can be used to link different notification types.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n1x2o0s9guj","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ndsw39rc73x","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Note:","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" I mention the ","type":"text"},{"text":"Z_DKNOTIFICATIONUSAGEMETADATAKEY__IDENTIFIER ","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":"as a semi-unique identifier because in some cases, like the Do Not Disturb notifications, the identifier repeats itself, but we can still use this to link the notification types together while analyzing the data.","type":"text"}]},{"type":"paragraph","attrs":{"id":"ncf26m4j466","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nmw1qkviqn6","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Here is a link to GitHub for a SQLite query that might assist with analyzing the database","type":"text"}]},{"type":"paragraph","attrs":{"id":"nrn879vlwka","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n4s7fe6zliq","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Device Settings:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n5rcn1lweup","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"When using this data in a forensic analysis, be sure to check the device notification settings. During testing, all applications tested had all notifications turned ON. These are the settings a user can change that could restrict the notification types you might encounter during an analysis. Figure 1 shows the settings menu for the Apple Messenger Application (com.apple.MobileSMS). Please check out the resources section to review additional research.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n66n5w4e2ij","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n2uvjrz1z7d","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"nwjzs9zwm6t","url":"https://assets.pubpub.org/ygt9zlof/21659644944980.png","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"navqridz0eu","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nojk56cev8m","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 1","type":"text"}]},{"type":"paragraph","attrs":{"id":"n2nnmze8kqg","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nzfg5wnwttv","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Research and Testing: ","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nmtd1aniyc9","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"The following sections will demonstrate how I was able to determine each notification type and how I recreated them in testing. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nz7vw606qax","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n5z8blelkkc","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Note","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":": During testing, Magnet AXIOM, ArtEx, and APOLLO parsed the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notifications. Cellebrite Physical Analyzer and iLEAPP did not. iLEAPP had a section for iOS notifications, but the data was being parsed from","type":"text"},{"text":"DeliveredNotifications.plist, ","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":"not the notifications from ","type":"text"},{"text":"KnowledgeC.db,","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" review the resources for additional information. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"npmj3lacz2t","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n45x0gys5bq","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"During testing, the test device was connected to ArtEx via ArtExtraction – Live Connection. This allowed me to run multiple tests, and I did not have to repeatedly acquire full file system dumps. The acquisition methods and tools listed above were used to validate what was being displayed in ArtEx. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nafkquv0zbs","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nf5u57gbgnk","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Note:","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" If you are a curious how to perform your own testing using ArtEx, here is a link to a recorded session of Cellebrite’s Ctrl + Alt + Del where ArtEx creator Ian Whiffin discusses how to use the ArtEx Live Connection to conduct research: ","type":"text"},{"text":"https://www.cellebrite.com/en/using-artifact-examiner-artex-to-investigate-an-artifact-on-a-device/","type":"text","marks":[{"type":"link","attrs":{"href":"https://www.cellebrite.com/en/using-artifact-examiner-artex-to-investigate-an-artifact-on-a-device/","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"neqm92odl59","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nqpy1o3mdvp","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Receive Notification Type:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"ne9tjiiwh6n","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"A ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type is when a notification is received and displayed on the device. Depending on user interaction and device status the notification could be viewed from the springboard, the Lock Screen and/or the Notification Center. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nbkes9bk1j5","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ncfleq4ff3t","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 2 has an example of a ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type in ArtEx. During testing, this was created by sending the test device a text message (SMS). The test device screen came on and displayed the notification. After a few seconds, the screen automatically turned OFF and went dark. I did not touch or interact with the device or the screen.","type":"text"}]},{"type":"paragraph","attrs":{"id":"na1392iepum","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"image","attrs":{"id":"n8a1b24dgvf","url":"https://assets.pubpub.org/f6rpcgyb/71659645034872.jpeg","href":null,"size":94,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"nim2x12b5ud","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 2","type":"text"}]},{"type":"paragraph","attrs":{"id":"nee6x8svum8","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nikk9d4sxdn","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"I turned the screen ON and OFF several times, using side button. During that time, I captured a screenshot of what the notification looked like on the device, seen in Figure 3. This did not affect or change the notification as it remained visible on the Lock Screen.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nbwha3v1omv","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ntw6c6leyry","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"nic8l5g004w","url":"https://assets.pubpub.org/x0iv3gaw/41659645064014.jpeg","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"nsp67sxlin5","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 3","type":"text"}]},{"type":"paragraph","attrs":{"id":"nk73d6i716d","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nlvfuqspj11","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"At 2:14 PM, I made a phone call to the test device, which was unanswered. When the phone call was received by the device and the InCallService application was brought into focus. A ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type was created, seen in Figure 4 and Figure 5.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nn6e0y0wiqv","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"naia5vw25mu","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"nm367nxwlcz","url":"https://assets.pubpub.org/xw6lxvgp/21659645088930.jpeg","href":null,"size":100,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"n6bdt2jq72a","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 4","type":"text"}]},{"type":"paragraph","attrs":{"id":"nivfmie1kin","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nmey298z4cq","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"n1ixmfgqi7r","url":"https://assets.pubpub.org/re61xtc7/41659645110209.jpeg","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"nb4ca3i6cki","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 5","type":"text"}]},{"type":"paragraph","attrs":{"id":"n07dmcqe7hm","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"njj2jump1dq","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"At 3:35 PM, the test device received a phone call from an unknown source. The phone call was unanswered. There was not any user interaction with the screen. After the phone stopped ringing, the screen turned OFF and went dark. A ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type was recorded via the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":", seen in Figure 6 and Figure 7. You will notice a ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type for the voicemail which followed the unanswered phone call. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nge476zo8yy","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nvcg7eqbotp","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Note:","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" During testing, when I answered or declined an incoming phone call, a ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type would not be logged in the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":". A ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type would be logged in the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" when a phone call was missed/unanswered and when a voicemail was received. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n26t3upu8d5","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n96eyk9n612","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"These are examples of a","type":"text"},{"text":" Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type that occurred on an iPhone with iOS 14.7.1. These types of notifications will be recorded when a notification is received by the device and when it is displayed on the device screen. In Figure 7, we have four notifications on the test device. There has been no user interaction with the device screen or the notifications.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nffk50w1ucl","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n1k8g905kpz","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"ndmri46z5ad","url":"https://assets.pubpub.org/7cltj7ts/41659645140886.jpeg","href":null,"size":100,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"nj6080qlqek","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 6","type":"text"}]},{"type":"paragraph","attrs":{"id":"naee3q9n3b2","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nnex9drbiyx","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"nngdqlnb77q","url":"https://assets.pubpub.org/3l3vopr9/41659645161479.jpeg","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"np1tthmuosl","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 7","type":"text"}]},{"type":"paragraph","attrs":{"id":"n7oklhuvdcp","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"neemlg2j5c9","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Note:","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" If an application is in focus on a device and new application data is received for that specific application, no ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type will be recorded. If the application is running in the background, a ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type will be recorded. Example: if the Apple Messenger application is in focus and additional messages are received, a ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type will not be recorded in the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":". ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nbih58yalp5","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n8r11yh7fss","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Note:","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" During testing, there was a time when I did not have mobile data service and attempted to send two photos via multimedia messenger. When I attempted to send the messages to an Android device, the iPhone testing device received notifications which indicated the messages failed. The device recorded two ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notifications. These notifications had the same ","type":"text"},{"text":"Z_DKNOTIFICATIONUSAGEMETADATAKEY__IDENTIFIER","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":", so again, just a reminder, these identifiers are semi-unique. There is a chance to have duplicates.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nsb48z24n4e","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nobq70f235z","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Hidden Notification Type:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nprecnjmfmd","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"A ","type":"text"},{"text":"Hidden","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type will be recorded when a notification is hidden from the Lock Screen notification area. This area can be viewed both when the device is locked and when a user swipes down on the screen to see the Notification Center. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nnb0avdikh9","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nfh9ujqjr99","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"During testing this occurred a few different ways:","type":"text"}]},{"type":"paragraph","attrs":{"id":"nrh5ffe1t2d","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n9tyrmdhvbf","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· If a device is locked and it receives a notification, it will be displayed on the Lock Screen. When a user unlocks the device and accesses the springboard or an application, the notifications that were displayed on the Lock Screen, will no longer be displayed, thus they are hidden, and ","type":"text"},{"text":"Hidden","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification types will be recorded in the ","type":"text"},{"text":"KnowledgeC.db.","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nuret2mgdt1","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ne3tn74iufk","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· If a device is unlocked and the user is navigating the springboard or an application is in focus and a notification is received, a Banner Notification will be displayed on the screen. These notifications will be listed in the Lock Screen area until the device screen turns off, either by a user or a device setting.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nofpfq5sv8z","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nspngs98jww","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Note:","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" Please review my previous blog about how to determine what value was set for the display auto-lock.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nvs4jxjfl8a","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"noufshjdya1","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Figure 7, there are four notifications displayed on the Lock Screen. At 4:38:56 PM, the test device was unlocked and I clicked on one of the SMS notification banners. An open button appeared to the left of the notification banner. Instead of clicking on the open button, I clicked on the home button unlocking the device. At that time all the notification banners were hidden from the Lock Screen. I checked the Lock Screen and verified that there were no notification banners visible, seen in Figure 8.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nnbpw927pr5","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"n65mju15y6s","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"noc99vra6rq","url":"https://assets.pubpub.org/gnpge4xh/21659645179776.jpeg","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"npjgujol42p","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nk1y1zkkzwq","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"},{"type":"hard_break"},{"text":"Figure 8","type":"text"}]},{"type":"paragraph","attrs":{"id":"nng0kokdg1f","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"na5iz8mshgo","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"While reviewing the notifications in ArtEx, seen in Figure 9, I noticed there are four ","type":"text"},{"text":"Hidden","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notifications logged at the time I unlocked the device. I researched if there was any way to link the ","type":"text"},{"text":"Hidden","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type to the ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":"notification type. Reminder, bundle identifications are only recorded with a ","type":"text"},{"text":"Receive ","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":"notification type. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nmdc1geqi4b","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nsk5o05d34b","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"naclnood97p","url":"https://assets.pubpub.org/srbb2kft/11659645191340.jpeg","href":null,"size":100,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"ngrdojbliqm","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 9","type":"text"}]},{"type":"paragraph","attrs":{"id":"nz0pk2qo0j8","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n7e8wc4pxlh","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"As seen in Figure 10, I noticed Magnet AXIOM was parsing the ","type":"text"},{"text":"ZSTRUCTUREDMETADATA table Z_DKNOTIFICATIONUSAGEMETADATAKEY__IDENTIFIER","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" with the notifications. After additional testing, I was able to determine this is the value that can be used to link related notification types together.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n5345gexi4g","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nhnfc5dyyn4","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"njbo794270x","url":"https://assets.pubpub.org/awupvpuf/61659645213845.png","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"nqrdcxfafyh","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 10","type":"text"}]},{"type":"paragraph","attrs":{"id":"nbju8udwww3","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n00ubs27g83","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Figure 11, we can see the data stored in the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" when the 4 notifications were received. Then we can see when the notifications are hidden from the lock screen and when they are cleared from the Notification Center. Later I will discuss the ","type":"text"},{"text":"IndirectClear","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type and describe how and why this happened, see the ","type":"text"},{"text":"IndirectClear","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" section for more details. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nlxd8ayiq9l","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n3n71721igl","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"ny9rbm6r1eq","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 11","type":"text"}]},{"type":"paragraph","attrs":{"id":"n0ecpn6kas8","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n78niqmv8yx","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In the next example, the test device received a SMS notification, Facebook Messenger notification and a Twitter notification. When the notifications were received there was no user interaction with the device. The screen turned ON and OFF on its own. After the three notifications were received, the test device was unlocked by clicking the home button and all notifications were hidden from the Lock Screen. These notifications can still be visible in the Notification Center. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nrrdahddoe1","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n6b51r0flak","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Figure 12 we can see the activity for the three notifications that were received and hidden. When the notifications were hidden from the Lock Screen, ","type":"text"},{"text":"Hidden","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification types were recorded for each notification. Figure 12 shows how these actions look like on the device and in the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":".","type":"text"}]},{"type":"paragraph","attrs":{"id":"n0o0pf9cd9f","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nw40l14lm1u","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"nfw6920arad","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"ndufa7efeqr","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 12","type":"text"}]},{"type":"paragraph","attrs":{"id":"n1r9va0ylet","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"now02rz6m5d","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"The previous examples had user – device interaction. Based on the testing, ","type":"text"},{"text":"Hidden","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notifications can be both user and non-user initiated.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n1r0hgdvm00","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n4emdjcro8j","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Figure 13, the Notification Center is checked for any active notifications, which there are none. The device is unlocked, and the Facebook Messenger is brought into focus. While the application was in focus, the device received a notification for a SMS message. There was no user interaction with this notification, and it disappears from the screen on its own. Another message is received, and another Banner Notification is displayed, it also did not have any user interaction and disappears on its own.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n5jfs5vufsq","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nxb16beyyq4","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"The Facebook Messenger application was sent to the background, and we can see the messenger application still has a badge notification count, these will only be cleared after the application data is viewed or handled within the application. When the notifications were received, the messenger application was running in the background. All the applications were closed, except for the Facebook Messenger application. While the Facebook Messenger application was in focus, a Facebook Messenger message was received. Notice the device did not display a Banner Notification, as previously seen with the SMS notifications. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n8m0n1cgu7l","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ng5tmd5gd84","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"After the screen is turned off and the device is locked, we can only see the two SMS notifications are displayed in the Notification Center. The Facebook Messenger message did not generate a ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type and will not be listed in the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":".","type":"text"}]},{"type":"paragraph","attrs":{"id":"nnlzm4jmnig","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nvw4z2l6uxp","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"n3elkkpqb8l","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 13","type":"text"}]},{"type":"paragraph","attrs":{"id":"n7son2otz2m","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nd9uwqfcxdk","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Clear Notification Type:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nxw9ovw450z","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"A ","type":"text"},{"text":"Clear","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type occurs when a user manually swipes left on the notification banner displayed in the Lock Screen or in the Notification Center, by doing so, reveals a clear button. When the user presses the clear button for an individual notification or the clear all buttons. It removes the notification from the Lock Screen and the Notification Center.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n81nuk1wck1","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n8yut1qolm7","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Note:","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" A corresponding ","type":"text"},{"text":"IndirectClear","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type will also be recorded with a matching timestamp as the ","type":"text"},{"text":"Clear","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":"notification type. Review the ","type":"text"},{"text":"IndirectClear","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type section for more details. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n765hxf7b7d","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nyxb0hbmphy","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Figure 14, the test device receives a notification for an incoming SMS message. Then at 7:45:55 PM, another notification is received for a second incoming SMS message.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n392v6863tr","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nuai384o7x1","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"The user accessed the Lock Screen notifications, swiped left on the second notification, and pressed the clear button. The notification was removed from the Lock Screen and will not be displayed in the Notification Center. After analyzing the database, when the clear button is selected, that specific notification will have both a ","type":"text"},{"text":"Clear ","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":"notification type and an ","type":"text"},{"text":"IndirectClear","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type with the same timestamp. ","type":"text"},{"text":" ","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nxnix5ak5n1","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nmk6o4gr90e","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"The user then accessed the Lock Screen, swiped right on the notification banner, and clicked the open button. The Messenger application was brought into focus and the message was viewed within the application. After analyzing the database when the open button was selected, that specific notification would have both a ","type":"text"},{"text":"DefaultAction","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type and an ","type":"text"},{"text":"IndirectClear","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type with the same timestamp. Review the ","type":"text"},{"text":"DefaultAction","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type section for more details. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n6143oazdw4","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nt7uj3g3gep","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Figure 14 we can see what these actions look like on the device and the data recorded in the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":". ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n3rt0h0z4yc","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n5o0mh5crt5","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"nbqwypzu1ur","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 14","type":"text"}]},{"type":"paragraph","attrs":{"id":"nn6hj6uznvt","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nb65prefryk","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Dismiss Notification Type:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n3ntrhen6tr","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"If a device is unlocked and the screen is ON when a notification is received, if the user swipes up on the notification, before it disappears on its own, a ","type":"text"},{"text":"Dismiss","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type will be recorded in the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":".","type":"text"}]},{"type":"paragraph","attrs":{"id":"n518ozpr2ym","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n02f0stku03","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Figure 15, the test device receives a Facebook Messenger message notification. The user swiped up on the notification to dismiss it. Then a SMS message notification is received, and the user swiped up on the notification to dismiss it. The user then locks the device and views the Lock Screen and Notification Center. The two notifications that were dismissed are no longer visible in the Lock Screen notification area, but they are displayed in the Notification Center. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ncmeswzlhgg","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n2hh9y0asjj","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"The SMS notification is cleared from the Notification Center and the Facebook Messenger notification is opened, thus bringing the Facebook Messenger application into focus. Figure 15, shows what this looks like on the device and how the data is recorded in the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":".","type":"text"}]},{"type":"paragraph","attrs":{"id":"n740w9afpzb","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"niwu2t4mt7a","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"njtorio4npf","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 15","type":"text"}]},{"type":"paragraph","attrs":{"id":"nuvzwpiiu9b","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nk8cn7v3dpj","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"IndirectClear Notification Type:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n6702oyyqp7","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"An ","type":"text"},{"text":"IndirectClear","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type will occur when a notification is no longer displayed in the Notification Center. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ndizdqcsxrp","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n04a9664bgk","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Figure 16 the test device as already received two notifications, one from a SMS message and another from Twitter. An additional Facebook Messenger message notification is received. At this time, the test device is locked, and the screen is turning ON when the notifications are received, then back OFF on its own after the notification has been displayed. Another Twitter notification is received and displayed. Special thanks to Kevin Pagano (@KevinPagano3) for his assistance with an additional notification during testing! An additional SMS message notification was received.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nyknef5d7ak","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nlq6i6puapj","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"The user unlocked the device by pressing the home button. This user action then hid the notifications from the Lock Screen and a ","type":"text"},{"text":"Hidden","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type was recorded for each one of the notifications that were displayed on the Lock Screen.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nsd3nf1n71h","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n3ebzh19c9t","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"After the notifications were hidden from the Lock Screen, the user checked the Notification Center, and all the past notifications are still visible. The user entered the Notification Center and used the clear button to clear the Facebook Messenger notification. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ndoyn70bbdm","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nipocgmpkie","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"During testing, I received a phone call from someone reminding me that my vehicle warranty was expired. After receiving the phone call notification, the device was unlocked, and the notification was hidden from the Lock Screen, then the user cleared it from the Notification Center. Then the user cleared one of the SMS notifications from the Notification Center. The user then unlocks the device and views the springboard. Notice that all the badge notification counters are still visible.","type":"text"}]},{"type":"paragraph","attrs":{"id":"ncarbbs4r4i","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n3penouqel3","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Figure 16, we can see what this looks like on the device and how the data is recorded in the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":".","type":"text"}]},{"type":"paragraph","attrs":{"id":"ndxdm6rf6g4","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nt209d7jtro","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"njxaytswdzz","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 16","type":"text"}]},{"type":"paragraph","attrs":{"id":"nkbrymxc7tf","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ni7aebpz9xi","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"An ","type":"text"},{"text":"IndirectClear","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type will be recorded when the application is opened which has pending data/badge notifications that have not been viewed. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nl0gvujjxiv","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n5egvfdoz46","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"DefaultAction Notification Type:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nw5dr5wo00z","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"The ","type":"text"},{"text":"DefaultAction","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type occurs when a notification is received and is used to open the application to view the data.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nd25pxexrk0","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nb19mqmgc53","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"We have already seen some examples of the ","type":"text"},{"text":"DefaultAction","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type, but we will review it and show how it was replicated during testing.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nzw2558itys","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nh13xg2qc57","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In this first example, Figure 17, the device was unlocked, and the user was navigating the springboard. The device received a SMS message notification, which was displayed on the device in a banner notification. The notification banner was clicked, and the Apple Messenger application was opened to view the data. You will notice the ","type":"text"},{"text":"DefaultAction","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" and ","type":"text"},{"text":"IndirectClear","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification types are logged one second apart. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nkbjo28w85p","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"niscm0hv4mt","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"nxgh5miojmy","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 17 ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n7ew61c48y0","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"njy5k3q286f","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Note:","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" When a notification is used to bring an application into focus, the method listed for bringing the application into focus will be ","type":"text"},{"text":"com.apple.SpringBoard.transitionReason.externalrequest","type":"text","marks":[{"type":"em"}]},{"text":". I’ll be doing more research into application in focus methods for both iOS 14 and 15 and will be writing something soon, so stay tuned.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n8wyt1s8awu","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nj815thbi8m","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Figure 18, the second example, we will be reviewing the data stored in the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" and attempt to determine what happened on the device, based on what we have already learned in this blog. Based on previous testing I believe:","type":"text"}]},{"type":"paragraph","attrs":{"id":"nytbmg6oyff","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nf50dk6gxnp","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· On 10/1/2021 at 19:13:14 UTC, the device was unlocked, the screen was on, and the device received a Facebook Messenger notification.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n0xbzkvoyur","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nqhdwglpbs8","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· At 19:13:16 UTC, the device user swiped up on the notification to dismiss it.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n2qp9jn5yqr","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nzxp9r9r7cn","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· At 19:13:48 UTC, the notification was hidden from the Lock Screen. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ntl675ud79m","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nycrqp2qg97","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· At 19:14:23 UTC, the device user accessed the Notification Center and opened the notification, which then brought the Facebook Messenger into focus.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nmkyx1xg8an","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n4mtas9c8uz","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"njmkmxmahxa","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 18","type":"text"}]},{"type":"paragraph","attrs":{"id":"np2bu3nrt7o","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nt4q0dho241","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Figure 19 and can see what these device events look like in ArtEx.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nq6my7tk7ge","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ntrpuf9199c","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"nwg2vyrm1a5","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 19","type":"text"}]},{"type":"paragraph","attrs":{"id":"nax0x3f2tog","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"njzj90iic0y","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Orb Notifications: ","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n18c47lq8m5","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"I have not been able to determine exactly what ","type":"text"},{"text":"Orb","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" stands for and if anyone could provide some insight it would be appreciated.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nn3eijxpjo4","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nhze6259tre","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"During testing, I would receive an ","type":"text"},{"text":"Orb","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type in the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" when a notification was received, and I interacted with the notification on the device screen. When I pressed and held the notification, the application would open in a small sub-window on the device. I could send messages or preform other actions within the application from this small sub-window. The following are some examples:","type":"text"}]},{"type":"paragraph","attrs":{"id":"nirjk1x5750","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nes2xh2s6gj","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Do not Disturb Notification:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n79tjlbirwk","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"During testing, I received several Do Not Disturb While Driving notifications. While the notification was displayed on the Lock Screen, if I clicked on the notification a sub-window would appear and an option to select, ","type":"text"},{"text":"I’m Not Driving","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":"would be displayed. When this small sub-window with this option would be displayed on the screen, I would receive an ","type":"text"},{"text":"Orb","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type in the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":", seen in Figure 20.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n7x3w69je44","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nwxwoyof85o","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"n2w1nm35j22","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 20","type":"text"}]},{"type":"paragraph","attrs":{"id":"n87bbxbip9u","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nuggr7f1k6p","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Apple Messenger:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nh7zrk3pg55","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"During testing, I was able to replicate the ","type":"text"},{"text":"Orb","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type by sending a SMS message to the test device, then clicking on the notification and opening the Apple Messenger application in a small sub-window, which allowed me to interact with the application in the small sub-window, which included sending a text message, while the device was locked as seen in Figure 21.","type":"text"}]},{"type":"paragraph","attrs":{"id":"ni6y82udrwf","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nz33ltwek2g","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"nkecrlkbn46","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 21","type":"text"}]},{"type":"paragraph","attrs":{"id":"nqh68s1g08t","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nzbe0pewbfl","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Josh Hickman Image Testing:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n3ijoca6spp","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"After my testing, I decided to test my knowledge of these notifications and loaded up Josh Hickman’s iPhone SE iOS 14.3 image into ArtEx.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nop57k9woin","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nxf63n6a09p","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Facebook Messenger:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n45idad6zqb","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Josh Hickman’s documentation there is a section for Facebook Messenger, which is displayed in Figure 22. Notice in Figure 22, his test device sends and receives several messages, media messages and video calls. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ns7ad59bywx","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nv7tw5v7vdx","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"n3jmmkm4xr9","url":"https://assets.pubpub.org/a3h3obwr/01659645334113.png","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"nujyczs68rq","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 22","type":"text"}]},{"type":"paragraph","attrs":{"id":"nz6z6ik8wfd","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"npfc2ph6kgm","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 23 is that same timeframe viewed in ArtEx. Notice between 14:32 though 15:18, no new notifications were being received on the device. This is because the Facebook Application was in focus, and everything is occurring in real time on the device. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n6fmd06dafo","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n2npcp8ws8x","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"At 15:24:14 there is a Receive notification type for Google Duo (com.google.Tachyon). ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nrvqofljunr","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n5pbsma5tnf","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"ngirwvo6op8","url":"https://assets.pubpub.org/slwk1j4u/71659645349084.png","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"njl0rnrke55","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 23 ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ny2psc7m54g","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nfg439fhyzd","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Google Duo:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nfp7uz3la2j","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Josh Hickman’s documentation there is a section for Google Duo, which is displayed in Figure 24. Notice in Figure 24, there is documentation that on 2/4/2021 at 15:24, a note is received, which contained a message ","type":"text"},{"text":"What is this??","type":"text","marks":[{"type":"em"}]},{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ne1py2dxsmo","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nxqcjbh6yrw","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"n6vw8u7g7ka","url":"https://assets.pubpub.org/2by364ya/61659645369647.png","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"n843txpi9qa","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 24","type":"text"}]},{"type":"paragraph","attrs":{"id":"nkqaz3zs5jy","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ngne210d61i","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 25 is that same timeframe viewed in ArtEx. Notice there is a ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type, followed by a ","type":"text"},{"text":"DefaultAction","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":", then an ","type":"text"},{"text":"IndirectClear","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type. This indicates that when the notification was received on the device, the user used the notification to bring the application into focus. We can see in ArtEx the application started in focus at 15:24:20, which is one second after the ","type":"text"},{"text":"DefaultAction","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type was logged. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nbiyzl4b66j","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nr56mxe2hzo","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"nfj9hfvz1zg","url":"https://assets.pubpub.org/e5gexzku/11659645383334.png","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"n1ov6ya7m26","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 25","type":"text"}]},{"type":"paragraph","attrs":{"id":"nj89b46ii5e","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nr9uihukz3a","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Messenger Application:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n4rhqhf3suf","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Josh Hickman’s documentation there is a section for Messages, which is displayed in Figure 26. Notice in Figure 26, there is documentation that on 2/15/2021 at 13:06 (Eastern Time) an iMessage is received. Because Josh Hickman’s device is set to Eastern Time and I am in Pacific Time, for this example I will be referencing artifacts in UTC.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n2yo4j8jj13","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nz94qdcxr1f","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"nulkplczenl","url":"https://assets.pubpub.org/nv5e6s6l/11659645395392.png","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"nk8faw3xikd","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 26","type":"text"}]},{"type":"paragraph","attrs":{"id":"nul08wl9o1l","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"njnrx87hyfy","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"According to Josh Hickman’s documentation his device received an iMessage at 18:06 UTC. Can we answer the following questions?","type":"text"}]},{"type":"paragraph","attrs":{"id":"nuhh0tq9l0l","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nt909dr1lyo","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· Did the device display a notification on the screen for this message?","type":"text"}]},{"type":"paragraph","attrs":{"id":"neyx71umkwp","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· Did the user interact with the screen if a notification was displayed?","type":"text"}]},{"type":"paragraph","attrs":{"id":"n3eyqujgzr4","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· How was the notification cleared from the device?","type":"text"}]},{"type":"paragraph","attrs":{"id":"n5w29ub7nxo","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n4th7qbi22i","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Figure 27, we can see in ArtEx at 18:04:18 UTC, the device was unlocked, but notice an application was not in focus. A message was sent at 18:04:46 UTC, but was not sent from the iPhone, it was sent from a synced Mac.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nftofxpnkty","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n8jxmsyqu3g","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"At 18:06:37 UTC, a ","type":"text"},{"text":"Receive","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type was received on the device, thus because the device is unlocked, a banner notification would have been displayed on the screen. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nsu04wipmfa","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n9z9zubdzrd","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"At 18:06:37 UTC, a ","type":"text"},{"text":"Dismiss","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type was recorded, thus when the banner notification was displayed on the device, the user interacted with the screen and dismissed the banner notification.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n16blvpxx4p","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n4e22bg7rf9","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"At 18:06:49 UTC, the Messenger application (com.apple.MobileSMS) was brought into focus via the home screen.","type":"text"}]},{"type":"paragraph","attrs":{"id":"ntxlzsk6hh3","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nwru0gqec9h","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Note: If the notification was used to open the application a ","type":"text"},{"text":"DefaultAction","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type would have been recorded and the method of bringing the application into focus would have been different. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n0k105vgijh","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ns8tyjje0zn","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"At 18:06:52 UTC, a ","type":"text"},{"text":"IndirectClear","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" notification type was recorded because the application was opened, and the user viewed the message. The notification will no longer be displayed on the Lock Screen or the Notification Center.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n6jvv1a3b57","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nweaixynh91","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Notice in Figure 27, there are several messages being sent back and forth. Some from the synced Mac and others from the iPhone, but notifications are not being recorded. This is because the Messenger application was in focus when these messages were being sent and received.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n30n67ehls2","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"npzu8503onr","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"image","attrs":{"id":"njbxqxfwhn1","url":"https://assets.pubpub.org/hg5sk7xp/11659645419980.png","href":null,"size":100,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"n12mpzt0d0j","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 27","type":"text"}]},{"type":"paragraph","attrs":{"id":"nnyyiss4tu2","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nrvyrb0nbxu","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"In Figure 28, I have combined ArtEx and the ","type":"text"},{"text":"KnowledgeC.db","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" date in a video to again show how this works together. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nqgpstyf8lg","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nxaueoahhzl","rtl":null,"class":"MsoNoSpacing","textAlign":null}},{"type":"paragraph","attrs":{"id":"nhglyzesroa","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Figure 28 ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n8geeyhanhi","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"heading","attrs":{"id":"considerations","rtl":null,"level":2,"fixedId":"","textAlign":null},"content":[{"text":"Considerations:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"ncrm652y4j8","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"Most of this testing was done on a device with iOS 14.7.1, but I believe the results of this testing should be true with other versions of iOS 14.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nuv0ei8zh0i","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"I plan to conduct some additional testing on how device notifications are stored if the device is connected to a vehicle with and without CarPlay. I have done some preliminary testing, and it appears to be very similar to what has already been detailed in this blog. I will add any additional information learned to this blog later. ","type":"text"}]},{"type":"heading","attrs":{"id":"conclusion","rtl":null,"level":2,"fixedId":"","textAlign":null},"content":[{"text":"Conclusion:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"ngawthbjcui","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"I believe it has been demonstrated there are certain types of notifications that can be used, in conjunction with other device data, to prove whether a user interacted with a device at a certain time. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n34q7jbqnik","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" Based on testing","type":"text"},{"text":" ZVALUESTRING","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" is the notification types and each notification type is created when:","type":"text"}]},{"type":"paragraph","attrs":{"id":"nt24v90ywnj","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· Clear = Notification was cleared by a user via the Lock Screen or Notification Center ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nou1lwownkm","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· DefaultAction = An application is opened via a notification","type":"text"}]},{"type":"paragraph","attrs":{"id":"n6m6nq5ux3v","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· Dismiss = Notification was dismissed by a device user when the notification was received","type":"text"}]},{"type":"paragraph","attrs":{"id":"npo097y033a","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· Hidden = When notifications are hidden from the Lock Screen ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n4xlp1ooy49","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· IndirectClear = When notifications are cleared from the Notification Center","type":"text"}]},{"type":"paragraph","attrs":{"id":"nt3fxgfg4ao","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· Orb = Is triggered via user interaction when an application is opened in a small sub-window ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nbdn8btnrsi","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· Receive = Is when a notification is received and displayed on the device","type":"text"}]},{"type":"paragraph","attrs":{"id":"ndzv11zbwzv","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"heading","attrs":{"id":"references","rtl":null,"level":2,"fixedId":"","textAlign":null},"content":[{"text":"References:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n7snoay3rnt","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· August 2018 – Sarah Edwards","type":"text"}]},{"type":"paragraph","attrs":{"id":"nf8gpz2ap0w","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"o ","type":"text"},{"text":"https://www.mac4n6.com/blog/2018/8/5/knowledge-is-power-using-the-knowledgecdb-database-on-macos-and-ios-to-determine-precise-user-and-application-usage","type":"text","marks":[{"type":"link","attrs":{"href":"https://www.mac4n6.com/blog/2018/8/5/knowledge-is-power-using-the-knowledgecdb-database-on-macos-and-ios-to-determine-precise-user-and-application-usage","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"n7hjukup0h2","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nbqcwu9lzb8","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"o ","type":"text"},{"text":"https://objectivebythesea.com/v3/talks/OBTS_v3_sEdwards.pdf","type":"text","marks":[{"type":"link","attrs":{"href":"https://objectivebythesea.com/v3/talks/OBTS_v3_sEdwards.pdf","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"ngcjlie88xu","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nz3a6rmt723","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· August 2019 – Christopher Vance ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n2290cuwg3n","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"o ","type":"text"},{"text":"https://blog.d204n6.com/2019/08/ios-12-delivered-notifications-and-new.html?m=1","type":"text","marks":[{"type":"link","attrs":{"href":"https://blog.d204n6.com/2019/08/ios-12-delivered-notifications-and-new.html?m=1","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"ny5v3pwosdd","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nfsemk0t7l4","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· October 2019 – Ian Whiffin","type":"text"}]},{"type":"paragraph","attrs":{"id":"ns1grm844h8","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"o ","type":"text"},{"text":"http://www.doubleblak.com/m/blogPosts.php?id=2","type":"text","marks":[{"type":"link","attrs":{"href":"http://www.doubleblak.com/m/blogPosts.php?id=2","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"n70tcjun9zd","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"nkkrwuhkpry","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"· Josh Hickman’s Test Device images:","type":"text"}]},{"type":"paragraph","attrs":{"id":"ndnmnueny7o","rtl":null,"class":"MsoNoSpacing","textAlign":null},"content":[{"text":"o ","type":"text"},{"text":"https://thebinaryhick.blog/","type":"text","marks":[{"type":"link","attrs":{"href":"https://thebinaryhick.blog/","title":null,"target":null}}]}]},{"type":"heading","attrs":{"id":"dfir-review","rtl":null,"level":1,"fixedId":"","textAlign":null},"content":[{"text":"DFIR Review","type":"text"}]},{"type":"paragraph","attrs":{"id":"ntf0p5omsp0","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Determining what notifications, if any, were displayed on a mobile device is a common question asked of forensic examiners. Taking it a step further, understanding what a user of a device did when they were presented with a notification can provide user behavior patterns. The author of this paper demonstrated their understanding of the KnowledgeC and the gaps in research associated with notifications. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"n2uhabbbx5o","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Reviewers found that some of the figures in the paper were missing or could not be viewed.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nk5sxaa4xp6","rtl":null,"class":null,"textAlign":null},"content":[{"text":"As the Notification Center may be available from the lock screen, examiners should be cautioned on attributing interactive behavior to a a specific individual without performing additional analysis.","type":"text"}]},{"type":"heading","attrs":{"id":"future-work-provided-by-dfir-review","rtl":null,"level":1,"fixedId":"","textAlign":null},"content":[{"text":"Future Work (provided by DFIR Review)","type":"text"}]},{"type":"paragraph","attrs":{"id":"nixk5lpcwsb","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Reviewers are interested in seeing additional values for ZVALUESTRING and additional data that may be associated with device usage. Reviewers also suggested not using video attachments in the submission, if possible, as they do not publish well.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nxykm24eus7","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Future work on this topic could include testing newer iOS versions to see if anything has changed and testing if additional forensic tools can verify this information. Reviewers also suggested trying different types of applications such as email and also looking at reminders and other alerts.","type":"text"}]},{"type":"heading","attrs":{"id":"reviewers","rtl":null,"level":1,"fixedId":"","textAlign":null},"content":[{"text":"Reviewers","type":"text"}]},{"type":"paragraph","attrs":{"id":"n7jagjqy3ck","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Jessica Hyde, David Loveall (subreviewer) (Methodology Review, Validated Review Using Reviewer Generated Datasets)","type":"text"}]},{"type":"paragraph","attrs":{"id":"nc9uc9crzzm","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Troy Pugliese (Methodology Review)","type":"text"}]},{"type":"paragraph","attrs":{"id":"n0aeen54fx7","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Aricia Kulm (Methodology Review)","type":"text"}]},{"type":"paragraph","attrs":{"id":"nfee9cdm6ig","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Zheng Jie Chan (Methodology Review)","type":"text"}]},{"type":"paragraph","attrs":{"id":"nyg39hsr47z","rtl":null,"class":null,"textAlign":null}},{"type":"paragraph","attrs":{"id":"n84np68voka","rtl":null,"class":null,"textAlign":null}}]},"initialDocKey":1415,"historyData":{"latestKey":1415,"currentKey":1415,"timestamps":{}},"isAVisitingCommenter":false,"isReviewingPub":false,"nextCollectionPub":null}}"></script><script id="chunk-name" type="text/plain" data-json=""Pub""></script><script src="/dist/vendor.0257e546351f036bbd7d.bundle.js"></script><script src="/dist/main.0543ebefe1cf4d13c7ba.js"></script><script>(function(){function c(){var b=a.contentDocument||a.contentWindow.document;if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'93a922fc4e0fd98b',t:'MTc0NjM3MzY0OS4wMDAwMDA='};var a=document.createElement('script');a.nonce='';a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script></body></html>