CINXE.COM
iOS Settings Display Auto-Lock & Require Passcode · DFIR Review
<!DOCTYPE html><html lang="en" data-reactroot=""><head><meta charSet="utf-8"/><link rel="alternate" type="application/rss+xml" title="iOS Settings Display Auto-Lock & Require Passcode RSS Feed" href="https://dfir.pubpub.org/rss.xml"/><title>iOS Settings Display Auto-Lock & Require Passcode · DFIR Review</title><meta property="og:title" content="iOS Settings Display Auto-Lock & Require Passcode"/><meta name="twitter:title" content="iOS Settings Display Auto-Lock & Require Passcode · DFIR Review"/><meta name="twitter:image:alt" content="iOS Settings Display Auto-Lock & Require Passcode · DFIR Review"/><meta name="citation_title" content="iOS Settings Display Auto-Lock & Require Passcode"/><meta name="dc.title" content="iOS Settings Display Auto-Lock & Require Passcode"/><meta property="og:site_name" content="DFIR Review"/><meta name="citation_journal_title" content="DFIR Review"/><meta property="og:url" content="https://dfir.pubpub.org/pub/khnqi0ff/release/1"/><meta property="og:type" content="article"/><meta name="citation_pdf_url" content="https://dfir.pubpub.org/pub/khnqi0ff/download/pdf"/><meta property="og:image" content="https://assets.pubpub.org/3yqqvtl4/71553968763873.png"/><meta property="og:image:url" content="https://assets.pubpub.org/3yqqvtl4/71553968763873.png"/><meta property="og:image:width" content="500"/><meta name="twitter:image" content="https://assets.pubpub.org/3yqqvtl4/71553968763873.png"/><link rel="icon" type="image/png" sizes="256x256" href="https://assets.pubpub.org/c8g3oakn/41553968740088.png"/><meta name="citation_author" content="Scott Koenig"/><meta name="dc.creator" content="Scott Koenig"/><meta property="article:published_time" content="Thu Jun 02 2022 21:43:02 GMT+0000 (Coordinated Universal Time)"/><meta property="dc.date" content="2022-5-2"/><meta name="citation_publication_date" content="2022/6/2"/><meta property="dc.publisher" content="PubPub"/><link rel="canonical" href="https://dfir.pubpub.org/pub/khnqi0ff"/><meta property="fb:app_id" content="924988584221879"/><meta name="twitter:card" content="summary"/><meta name="twitter:site" content="@pubpub"/><meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no"/><meta name="google-site-verification" content="jmmJFnkSOeIEuS54adOzGMwc0kwpsa8wQ-L4GyPpPDg"/><link rel="stylesheet" type="text/css" href="/dist/main.8953e10b2e394e83bb73.css"/><link rel="search" type="application/opensearchdescription+xml" title="DFIR Review" href="/opensearch.xml"/></head><body class="pub-body-wrapper active-pub-khnqi0ff"><script>0</script><div id="root"><div id="app" class=""><style type="text/css">:root { --community-accent-dark: #2D2E2F; --community-accent-dark-faded-30: rgb(63, 63, 63); --community-accent-dark-faded: rgba(45, 46, 47, 0.050000000000000044); }</style><style> .accent-background { background-color: #2D2E2F; } .accent-color { color: #FFFFFF; } .accent-background.header-component, .accent-background.nav-bar-component, .accent-background.footer-component, .accent-background.nav-item-background, .accent-background.image-wrapper{ background-color: #2D2E2F; } .accent-color.header-component, .accent-color.nav-bar-component, .accent-color.footer-component, .accent-color.nav-item { color: #FFFFFF; } .bp3-button.bp3-intent-primary:not(.bp3-outlined) { background-color: rgba(45, 46, 47, 0.6); color: #FFFFFF; } .bp3-button.bp3-intent-primary:not(.bp3-outlined):hover:not(.bp3-disabled) { background-color: rgba(45, 46, 47, 0.8); color: #FFFFFF; } .bp3-button.bp3-intent-primary:not(.bp3-outlined):active:not(.bp3-disabled), .bp3-button.bp3-intent-primary.bp3-active:not(.bp3-disabled) { background-color: #2D2E2F; color: #FFFFFF; } .bp3-button.bp3-intent-primary.bp3-outlined { border-color: #2D2E2F; color: #2D2E2F; } .bp3-button.bp3-intent-primary.bp3-outlined:hover:not(.bp3-disabled) { background-color: rgba(45, 46, 47, 0.09999999999999998); color: #2D2E2F; } .bp3-button.bp3-intent-primary.bp3-outlined:active:not(.bp3-disabled), .bp3-button.bp3-intent-primary.bp3-active:not(.bp3-disabled) { background-color: rgba(45, 46, 47, 0.19999999999999996); color: #2D2E2F; } .bp3-tree-node.bp3-tree-node-selected > .bp3-tree-node-content { background-color: #2D2E2F; } .bp3-tag.bp3-intent-primary { background: #2D2E2F; color: #FFFFFF; } .bp3-tag.bp3-minimal.bp3-intent-primary { background-color: rgba(45, 46, 47, 0.09999999999999998); color: inherit; } .accent-color .bp3-button:not([class*="bp3-intent-primary"]), .accent-color .bp3-button:not([class*="bp3-intent-success"]), .accent-color .bp3-button:not([class*="bp3-intent-warning"]), .accent-color .bp3-button:not([class*="bp3-intent-danger"]), .accent-color .bp3-button[class*="bp3-icon"]::before { color: inherit; } .accent-color a, .accent-color a:hover { color: inherit; } .bp3-tab[aria-selected="true"], .bp3-tab:not([aria-selected="true"]):hover { box-shadow: inset 0 -3px 0 rgba(45, 46, 47, 0.09999999999999998); } .bp3-tab[aria-selected="true"] { box-shadow: inset 0 -3px 0 #2D2E2F; } .thread:hover:after { background-color: #2D2E2F; } .bp3-slider-progress.bp3-intent-primary, .bp3-dark .bp3-slider-progress.bp3-intent-primary { background: #2D2E2F; } .bp3-slider-handle .bp3-slider-label { background: #2D2E2F; color: #FFFFFF; } .highlight-dot-wrapper .highlight-dot { background-color: #2D2E2F; } .changelog-callout { background: rgba(45, 46, 47, 0.09999999999999998) !important; } .changelog-callout .release-label { color: #2D2E2F; border: 1px dashed #2D2E2F; } span.citation:hover { color: #2D2E2F; } .overflow-gradient { background: linear-gradient(90deg, rgba(45, 46, 47, 0) 0%, rgba(45, 46, 47, 0) 85%, #2D2E2F 100%); } </style><a href="#main-content" tabindex="0" class="skip-link-component tab-to-show-component">Skip to main content</a><header class="header-component accent-background accent-color"><div class="main"><div class="container "><div class="row"><div class="col-12 main-content"><div class="logo-wrapper"><a href="/" aria-label="DFIR Review"><img alt="" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImhuZHdvMDAzLzYxNjc1Mzc0NjMxMDQ5LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJoZWlnaHQiOjUwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0="/></a></div><div class="global-controls-component"><a role="button" href="/search" aria-label="Search" class="bp3-button bp3-minimal mobile-aware-component__mobile" tabindex="0"><span icon="search" class="bp3-icon bp3-icon-search"><svg data-icon="search" width="16" height="16" viewBox="0 0 16 16"><path d="M15.55 13.43l-2.67-2.68a6.94 6.94 0 001.11-3.76c0-3.87-3.13-7-7-7s-7 3.13-7 7 3.13 7 7 7c1.39 0 2.68-.42 3.76-1.11l2.68 2.67a1.498 1.498 0 102.12-2.12zm-8.56-1.44c-2.76 0-5-2.24-5-5s2.24-5 5-5 5 2.24 5 5-2.24 5-5 5z" fill-rule="evenodd"></path></svg></span></a><a role="button" href="/search" aria-label="Search" class="bp3-button bp3-large bp3-minimal mobile-aware-component__desktop" tabindex="0"><span class="bp3-button-text">Search</span></a><button type="button" style="display:inline-flex;-webkit-appearance:unset" aria-expanded="false" aria-controls="id-2" aria-haspopup="menu" aria-label="Dashboard menu" class="bp3-button bp3-minimal mobile-aware-component__mobile"><span icon="settings" class="bp3-icon bp3-icon-settings"><svg data-icon="settings" width="16" height="16" viewBox="0 0 16 16"><path d="M3 1c0-.55-.45-1-1-1S1 .45 1 1v3h2V1zm0 4H1c-.55 0-1 .45-1 1v2c0 .55.45 1 1 1h2c.55 0 1-.45 1-1V6c0-.55-.45-1-1-1zm12-4c0-.55-.45-1-1-1s-1 .45-1 1v2h2V1zM9 1c0-.55-.45-1-1-1S7 .45 7 1v6h2V1zM1 15c0 .55.45 1 1 1s1-.45 1-1v-5H1v5zM15 4h-2c-.55 0-1 .45-1 1v2c0 .55.45 1 1 1h2c.55 0 1-.45 1-1V5c0-.55-.45-1-1-1zm-2 11c0 .55.45 1 1 1s1-.45 1-1V9h-2v6zM9 8H7c-.55 0-1 .45-1 1v2c0 .55.45 1 1 1h2c.55 0 1-.45 1-1V9c0-.55-.45-1-1-1zm-2 7c0 .55.45 1 1 1s1-.45 1-1v-2H7v2z" fill-rule="evenodd"></path></svg></span></button><button type="button" style="display:inline-flex;-webkit-appearance:unset" aria-expanded="false" aria-controls="id-2" aria-haspopup="menu" aria-label="Dashboard menu" class="bp3-button bp3-large bp3-minimal mobile-aware-component__desktop"><span class="bp3-button-text">Dashboard</span><span icon="caret-down" class="bp3-icon bp3-icon-caret-down"><svg data-icon="caret-down" width="16" height="16" viewBox="0 0 16 16"><desc>caret-down</desc><path d="M12 6.5c0-.28-.22-.5-.5-.5h-7a.495.495 0 00-.37.83l3.5 4c.09.1.22.17.37.17s.28-.07.37-.17l3.5-4c.08-.09.13-.2.13-.33z" fill-rule="evenodd"></path></svg></span></button><a role="button" href="/login?redirect=/pub/khnqi0ff/release/1" class="bp3-button bp3-minimal mobile-aware-component__mobile" tabindex="0"><span class="bp3-button-text">Login</span></a><a role="button" href="/login?redirect=/pub/khnqi0ff/release/1" class="bp3-button bp3-large bp3-minimal mobile-aware-component__desktop" tabindex="0"><span class="bp3-button-text">Login or Signup</span></a></div></div></div></div></div></header><nav class="nav-bar-component accent-background accent-color"><div class="container "><div class="row"><div class="col-12 "><div class="scrollable-nav"><ul class="nav-list"><li><a href="/"><span class="title">DFIR Review</span></a></li><li><a href="/blog"><span class="title">Stats</span></a></li><li><a href="/reviewers"><span class="title">Reviewers</span></a></li><li><a href="/submission-guidance"><span class="title">Submission Guidance</span></a></li><li><a href="/pub"><span class="title">Publications</span></a></li><li><a href="/about"><span class="title">Aims & Scope</span></a></li><li><a href="/review-guidance"><span class="title">Review Guidance</span></a></li><li><a href="/community"><span class="title">Community</span></a></li><li><a href="/dfrws"><span class="title">DFRWS.org</span></a></li></ul><div class="overflow-gradient"></div></div></div></div></div></nav><div id="main-content" tabindex="-1"><div id="pub-container"><div class="pub-header-background-component pub-header-theme-dark pub-header-component"><div class="background-element background-white-layer"></div><div class="background-element background-color" style="background-color:rgba(0, 0, 0, 0.0275)"></div><div class="background-element background-safety-layer"></div><div class="container pub"><div class="row"><div class="col-12 pub-header-column"><div class="pub-header-content-component"><div class="pub-header-top-area has-bottom-hairline"><div class="basic-details"><span class="metadata-pair"><b class="pub-header-themed-secondary">Published on </b>Jun 02, 2022</span><div class="show-details-placeholder"></div></div></div><div class="title-group-component"><h1 class="title"><span class="text-wrapper">iOS Settings Display Auto-Lock & Require Passcode</span></h1><div class="byline-component"><span class="text-wrapper"><span>by<!-- --> </span><span><a href="/user/scott-koenig" class="hoverline">Scott Koenig</a></span></span></div><div class="published-date"><span class="pub-header-themed-secondary">Published on</span><span>Jun 02, 2022</span></div></div><div class="utility-buttons-component"><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left show-header-details-button"><div class="pub-header-themed-box icon-container"><span icon="info-sign" class="bp3-icon bp3-icon-info-sign"><svg data-icon="info-sign" width="14" height="14" viewBox="0 0 16 16"><path d="M8 0C3.58 0 0 3.58 0 8s3.58 8 8 8 8-3.58 8-8-3.58-8-8-8zM7 3h2v2H7V3zm3 10H6v-1h1V7H6V6h3v6h1v1z" fill-rule="evenodd"></path></svg></span></div></button><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left cite-button"><div class="pub-header-themed-box icon-container"><span class="bp3-icon" data-icon="cite" aria-label="" aria-hidden="true"><svg width="14px" height="14px" viewBox="0 0 24 24"><g><path d="M5.56 22.286v-2.548h-2.039v-15.476h2.039v-2.548h-5.56v20.573h5.56zM24 22.286v-20.573h-5.583v2.548h2.039v15.476h-2.039v2.548h5.583z"></path><path d="M13.918 5.993l-0.421 3.1h-2.409l0.438-3.1h-1.348l-0.421 3.1h-1.702v1.23h1.516l-0.404 2.982h-1.668v1.23h1.483l-0.438 3.083h1.331l0.438-3.083h2.393l-0.438 3.083h1.348l0.421-3.083h1.719v-1.23h-1.533l0.404-2.982h1.685v-1.23h-1.483l0.421-3.1h-1.331zM10.902 10.324h2.393l-0.388 2.982h-2.409l0.404-2.982z"></path></g></svg></span></div><div class="label">Cite</div></button><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left"><div class="pub-header-themed-box icon-container"><span class="bp3-icon" data-icon="share2" aria-label="" aria-hidden="true"><svg width="14px" height="14px" viewBox="0 0 32 32"><path d="M25.524 22.54c-1.206 0-2.286 0.476-3.111 1.222l-11.317-6.587c0.079-0.365 0.143-0.73 0.143-1.111s-0.063-0.746-0.143-1.111l11.19-6.524c0.857 0.794 1.984 1.286 3.238 1.286 2.635 0 4.762-2.127 4.762-4.762s-2.127-4.762-4.762-4.762c-2.635 0-4.762 2.127-4.762 4.762 0 0.381 0.064 0.746 0.143 1.111l-11.191 6.524c-0.857-0.794-1.984-1.286-3.238-1.286-2.635 0-4.762 2.127-4.762 4.762s2.127 4.762 4.762 4.762c1.254 0 2.381-0.492 3.238-1.286l11.302 6.603c-0.079 0.333-0.127 0.683-0.127 1.032 0 2.556 2.079 4.635 4.635 4.635s4.635-2.079 4.635-4.635c0-2.556-2.079-4.635-4.635-4.635z"></path></svg></span></div><div class="label">Social</div></button><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left"><div class="pub-header-themed-box icon-container"><span class="bp3-icon" data-icon="download2" aria-label="" aria-hidden="true"><svg width="14px" height="14px" viewBox="0 0 32 32"><path d="M28.963 11.37h-7.407v-11.111h-11.111v11.111h-7.407l12.963 12.963 12.963-12.963zM3.037 28.037v3.704h25.926v-3.704h-25.926z"></path></svg></span></div><div class="label">Download</div></button><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left"><div class="pub-header-themed-box icon-container"><span class="bp3-icon" data-icon="toc" aria-label="" aria-hidden="true"><svg width="14px" height="14px" viewBox="0 0 24 24"><g><path d="M17.077 19.582h-11.538v3.033h11.538v-3.033zM24 7.451h-18.462v3.033h18.462v-3.033zM5.538 16.55h18.462v-3.033h-18.462v3.033zM5.538 1.385v3.033h18.462v-3.033h-18.462z"></path><path d="M2.769 2.769c0 0.765-0.62 1.385-1.385 1.385s-1.385-0.62-1.385-1.385c0-0.765 0.62-1.385 1.385-1.385s1.385 0.62 1.385 1.385z"></path></g></svg></span></div><div class="label">Contents</div></button></div><div class="draft-release-buttons-component"><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left mobile-aware-component__mobile"><div class="pub-header-themed-box icon-container"><span icon="history" class="bp3-icon bp3-icon-history"><svg data-icon="history" width="14" height="14" viewBox="0 0 16 16"><path d="M8 3c-.55 0-1 .45-1 1v4c0 .28.11.53.29.71l2 2a1.003 1.003 0 001.42-1.42L9 7.59V4c0-.55-.45-1-1-1zm0-3a7.95 7.95 0 00-6 2.74V1c0-.55-.45-1-1-1S0 .45 0 1v4c0 .55.45 1 1 1h4c.55 0 1-.45 1-1s-.45-1-1-1H3.54C4.64 2.78 6.23 2 8 2c3.31 0 6 2.69 6 6 0 2.61-1.67 4.81-4 5.63v-.01c-.63.23-1.29.38-2 .38-3.31 0-6-2.69-6-6 0-.55-.45-1-1-1s-1 .45-1 1c0 4.42 3.58 8 8 8 .34 0 .67-.03 1-.07.02 0 .04-.01.06-.01C12.98 15.4 16 12.06 16 8c0-4.42-3.58-8-8-8z" fill-rule="evenodd"></path></svg></span></div></button><button style="display:inline-flex;-webkit-appearance:unset" type="button" class="large-header-button-component pub-header-themed-box-hover-target mobile-aware-component__desktop" aria-expanded="false" aria-controls="id-11" aria-haspopup="menu" aria-label="Choose a historical release of this Pub"><div class="button-box pub-header-themed-box no-label"><span icon="history" class="bp3-icon bp3-icon-history"><svg data-icon="history" width="22" height="22" viewBox="0 0 20 20"><path d="M10 0C6.71 0 3.82 1.6 2 4.05V2c0-.55-.45-1-1-1s-1 .45-1 1v4c0 .55.45 1 1 1h4c.55 0 1-.45 1-1s-.45-1-1-1H3.76C5.23 3.17 7.47 2 10 2c4.42 0 8 3.58 8 8s-3.58 8-8 8-8-3.58-8-8c0-.55-.45-1-1-1s-1 .45-1 1c0 5.52 4.48 10 10 10s10-4.48 10-10S15.52 0 10 0zm0 3c-.55 0-1 .45-1 1v6c0 .28.11.53.29.71l3 3a1.003 1.003 0 001.42-1.42L11 9.59V4c0-.55-.45-1-1-1z" fill-rule="evenodd"></path></svg></span><span icon="caret-down" class="bp3-icon bp3-icon-caret-down caret"><svg data-icon="caret-down" width="10" height="10" viewBox="0 0 16 16"><path d="M12 6.5c0-.28-.22-.5-.5-.5h-7a.495.495 0 00-.37.83l3.5 4c.09.1.22.17.37.17s.28-.07.37-.17l3.5-4c.08-.09.13-.2.13-.33z" fill-rule="evenodd"></path></svg></span></div><div class="outer-label"><div class="top pub-header-themed-secondary">last released</div><div class="bottom"><time dateTime="2022-06-02T21:43:02.509Z" title="2022-06-02 21:43">3 years ago</time></div></div></button></div></div><button type="button" class="small-header-button-component pub-header-themed-box-hover-target label-left details-button"><div class="pub-header-themed-box icon-container"><span icon="expand-all" class="bp3-icon bp3-icon-expand-all"><svg data-icon="expand-all" width="14" height="14" viewBox="0 0 16 16"><path d="M4 7c.28 0 .53-.11.71-.29L8 3.41l3.29 3.29c.18.19.43.3.71.3a1.003 1.003 0 00.71-1.71l-4-4C8.53 1.11 8.28 1 8 1s-.53.11-.71.29l-4 4A1.003 1.003 0 004 7zm8 2c-.28 0-.53.11-.71.29L8 12.59l-3.29-3.3a1.003 1.003 0 00-1.42 1.42l4 4c.18.18.43.29.71.29s.53-.11.71-.29l4-4A1.003 1.003 0 0012 9z" fill-rule="evenodd"></path></svg></span></div><div class="label">Show details</div></button></div></div></div><div class="pub-header-sticky-component"><div class="sticky-title">iOS Settings Display Auto-Lock & Require Passcode</div><div class="sticky-buttons"><button type="button" style="display:inline-flex;-webkit-appearance:unset" aria-expanded="false" aria-controls="id-13" aria-haspopup="menu" aria-label="Table of contents" class="bp3-button bp3-minimal contents-button"><span class="bp3-button-text">Contents</span></button><span class="dot">·</span><button type="button" class="bp3-button bp3-minimal"><span icon="double-chevron-up" class="bp3-icon bp3-icon-double-chevron-up"><svg data-icon="double-chevron-up" width="16" height="16" viewBox="0 0 16 16"><path d="M4 8c.28 0 .53-.11.71-.29L8 4.41l3.29 3.29c.18.19.43.3.71.3a1.003 1.003 0 00.71-1.71l-4-4C8.53 2.11 8.28 2 8 2s-.53.11-.71.29l-4 4A1.003 1.003 0 004 8zm4.71-.71C8.53 7.11 8.28 7 8 7s-.53.11-.71.29l-4 4a1.003 1.003 0 001.42 1.42L8 9.41l3.29 3.29c.18.19.43.3.71.3a1.003 1.003 0 00.71-1.71l-4-4z" fill-rule="evenodd"></path></svg></span></button></div></div></div><div class="pub-document-component"><div class="pub-grid"><div class="main-content"><main class="pub-body-component"><div class="editor ProseMirror read-only"><h1 id="synopsis">Synopsis</h1><div class="tableWrapper" id="7pnvpve7ye" data-smaller-font="false"><table><tbody><tr><td><p id="ca09dpu7kq"><strong>Forensics Question:</strong> <br/>Where in an iPhone extraction is the Display Auto-Lock setting stored?</p></td><td><p id="n4x03e4rspv"></p><figure id="3z7uqe08aw" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/otm7hspl/01604324623084.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im90bTdoc3BsLzAxNjA0MzI0NjIzMDg0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im90bTdoc3BsLzAxNjA0MzI0NjIzMDg0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im90bTdoc3BsLzAxNjA0MzI0NjIzMDg0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im90bTdoc3BsLzAxNjA0MzI0NjIzMDg0LnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="3z7uqe08aw-figure-caption"><div><div></div></div></figcaption></figure></td></tr><tr><td><p id="tapzxzhb9k"><strong>OS Version:</strong> <br/>Apple iPhone 6s Plus</p><p id="n4klbbxl1cb">iOS: 14.4.2 (18D70)</p><p id="ngpq3x6tp7d">Older iOS versions checked: 12.4.8 and 13.5.1<br/></p></td><td><p id="n391zwd0vvf"></p><figure id="nlkqjkuo9y6" data-node-type="image" data-size="50" data-align="center" data-url="https://assets.pubpub.org/9636kems/61615840870473.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Ijk2MzZrZW1zLzYxNjE1ODQwODcwNDczLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Ijk2MzZrZW1zLzYxNjE1ODQwODcwNDczLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Ijk2MzZrZW1zLzYxNjE1ODQwODcwNDczLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Ijk2MzZrZW1zLzYxNjE1ODQwODcwNDczLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="nlkqjkuo9y6-figure-caption"><div><div></div></div></figcaption></figure></td></tr><tr><td><p id="zc8ryi5sxh"><strong>Tools:</strong> <br/>Cellebrite UFED 4PC 7.47.0.247</p><p id="nqh9bdssj58">Cellebrite Physical Analyzer 7.47.0.58 & 7.48.0.49</p><p id="nbwyb3mi5bf">Magnet AXIOM 5.4.0.26185</p><p id="nwyq646eax0">ArtEx 1.6.0.0 & 2.0.0.4</p><p id="nakeiytbtx2">Mushy 2.0.0.6</p></td><td><p id="njvcbgnlcqn"></p></td></tr></tbody></table></div><p id="npqh6p8iuob">A classmate of mine contacted me and posed a question, “Where in an iPhone extraction is the Display Auto-Lock setting stored?” Thanks, Tyler Wuestenhagen, for posing the question and getting me thinking.</p><p id="ncoruksx4i7">I did a little research, like reviewing the SANS FOR585 poster and class notes, but could not find the easy answer. I reached out to some other examiners, and they too were a bit puzzled about where those settings might be saved or which property list (plist) they might be stored in.</p><p id="nocfbvbt6wt">Tyler was able to narrow down the search when he discovered the <em><strong>PublicEffectiveUserSettings.plist</strong></em>. This plist can be found at the following location on iPhone extractions: <em>\private\var\mobile\Library\UserConfigurationProfiles\PublicInfo\</em></p><p id="nfj6udrvkrc">After learning about the plist, I started working on testing and validating the data stored in the plist.</p><p id="nqz64vuozto">During testing, the data was acquired using the following tools and methods. The <em>PublicEffectiveUserSettings.plist</em> was found in each of the data extractions listed:</p><p id="nfk4ye886yi">Cellebrite Advance Logical Extraction – UFED 4PC</p><p id="nl8zxszpvpl">Cellebrite Advance Logical Full File System – device jailbroken with Checkm8 – UFED 4PC</p><p id="n8t0zh0gvx9">ArtEx ArtExtraction – Full Extraction – device jailbroken with Checkm8</p><p id="ng02oww68ad">ArtEx ArtExtraction – Live Connection – device jailbroken with Checkm8</p><p id="n5g7u6en8qp">Graykey Full File System</p><p id="n03pux23mnz">Based on testing, I have determined there are several device settings stored within the <em>PublicEffectiveUserSettings.plist</em>, but I will only be discussing two of those settings: the <em><strong>Display Auto-Lock setting</strong></em> and the <em><strong>Required Passcode setting</strong></em>.</p><figure id="njdo4xe29ru" data-node-type="image" data-size="50" data-align="full" data-url="https://assets.pubpub.org/wio8nklv/01649340049910.png" data-caption="<p>A screenshot of a phone Description automatically generated with medium confidence</p>" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Indpbzhua2x2LzAxNjQ5MzQwMDQ5OTEwLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Indpbzhua2x2LzAxNjQ5MzQwMDQ5OTEwLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Indpbzhua2x2LzAxNjQ5MzQwMDQ5OTEwLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Indpbzhua2x2LzAxNjQ5MzQwMDQ5OTEwLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt="" aria-labelledby="njdo4xe29ru-figure-caption"/><figcaption id="njdo4xe29ru-figure-caption"><div><div><p>A screenshot of a phone Description automatically generated with medium confidence</p></div></div></figcaption></figure><p id="ng2vckdkafx">Figure 1</p><p id="nezqosxqv0j"><strong>Display & Brightness Auto-Lock Setting:</strong></p><p id="njneq4ia8r7">In the Display & Brightness setting there is a setting titled <em>Auto-Lock</em> as seen in Figure 2.</p><figure id="nj24n4b1l7a" data-node-type="image" data-size="50" data-align="full" data-url="https://assets.pubpub.org/n9cg168p/21649340049911.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im45Y2cxNjhwLzIxNjQ5MzQwMDQ5OTExLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im45Y2cxNjhwLzIxNjQ5MzQwMDQ5OTExLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im45Y2cxNjhwLzIxNjQ5MzQwMDQ5OTExLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im45Y2cxNjhwLzIxNjQ5MzQwMDQ5OTExLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="nj24n4b1l7a-figure-caption"><div><div></div></div></figcaption></figure><p id="nufq6s8n7x6">Figure 2</p><p id="n70y66gpcd6">During testing, the Display Auto-Lock options were 30 Seconds, 1 Minute, 2 Minutes, 3 Minutes, 4 Minutes, 5 Minutes and Never:</p><figure id="nnn94podjfj" data-node-type="image" data-size="50" data-align="full" data-url="https://assets.pubpub.org/o7zu94jo/61649340049912.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im83enU5NGpvLzYxNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im83enU5NGpvLzYxNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im83enU5NGpvLzYxNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6Im83enU5NGpvLzYxNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="nnn94podjfj-figure-caption"><div><div></div></div></figcaption></figure><p id="neq7869f69m">Figure 3</p><p id="n0m5ylhc7c4">These Display Auto-Lock settings are stored in the <em>PublicEffectiveUserSettings.plist</em> in seconds. For example: if the Display Auto-Lock setting is set to auto-lock after 2 minutes as seen in Figure 3, the <em>value</em> key integer will be “120” meaning 120 seconds or 2 minutes.</p><p id="ni7winji862">To find this <em>value</em> key integer within the <em>PublicEffectiveUserSettings.plist</em> you will need to find the <em>restrictedValue</em> key, then the <em>maxInactivity</em> key. Once you have located these keys you will notice an integer that represents the setting value in seconds, as seen in Figure 4.</p><p id="npmuchd3hsq">Apple Developer website, <a href="https://developer.apple.com/documentation/devicemanagement/passcode" title="">https://developer.apple.com/documentation/devicemanagement/passcode</a>, defines <em>maxInactivity</em> as “the maximum number of minutes for which the device can be idle, without being unlocked by the user, before it gets locked by the system. When this limit is reached, the device is locked and the passcode must be entered. The user can edit this setting, but the value cannot exceed the maxInactivity value.”</p><figure id="n662lxf9pjp" data-node-type="image" data-size="50" data-align="full" data-url="https://assets.pubpub.org/sr1ehyny/71649340049912.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InNyMWVoeW55LzcxNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InNyMWVoeW55LzcxNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InNyMWVoeW55LzcxNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InNyMWVoeW55LzcxNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="n662lxf9pjp-figure-caption"><div><div></div></div></figcaption></figure><p id="nq84x879yh9">Figure 4</p><p id="ntmo4kamf54">You will also notice a key for <em>rangeMinimum</em>. This key integer is the value in seconds for the minimum setting. Notice in Figure 3, the minimum setting is 30 seconds.</p><p id="ninfghdlihy">Note: There are several ways to view property lists, that include on an Apple computer, within forensic tools and third party plist viewing tools. In this instance, I used Ian Whiffin’s “Mushy PLIST Viewer,” which can be downloaded at the following link along with his other FREE tools: <a href="https://www.doubleblak.com/software.php" title="">https://www.doubleblak.com/software.php</a></p><p id="n0b7zk38117"><strong>Touch ID & Passcode Require Passcode Setting:</strong></p><p id="nxlb0joklui">In the Touch ID & Passcode settings there is a setting titled “Require Passcode” as seen in Figure 5.</p><figure id="nvx59iy09tg" data-node-type="image" data-size="50" data-align="full" data-url="https://assets.pubpub.org/xq7295yy/61649340049912.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InhxNzI5NXl5LzYxNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InhxNzI5NXl5LzYxNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InhxNzI5NXl5LzYxNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6InhxNzI5NXl5LzYxNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="nvx59iy09tg-figure-caption"><div><div></div></div></figcaption></figure><p id="nnwi34iuxkp">Figure 5</p><p id="nxlwwryg0ey">During testing, the Require Passcode options were Immediately, After 1 minute, After 5 minutes, After 15 minutes, After 1 hour and After 4 hours:</p><figure id="nxnht79b40v" data-node-type="image" data-size="50" data-align="full" data-url="https://assets.pubpub.org/axq6rbx6/11649340049912.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImF4cTZyYng2LzExNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImF4cTZyYng2LzExNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImF4cTZyYng2LzExNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6ImF4cTZyYng2LzExNjQ5MzQwMDQ5OTEyLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="nxnht79b40v-figure-caption"><div><div></div></div></figcaption></figure><p id="n4i8oqb3fmm">Figure 6</p><p id="neqdf9emcva">Similarly with the Display Auto-Lock settings, these settings are stored in the <em>PublicEffectiveUserSettings.plist</em> in seconds. For example: if Require Passcode setting is set to be required after 5 minutes as depicted in Figure 6, the <em>value</em> key integer will be “300” meaning 300 seconds or 5 minutes.</p><p id="ngwy6wl1trm">To find this <em>value</em> key integer within the <em>PublicEffectiveUserSettings.plist</em> you will need to find the <em>restrictedValue</em> key, then the <em>maxGracePeriod</em> key. Once you have located these keys, you will notice an integer that represents the setting value in seconds, as seen in Figure 7.</p><p id="ny8m660xul6">Apple Developer website, <a href="https://developer.apple.com/documentation/devicemanagement/passcode" title="">https://developer.apple.com/documentation/devicemanagement/passcode</a>, defines <em>maxGracePeriod</em> as “the maximum grace period, in minutes, to unlock the phone without entering a passcode. The default is 0, which is no grace period and requires a passcode immediately.”</p><figure id="n3k6py42mq1" data-node-type="image" data-size="50" data-align="full" data-url="https://assets.pubpub.org/22hovziq/21649340049913.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjIyaG92emlxLzIxNjQ5MzQwMDQ5OTEzLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjIyaG92emlxLzIxNjQ5MzQwMDQ5OTEzLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjIyaG92emlxLzIxNjQ5MzQwMDQ5OTEzLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjIyaG92emlxLzIxNjQ5MzQwMDQ5OTEzLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="n3k6py42mq1-figure-caption"><div><div></div></div></figcaption></figure><p id="nuqslcbd9dz">Figure 7</p><p id="n6w6cobuflu">In Figure 7 you will notice additional keys are highlighted. The additional keys listed under the <em>maxGracePeriod</em> key, are <em>rangeMaximum</em> and <em>rangeMinimum</em>. These keys indicate the maximum setting and minimum setting within the setting menu as seen in Figure 6.</p><p id="nnwkpi95mgh">During testing, I made changes to the device settings six times. Below are the device settings followed by the values listed in the <em>PublicEffectiveUserSettings.plist</em>.</p><p id="n473gctyst1"><em><strong>Test One</strong></em></p><p id="nl2qquh83pp">No passcode</p><p id="ntkjsgw2p0w">Display Auto-Lock = 2 minutes</p><p id="nv9xoey8nxe">Require Passcode = not set</p><p id="na7ogxjrwmb">maxInactivity value = 120</p><p id="n8n12adw9zf">maxGracePeriod value = 0</p><p id="nlwqnftno7v"><em><strong>Test Two</strong></em></p><p id="no3c9zsqaxl">6-digit passcode</p><p id="nayxwx09bbu">Display Auto-Lock = 30 seconds</p><p id="ncwfvok4t74">Require Passcode = immediately</p><p id="ntknij48mnn">maxInactivity value = 30</p><p id="npx68vmvaqm">maxGracePeriod value = 0</p><p id="ne16lxzsmb0"><em><strong>Test Three</strong></em></p><p id="ng6mrlp0pv0">6-digit passcode</p><p id="nrtvtzq1tk7">Display Auto-Lock = never</p><p id="ni21emwr3sw">Require Passcode = 1 minute</p><p id="n353y64wn5r">maxInactivity value = 2147483647</p><p id="nex406f4r6v">maxGracePeriod value = 60</p><p id="nqnp3ant3fx">Take note, in test three, the Screen Auto-Lock setting was set to never and the maxInactivity value is “2147483647.”</p><p id="n9vdl30ruxk"><em><strong>Test Four</strong></em></p><p id="n0xjush2owb">6-digit passcode</p><p id="nkvapvbdefs">Display Auto-Lock = 1 minute</p><p id="nwd6tvdr40d">Require Passcode = 5 minute</p><p id="nenetn58sfm">maxInactivity value = 60</p><p id="ng5pci92595">maxGracePeriod value = 300</p><p id="nsw9j4gvsnw"><em><strong>Test Five</strong></em></p><p id="n7v1wb83032">6-digit passcode</p><p id="n1z81xw6lkw">Display Auto-Lock = 3 minutes</p><p id="ndngkyvr3k1">Require Passcode = 4 hours</p><p id="nzcju92jb3n">maxInactivity value = 180</p><p id="noqxtqzlse3">maxGracePeriod value = 14400</p><p id="nkrkw7u9h73"><em><strong>Test Six</strong></em></p><p id="nxxnjnd7vr9">No passcode</p><p id="njnay0ffd58">Display Auto-Lock = 2 minutes</p><p id="nbol30q1661">Require Passcode = 5 minutes</p><p id="n1eq05v84kk">maxInactivity value = 120</p><p id="n182z8ehxqz">maxGracePeriod value = 300</p><p id="nj23o65w6r4">After testing, I removed the passcode from the test device. When I checked the settings for Require Passcode, it was grayed out, but was still set on the last setting, which was after 5 minutes as seen in Figure 8.</p><figure id="n4qw7w83va5" data-node-type="image" data-size="50" data-align="full" data-url="https://assets.pubpub.org/3p2vn9na/41649340049913.png" data-caption="" data-alt-text="" data-hide-label="false"><img srcSet="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjNwMnZuOW5hLzQxNjQ5MzQwMDQ5OTEzLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0= 1x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjNwMnZuOW5hLzQxNjQ5MzQwMDQ5OTEzLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MTYwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 2x,https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjNwMnZuOW5hLzQxNjQ5MzQwMDQ5OTEzLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6MjQwMCwiZml0IjoiaW5zaWRlIiwid2l0aG91dEVubGFyZ2VtZW50Ijp0cnVlfX19 3x" src="https://resize-v3.pubpub.org/eyJidWNrZXQiOiJhc3NldHMucHVicHViLm9yZyIsImtleSI6IjNwMnZuOW5hLzQxNjQ5MzQwMDQ5OTEzLnBuZyIsImVkaXRzIjp7InJlc2l6ZSI6eyJ3aWR0aCI6ODAwLCJmaXQiOiJpbnNpZGUiLCJ3aXRob3V0RW5sYXJnZW1lbnQiOnRydWV9fX0=" alt=""/><figcaption id="n4qw7w83va5-figure-caption"><div><div></div></div></figcaption></figure><p id="nim9jtjmifs">Figure 8</p><p id="n474sxti49j">After noticing this, I conducted another extraction and discovered the plist <em>maxGracePeriod</em> value was still set at 300 seconds. I tested to determine if this setting was still active even though the device did not have a passcode. I changed the Display Auto-Lock setting to never, turned the screen on and set the device on my desk. After 5 minutes, the display did not auto-lock and the device did not require a passcode, thus even though this setting was still set in the plist, it was not active and did not make any changes to the device status.</p><p id="nm2fm1dfznq">Consideration: I did not test every possibility using these settings. You should also consider additional factors might affect these settings prior to the data acquisition. An example of this could be a first responder / different examiner making changes to these settings when the device is seized or when the data is acquired but failed to document these changes. Some forensic tools recommend making changes to these settings prior to data acquisition.</p><p id="np4dkiq6xlg">In conclusion, I would like to say thanks to everyone who assisted with validation of this writeup. I hope this information will help you with future analysis.</p><h1 id="dfir-review">DFIR Review</h1><p id="r2022352288">The author provides clear documentation of the testing procedures as well as references to the Apple Developer website. The inclusion of specific graphics from the mobile device, and the property list files certainly appeases the visual learner whom may be quickly researching the methodology. The author has provided sufficient details to allow others to replicate the tests conducted and has described the steps needed to validate the tests conducted.<br/></p><p id="ni5ggqxlmv3">The reviewers found that the pertinent file can be found in an iOS backup (DeviceUDID/3a/3aef6f188cf22d663030b159b271f1f2591cf56a) so forensic tools are not needed to identify this information.</p><p id="nn38mhta5hh">It was suggested that the author also mention the existence of the same file and the same settings on iPadOS. On iPadOS, the Display Auto-Lock options are 2 minutes, 5 minutes, 10 minutes, 15 minutes and Never. It was also suggested that “Touch ID & Passcode” settings could be “Face ID & Passcode” depending on the device being used. It was also noted that if the user configured their device with Touch ID or Face ID, the Require Passcode setting is automatically set to Immediately. This is the only option available and therefore cannot be changed by the user.</p><p id="nx3dlmu1apd">One important factor having an influence on this setting is the handling of the device by the examiner or first responders before extraction. This setting is sometimes modified to avoid locking an unlocked phone when the password is unknown. As discussed by the author, common extraction tools require the examiner to change the auto-lock setting to “never”. It is important to emphasize the importance of the chain of custody and documentation of any modifications applied to the phone before reporting about a setting, because it may not correspond to the original value set by the user.</p><h1 id="future-work">Future Work</h1><p id="n99k1oph311">Future work could include looking at devices that are jailbroken vs. devices that are not jailbroken.</p><h1 id="reviewers">Reviewers</h1><p id="n08o2pgw4mh">Eric Eppley (Methodology Review)</p><p id="p49pzvndiv">Anthony Knutson (Methodology Review, Validated Review Using Reviewer Generated Datasets)</p><p id="nwksvha1ye6">Johann Polewczyk (Methodology Review, Validated Review Using Reviewer Generated Datasets)</p><p id="nv94s9dx4sm">Aurèle Scoundrianos (Methodology Review, Validated Review Using Reviewer Generated Datasets)</p></div></main></div><div class="side-content"></div></div><div class="pub-bottom-component"><div class="inner"><div class="pub-bottom-section-component pub-bottom-license"><div role="none" class="top-row"><div class="left-title">License</div><div class="center-content"><div class="center-content-item"><a target="_blank" rel="license noopener noreferrer" class="license-link" href="https://creativecommons.org/licenses/by/4.0/"><img width="75" alt="" src="/static/license/cc-by.svg" class="license-image"/>Creative Commons Attribution 4.0 International License<!-- --> <!-- -->(CC-BY 4.0)</a></div></div><div class="right-icons" role="none"></div></div></div><div class="pub-bottom-section-component expanded"><div role="button" class="top-row" style="cursor:pointer"><div class="left-title">Comments</div><div class="center-content"><div class="center-content-item">0</div></div><div class="right-icons" role="none"><button type="button" aria-label="Search comments" class="bp3-button bp3-minimal"><span icon="search" class="bp3-icon bp3-icon-search"><svg fill="#2D2E2F" data-icon="search" width="14" height="14" viewBox="0 0 16 16"><path d="M15.55 13.43l-2.67-2.68a6.94 6.94 0 001.11-3.76c0-3.87-3.13-7-7-7s-7 3.13-7 7 3.13 7 7 7c1.39 0 2.68-.42 3.76-1.11l2.68 2.67a1.498 1.498 0 102.12-2.12zm-8.56-1.44c-2.76 0-5-2.24-5-5s2.24-5 5-5 5 2.24 5 5-2.24 5-5 5z" fill-rule="evenodd"></path></svg></span></button><button type="button" aria-label="Sort comments" aria-expanded="false" aria-controls="id-14" aria-haspopup="dialog" class="bp3-button bp3-minimal"><span icon="sort" class="bp3-icon bp3-icon-sort"><svg fill="#2D2E2F" data-icon="sort" width="14" height="14" viewBox="0 0 16 16"><path d="M5 12c-.28 0-.53.11-.71.29l-.29.3V9c0-.55-.45-1-1-1s-1 .45-1 1v3.59l-.29-.29A.965.965 0 001 12a1.003 1.003 0 00-.71 1.71l2 2c.18.18.43.29.71.29s.53-.11.71-.29l2-2A1.003 1.003 0 005 12zm3-9h7c.55 0 1-.45 1-1s-.45-1-1-1H8c-.55 0-1 .45-1 1s.45 1 1 1zm7 2H8c-.55 0-1 .45-1 1s.45 1 1 1h7c.55 0 1-.45 1-1s-.45-1-1-1zm0 8H8c-.55 0-1 .45-1 1s.45 1 1 1h7c.55 0 1-.45 1-1s-.45-1-1-1zm0-4H8c-.55 0-1 .45-1 1s.45 1 1 1h7c.55 0 1-.45 1-1s-.45-1-1-1z" fill-rule="evenodd"></path></svg></span></button><button type="button" aria-label="Filter comments" aria-expanded="false" aria-controls="id-15" aria-haspopup="dialog" class="bp3-button bp3-minimal"><span icon="filter" class="bp3-icon bp3-icon-filter"><svg fill="#2D2E2F" data-icon="filter" width="14" height="14" viewBox="0 0 16 16"><path d="M13.99.99h-12a1.003 1.003 0 00-.71 1.71l4.71 4.71V14a1.003 1.003 0 001.71.71l2-2c.18-.18.29-.43.29-.71V7.41L14.7 2.7a1.003 1.003 0 00-.71-1.71z" fill-rule="evenodd"></path></svg></span></button><button type="button" aria-label="Collapse this section" class="bp3-button bp3-minimal"><span icon="collapse-all" class="bp3-icon bp3-icon-collapse-all"><svg fill="#2D2E2F" data-icon="collapse-all" width="14" height="14" viewBox="0 0 16 16"><path d="M7.29 6.71c.18.18.43.29.71.29s.53-.11.71-.29l4-4a1.003 1.003 0 00-1.42-1.42L8 4.59l-3.29-3.3a1.003 1.003 0 00-1.42 1.42l4 4zm1.42 2.58C8.53 9.11 8.28 9 8 9s-.53.11-.71.29l-4 4a1.003 1.003 0 001.42 1.42L8 11.41l3.29 3.29c.18.19.43.3.71.3a1.003 1.003 0 00.71-1.71l-4-4z" fill-rule="evenodd"></path></svg></span></button></div></div><div class="section-content"><div class="pub-discussions-component"><style> .discussion-list .discussion-thread-component.preview:hover, .discussion-list .discussion-thread-component.expanded-preview { border-left: 3px solid #2D2E2F; padding-left: calc(1em - 2px); } </style><div class="discussion-list"><div class="thread-comment-component input"><div class="avatar-wrapper"><div class="avatar-component" style="width:18px;min-width:18px;height:18px;border-width:0;font-size:7px;background-color:#2D2E2F;z-index:initial;border-radius:50%"><div>?</div></div></div><a role="button" class="bp3-button bp3-small discussion-primary-button" href="/login?redirect=/pub/khnqi0ff/release/1" tabindex="0"><span class="bp3-button-text">Login to discuss</span></a></div><div class="empty-state bp3-non-ideal-state"><div class="bp3-non-ideal-state-visual"><span icon="comment" class="bp3-icon bp3-icon-comment"><svg data-icon="comment" width="60" height="60" viewBox="0 0 20 20"><desc>comment</desc><path d="M19 1H1c-.55 0-1 .45-1 1v12c0 .55.45 1 1 1h3v4a1.003 1.003 0 001.71.71l4.7-4.71H19c.55 0 1-.45 1-1V2c0-.55-.45-1-1-1zM4 10c-1.1 0-2-.9-2-2s.9-2 2-2 2 .9 2 2-.9 2-2 2zm6 0c-1.1 0-2-.9-2-2s.9-2 2-2 2 .9 2 2-.9 2-2 2zm6 0c-1.1 0-2-.9-2-2s.9-2 2-2 2 .9 2 2-.9 2-2 2z" fill-rule="evenodd"></path></svg></span></div><div class="bp3-heading">No comments here</div><div> Why not start the discussion?</div></div></div></div></div></div></div></div><div class="pub-link-controller-component"></div></div></div></div><div class="footer-component accent-background accent-color"><div class="container "><div class="row"><div class="col-12 "><div class="left"></div><div class="right"><div class="footer-title"><a href="/">DFIR Review</a></div><ul class="separated"><li><a class="link" href="/rss.xml">RSS</a></li><li><a class="link" href="/legal">Legal</a></li></ul></div></div></div></div><div class="built-on"><a href="https://www.pubpub.org">Published with<img class="logo" src="/static/logoWhite.svg" alt="PubPub logo"/></a></div></div></div></div><script crossorigin="anonymous" src="https://polyfill-fastly.io/v3/polyfill.min.js?features=default,fetch,HTMLCanvasElement.prototype.toBlob,Node.prototype.contains,Array.prototype.find,Array.from,Number.isNaN,Object.assign,Object.entries,Object.values,Promise,requestIdleCallback,String.prototype.includes,URL,URLSearchParams"></script><script id="initial-data" type="text/plain" data-json="{"communityData":{"id":"b0ac9c28-479a-496c-884c-7ae8fc26e385","subdomain":"dfir","domain":null,"title":"DFIR Review","citeAs":null,"publishAs":null,"description":"DFIR Review responds to the need for a focal point for up-to-date community-reviewed applied research and testing in digital forensics and incident response. DFIR Review concentrates on targeted studies of specific devices, digital traces, analysis methods, and criminal activity","avatar":"https://assets.pubpub.org/3yqqvtl4/71553968763873.png","favicon":"https://assets.pubpub.org/c8g3oakn/41553968740088.png","accentColorLight":"#FFFFFF","accentColorDark":"#2D2E2F","hideCreatePubButton":true,"headerLogo":"https://assets.pubpub.org/hndwo003/61675374631049.png","headerLinks":null,"headerColorType":"dark","useHeaderTextAccent":false,"hideHero":false,"hideHeaderLogo":false,"heroLogo":null,"heroBackgroundImage":null,"heroBackgroundColor":"#0558b3","heroTextColor":null,"useHeaderGradient":true,"heroImage":null,"heroTitle":"DFIR Review","heroText":"DFIR Review responds to the need for a focal point for up-to-date community-reviewed applied research and testing in digital forensics and incident response. DFIR Review concentrates on targeted studies of specific devices, digital traces, analysis methods, and criminal activity","heroPrimaryButton":{},"heroSecondaryButton":{},"heroAlign":"left","navigation":[{"id":"0f373a2c-c88d-4615-901f-9f3007392c8a","type":"page"},{"id":"b4ba8d5a-2328-4d86-ad66-f8c2c76a506f","type":"page"},{"id":"a8a6a998-952b-45ac-9dde-1e1fef976417","type":"page"},{"id":"6a7dd0ce-1852-4aa8-b858-dd9e4fcc23e7","type":"page"},{"id":"c9d33e1b-70ca-4f00-935e-8b048a2db8aa","type":"page"},{"id":"b1a5d079-3ee0-4434-a65f-c1b0cc624b45","type":"page"},{"id":"2bd22226-03c8-4300-b555-73eb1d6a582d","type":"page"},{"id":"9a0a763a-139f-4380-8620-47bf9e307106","type":"page"},{"id":"a7126096-fe0b-49af-a377-e69d372934d0","type":"page"}],"hideNav":false,"navLinks":null,"footerLinks":null,"footerLogoLink":null,"footerTitle":null,"footerImage":null,"website":"","facebook":"","twitter":"","instagram":null,"mastodon":null,"linkedin":null,"bluesky":null,"github":null,"email":"","socialLinksLocation":null,"issn":null,"isFeatured":null,"viewHash":"qz0cilrt","editHash":"bqi37oih","premiumLicenseFlag":false,"defaultPubCollections":[],"analyticsSettings":null,"spamTagId":"16a43a5f-d437-4a0a-9721-4781fc993f4e","organizationId":null,"scopeSummaryId":"aa45c5c8-46a9-480c-912b-0ace04e252d4","createdAt":"2019-03-23T18:09:32.984Z","updatedAt":"2023-02-02T21:50:33.149Z","scopeSummary":{"id":"aa45c5c8-46a9-480c-912b-0ace04e252d4","collections":1,"pubs":41,"discussions":8,"reviews":0,"submissions":0,"createdAt":"2021-04-26T16:49:17.482Z","updatedAt":"2025-03-18T02:21:15.927Z"},"spamTag":{"id":"16a43a5f-d437-4a0a-9721-4781fc993f4e","status":"confirmed-not-spam","statusUpdatedAt":"2025-03-25T17:07:04.197Z","fields":{},"spamScore":0,"spamScoreComputedAt":"2023-02-02T21:50:33.162Z","spamScoreVersion":1,"createdAt":"2022-12-07T19:10:59.508Z","updatedAt":"2025-03-25T17:07:04.197Z"},"pages":[{"id":"b1a5d079-3ee0-4434-a65f-c1b0cc624b45","title":"Aims & Scope","slug":"about","description":"DFIR Review Aims & Scope","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"e8ydkitt","layout":[{"id":"wpmh8voe","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"heading","attrs":{"id":"dfir-review---aims-scope","rtl":null,"level":1,"fixedId":"","textAlign":null},"content":[{"text":"DFIR Review - Aims & Scope","type":"text"}]},{"type":"paragraph","attrs":{"id":"nk8u9egeeah","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Rapid review and dissemination of up-to-date results of applied research and testing is necessary to keep pace with changes in technology and cybercrime. The Internet-of-Things (IoT) and smartphone applications are prime examples of the unprecedented proliferation of new devices and digital traces. New versions of operating systems can also have data structures that contain valuable information from a forensic perspective. When a new type of digital trace is found to be relevant to a legal matter, it may be the first time it has been studied from a forensic perspective. New approaches to analysing digital traces can help develop insights in an investigation. Often this type of material is shared via blogs by active practitioners who are the first to tackle new devices, uncover new digital traces, and encounter new forms of criminal activity. Currently, these posts do not undergo community review or vetting, and are not presented or published in a formalized forum for long term reference. The faster this knowledge can be produced, reviewed, and shared among the DFIR community, the better able we will be to deal with new devices, digital traces, and criminal activities. DFIR Review aims to take the up-to-date rapid content created by practitioners and distributed regularly via blogs and provide review such that the findings can be cited and stored in a referenceable format so that it may be used by others including for reference in legal and other matters while crediting the originating source such as a practitioner blog.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n3ng0n83wot","rtl":null,"class":null,"textAlign":null}},{"type":"heading","attrs":{"id":"review","rtl":null,"level":3,"fixedId":"","textAlign":null},"content":[{"text":"Review","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nljdv0w59dg","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Submissions to DFIR Review will be reviewed rapidly by a panel of qualified members of the community to include practitioners, researchers, graduate students and others working in the digital forensics field. Submissions will be accepted or rejected on the basis of reviewer responses following these criteria:","type":"text"}]},{"type":"paragraph","attrs":{"id":"nxkaguaiv0n","rtl":null,"class":"rtecenter","textAlign":null},"content":[{"text":"Reviewer Guidance","type":"text","marks":[{"type":"link","attrs":{"href":"review-guidance","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"ne057aizup3","rtl":null,"class":null,"textAlign":null},"content":[{"text":"For accepted submissions, reviewers will provide a detailed response including comments, further research concepts that may not have been explored, as well as validation and/or verification of initial research. The intent is that this response material will be presented along with the submission on DFIR Review.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nj7lk5w62hk","rtl":null,"class":null,"textAlign":null}},{"type":"heading","attrs":{"id":"presentation","rtl":null,"level":3,"fixedId":"","textAlign":null},"content":[{"text":"Presentation","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nmlms51diln","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Accepted submissions will be made available on the DFRWS website open access under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/). Accepted submissions will be organized along with reviewer response materials. Although authors can revise accepted materials on the basis of reviewer feedback, this is not a requirement for publication, taking into account that practitioners may not have time to rework a submission or perform additional research. Authors can post their work on their personal website or blog with a reference to the publication in DFIR Review. In this way, DFIR Review is the system of record for the work, and authors can disseminate their work with a reference to the publication in DFIR Review.","type":"text"}]},{"type":"paragraph","attrs":{"id":"naicemtgxdg","rtl":null,"class":null,"textAlign":null}},{"type":"heading","attrs":{"id":"submissions","rtl":null,"level":3,"fixedId":"","textAlign":null},"content":[{"text":"Submissions","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n5ghelqimur","rtl":null,"class":null,"textAlign":null},"content":[{"text":"DFIR Review welcomes submissions that provide up-to-date knowledge in digital forensics and incident response, as well as test results that validate or update prior studies. The DFIR Review community will actively encourage authors to submit their work, and will assist authors throughout the submission process as needed. Topics of interest include:","type":"text"}]},{"type":"bullet_list","attrs":{"id":"n8yhzvlmrlq","rtl":null},"content":[{"type":"list_item","content":[{"type":"paragraph","attrs":{"id":"nn3ihqrnag2","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Forensic treatment of new devices, including Internet-of-Things","type":"text"}]}]},{"type":"list_item","content":[{"type":"paragraph","attrs":{"id":"nedidix8y5q","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Forensic analysis of new smartphone apps or updated versions (inclusion of open source tools encouraged)","type":"text"}]}]},{"type":"list_item","content":[{"type":"paragraph","attrs":{"id":"nlt1vg7bgka","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Forensic analysis of new data structures on operating systems","type":"text"}]}]},{"type":"list_item","content":[{"type":"paragraph","attrs":{"id":"nhoxhzvfab7","rtl":null,"class":null,"textAlign":null},"content":[{"text":"New methods of analysing digital traces to find patterns, links and other insights","type":"text"}]}]},{"type":"list_item","content":[{"type":"paragraph","attrs":{"id":"n4emu4f3xwp","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Insights into new ways that criminals are using technology, emphasizing technical elements and potential solutions","type":"text"}]}]},{"type":"list_item","content":[{"type":"paragraph","attrs":{"id":"nvo51ty1z6o","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Validation and testing of new forensic tool features (inclusion of test data preferred)","type":"text"}]}]}]},{"type":"paragraph","attrs":{"id":"ny6tg2u0pg2","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Submit via EasyChair: ","type":"text"},{"text":"https://easychair.org/conferences/?conf=dfirr2023","type":"text","marks":[{"type":"link","attrs":{"href":"https://easychair.org/conferences/?conf=dfirr2023","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"n09z0jhp5vv","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Submission implies that the work will not have been published elsewhere (except in as an abstract, academic thesis, preprint or personal blog), and publication in a virtual proceedings is approved by all authors and tacitly or explicitly by the responsible authorities where the work was carried out. Authors of high impact work will be encouraged to further develop their work and submit it to DFRWS conferences and other DFIR community events and publications.","type":"text"}]},{"type":"paragraph","attrs":{"id":"ncgh3dca42r","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Inquiries can be directed to DFIR@dfrws.org","type":"text"}]},{"type":"paragraph","attrs":{"id":"nwbwbuygrva","rtl":null,"class":null,"textAlign":null}},{"type":"heading","attrs":{"id":"copyright-and-rights","rtl":null,"level":3,"fixedId":"","textAlign":null},"content":[{"text":"Copyright and Rights","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n1kp4gmi6mu","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Authors will retain copyright of their work in DFIR Review. Authors will grant DFRWS the non-exclusive right to include the material in any form throughout the world, in all languages, for all time, effective when and if the work is accepted for publication.","type":"text"}]}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2019-03-30T17:21:31.710Z"},{"id":"a7126096-fe0b-49af-a377-e69d372934d0","title":"DFRWS.org","slug":"dfrws","description":"DFRWS community support and activities.","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"m6xca1m0","layout":[{"id":"jcfro4os","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"heading","attrs":{"id":"dfrws","level":1},"content":[{"text":"DFRWS","type":"text","currIndex":0}],"currIndex":0},{"type":"paragraph","attrs":{"class":null},"content":[{"text":"DFIR Review is part of DFRWS, a non-profit, volunteer organization dedicated to bringing together everyone with a legitimate interest in digital forensics to address the emerging challenges of our field. DFRWS organizes digital forensic conferences, challenges, and international collaboration to help drive the direction of research and development.","type":"text","currIndex":0}],"currIndex":1},{"type":"paragraph","attrs":{"class":null},"currIndex":2},{"type":"paragraph","attrs":{"class":null},"content":[{"text":"Additional information about DFRWS conferences and publications: ","type":"text","currIndex":0},{"text":"www.DFRWS.org","type":"text","marks":[{"type":"link","attrs":{"href":"https://www.dfrws.org","title":null,"target":null}}],"currIndex":1}],"currIndex":3}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2019-03-31T06:36:38.964Z"},{"id":"c9d33e1b-70ca-4f00-935e-8b048a2db8aa","title":"Publications","slug":"pub","description":"Published work and reviews.","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"54wh5ywg","layout":[{"id":"amkwtrbk","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"heading","attrs":{"id":"dfir-review---publications","level":1},"content":[{"text":"DFIR Review - Publications","type":"text","currIndex":0}],"currIndex":0},{"type":"paragraph","attrs":{"class":null},"content":[{"text":"Reviewed and accepted work addressing emerging challenges in digital forensics, incident response, and cyber-investigation. ","type":"text","currIndex":0}],"currIndex":1}]},"align":"left"}},{"id":"gruw36cv","type":"pubs","content":{"size":"medium","limit":0,"title":"","pubIds":[],"pubPreviewType":"medium"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2019-03-31T06:32:20.073Z"},{"id":"a8a6a998-952b-45ac-9dde-1e1fef976417","title":"Reviewers","slug":"reviewers","description":"Thank you page acknowledging our reviewers","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"aj895cs6","layout":[{"id":"n102ug0t","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"paragraph","attrs":{"id":"fta2auwwsi","class":null},"content":[{"text":"Thank you to all of the volunteer reviewers who contribute their time to conduct thorough reviews of DFIR Review. Please see the bios of selected reviewers below.","type":"text"}]},{"type":"paragraph","attrs":{"id":"0pl4vgpemk","class":null}},{"type":"paragraph","attrs":{"id":"3rcmkxfsl1","class":null},"content":[{"text":"Addisu Afework","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"efzsdtbd9a","class":null},"content":[{"text":"Addisu Afework is a Digital Forensics researcher in a governmental agency. Since 2017, he has been performing digital forensics research on smart home IoT devices. Before studying his MSc in Legal Informatics and Digital Forensics Science, he was working in the cybersecurity field since 2009 as a cybersecurity engineer. Currently, he is working on developing tools and procedures in the digital forensics investigation area. Addisu is interested in researching and developing tools and methods to assist digital forensic investigators to easily and efficiently conduct investigations. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"p0ks0nrivq","class":null}},{"type":"paragraph","attrs":{"id":"ms99wbnrut","class":null},"content":[{"text":"Timothy Bollé","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"uld75x0t2x","class":null},"content":[{"text":"Timothy Bollé is a PhD Student in Digital Forensic and Investigation at the University of Lausanne, under the supervision of Dr. Eoghan Casey. He received his BSc and MSc in forensic science, from the School of Criminal Sciences at the University of Lausanne. During his master, he performed research and development in collaboration with Swiss police to detect repetitions in online fraud. His area of expertise includes research and development in digital forensic science, specializing in machine learning. His PhD research focuses on effective use of machine learning to support forensic analysis of digital evidence. Alongside his PhD and teaching activities, he performed practical case work through the forensic science laboratory that is part the School of Criminal Sciences. When he is not in front of his computer, he enjoys to look at the various astronomical objects through his telescope. He his currently working on his thesis and on developing correlation systems to find links across different cases for a European project. You can reach him at timothy.bolle@unil.ch.","type":"text"}]},{"type":"paragraph","attrs":{"id":"maarbjqhfa","class":null}},{"type":"paragraph","attrs":{"id":"0kxc8cughk","class":null},"content":[{"text":"Ali Hadi","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"sl2qlnesfh","class":null},"content":[{"text":"Ali Hadi is a Senior Cybersecurity Specialist with 14+ years of industrial experience in Information Technology (IT), currently working as a full time professor and researcher for the Computer & Digital Forensics Dept. at Champlain College, USA. He provides consulting in several areas of Cybersecurity including digital forensics and incident response, malware analysis, cyber threat hunting, and penetration testing. He is also an author, speaker, and freelance instructor. His research interests include digital forensics, incident response, cyber threat hunting, and malware analysis.","type":"text"}]},{"type":"paragraph","attrs":{"id":"unbzsbrrog","class":null}},{"type":"paragraph","attrs":{"id":"1dwltx7xjj","class":null},"content":[{"text":"Jessica Hyde","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"vavo0ol12x","class":null},"content":[{"text":"Jessica Hyde is an experienced forensic examiner in both the commercial and government sectors. She is currently the Director of Forensics at Magnet Forensics and an Adjunct Professor teaching Mobile Forensics in the graduate program at George Mason University, where she achieved an MS in Computer Forensics. Jessica is the host of Cache Up, a weekly podcast where she interviews digital forensics practitioners. She is also involved in several community efforts including as Chair of DFIR Review, 1st Vice President of the New York Metro High Tech Crime International Association Chapter, advisory board for Cyber Sleuths Lab, and a member of the Editorial Board for the Forensic Science International: Digital Investigations Journal. Her previous roles included performing forensic examinations as a Sr. Mobile Exploitation Analyst for Basis Technology, Senior at EY, and Senior Electrical Engineer at American Systems. Jessica is also proud to be a veteran of the United States Marine Corps.","type":"text"}]},{"type":"paragraph","attrs":{"id":"4r8m1leg9d","class":null}},{"type":"paragraph","attrs":{"id":"cnx7uh53hc","class":null},"content":[{"text":"Alex O. Ogbole","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"w1olaw9uge","class":null},"content":[{"text":"He is an Investigator and Digital Forensic Analyst with the Economic and Financial Crimes Commission (EFCC) Nigeria. He has over a decade’s experience in digital forensics, evidence management, and investigation of financial and cyber-related criminal cases. He holds a bachelor’s degree in computer sciences and a master’s degree (in-view) in Legal Informatics and Forensic Science from Hallym University Chuncheon, South Korea. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"rny1zjjden","class":null}},{"type":"paragraph","attrs":{"id":"ev024rb2ea","class":null},"content":[{"text":"Elénore Ryser","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"f9j3x9kxtz","class":null},"content":[{"text":"Elénore Ryser has a MSc in Forensic Science and is a PhD student at the University of Lausanne. Her main areas of research cover a typology of digital traces, the evaluation of digital traces and communication of digital forensic results as well as geo-localisation evidences. In 2019, she received a grant from the Société Académique Vaudoise to support her PhD research.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nv29rz80i96","class":null}},{"type":"paragraph","attrs":{"id":"n4f1d0jonc3","class":null},"content":[{"text":"Brett Shavers","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nblu5btvwzi","class":null},"content":[{"text":"Brett Shavers is a digital forensics examiner whose experience spans a law enforcement career investigating cybercrime and serving as a consultant, expert witness, and special master in civil litigation cases. Brett has well over 1,000 hours of formal digital forensics training from a variety of U.S. federal agencies and forensic software companies. He has provided private consultation to government agencies and law firms in sensitive legal matters ranging from internal employee matters to class action litigation. Brett has also taught digital forensics and investigative techniques to dozens of law enforcement agencies internationally and at graduate-level educational programs. He is an award-winning author of several respected digital forensics books such as Placing the Suspect Behind the Keyboard, Hiding Behind the Keyboard, and the X-Ways Forensics Practitioner’s Guide. Brett also manages the DFIR Training website, www.dfir.training as a free resource for the DFIR community. You can find Brett at www.dfir.training and ","type":"text"},{"text":"www.brettshavers.com","type":"text","marks":[{"type":"link","attrs":{"href":"http://www.brettshavers.com/","title":null,"target":"_blank"}}]},{"text":".","type":"text"}]},{"type":"paragraph","attrs":{"id":"niceabdzcj5","class":null}},{"type":"paragraph","attrs":{"id":"wjfgouj9bd","class":null},"content":[{"text":"Hannes Spichiger","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"0tgf0rrgvw","class":null},"content":[{"text":"Hannes Spichiger is a PhD Student at the University of Lausanne interested in questions of reliability and uncertainty related to digital evidence. His thesis is focused on the localisation of persons based on mobile phone traces. In addition to his research activity, he works part time as a specialist for digital investigation at the Neuchâtel Police force in Switzerland. His technical specialisation is mostly centred around the analysis of mobile phones.","type":"text"}]},{"type":"paragraph","attrs":{"id":"x1d7u0dcoo","class":null}},{"type":"paragraph","attrs":{"id":"dgm9r38f2u","class":null},"content":[{"text":"Joe Walsh","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"u7n29eiqth","class":null},"content":[{"text":"Joe Walsh teaches digital forensics and computer security courses at DeSales University. Prior to accepting this position, he worked as a senior security consultant for a computer security firm where he was responsible for performing security assessments, conducting penetration testing, and responding to computer security incidents. He has been a police officer for thirteen years. Joe is a former member of the Internet Crimes Against Children (ICAC) task force and the FBI Child Exploitation Task Force, where he was responsible for conducting online undercover investigations and forensic examinations of digital evidence. He has been recognized in court as an expert in computer crime and digital forensics. Joe has a bachelor’s degree in Computer Information Systems and earned his master’s degree in Criminal Justice with a concentration in Digital Forensics at DeSales University. He recently completed his second master's degree in Information Systems with a concentration in Cybersecurity and is currently pursuing a Ph.D. in Information Systems with a specialization in Information Systems Cyber Security.","type":"text"}]},{"type":"paragraph","attrs":{"id":"316deb0ade","class":null}}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2021-01-07T20:03:12.970Z"},{"id":"9a0a763a-139f-4380-8620-47bf9e307106","title":"Community","slug":"community","description":"Organizers, reviewers and other community members","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"faat8dm3","layout":[{"id":"0orzouf3","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{},"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"heading","attrs":{"id":"dfir-review---community","rtl":null,"level":1,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"DFIR Review - Community","type":"text"}]},{"type":"paragraph","attrs":{"id":"njvmqvwrc72","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"The DFIR Review community is part of the Digital Forensic Research Conference (","type":"text"},{"text":"DFRWS.org","type":"text","marks":[{"type":"link","attrs":{"href":"https://www.dfrws.org","title":null,"target":null,"pubEdgeId":null}}]},{"text":"). The following individuals are involved with the coordination of DFIR Review and performing reviews of submitted work.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nmhcg32xrcr","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"type":"heading","attrs":{"id":"organizing-committee","rtl":null,"level":3,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Organizing Committee","type":"text"}]},{"type":"table","attrs":{"id":"nl858e11jp1","size":null,"align":null,"hideLabel":false,"smallerFont":false,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nob2cd5m6pw","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Chair","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nluano1hjzi","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Jessica Hyde (George Mason University & Hexordia)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nevuw0krmqk","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Vice Chair","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"n9rt66lkf8r","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Eoghan Casey (University of Lausanne & Digital Forensics Solutions)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"ncp0cp7e75w","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Program Chair","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"njo8hz6z3fc","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Elénore Ryser (University of Lausanne)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"n9qm9vvhvke","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Program Vice Chairs","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nm0e0289thf","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Holger Morgenstern (Albstadt-Sigmaringen University)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nfwuwcdtt5p","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Publication Co-Chairs","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"n3xjynkt6hp","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Joseph Walsh (DeSales University)","type":"text"}]},{"type":"paragraph","attrs":{"id":"nyue3ejt816","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Johannn Polewczyk (University of Lausanne)","type":"text"},{"type":"hard_break","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"text":"Stephen Boyce (Marymount University & Magnet Forensics)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"n3z0ooxd4e9","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Industry Practitioner Liaisons","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nl0vizkjnsc","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Brett Shavers (DFIR Training)","type":"text"},{"type":"hard_break","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"text":"Tony Knutson (SANS Institute, Kroll)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nn4f52e3b48","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Government Practitioner Liaison","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nsqzhip8skn","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Open","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"n7d817t277l","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Communications Chair","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nlweyvguct0","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Prashanth Kumar Reddy Malise (George Mason University)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nb3g91k5nvm","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Academia Liaison","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nvyh6n6hw1i","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Mark McKinnon (Davenport University)","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[281],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nb8y6poo5ut","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"DFRWS Liaison","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nxdbp7wyl5g","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Daryl Pfeif (Digital Forensics Solutions)","type":"text"}]}]}]}]},{"type":"paragraph","attrs":{"id":"nqeycm08v59","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"type":"heading","attrs":{"id":"gold-reviewers","rtl":null,"level":3,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Gold Reviewers","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n8i5812w1z4","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Addisu Afework Birhanu","type":"text"}]},{"type":"paragraph","attrs":{"id":"n1kh4iysins","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Jessica Hyde","type":"text"}]},{"type":"heading","attrs":{"id":"silver-reviewers","rtl":null,"level":3,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Silver Reviewers","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n6fdc4jxn5f","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Timothy Bollé","type":"text"}]},{"type":"paragraph","attrs":{"id":"n7o01htwz3d","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Yohannes Yemane Brhan","type":"text"}]},{"type":"paragraph","attrs":{"id":"nj5kt6d91wk","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Lisa Brown","type":"text"}]},{"type":"paragraph","attrs":{"id":"nrc1291xnwq","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Eric Eppley","type":"text"}]},{"type":"paragraph","attrs":{"id":"nzkiahta6tk","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Ali Hadi","type":"text"}]},{"type":"paragraph","attrs":{"id":"n8zwsae7fd4","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Anthony Knutson","type":"text"}]},{"type":"paragraph","attrs":{"id":"ndqp4i8u6ib","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Nickolas Ligman","type":"text"}]},{"type":"paragraph","attrs":{"id":"nebcnn9kssg","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Johann Polewczyk","type":"text"}]},{"type":"paragraph","attrs":{"id":"neui5xdpmvn","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Francesco Servida","type":"text"}]},{"type":"paragraph","attrs":{"id":"nk4y4uj79rp","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Linda Shou","type":"text"}]},{"type":"heading","attrs":{"id":"reviewers","rtl":null,"level":3,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviewers","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n9s3lh9ajpy","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Zheng Jie Chan","type":"text"}]},{"type":"paragraph","attrs":{"id":"n8elkug24sb","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Amanda Chung","type":"text"}]},{"type":"paragraph","attrs":{"id":"n2aabge5wje","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Manon Fischer","type":"text"}]},{"type":"paragraph","attrs":{"id":"npnfnj8l2wd","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Joshua I. James","type":"text"}]},{"type":"paragraph","attrs":{"id":"no912s063do","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Selena Ley","type":"text"}]},{"type":"paragraph","attrs":{"id":"njxapqpjwad","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Prashanth Malise","type":"text"}]},{"type":"paragraph","attrs":{"id":"nwsmf4uk2w9","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Doug Metz","type":"text"}]},{"type":"paragraph","attrs":{"id":"nxnafg3l6oq","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Sungmi Park","type":"text"}]},{"type":"paragraph","attrs":{"id":"n0g52jkbwup","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Elénore Ryser","type":"text"}]},{"type":"paragraph","attrs":{"id":"nggzzzcdghx","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Bradley Schatz","type":"text"}]},{"type":"paragraph","attrs":{"id":"n3f48kee4la","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Aurèle Scoundrianos","type":"text"}]},{"type":"paragraph","attrs":{"id":"nxfzzfjv0bj","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Brett Shavers","type":"text"}]},{"type":"paragraph","attrs":{"id":"nhm88qaxmrz","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Hannes Spichiger","type":"text"}]},{"type":"paragraph","attrs":{"id":"nit2iq3d23w","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Adrien Vincart","type":"text"}]},{"type":"paragraph","attrs":{"id":"n4k32e401lj","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Ryan Wesley","type":"text"}]},{"type":"paragraph","attrs":{"id":"nqk71vxqngp","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Mike Williamson","type":"text"}]},{"type":"paragraph","attrs":{"id":"nsa2fmswdj9","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Sara Pierce","type":"text"}]},{"type":"paragraph","attrs":{"id":"nq1yf68ueg1","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Rishitha Reddy Munugala","type":"text"}]},{"type":"paragraph","attrs":{"id":"nbu3tm23f7c","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Saarthik Tannan","type":"text"}]},{"type":"paragraph","attrs":{"id":"nrp61pupf81","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Madison Brumbelow ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ni74qzjo8sp","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Utta Von Nuremburg","type":"text"}]},{"type":"paragraph","attrs":{"id":"npl1u0vkavz","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Kristin Ibanez","type":"text"}]},{"type":"paragraph","attrs":{"id":"n9qfsttvt14","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Charina Marrion","type":"text"}]},{"type":"paragraph","attrs":{"id":"nud0ag5mn1t","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Jad Saliba","type":"text"}]},{"type":"paragraph","attrs":{"id":"nao5nk4co3i","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Alexander Brunner","type":"text"}]},{"type":"paragraph","attrs":{"id":"nyr4o65w4ru","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Rishi Krishnan","type":"text"}]},{"type":"paragraph","attrs":{"id":"n108kjc0y31","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"type":"paragraph","attrs":{"id":"ndtssgtyvl1","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2019-03-30T18:15:15.380Z"},{"id":"2bd22226-03c8-4300-b555-73eb1d6a582d","title":"Review Guidance","slug":"review-guidance","description":"Criteria and guidelines for evaluating DFIR Review submissions.","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"pbpqub3l","layout":[{"id":"d93kbyyg","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{},"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"heading","attrs":{"id":"dfir-review---guidance","rtl":null,"level":1,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"DFIR Review - Guidance","type":"text"}]},{"type":"paragraph","attrs":{"id":"ic90m4lbu1","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"The following guidance is intended for reviewers to use in both assessing and drafting their review. Please be cognizant that comments will be included in the publication of the submission. If upon assignment you recognize that you are not suited to perform the review (i.e. schedule conflicts, not an area of expertise, etc.), please send an email to the TPC as soon as possible so that another reviewer may be assigned.","type":"text"}]},{"type":"paragraph","attrs":{"id":"x3lj85fcgz","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"type":"heading","attrs":{"id":"categories-of-review","rtl":null,"level":4,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Categories of Review","type":"text","marks":[{"type":"strong"}]}]},{"type":"table","attrs":{"id":"4ru0p1lqtj","size":null,"align":null,"hideLabel":false,"smallerFont":false,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[183],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"h48sq7n1wm","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Methodology Review","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[369],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"ipmaixvsto","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"This review is a read through and verification that the concepts and methods expressed in the submission are sound. This is the lowest level review. This method should only be used when it is the only available method to the reviewer or the content is not suitable for a higher level review.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"image","attrs":{"id":"qcaisrdf1j","url":"https://assets.pubpub.org/0osmcztc/31554327656996.png","href":null,"size":49,"align":"center","altText":"","caption":"","hideLabel":false,"suggestionId":null,"fullResolution":false,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[183],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"w1yn0ety3k","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Verified Review using Author Provided Datasets","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[369],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"wh4ugfxa51","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"This review requires verifying the technical details of the submission with a set of data provided by the author. It is expected that this review category is the minimum requirement when data is provided by the author.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"image","attrs":{"id":"6h80l2c4aj","url":"https://assets.pubpub.org/n6fvj3o0/71554327672214.png","href":null,"size":49,"align":"center","altText":"","caption":"","hideLabel":false,"suggestionId":null,"fullResolution":false,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[183],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"3hzixhujhp","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Validated Review using Reviewer Generated Datasets","type":"text","marks":[{"type":"em"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[369],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"32ay6jab2m","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"This is the “gold standard” for DFIR Review. When possible, this is the preferred method of review. When conducting this type of review, please ensure you include the OS/app/HW versions you are validating with in your review. It is completely acceptable to extend beyond the initial review with your learnings.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"image","attrs":{"id":"phzkvuu9h9","url":"https://assets.pubpub.org/3q7iw5tx/21554327684657.png","href":null,"size":49,"align":"center","altText":"","caption":"","hideLabel":false,"suggestionId":null,"fullResolution":false,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}}]}]}]},{"type":"heading","attrs":{"id":"reviewer-confidence","rtl":null,"level":4,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviewer Confidence","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nf351r1fcb","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"This is where the reviewer states their confidence with the material under review and their ability to provide a review. If you feel that you are a 1 or a 2, it is suggested that you email the Technical Program Committee and inform them that you are not comfortable performing the review so someone with more experience in that area of forensics can be assigned the review.","type":"text"}]},{"type":"paragraph","attrs":{"id":"sldjxeoggf","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"type":"heading","attrs":{"id":"review-guidelines","rtl":null,"level":4,"fixedId":"","textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Review Guidelines","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"w6q8pl05jo","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews will be published along with the accepted article in addition to the name of the reviewer and the category or review performed.","type":"text"}]},{"type":"bullet_list","attrs":{"id":"gcirgi18cz","rtl":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"7bgjwn9p5u","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should be comprehensive and should highlight the reviewer's knowledge of the subject matter in the article.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"zv1bwwy5vu","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should provide practitioners, lawyers, and judges with assurance that the article is reliable and complete.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"89jgh2k4o2","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews can state how the article can be useful in a digital investigation, and any associated limitations or risks.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"eghi9j8xnu","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should state if an article is trivial or not useful for addressing questions in a digital investigation.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"t5p53ll9u1","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should state if the article misses important details.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"5ekmydmqjo","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should explain the basis of the review (testing performed, prior knowledge from a case, etc.) including details regarding verification/validation via use of the author provided data sets or creation of data sets by the reviewer. When validating with reviewer generated data, please provide details as to OS, app, hardware used for the testing as applicable.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"z6ky625z73","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should highlight related questions that could be explored in future research.","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"7lh03rosl2","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should describe technical details of any testing performed, such as:","type":"text"}]}]}]},{"type":"paragraph","attrs":{"id":"swk3tzi33s","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"\"","type":"text"},{"text":"Using Autopsy version 4.10, I confirmed that the digital trace described in this article was present on Windows 10. In addition, I confirmed that the trace was compatible with the activity/interpretation presented in this article.","type":"text","marks":[{"type":"em"}]},{"text":"\"","type":"text"}]},{"type":"paragraph","attrs":{"id":"udcf2whdll","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}},{"type":"paragraph","attrs":{"id":"iqbm1mbg29","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"If we cannot repeat the steps that are presented in the article, we should state this, such as:","type":"text"}]},{"type":"paragraph","attrs":{"id":"4dh6aj6gdw","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"\"","type":"text"},{"text":"After performing the specified action in the article on a Windows 10 system, I examined the XYZ.dat file using a hex viewer but did not find the digital traces described in this article. However, I did not observe the digital traces described in this article. The traces I observed showed that the specified action occurred, but did not include additional details presented in the article (consider providing a screenshot of observed trace).","type":"text","marks":[{"type":"em"}]},{"text":"\"","type":"text"}]},{"type":"paragraph","attrs":{"id":"1kc9evklwj","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"OR","type":"text"}]},{"type":"paragraph","attrs":{"id":"psxmh1n0vy","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"\"","type":"text"},{"text":"Although it was not possible to perform testing on the same type of system (vehicle), I tested the XYZ application independently on an Android ABC device and obtained results that were compatible with those presented in this article","type":"text","marks":[{"type":"em"}]},{"text":"\"","type":"text"}]},{"type":"bullet_list","attrs":{"id":"m8ullauqum","rtl":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"ce971rvguk","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reviews should highlight related questions that could be explored in future research.","type":"text"}]}]}]},{"type":"paragraph","attrs":{"id":"s0guqkqk5o","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"An explanation video covering reviewer guidance and process is available here: ","type":"text"},{"text":"https://bit.ly/DFIRReviewGuidance","type":"text","marks":[{"type":"link","attrs":{"href":"https://bit.ly/DFIRReviewGuidance","title":null,"target":null,"pubEdgeId":null}}]}]},{"type":"paragraph","attrs":{"id":"fjuk3m4tav","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Review Rubric","type":"text","marks":[{"type":"strong"}]}]},{"type":"table","attrs":{"id":"qnvm4c1qr7","size":null,"align":null,"hideLabel":false,"smallerFont":false,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[127],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"cbj5z74dxf","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Criteria","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"cs0j5hsmz9","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Reject","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"nw5poar7ge","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Revise","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"qx7lgaafyc","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Accept","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[127],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"wluzvqh811","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Content and Organization ","type":"text","marks":[{"type":"strong"}]},{"type":"hard_break","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"marks":[{"type":"strong"}]},{"text":"(Weight 60%)","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"0ega3gnx7y","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Substantial omission of details. Serious factual errors. Poorly organized.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"avvu5uu7a0","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Omission of minor pertinent details. Small factual errors. Overall organization good, but individual sections lack coherence/ depth or good content presented in a disorganized fashion. Excessive information not pertinent to subject.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"yfqnghf4xm","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Follows the submission guidelines, providing all pertinent details. No factual errors. Well organized in pursuit of a clearly defined objectives.","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[127],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"1rss3h1sxg","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Use of Sources* ","type":"text","marks":[{"type":"strong"}]},{"type":"hard_break","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"marks":[{"type":"strong"}]},{"text":"(Weight 30%)","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"991l6a92jl","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Little use of supporting sources, mostly generalities. Overuse of links to or quotations from other texts/websites.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"yudc6vs551","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Scanty use of supporting sources. Minor misuse of sources, or selection of inappropriate sources. Incomplete details.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"d6vk3vkb08","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Drawing on several details from sources (rather than general concepts) and/or multiple sources. Appropriate use and choice of sources.","type":"text"}]}]}]},{"type":"table_row","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":[127],"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"4kgfimc5z6","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Grammar and Language ","type":"text","marks":[{"type":"strong"}]},{"type":"hard_break","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"marks":[{"type":"strong"}]},{"text":"(Weight 10%)","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"ou57jqf397","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Substantial grammar and/or typographical errors that confuse clarity and sense. Misuse of vocabulary; excessive repetition in expression.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"c4txjy47gu","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Some grammatical/ typographical errors, but without effect on sense. Repetitious use of vocabulary or expression.","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"x6tw7j8ey8","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Few to no grammatical errors or typos.","type":"text"}]}]}]}]},{"type":"paragraph","attrs":{"id":"4sabm68tbt","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"* Submissions should contain sufficient details to repeat the process and determine whether or not the results are compatible with those described in the submission. All testing or other sources should be described in the review. Sources includes not just citations but testing that is thoroughly described. Author created testing is a source.","type":"text"}]},{"type":"paragraph","attrs":{"id":"38b1mux24u","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Review Timelines","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"y4f99cyjje","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Submissions are accepted on a per month basis and reviewed in the next month. For example submissions between Feb 1st and 28th will be assigned in early March for review completion by mid-March. If you are unable to provide a timely review, please notify the Program Chair(s) as quickly as possible so the review may be re-assigned. ","type":"text"}]},{"type":"paragraph","attrs":{"id":"1nzt6o5m4i","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Format for text block of review","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"mk4xniq6no","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Please format your comments such that you indicate the type(s) of reviews followed by comments in 3 categories.","type":"text"}]},{"type":"paragraph","attrs":{"id":"whauqposzg","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Type of Review: ","type":"text","marks":[{"type":"em"}]},{"text":"Methodology Review and Verified Review using Author Provided Datasets (Please indicate if this is a Methodology Review, Verified Review using Author Provided Datasets, or Validated using Reviewer Generated Datasets).","type":"text"}]},{"type":"paragraph","attrs":{"id":"sh8nj7v7jg","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Omissions and Questions about the work:","type":"text","marks":[{"type":"em"}]}]},{"type":"ordered_list","attrs":{"id":"wi04ywbezr","rtl":null,"order":1,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"xf0lyd67r1","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"What is meant by x?","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"ks3ok21n17","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Was y tested?","type":"text"}]}]}]},{"type":"paragraph","attrs":{"id":"6xmhxxtf0m","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Future work:","type":"text","marks":[{"type":"em"}]}]},{"type":"ordered_list","attrs":{"id":"x9fzln9kcl","rtl":null,"order":1,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"m1r3g3hsla","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Future work could include validation on z platform","type":"text"}]}]}]},{"type":"paragraph","attrs":{"id":"a0v8xdv8ll","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Formatting suggestions and typographical errors:","type":"text","marks":[{"type":"em"}]}]},{"type":"ordered_list","attrs":{"id":"e48yaa32ms","rtl":null,"order":1,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"ad5eow1jiq","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Figure 3 is labeled incorrectly as Figure 4","type":"text"}]}]},{"type":"list_item","attrs":{"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"type":"paragraph","attrs":{"id":"bve6ohp2en","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"community is misspelled on page 3","type":"text"}]},{"type":"paragraph","attrs":{"id":"2d4e4d9mo2","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null}}]}]},{"type":"paragraph","attrs":{"id":"t3gknsknon","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Questions?","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"xvrj74tpko","rtl":null,"class":null,"textAlign":null,"suggestionId":null,"suggestionKind":null,"suggestionUserId":null,"suggestionTimestamp":null,"suggestionDiscussionId":null,"suggestionOriginalAttrs":null},"content":[{"text":"Contact us at dfirreview@dfrws.org","type":"text"}]}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2019-03-30T17:24:56.535Z"},{"id":"b4ba8d5a-2328-4d86-ad66-f8c2c76a506f","title":"Stats","slug":"blog","description":"Blog post with stats for DFIR Review","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"fnjtgcsg","layout":[{"id":"xpwsx1ff","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"paragraph","attrs":{"id":"n3uvj3mojvp","class":null},"content":[{"text":"DFIR Review – Year in Review 2020 Statistics","type":"text","marks":[{"type":"strong"}]},{"text":" (cross-posted from https://www.dfir.training/dfir-blog/dfir-review-year-in-review)","type":"text"}]},{"type":"paragraph","attrs":{"id":"n6juf9nhy7l","class":null},"content":[{"text":"Feb 7, 2021","type":"text"}]},{"type":"paragraph","attrs":{"id":"nylv7n651m3","class":"MsoNormal"},"content":[{"text":"Hi! We at DFIR Review wanted to take a moment to share some of the great things all the volunteers at DFIR Review have been doing over the last year and all the great peer-reviewed posts available at ","type":"text"},{"text":"dfir.pubpub.org","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/","title":null,"target":null}}]},{"text":".","type":"text"}]},{"type":"paragraph","attrs":{"id":"nq2vfwvfnix","class":"MsoNormal"},"content":[{"text":"For those who are unfamiliar, DFIR Review is a project under ","type":"text"},{"text":"DFRWS","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfrws.org/","title":null,"target":null}}]},{"text":" that conducts peer review of content and blogs, regardless of if they have already been posted. The goal of this project is to provide verification, validation, and review of digital forensics content that is rapidly shared by practitioners. This allows for the review process to take place while the content is still available to the community.","type":"text"}]},{"type":"paragraph","attrs":{"id":"n630v13lo3j","class":"MsoNormal"},"content":[{"text":"In 2020, DFIR Review published 11 pieces including the following:","type":"text"}]},{"type":"paragraph","attrs":{"id":"njquwnpvnyq","class":"MsoListParagraphCxSpFirst"},"content":[{"text":"· ","type":"text"},{"text":"Google Search Bar & Search Term History – Are You Finding Everything by Joshua Hickman","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/wpbdig8l","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nw3nmuneafp","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"OK Computer…er…Google. Dissecting Google Assistant (Part 1) by Joshua Hickman","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/eivkytr1","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nuqku8khss8","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"OK Computer…er…Google. Dissecting Google Assistant (Part Deux) by Joshua Hickman","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/eivkytr1","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"np1z3kyai28","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"Chromebook Forensic Acquisition by Daniel Dickerman","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/inkjsqrh","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"na2dtd9t866","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"Parsing Google’s Now Playing History on Pixel Devices by Kevin Pagano","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/xbvsrjt5","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"n827jpi13ne","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"Windows 10 Jump List and Link File Artifacts – Saved, Copied, and Moved by Larry Jones","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/wfuxlu9v","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nmw1m3fbfx8","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"Tinkering with TikTok Timestamps by Ryan Benson","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/9llea7yp","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nzabtw21n2t","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"How Android Bluetooth Connections Can Determine if a Driver had Their Hands on the Wheel During an Accident by Heather Mahalik","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/6ysxvhvc","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nty3qc3v9ab","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"Can Google Takeout Location Data Be Trusted? By Ross Donnelly","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/d39u7lg1","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nyi40hf6d43","class":"MsoListParagraphCxSpMiddle"},"content":[{"text":"· ","type":"text"},{"text":"How to Use iOS Bluetooth Connections to Solve Crimes Faster by Heather Mahalik and Matt Goeckel","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/frknihlg","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"njuk6qfjsy8","class":"MsoListParagraphCxSpLast"},"content":[{"text":"· ","type":"text"},{"text":"Can You Track Processes Accessing the Camera and Microphone on Windows 10? By Zachary Stanford","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/pub/nm5b39ae","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"ng9zp1lfo6h","class":"MsoNormal"},"content":[{"text":"The magic behind this cadre of publications is the ","type":"text"},{"text":"DFIR Review Community","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/community","title":null,"target":null}}]},{"text":" and ","type":"text"},{"text":"reviewers","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/reviewers","title":null,"target":null}}]},{"text":". We have a community of over 30 reviewers who have completed 100 reviews. Our community is truly global with contributions from 15 countries across 4 continents!","type":"text"}]},{"type":"paragraph","attrs":{"id":"noi6sl2ie5l","class":"MsoNormal"}},{"type":"paragraph","attrs":{"id":"ngkvtiqievw","class":"MsoNormal"},"content":[{"text":"Thank you to everyone who has contributed be it as an author, reviewer, or organizing committee. We hope to be able to share even more throughout 2021. Have content you want to submit to DFIR Review? Check out our ","type":"text"},{"text":"submission guidance","type":"text","marks":[{"type":"link","attrs":{"href":"https://dfir.pubpub.org/submission-guidance","title":null,"target":null}}]},{"text":". If you are interested in being a reviewer, please feel free to email us at ","type":"text"},{"text":"dfirreview@dfrws.org","type":"text","marks":[{"type":"link","attrs":{"href":"mailto:dfirreview@dfrws.org","title":null,"target":null}}]}]},{"type":"paragraph","attrs":{"id":"nm5w5cylpe4","class":null}},{"type":"paragraph","attrs":{"id":"nply4zgf0ih","class":null},"content":[{"text":"Slide-deck of the stats","type":"text","marks":[{"type":"link","attrs":{"href":"https://www.dfir.training/dfir-review-year-in-review-2020/file","title":null,"target":null}}]}]}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2021-02-07T19:35:12.262Z"},{"id":"6a7dd0ce-1852-4aa8-b858-dd9e4fcc23e7","title":"Submission Guidance","slug":"submission-guidance","description":"","avatar":null,"isPublic":true,"isNarrowWidth":null,"viewHash":"2o9h9at6","layout":[{"id":"zd5ru333","type":"text","content":{"text":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"heading","attrs":{"id":"dfir-review---submission-guidance","rtl":null,"level":1,"fixedId":"","textAlign":null},"content":[{"text":"DFIR Review - Submission Guidance","type":"text"}]},{"type":"paragraph","attrs":{"id":"mpox5nedvm","rtl":null,"class":null,"textAlign":null}},{"type":"paragraph","attrs":{"id":"333wqr8yd8","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Thank you for your interest in submitting to DFIRReview. Please submit via ","type":"text"},{"text":"https://easychair.org/conferences/?conf=dfirr2023","type":"text","marks":[{"type":"link","attrs":{"href":"https://easychair.org/conferences/?conf=dfirr2023","title":null,"target":null}}]},{"text":" ","type":"text"}]},{"type":"paragraph","attrs":{"id":"ni3c4l2wcr","rtl":null,"class":null,"textAlign":null},"content":[{"text":"The following guidance is intended for submitters to utilize in formatting their files submitted to DFIR Review. As DFIR Review is designed for the review of already relieved works, it is suggested that articles be posted in advance as blogs. Author names are not blind to reviewers as submissions for this project are typically already in the public view.","type":"text"}]},{"type":"paragraph","attrs":{"id":"34xpelqcy8","rtl":null,"class":null,"textAlign":null},"content":[{"text":"DFIRReview accepts submissions for an entire month at a time. At the beginning of the next month those papers are assigned for a review period. For example, Reviews submitted between Jan 1 and Jan 31 will be reviewed in February with a decision to the author expected by the end of February","type":"text"}]},{"type":"paragraph","attrs":{"id":"e6jc08o2jj","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Please add the following headers to your blog post with the content filled in and submit your attachment as a .docx file. This will help ensure the best possible publication of your content:","type":"text"}]},{"type":"paragraph","attrs":{"id":"t9p2x2zcx4","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Synopsis:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"ljaq43noa3","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Forensics Question: ","type":"text","marks":[{"type":"strong"}]},{"text":"What is the goal of your paper? What are you trying to answer?","type":"text"}]},{"type":"paragraph","attrs":{"id":"alb8fp1l75","rtl":null,"class":null,"textAlign":null},"content":[{"text":"OS Version:","type":"text","marks":[{"type":"strong"}]},{"text":" Include the applicable Operating System and/or Application versions applies to your content","type":"text"}]},{"type":"paragraph","attrs":{"id":"8l222dkh42","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Tools:","type":"text","marks":[{"type":"strong"}]},{"text":" Please list any and all tools used to create, test, and/or validate your content.","type":"text"}]},{"type":"paragraph","attrs":{"id":"gk0ulcc0n9","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Thank you!","type":"text"}]},{"type":"paragraph","attrs":{"id":"lr8118ce91","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Questions?","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"z50oi5bfgm","rtl":null,"class":null,"textAlign":null},"content":[{"text":"Contact us at dfirreview@dfrws.org","type":"text"}]}]},"align":"left"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2020-05-28T21:59:19.835Z"},{"id":"0f373a2c-c88d-4615-901f-9f3007392c8a","title":"DFIR Review","slug":"","description":"DFIR Review responds to the need for a focal point for up-to-date community-reviewed applied research and testing in digital forensics and incident response. DFIR Review concentrates on targeted studies of specific devices, digital traces, analysis methods, and criminal activity.","avatar":"https://assets.pubpub.org/3ej3id6s/11553968629226.png","isPublic":true,"isNarrowWidth":null,"viewHash":"dfgao2b3","layout":[{"id":"yjymbe9d","type":"banner","content":{"text":"We are actively seeking reviewers! Interested? Email us at dfirreview@dfrws.org ","align":"center","buttonUrl":"","buttonText":"","buttonType":"none","showButton":false,"backgroundSize":"full","backgroundColor":"#3275d8","backgroundImage":"","backgroundHeight":"narrow","defaultCollectionIds":[]}},{"id":"kqa6nus3","type":"banner","content":{"text":"Submit topics of interest for research","align":"center","buttonUrl":"https://bit.ly/DFIRReviewRequests","buttonText":"Research Request","buttonType":"link","showButton":true,"backgroundSize":"full","backgroundColor":"#3275d8","backgroundImage":"","backgroundHeight":"narrow","defaultCollectionIds":[]}},{"id":"bzmjons3","type":"pubs","content":{"sort":"creation-date","limit":0,"title":"","pubIds":[],"collectionIds":[],"pubPreviewType":"medium"}},{"id":"xw3itri0","type":"pubs","content":{"limit":8,"title":"Featured Posts","pubIds":[],"collectionIds":[],"pubPreviewType":"medium"}}],"layoutAllowsDuplicatePubs":false,"createdAt":"2019-03-23T18:09:32.990Z"}],"collections":[{"id":"4d6cbcc5-a3fc-459d-820d-1d4a5f7362d7","title":"Papers","slug":"dsthj493","avatar":null,"isRestricted":true,"isPublic":true,"viewHash":"w3mlztuf","editHash":"k7ll8o5q","metadata":null,"kind":"tag","doi":null,"readNextPreviewSize":"choose-best","layout":{"blocks":[{"id":"m5nt3cew","type":"collection-header","content":{}},{"id":"82wrvv3v","type":"pubs","content":{"sort":"collection-rank","pubPreviewType":"medium"}}],"isNarrow":false},"layoutAllowsDuplicatePubs":false,"pageId":"0f373a2c-c88d-4615-901f-9f3007392c8a","communityId":"b0ac9c28-479a-496c-884c-7ae8fc26e385","scopeSummaryId":"1db60c83-a461-4697-a639-fb7d951333bb","crossrefDepositRecordId":null,"createdAt":"2019-03-30T17:19:53.991Z","updatedAt":"2021-04-26T16:48:52.977Z","members":[]}]},"loginData":{"id":null},"locationData":{"hostname":"dfir.pubpub.org","path":"/pub/khnqi0ff/release/1","params":{"pubSlug":"khnqi0ff","releaseNumber":"1"},"query":{},"queryString":"?","isDashboard":false,"isBasePubPub":false,"isProd":true,"isDuqDuq":false,"isQubQub":false,"appCommit":"6d87aaeef578ba6bd8c8ce36fb866b505dd22469"},"scopeData":{"elements":{"activeTargetType":"pub","activeTargetName":"Pub","activeTarget":{"id":"9cb45d00-07ba-491a-a579-a59bd8481990","slug":"khnqi0ff","title":"iOS Settings Display Auto-Lock & Require Passcode","htmlTitle":null,"description":null,"htmlDescription":null,"avatar":null,"customPublishedAt":null,"doi":null,"labels":null,"downloads":null,"metadata":null,"viewHash":"vr4t65e9","editHash":"k5nk6s4v","reviewHash":"m0cjmotj","commentHash":"e5jaa1ls","draftId":"39e1ae77-6aaa-4bf3-9555-b9382e39ca01","communityId":"b0ac9c28-479a-496c-884c-7ae8fc26e385","crossrefDepositRecordId":null,"scopeSummaryId":"f1b0aae4-10e9-4895-8c46-24366d77d9be","createdAt":"2022-04-07T14:00:29.463Z","updatedAt":"2022-11-17T22:41:05.202Z","collectionPubs":[],"releases":[{"id":"a7e60a4e-d6c2-4208-98ad-f6484adf3080","historyKey":1074}],"submission":null},"activePub":{"id":"9cb45d00-07ba-491a-a579-a59bd8481990","slug":"khnqi0ff","title":"iOS Settings Display Auto-Lock & Require Passcode","htmlTitle":null,"description":null,"htmlDescription":null,"avatar":null,"customPublishedAt":null,"doi":null,"labels":null,"downloads":null,"metadata":null,"viewHash":"vr4t65e9","editHash":"k5nk6s4v","reviewHash":"m0cjmotj","commentHash":"e5jaa1ls","draftId":"39e1ae77-6aaa-4bf3-9555-b9382e39ca01","communityId":"b0ac9c28-479a-496c-884c-7ae8fc26e385","crossrefDepositRecordId":null,"scopeSummaryId":"f1b0aae4-10e9-4895-8c46-24366d77d9be","createdAt":"2022-04-07T14:00:29.463Z","updatedAt":"2022-11-17T22:41:05.202Z","collectionPubs":[],"releases":[{"id":"a7e60a4e-d6c2-4208-98ad-f6484adf3080","historyKey":1074}],"submission":null},"activeCollection":null,"activeIds":{"pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","collectionId":null,"communityId":"b0ac9c28-479a-496c-884c-7ae8fc26e385"},"inactiveCollections":[],"activeCommunity":{"id":"b0ac9c28-479a-496c-884c-7ae8fc26e385","subdomain":"dfir","domain":null,"title":"DFIR Review","citeAs":null,"publishAs":null,"description":"DFIR Review responds to the need for a focal point for up-to-date community-reviewed applied research and testing in digital forensics and incident response. DFIR Review concentrates on targeted studies of specific devices, digital traces, analysis methods, and criminal activity","avatar":"https://assets.pubpub.org/3yqqvtl4/71553968763873.png","favicon":"https://assets.pubpub.org/c8g3oakn/41553968740088.png","accentColorLight":"#FFFFFF","accentColorDark":"#2D2E2F","hideCreatePubButton":true,"headerLogo":"https://assets.pubpub.org/hndwo003/61675374631049.png","headerLinks":null,"headerColorType":"dark","useHeaderTextAccent":false,"hideHero":false,"hideHeaderLogo":false,"heroLogo":null,"heroBackgroundImage":null,"heroBackgroundColor":"#0558b3","heroTextColor":null,"useHeaderGradient":true,"heroImage":null,"heroTitle":"DFIR Review","heroText":"DFIR Review responds to the need for a focal point for up-to-date community-reviewed applied research and testing in digital forensics and incident response. DFIR Review concentrates on targeted studies of specific devices, digital traces, analysis methods, and criminal activity","heroPrimaryButton":{},"heroSecondaryButton":{},"heroAlign":"left","navigation":[{"id":"0f373a2c-c88d-4615-901f-9f3007392c8a","type":"page"},{"id":"b4ba8d5a-2328-4d86-ad66-f8c2c76a506f","type":"page"},{"id":"a8a6a998-952b-45ac-9dde-1e1fef976417","type":"page"},{"id":"6a7dd0ce-1852-4aa8-b858-dd9e4fcc23e7","type":"page"},{"id":"c9d33e1b-70ca-4f00-935e-8b048a2db8aa","type":"page"},{"id":"b1a5d079-3ee0-4434-a65f-c1b0cc624b45","type":"page"},{"id":"2bd22226-03c8-4300-b555-73eb1d6a582d","type":"page"},{"id":"9a0a763a-139f-4380-8620-47bf9e307106","type":"page"},{"id":"a7126096-fe0b-49af-a377-e69d372934d0","type":"page"}],"hideNav":false,"navLinks":null,"footerLinks":null,"footerLogoLink":null,"footerTitle":null,"footerImage":null,"website":"","facebook":"","twitter":"","instagram":null,"mastodon":null,"linkedin":null,"bluesky":null,"github":null,"email":"","socialLinksLocation":null,"issn":null,"isFeatured":null,"viewHash":"qz0cilrt","editHash":"bqi37oih","premiumLicenseFlag":false,"defaultPubCollections":[],"analyticsSettings":null,"spamTagId":"16a43a5f-d437-4a0a-9721-4781fc993f4e","organizationId":null,"scopeSummaryId":"aa45c5c8-46a9-480c-912b-0ace04e252d4","createdAt":"2019-03-23T18:09:32.984Z","updatedAt":"2023-02-02T21:50:33.149Z"}},"memberData":[],"activePermissions":{"activePermission":null,"canView":false,"canEdit":false,"canManage":false,"canAdmin":false,"canAdminCommunity":false,"canManageCommunity":false,"canViewCommunity":false,"canEditCommunity":false,"isSuperAdmin":false,"canCreateReviews":false,"canCreateDiscussions":true,"canViewDraft":false,"canEditDraft":false},"activeCounts":{"reviews":0,"submissions":0},"scope":{"pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","communityId":"b0ac9c28-479a-496c-884c-7ae8fc26e385"},"facets":{"CitationStyle":{"props":{"citationStyle":{"sources":[{"scope":{"kind":"root"},"value":"apa","facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"9ada8f91-3b56-4ddc-81af-04a762d83bae","value":"apa"}],"value":"apa"},"inlineCitationStyle":{"sources":[{"scope":{"kind":"root"},"value":"count","facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"9ada8f91-3b56-4ddc-81af-04a762d83bae","value":"count"}],"value":"count"}},"value":{"citationStyle":"apa","inlineCitationStyle":"count"},"stack":[{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"value":{"citationStyle":"apa","inlineCitationStyle":"count"},"facetBindingId":"9ada8f91-3b56-4ddc-81af-04a762d83bae"}]},"License":{"props":{"kind":{"sources":[{"scope":{"kind":"root"},"value":"cc-by","facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"0a8272c4-2f52-4bda-b47d-8a4f544a1c56","value":"cc-by"}],"value":"cc-by"},"copyrightSelection":{"sources":[{"scope":{"kind":"root"},"value":{"choice":"infer-from-scope","year":null},"facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"0a8272c4-2f52-4bda-b47d-8a4f544a1c56","value":{"choice":"infer-from-scope","year":null}}],"value":{"choice":"infer-from-scope","year":null}}},"value":{"kind":"cc-by","copyrightSelection":{"choice":"infer-from-scope","year":null}},"stack":[{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"value":{"kind":"cc-by","copyrightSelection":{"choice":"infer-from-scope","year":null}},"facetBindingId":"0a8272c4-2f52-4bda-b47d-8a4f544a1c56"}]},"NodeLabels":{"props":{"image":{"sources":[{"scope":{"kind":"root"},"value":{"enabled":false,"text":"Image"},"facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"8199e3ef-b40f-45cb-af2f-1f807460787b","value":{"enabled":false,"text":"Figure"}}],"value":{"enabled":false,"text":"Figure"}},"video":{"sources":[{"scope":{"kind":"root"},"value":{"enabled":false,"text":"Video"},"facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"8199e3ef-b40f-45cb-af2f-1f807460787b","value":{"enabled":false,"text":"Video"}}],"value":{"enabled":false,"text":"Video"}},"audio":{"sources":[{"scope":{"kind":"root"},"value":{"enabled":false,"text":"Audio"},"facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"8199e3ef-b40f-45cb-af2f-1f807460787b","value":{"enabled":false,"text":"Audio"}}],"value":{"enabled":false,"text":"Audio"}},"table":{"sources":[{"scope":{"kind":"root"},"value":{"enabled":false,"text":"Table"},"facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"8199e3ef-b40f-45cb-af2f-1f807460787b","value":{"enabled":false,"text":"Table"}}],"value":{"enabled":false,"text":"Table"}},"math":{"sources":[{"scope":{"kind":"root"},"value":{"enabled":false,"text":"Equation"},"facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"8199e3ef-b40f-45cb-af2f-1f807460787b","value":{"enabled":false,"text":"Equation"}}],"value":{"enabled":false,"text":"Equation"}},"iframe":{"sources":[{"scope":{"kind":"root"},"value":{"enabled":false,"text":"Iframe"},"facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"8199e3ef-b40f-45cb-af2f-1f807460787b","value":{"enabled":false,"text":"Iframe"}}],"value":{"enabled":false,"text":"Iframe"}}},"value":{"image":{"enabled":false,"text":"Figure"},"video":{"enabled":false,"text":"Video"},"audio":{"enabled":false,"text":"Audio"},"table":{"enabled":false,"text":"Table"},"math":{"enabled":false,"text":"Equation"},"iframe":{"enabled":false,"text":"Iframe"}},"stack":[{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"value":{"image":{"enabled":false,"text":"Figure"},"video":{"enabled":false,"text":"Video"},"audio":{"enabled":false,"text":"Audio"},"table":{"enabled":false,"text":"Table"},"math":{"enabled":false,"text":"Equation"},"iframe":{"enabled":false,"text":"Iframe"}},"facetBindingId":"8199e3ef-b40f-45cb-af2f-1f807460787b"}]},"PubEdgeDisplay":{"props":{"defaultsToCarousel":{"sources":[{"scope":{"kind":"root"},"value":true,"facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"7f110780-9873-40ee-af34-9e8eb17c9ed5","value":true}],"value":true},"descriptionIsVisible":{"sources":[{"scope":{"kind":"root"},"value":true,"facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"7f110780-9873-40ee-af34-9e8eb17c9ed5","value":true}],"value":true}},"value":{"defaultsToCarousel":true,"descriptionIsVisible":true},"stack":[{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"value":{"defaultsToCarousel":true,"descriptionIsVisible":true},"facetBindingId":"7f110780-9873-40ee-af34-9e8eb17c9ed5"}]},"PubHeaderTheme":{"props":{"backgroundImage":{"sources":[{"scope":{"kind":"root"},"value":null,"facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"27e6dcdf-57e4-4ed6-92b5-4183eb53c1a2","value":""}],"value":""},"backgroundColor":{"sources":[{"scope":{"kind":"root"},"value":"community","facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"27e6dcdf-57e4-4ed6-92b5-4183eb53c1a2","value":"light"}],"value":"light"},"textStyle":{"sources":[{"scope":{"kind":"root"},"value":"light","facetBindingId":null},{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"facetBindingId":"27e6dcdf-57e4-4ed6-92b5-4183eb53c1a2","value":"dark"}],"value":"dark"}},"value":{"backgroundImage":"","backgroundColor":"light","textStyle":"dark"},"stack":[{"scope":{"kind":"pub","id":"9cb45d00-07ba-491a-a579-a59bd8481990"},"value":{"backgroundImage":"","backgroundColor":"light","textStyle":"dark"},"facetBindingId":"27e6dcdf-57e4-4ed6-92b5-4183eb53c1a2"}]}}},"featureFlags":{"releaseDiscussionsDialog":false,"activityDigestSubscribeToggle":true,"notifications":true,"submissions":true,"surveySummer22":false,"reviews":false,"comments":false,"htmlPubHeaderValues":false,"minimal-header":false,"minimal-footer":false,"customScripts":false,"collapsible-header":false,"two-column-footer":false,"suggestedEdits":false,"collapsible-header-bpc":false,"customAnalyticsProvider":false,"newAnalytics":true,"bodyContributors":false,"noCookieBanner":false},"initialNotificationsData":{"hasNotifications":false,"hasUnreadNotifications":false},"dismissedUserDismissables":{}}"></script><script id="view-data" type="text/plain" data-json="{"pubData":{"subscription":null,"id":"9cb45d00-07ba-491a-a579-a59bd8481990","slug":"khnqi0ff","title":"iOS Settings Display Auto-Lock & Require Passcode","htmlTitle":null,"description":null,"htmlDescription":null,"avatar":null,"customPublishedAt":null,"doi":null,"labels":null,"downloads":null,"metadata":null,"viewHash":null,"editHash":null,"reviewHash":null,"commentHash":null,"draftId":"39e1ae77-6aaa-4bf3-9555-b9382e39ca01","communityId":"b0ac9c28-479a-496c-884c-7ae8fc26e385","crossrefDepositRecordId":null,"scopeSummaryId":"f1b0aae4-10e9-4895-8c46-24366d77d9be","createdAt":"2022-04-07T14:00:29.463Z","updatedAt":"2022-11-17T22:41:05.202Z","members":[{"id":"f777bffb-6a08-400c-a57c-6c52c967bea9","permissions":"manage","isOwner":true,"subscribedToActivityDigest":false,"userId":"30aa145b-85e3-45f0-af37-2431daffd78a","pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","collectionId":null,"communityId":null,"organizationId":null,"createdAt":"2022-04-07T14:00:29.515Z","updatedAt":"2022-04-07T14:00:29.515Z"}],"draft":null,"submission":null,"crossrefDepositRecord":null,"scopeSummary":{"id":"f1b0aae4-10e9-4895-8c46-24366d77d9be","collections":0,"pubs":0,"discussions":0,"reviews":0,"submissions":0,"createdAt":"2022-04-07T14:00:29.481Z","updatedAt":"2022-04-07T14:00:29.481Z"},"inboundEdges":[],"outboundEdges":[],"reviews":[],"discussions":[],"releases":[{"id":"a7e60a4e-d6c2-4208-98ad-f6484adf3080","noteContent":null,"noteText":null,"pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","userId":"30aa145b-85e3-45f0-af37-2431daffd78a","docId":"d2613db5-8f52-4d0b-80a0-72f1bf9ca9a5","historyKey":1074,"historyKeyMissing":false,"createdAt":"2022-06-02T21:43:02.509Z","updatedAt":"2022-06-02T21:43:02.509Z"}],"collectionPubs":[],"attributions":[{"id":"e966d0a2-f83d-4532-857b-96ea2a70ea77","name":null,"avatar":null,"title":null,"order":0.75,"isAuthor":true,"roles":null,"affiliation":null,"orcid":null,"userId":"2b028128-c5e1-47da-8c59-af7b26d83970","pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","createdAt":"2022-04-07T14:01:13.636Z","updatedAt":"2022-04-07T14:01:13.636Z","user":{"id":"2b028128-c5e1-47da-8c59-af7b26d83970","firstName":"Scott","lastName":"Koenig","fullName":"Scott Koenig","avatar":"https://assets.pubpub.org/f088ur44/01599601723720.jpg","slug":"scott-koenig","initials":"SK","title":"DFIR Examiner","orcid":""}}],"exports":[{"id":"695db323-b092-4e84-b9f5-201d6c92abfa","format":"odt","url":"https://assets.pubpub.org/wahlbbz0/9cb45d00-07ba-491a-a579-a59bd8481990.odt","historyKey":1074,"pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","workerTaskId":"d5b44727-bb52-44d0-9f76-8ff3bc32c3d9","createdAt":"2022-06-02T21:43:03.048Z","updatedAt":"2022-06-02T21:43:25.737Z"},{"id":"4bc319cc-a30a-4eee-b9ee-53fdd7774f7a","format":"pdf","url":"https://assets.pubpub.org/jta4d76z/9cb45d00-07ba-491a-a579-a59bd8481990.pdf","historyKey":1074,"pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","workerTaskId":"5b51d2b5-d324-4d6d-a3e3-deb26207672f","createdAt":"2022-06-02T21:43:02.811Z","updatedAt":"2022-06-05T15:00:07.768Z"},{"id":"dd39247b-dfee-45f6-92f5-0c61bf0a3842","format":"epub","url":"https://assets.pubpub.org/qqog53yf/9cb45d00-07ba-491a-a579-a59bd8481990.epub","historyKey":1074,"pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","workerTaskId":"a7071413-3b5f-49ef-a6ae-d6ca195990c0","createdAt":"2022-06-02T21:43:02.848Z","updatedAt":"2022-12-18T16:04:36.881Z"},{"id":"0c4ce463-e3f4-4cbb-949b-4821ea315ffd","format":"html","url":null,"historyKey":1074,"pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","workerTaskId":"f9286765-960b-4748-8980-024617a91aac","createdAt":"2022-06-02T21:43:02.875Z","updatedAt":"2022-06-02T21:43:03.042Z"},{"id":"540c8061-531f-4ff6-a935-6ee8c4a053f0","format":"docx","url":"https://assets.pubpub.org/1sdbw0q8/9cb45d00-07ba-491a-a579-a59bd8481990.docx","historyKey":1074,"pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","workerTaskId":"7672c365-d133-48fb-b341-e7cb84f9e7b5","createdAt":"2022-06-02T21:43:02.813Z","updatedAt":"2022-06-02T21:43:25.955Z"},{"id":"5ea993d0-2b1e-49ca-8a7d-8ffbf114b89b","format":"tex","url":"https://assets.pubpub.org/ew4s5q6p/9cb45d00-07ba-491a-a579-a59bd8481990.tex","historyKey":1074,"pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","workerTaskId":"d251a99e-90ef-4874-862c-5602ef6ce193","createdAt":"2022-06-02T21:43:03.017Z","updatedAt":"2022-06-02T21:43:20.555Z"},{"id":"6bf325ea-8f83-4bb1-899c-a992dc6bbe34","format":"markdown","url":"https://assets.pubpub.org/euex2y9c/9cb45d00-07ba-491a-a579-a59bd8481990.md","historyKey":1074,"pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","workerTaskId":"4b42e264-6b46-49c9-9cdf-372bbd4708d5","createdAt":"2022-06-02T21:43:02.873Z","updatedAt":"2022-06-02T21:43:22.724Z"},{"id":"05754e96-e1eb-4ec8-b71b-7f28d9e9a566","format":"plain","url":"https://assets.pubpub.org/vzvei08r/9cb45d00-07ba-491a-a579-a59bd8481990.txt","historyKey":1074,"pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","workerTaskId":"f7dcb0c6-2d11-491c-ad26-f2cfada415ee","createdAt":"2022-06-02T21:43:02.986Z","updatedAt":"2022-06-02T21:43:22.737Z"},{"id":"93a76fdf-8fef-423f-ba8e-1961edef51e4","format":"jats","url":null,"historyKey":1074,"pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","workerTaskId":"81f913d7-ecba-4b05-9c5a-72880ce7cf69","createdAt":"2022-06-02T21:43:03.062Z","updatedAt":"2022-06-02T21:43:03.077Z"},{"id":"8e795b50-6d1b-4f2b-ac2b-e5eea20ed588","format":"json","url":"https://assets.pubpub.org/huqak25v/9cb45d00-07ba-491a-a579-a59bd8481990.json","historyKey":1074,"pubId":"9cb45d00-07ba-491a-a579-a59bd8481990","workerTaskId":"bd2435d9-abb0-461d-b28b-09b368df1276","createdAt":"2022-06-02T21:43:03.063Z","updatedAt":"2022-06-02T21:43:27.652Z"}],"isRelease":true,"releaseNumber":1,"initialStructuredCitations":{},"citationData":{"pub":{"default":"<div class=\"csl-bib-body\"> <div data-csl-entry-id=\"temp_id_6555257380139892\" class=\"csl-entry\">Koenig, S. (2022). iOS Settings Display Auto-Lock &#38; Require Passcode. <i>DFIR Review</i>. Retrieved from https://dfir.pubpub.org/pub/khnqi0ff</div></div>","apa":"<div class=\"csl-bib-body\"> <div data-csl-entry-id=\"temp_id_6555257380139892\" class=\"csl-entry\">Koenig, S. (2022). iOS Settings Display Auto-Lock &#38; Require Passcode. <i>DFIR Review</i>. https://dfir.pubpub.org/pub/khnqi0ff</div></div>","harvard":"<div class=\"csl-bib-body\"> <div data-csl-entry-id=\"temp_id_6555257380139892\" class=\"csl-entry\">Koenig, S. (2022) 'iOS Settings Display Auto-Lock &#38; Require Passcode', <i>DFIR Review</i> [Preprint]. Available at: https://dfir.pubpub.org/pub/khnqi0ff.</div></div>","vancouver":"<div class=\"csl-bib-body\"> <div data-csl-entry-id=\"temp_id_6555257380139892\" class=\"csl-entry\"> <div class=\"csl-left-margin\">1. </div><div class=\"csl-right-inline\">Koenig S. iOS Settings Display Auto-Lock &#38; Require Passcode. DFIR Review [Internet]. 2022 Jun 2; Available from: https://dfir.pubpub.org/pub/khnqi0ff</div> </div></div>","bibtex":"@article{Koenig2022iOS,\n\tauthor = {Koenig, Scott},\n\tjournal = {DFIR Review},\n\tyear = {2022},\n\tmonth = {jun 2},\n\tnote = {https://dfir.pubpub.org/pub/khnqi0ff},\n\tpublisher = {},\n\ttitle = {iOS {Settings} {Display} {Auto}-{Lock} & {Require} {Passcode}},\n}\n\n"}},"siblingEdges":[],"initialDoc":{"type":"doc","attrs":{"meta":{}},"content":[{"type":"heading","attrs":{"id":"synopsis","level":1,"fixedId":"","textAlign":null},"content":[{"text":"Synopsis","type":"text"}]},{"type":"table","attrs":{"id":"7pnvpve7ye","hideLabel":false},"content":[{"type":"table_row","content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null},"content":[{"type":"paragraph","attrs":{"id":"ca09dpu7kq","class":null,"textAlign":null},"content":[{"text":"Forensics Question:","type":"text","marks":[{"type":"strong"}]},{"text":" ","type":"text"},{"type":"hard_break"},{"text":"Where in an iPhone extraction is the Display Auto-Lock setting stored?","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null},"content":[{"type":"paragraph","attrs":{"id":"n4x03e4rspv","class":null,"textAlign":null}},{"type":"image","attrs":{"id":"3z7uqe08aw","url":"https://assets.pubpub.org/otm7hspl/01604324623084.png","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}}]}]},{"type":"table_row","content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null},"content":[{"type":"paragraph","attrs":{"id":"tapzxzhb9k","class":null,"textAlign":null},"content":[{"text":"OS Version:","type":"text","marks":[{"type":"strong"}]},{"text":" ","type":"text"},{"type":"hard_break"},{"text":"Apple iPhone 6s Plus","type":"text"}]},{"type":"paragraph","attrs":{"id":"n4klbbxl1cb","class":null,"textAlign":null},"content":[{"text":"iOS: 14.4.2 (18D70)","type":"text"}]},{"type":"paragraph","attrs":{"id":"ngpq3x6tp7d","class":null,"textAlign":null},"content":[{"text":"Older iOS versions checked: 12.4.8 and 13.5.1","type":"text"},{"type":"hard_break"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null},"content":[{"type":"paragraph","attrs":{"id":"n391zwd0vvf","class":null,"textAlign":null}},{"type":"image","attrs":{"id":"nlkqjkuo9y6","url":"https://assets.pubpub.org/9636kems/61615840870473.png","href":null,"size":50,"align":"center","altText":"","caption":"","hideLabel":false,"fullResolution":false}}]}]},{"type":"table_row","content":[{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null},"content":[{"type":"paragraph","attrs":{"id":"zc8ryi5sxh","class":null,"textAlign":null},"content":[{"text":"Tools:","type":"text","marks":[{"type":"strong"}]},{"text":" ","type":"text"},{"type":"hard_break"},{"text":"Cellebrite UFED 4PC 7.47.0.247","type":"text"}]},{"type":"paragraph","attrs":{"id":"nqh9bdssj58","class":null,"textAlign":null},"content":[{"text":"Cellebrite Physical Analyzer 7.47.0.58 & 7.48.0.49","type":"text"}]},{"type":"paragraph","attrs":{"id":"nbwyb3mi5bf","class":null,"textAlign":null},"content":[{"text":"Magnet AXIOM 5.4.0.26185","type":"text"}]},{"type":"paragraph","attrs":{"id":"nwyq646eax0","class":null,"textAlign":null},"content":[{"text":"ArtEx 1.6.0.0 & 2.0.0.4","type":"text"}]},{"type":"paragraph","attrs":{"id":"nakeiytbtx2","class":null,"textAlign":null},"content":[{"text":"Mushy 2.0.0.6","type":"text"}]}]},{"type":"table_cell","attrs":{"colspan":1,"rowspan":1,"colwidth":null,"background":null},"content":[{"type":"paragraph","attrs":{"id":"njvcbgnlcqn","class":null,"textAlign":null}}]}]}]},{"type":"paragraph","attrs":{"id":"npqh6p8iuob","class":null,"textAlign":null},"content":[{"text":"A classmate of mine contacted me and posed a question, “Where in an iPhone extraction is the Display Auto-Lock setting stored?” Thanks, Tyler Wuestenhagen, for posing the question and getting me thinking.","type":"text"}]},{"type":"paragraph","attrs":{"id":"ncoruksx4i7","class":null,"textAlign":null},"content":[{"text":"I did a little research, like reviewing the SANS FOR585 poster and class notes, but could not find the easy answer. I reached out to some other examiners, and they too were a bit puzzled about where those settings might be saved or which property list (plist) they might be stored in.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nocfbvbt6wt","class":null,"textAlign":null},"content":[{"text":"Tyler was able to narrow down the search when he discovered the ","type":"text"},{"text":"PublicEffectiveUserSettings.plist","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":". This plist can be found at the following location on iPhone extractions: ","type":"text"},{"text":"\\private\\var\\mobile\\Library\\UserConfigurationProfiles\\PublicInfo\\","type":"text","marks":[{"type":"em"}]}]},{"type":"paragraph","attrs":{"id":"nfj6udrvkrc","class":null,"textAlign":null},"content":[{"text":"After learning about the plist, I started working on testing and validating the data stored in the plist.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nqz64vuozto","class":null,"textAlign":null},"content":[{"text":"During testing, the data was acquired using the following tools and methods. The ","type":"text"},{"text":"PublicEffectiveUserSettings.plist","type":"text","marks":[{"type":"em"}]},{"text":" was found in each of the data extractions listed:","type":"text"}]},{"type":"paragraph","attrs":{"id":"nfk4ye886yi","class":null,"textAlign":null},"content":[{"text":"Cellebrite Advance Logical Extraction – UFED 4PC","type":"text"}]},{"type":"paragraph","attrs":{"id":"nl8zxszpvpl","class":null,"textAlign":null},"content":[{"text":"Cellebrite Advance Logical Full File System – device jailbroken with Checkm8 – UFED 4PC","type":"text"}]},{"type":"paragraph","attrs":{"id":"n8t0zh0gvx9","class":null,"textAlign":null},"content":[{"text":"ArtEx ArtExtraction – Full Extraction – device jailbroken with Checkm8","type":"text"}]},{"type":"paragraph","attrs":{"id":"ng02oww68ad","class":null,"textAlign":null},"content":[{"text":"ArtEx ArtExtraction – Live Connection – device jailbroken with Checkm8","type":"text"}]},{"type":"paragraph","attrs":{"id":"n5g7u6en8qp","class":null,"textAlign":null},"content":[{"text":"Graykey Full File System","type":"text"}]},{"type":"paragraph","attrs":{"id":"n03pux23mnz","class":null,"textAlign":null},"content":[{"text":"Based on testing, I have determined there are several device settings stored within the ","type":"text"},{"text":"PublicEffectiveUserSettings.plist","type":"text","marks":[{"type":"em"}]},{"text":", but I will only be discussing two of those settings: the ","type":"text"},{"text":"Display Auto-Lock setting","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":" and the ","type":"text"},{"text":"Required Passcode setting","type":"text","marks":[{"type":"em"},{"type":"strong"}]},{"text":".","type":"text"}]},{"type":"image","attrs":{"id":"njdo4xe29ru","url":"https://assets.pubpub.org/wio8nklv/01649340049910.png","href":null,"size":50,"align":"full","altText":"","caption":"<p>A screenshot of a phone Description automatically generated with medium confidence</p>","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"ng2vckdkafx","class":null,"textAlign":null},"content":[{"text":"Figure 1","type":"text"}]},{"type":"paragraph","attrs":{"id":"nezqosxqv0j","class":null,"textAlign":null},"content":[{"text":"Display & Brightness Auto-Lock Setting:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"njneq4ia8r7","class":null,"textAlign":null},"content":[{"text":"In the Display & Brightness setting there is a setting titled ","type":"text"},{"text":"Auto-Lock","type":"text","marks":[{"type":"em"}]},{"text":" as seen in Figure 2.","type":"text"}]},{"type":"image","attrs":{"id":"nj24n4b1l7a","url":"https://assets.pubpub.org/n9cg168p/21649340049911.png","href":null,"size":50,"align":"full","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"nufq6s8n7x6","class":null,"textAlign":null},"content":[{"text":"Figure 2","type":"text"}]},{"type":"paragraph","attrs":{"id":"n70y66gpcd6","class":null,"textAlign":null},"content":[{"text":"During testing, the Display Auto-Lock options were 30 Seconds, 1 Minute, 2 Minutes, 3 Minutes, 4 Minutes, 5 Minutes and Never:","type":"text"}]},{"type":"image","attrs":{"id":"nnn94podjfj","url":"https://assets.pubpub.org/o7zu94jo/61649340049912.png","href":null,"size":50,"align":"full","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"neq7869f69m","class":null,"textAlign":null},"content":[{"text":"Figure 3","type":"text"}]},{"type":"paragraph","attrs":{"id":"n0m5ylhc7c4","class":null,"textAlign":null},"content":[{"text":"These Display Auto-Lock settings are stored in the ","type":"text"},{"text":"PublicEffectiveUserSettings.plist","type":"text","marks":[{"type":"em"}]},{"text":" in seconds. For example: if the Display Auto-Lock setting is set to auto-lock after 2 minutes as seen in Figure 3, the ","type":"text"},{"text":"value","type":"text","marks":[{"type":"em"}]},{"text":" key integer will be “120” meaning 120 seconds or 2 minutes.","type":"text"}]},{"type":"paragraph","attrs":{"id":"ni7winji862","class":null,"textAlign":null},"content":[{"text":"To find this ","type":"text"},{"text":"value","type":"text","marks":[{"type":"em"}]},{"text":" key integer within the ","type":"text"},{"text":"PublicEffectiveUserSettings.plist","type":"text","marks":[{"type":"em"}]},{"text":" you will need to find the ","type":"text"},{"text":"restrictedValue","type":"text","marks":[{"type":"em"}]},{"text":" key, then the ","type":"text"},{"text":"maxInactivity","type":"text","marks":[{"type":"em"}]},{"text":" key. Once you have located these keys you will notice an integer that represents the setting value in seconds, as seen in Figure 4.","type":"text"}]},{"type":"paragraph","attrs":{"id":"npmuchd3hsq","class":null,"textAlign":null},"content":[{"text":"Apple Developer website, ","type":"text"},{"text":"https://developer.apple.com/documentation/devicemanagement/passcode","type":"text","marks":[{"type":"link","attrs":{"href":"https://developer.apple.com/documentation/devicemanagement/passcode","title":"","target":null}}]},{"text":", defines ","type":"text"},{"text":"maxInactivity","type":"text","marks":[{"type":"em"}]},{"text":" as “the maximum number of minutes for which the device can be idle, without being unlocked by the user, before it gets locked by the system. When this limit is reached, the device is locked and the passcode must be entered. The user can edit this setting, but the value cannot exceed the maxInactivity value.”","type":"text"}]},{"type":"image","attrs":{"id":"n662lxf9pjp","url":"https://assets.pubpub.org/sr1ehyny/71649340049912.png","href":null,"size":50,"align":"full","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"nq84x879yh9","class":null,"textAlign":null},"content":[{"text":"Figure 4","type":"text"}]},{"type":"paragraph","attrs":{"id":"ntmo4kamf54","class":null,"textAlign":null},"content":[{"text":"You will also notice a key for ","type":"text"},{"text":"rangeMinimum","type":"text","marks":[{"type":"em"}]},{"text":". This key integer is the value in seconds for the minimum setting. Notice in Figure 3, the minimum setting is 30 seconds.","type":"text"}]},{"type":"paragraph","attrs":{"id":"ninfghdlihy","class":null,"textAlign":null},"content":[{"text":"Note: There are several ways to view property lists, that include on an Apple computer, within forensic tools and third party plist viewing tools. In this instance, I used Ian Whiffin’s “Mushy PLIST Viewer,” which can be downloaded at the following link along with his other FREE tools: ","type":"text"},{"text":"https://www.doubleblak.com/software.php","type":"text","marks":[{"type":"link","attrs":{"href":"https://www.doubleblak.com/software.php","title":"","target":null}}]}]},{"type":"paragraph","attrs":{"id":"n0b7zk38117","class":null,"textAlign":null},"content":[{"text":"Touch ID & Passcode Require Passcode Setting:","type":"text","marks":[{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nxlb0joklui","class":null,"textAlign":null},"content":[{"text":"In the Touch ID & Passcode settings there is a setting titled “Require Passcode” as seen in Figure 5.","type":"text"}]},{"type":"image","attrs":{"id":"nvx59iy09tg","url":"https://assets.pubpub.org/xq7295yy/61649340049912.png","href":null,"size":50,"align":"full","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"nnwi34iuxkp","class":null,"textAlign":null},"content":[{"text":"Figure 5","type":"text"}]},{"type":"paragraph","attrs":{"id":"nxlwwryg0ey","class":null,"textAlign":null},"content":[{"text":"During testing, the Require Passcode options were Immediately, After 1 minute, After 5 minutes, After 15 minutes, After 1 hour and After 4 hours:","type":"text"}]},{"type":"image","attrs":{"id":"nxnht79b40v","url":"https://assets.pubpub.org/axq6rbx6/11649340049912.png","href":null,"size":50,"align":"full","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"n4i8oqb3fmm","class":null,"textAlign":null},"content":[{"text":"Figure 6","type":"text"}]},{"type":"paragraph","attrs":{"id":"neqdf9emcva","class":null,"textAlign":null},"content":[{"text":"Similarly with the Display Auto-Lock settings, these settings are stored in the ","type":"text"},{"text":"PublicEffectiveUserSettings.plist","type":"text","marks":[{"type":"em"}]},{"text":" in seconds. For example: if Require Passcode setting is set to be required after 5 minutes as depicted in Figure 6, the ","type":"text"},{"text":"value","type":"text","marks":[{"type":"em"}]},{"text":" key integer will be “300” meaning 300 seconds or 5 minutes.","type":"text"}]},{"type":"paragraph","attrs":{"id":"ngwy6wl1trm","class":null,"textAlign":null},"content":[{"text":"To find this ","type":"text"},{"text":"value","type":"text","marks":[{"type":"em"}]},{"text":" key integer within the ","type":"text"},{"text":"PublicEffectiveUserSettings.plist","type":"text","marks":[{"type":"em"}]},{"text":" you will need to find the ","type":"text"},{"text":"restrictedValue","type":"text","marks":[{"type":"em"}]},{"text":" key, then the ","type":"text"},{"text":"maxGracePeriod","type":"text","marks":[{"type":"em"}]},{"text":" key. Once you have located these keys, you will notice an integer that represents the setting value in seconds, as seen in Figure 7.","type":"text"}]},{"type":"paragraph","attrs":{"id":"ny8m660xul6","class":null,"textAlign":null},"content":[{"text":"Apple Developer website, ","type":"text"},{"text":"https://developer.apple.com/documentation/devicemanagement/passcode","type":"text","marks":[{"type":"link","attrs":{"href":"https://developer.apple.com/documentation/devicemanagement/passcode","title":"","target":null}}]},{"text":", defines ","type":"text"},{"text":"maxGracePeriod","type":"text","marks":[{"type":"em"}]},{"text":" as “the maximum grace period, in minutes, to unlock the phone without entering a passcode. The default is 0, which is no grace period and requires a passcode immediately.”","type":"text"}]},{"type":"image","attrs":{"id":"n3k6py42mq1","url":"https://assets.pubpub.org/22hovziq/21649340049913.png","href":null,"size":50,"align":"full","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"nuqslcbd9dz","class":null,"textAlign":null},"content":[{"text":"Figure 7","type":"text"}]},{"type":"paragraph","attrs":{"id":"n6w6cobuflu","class":null,"textAlign":null},"content":[{"text":"In Figure 7 you will notice additional keys are highlighted. The additional keys listed under the ","type":"text"},{"text":"maxGracePeriod","type":"text","marks":[{"type":"em"}]},{"text":" key, are ","type":"text"},{"text":"rangeMaximum","type":"text","marks":[{"type":"em"}]},{"text":" and ","type":"text"},{"text":"rangeMinimum","type":"text","marks":[{"type":"em"}]},{"text":". These keys indicate the maximum setting and minimum setting within the setting menu as seen in Figure 6.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nnwkpi95mgh","class":null,"textAlign":null},"content":[{"text":"During testing, I made changes to the device settings six times. Below are the device settings followed by the values listed in the ","type":"text"},{"text":"PublicEffectiveUserSettings.plist","type":"text","marks":[{"type":"em"}]},{"text":".","type":"text"}]},{"type":"paragraph","attrs":{"id":"n473gctyst1","class":null,"textAlign":null},"content":[{"text":"Test One","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nl2qquh83pp","class":null,"textAlign":null},"content":[{"text":"No passcode","type":"text"}]},{"type":"paragraph","attrs":{"id":"ntkjsgw2p0w","class":null,"textAlign":null},"content":[{"text":"Display Auto-Lock = 2 minutes","type":"text"}]},{"type":"paragraph","attrs":{"id":"nv9xoey8nxe","class":null,"textAlign":null},"content":[{"text":"Require Passcode = not set","type":"text"}]},{"type":"paragraph","attrs":{"id":"na7ogxjrwmb","class":null,"textAlign":null},"content":[{"text":"maxInactivity value = 120","type":"text"}]},{"type":"paragraph","attrs":{"id":"n8n12adw9zf","class":null,"textAlign":null},"content":[{"text":"maxGracePeriod value = 0","type":"text"}]},{"type":"paragraph","attrs":{"id":"nlwqnftno7v","class":null,"textAlign":null},"content":[{"text":"Test Two","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"no3c9zsqaxl","class":null,"textAlign":null},"content":[{"text":"6-digit passcode","type":"text"}]},{"type":"paragraph","attrs":{"id":"nayxwx09bbu","class":null,"textAlign":null},"content":[{"text":"Display Auto-Lock = 30 seconds","type":"text"}]},{"type":"paragraph","attrs":{"id":"ncwfvok4t74","class":null,"textAlign":null},"content":[{"text":"Require Passcode = immediately","type":"text"}]},{"type":"paragraph","attrs":{"id":"ntknij48mnn","class":null,"textAlign":null},"content":[{"text":"maxInactivity value = 30","type":"text"}]},{"type":"paragraph","attrs":{"id":"npx68vmvaqm","class":null,"textAlign":null},"content":[{"text":"maxGracePeriod value = 0","type":"text"}]},{"type":"paragraph","attrs":{"id":"ne16lxzsmb0","class":null,"textAlign":null},"content":[{"text":"Test Three","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"ng6mrlp0pv0","class":null,"textAlign":null},"content":[{"text":"6-digit passcode","type":"text"}]},{"type":"paragraph","attrs":{"id":"nrtvtzq1tk7","class":null,"textAlign":null},"content":[{"text":"Display Auto-Lock = never","type":"text"}]},{"type":"paragraph","attrs":{"id":"ni21emwr3sw","class":null,"textAlign":null},"content":[{"text":"Require Passcode = 1 minute","type":"text"}]},{"type":"paragraph","attrs":{"id":"n353y64wn5r","class":null,"textAlign":null},"content":[{"text":"maxInactivity value = 2147483647","type":"text"}]},{"type":"paragraph","attrs":{"id":"nex406f4r6v","class":null,"textAlign":null},"content":[{"text":"maxGracePeriod value = 60","type":"text"}]},{"type":"paragraph","attrs":{"id":"nqnp3ant3fx","class":null,"textAlign":null},"content":[{"text":"Take note, in test three, the Screen Auto-Lock setting was set to never and the maxInactivity value is “2147483647.”","type":"text"}]},{"type":"paragraph","attrs":{"id":"n9vdl30ruxk","class":null,"textAlign":null},"content":[{"text":"Test Four","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n0xjush2owb","class":null,"textAlign":null},"content":[{"text":"6-digit passcode","type":"text"}]},{"type":"paragraph","attrs":{"id":"nkvapvbdefs","class":null,"textAlign":null},"content":[{"text":"Display Auto-Lock = 1 minute","type":"text"}]},{"type":"paragraph","attrs":{"id":"nwd6tvdr40d","class":null,"textAlign":null},"content":[{"text":"Require Passcode = 5 minute","type":"text"}]},{"type":"paragraph","attrs":{"id":"nenetn58sfm","class":null,"textAlign":null},"content":[{"text":"maxInactivity value = 60","type":"text"}]},{"type":"paragraph","attrs":{"id":"ng5pci92595","class":null,"textAlign":null},"content":[{"text":"maxGracePeriod value = 300","type":"text"}]},{"type":"paragraph","attrs":{"id":"nsw9j4gvsnw","class":null,"textAlign":null},"content":[{"text":"Test Five","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"n7v1wb83032","class":null,"textAlign":null},"content":[{"text":"6-digit passcode","type":"text"}]},{"type":"paragraph","attrs":{"id":"n1z81xw6lkw","class":null,"textAlign":null},"content":[{"text":"Display Auto-Lock = 3 minutes","type":"text"}]},{"type":"paragraph","attrs":{"id":"ndngkyvr3k1","class":null,"textAlign":null},"content":[{"text":"Require Passcode = 4 hours","type":"text"}]},{"type":"paragraph","attrs":{"id":"nzcju92jb3n","class":null,"textAlign":null},"content":[{"text":"maxInactivity value = 180","type":"text"}]},{"type":"paragraph","attrs":{"id":"noqxtqzlse3","class":null,"textAlign":null},"content":[{"text":"maxGracePeriod value = 14400","type":"text"}]},{"type":"paragraph","attrs":{"id":"nkrkw7u9h73","class":null,"textAlign":null},"content":[{"text":"Test Six","type":"text","marks":[{"type":"em"},{"type":"strong"}]}]},{"type":"paragraph","attrs":{"id":"nxxnjnd7vr9","class":null,"textAlign":null},"content":[{"text":"No passcode","type":"text"}]},{"type":"paragraph","attrs":{"id":"njnay0ffd58","class":null,"textAlign":null},"content":[{"text":"Display Auto-Lock = 2 minutes","type":"text"}]},{"type":"paragraph","attrs":{"id":"nbol30q1661","class":null,"textAlign":null},"content":[{"text":"Require Passcode = 5 minutes","type":"text"}]},{"type":"paragraph","attrs":{"id":"n1eq05v84kk","class":null,"textAlign":null},"content":[{"text":"maxInactivity value = 120","type":"text"}]},{"type":"paragraph","attrs":{"id":"n182z8ehxqz","class":null,"textAlign":null},"content":[{"text":"maxGracePeriod value = 300","type":"text"}]},{"type":"paragraph","attrs":{"id":"nj23o65w6r4","class":null,"textAlign":null},"content":[{"text":"After testing, I removed the passcode from the test device. When I checked the settings for Require Passcode, it was grayed out, but was still set on the last setting, which was after 5 minutes as seen in Figure 8.","type":"text"}]},{"type":"image","attrs":{"id":"n4qw7w83va5","url":"https://assets.pubpub.org/3p2vn9na/41649340049913.png","href":null,"size":50,"align":"full","altText":"","caption":"","hideLabel":false,"fullResolution":false}},{"type":"paragraph","attrs":{"id":"nim9jtjmifs","class":null,"textAlign":null},"content":[{"text":"Figure 8","type":"text"}]},{"type":"paragraph","attrs":{"id":"n474sxti49j","class":null,"textAlign":null},"content":[{"text":"After noticing this, I conducted another extraction and discovered the plist ","type":"text"},{"text":"maxGracePeriod","type":"text","marks":[{"type":"em"}]},{"text":" value was still set at 300 seconds. I tested to determine if this setting was still active even though the device did not have a passcode. I changed the Display Auto-Lock setting to never, turned the screen on and set the device on my desk. After 5 minutes, the display did not auto-lock and the device did not require a passcode, thus even though this setting was still set in the plist, it was not active and did not make any changes to the device status.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nm2fm1dfznq","class":null,"textAlign":null},"content":[{"text":"Consideration: I did not test every possibility using these settings. You should also consider additional factors might affect these settings prior to the data acquisition. An example of this could be a first responder / different examiner making changes to these settings when the device is seized or when the data is acquired but failed to document these changes. Some forensic tools recommend making changes to these settings prior to data acquisition.","type":"text"}]},{"type":"paragraph","attrs":{"id":"np4dkiq6xlg","class":null,"textAlign":null},"content":[{"text":"In conclusion, I would like to say thanks to everyone who assisted with validation of this writeup. I hope this information will help you with future analysis.","type":"text"}]},{"type":"heading","attrs":{"id":"dfir-review","level":1,"fixedId":"","textAlign":null},"content":[{"text":"DFIR Review","type":"text"}]},{"type":"paragraph","attrs":{"id":"r2022352288","class":null,"textAlign":null},"content":[{"text":"The author provides clear documentation of the testing procedures as well as references to the Apple Developer website. The inclusion of specific graphics from the mobile device, and the property list files certainly appeases the visual learner whom may be quickly researching the methodology. The author has provided sufficient details to allow others to replicate the tests conducted and has described the steps needed to validate the tests conducted.","type":"text"},{"type":"hard_break"}]},{"type":"paragraph","attrs":{"id":"ni5ggqxlmv3","class":null,"textAlign":null},"content":[{"text":"The reviewers found that the pertinent file can be found in an iOS backup (DeviceUDID/3a/3aef6f188cf22d663030b159b271f1f2591cf56a) so forensic tools are not needed to identify this information.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nn38mhta5hh","class":null,"textAlign":null},"content":[{"text":"It was suggested that the author also mention the existence of the same file and the same settings on iPadOS. On iPadOS, the Display Auto-Lock options are 2 minutes, 5 minutes, 10 minutes, 15 minutes and Never. It was also suggested that “Touch ID & Passcode” settings could be “Face ID & Passcode” depending on the device being used. It was also noted that if the user configured their device with Touch ID or Face ID, the Require Passcode setting is automatically set to Immediately. This is the only option available and therefore cannot be changed by the user.","type":"text"}]},{"type":"paragraph","attrs":{"id":"nx3dlmu1apd","class":null,"textAlign":null},"content":[{"text":"One important factor having an influence on this setting is the handling of the device by the examiner or first responders before extraction. This setting is sometimes modified to avoid locking an unlocked phone when the password is unknown. As discussed by the author, common extraction tools require the examiner to change the auto-lock setting to “never”. It is important to emphasize the importance of the chain of custody and documentation of any modifications applied to the phone before reporting about a setting, because it may not correspond to the original value set by the user.","type":"text"}]},{"type":"heading","attrs":{"id":"future-work","level":1,"fixedId":"","textAlign":null},"content":[{"text":"Future Work","type":"text"}]},{"type":"paragraph","attrs":{"id":"n99k1oph311","class":null,"textAlign":null},"content":[{"text":"Future work could include looking at devices that are jailbroken vs. devices that are not jailbroken.","type":"text"}]},{"type":"heading","attrs":{"id":"reviewers","level":1,"fixedId":"","textAlign":null},"content":[{"text":"Reviewers","type":"text"}]},{"type":"paragraph","attrs":{"id":"n08o2pgw4mh","class":null,"textAlign":null},"content":[{"text":"Eric Eppley (Methodology Review)","type":"text"}]},{"type":"paragraph","attrs":{"id":"p49pzvndiv","class":null,"textAlign":null},"content":[{"text":"Anthony Knutson (Methodology Review, Validated Review Using Reviewer Generated Datasets)","type":"text"}]},{"type":"paragraph","attrs":{"id":"nwksvha1ye6","class":null,"textAlign":null},"content":[{"text":"Johann Polewczyk (Methodology Review, Validated Review Using Reviewer Generated Datasets)","type":"text"}]},{"type":"paragraph","attrs":{"id":"nv94s9dx4sm","class":null,"textAlign":null},"content":[{"text":"Aurèle Scoundrianos (Methodology Review, Validated Review Using Reviewer Generated Datasets)","type":"text"}]}]},"initialDocKey":1074,"historyData":{"latestKey":1074,"currentKey":1074,"timestamps":{}},"isAVisitingCommenter":false,"isReviewingPub":false,"nextCollectionPub":null}}"></script><script id="chunk-name" type="text/plain" data-json=""Pub""></script><script src="/dist/vendor.0257e546351f036bbd7d.bundle.js"></script><script src="/dist/main.0543ebefe1cf4d13c7ba.js"></script><script>(function(){function c(){var b=a.contentDocument||a.contentWindow.document;if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'92ac284a6889561c',t:'MTc0MzcyMDk2OS4wMDAwMDA='};var a=document.createElement('script');a.nonce='';a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script></body></html>