Session Type
Lab
Name
Making MAGaK: Using GrayKey and AXIOM Together to Maximize iOS Investigations
Speakers
Trey Amick | Magnet Forensics
Description

In this lab, students will learn how to maximize the workflow between the GrayKey and Magnet AXIOM software. Hands-on demonstrations will allow students to explore the latest versions of iOS, understand what information is available at what level of data protection, and explore file-system specific artifacts. Students will learn how to use the extracted keychain information to bolster their investigations by tracking information that can allow access to cloud services as well as encrypted application data on the local iOS device. Coverage of file-system specific artifacts like KnowledgeC, PowerLog, and Location data will be explored so students can learn how these artifacts can lend incredible supporting evidence to a case by using real-world examples.

This lab is restricted to law enforcement and government attendees only. As this will be strictly enforced, please be advised that valid government organization ID must be presented at registration check-in AND upon entrance to these restricted sessions.

If you would like to apply for a CPE credit for attending this lab session, Magnet Forensics will issue a certificate of attendance after the completion of the conference. In order to qualify for this certificate, you must validate your attendance by checking in and checking out of the session on-site.