1. Key points

What shifted

  1. Password cracking: from "expensive and slow" to "impossible in principle." 2025, Chikin: scrypt is "very hard to speed up and parallelize, because it works with memory" (00:52:34), ~20,000 passwords per second, "to exhaust an eight-character password, we'd need a full 10 thousand years" (00:59:43) — an economic problem whose answer is more machines. 2026, the same speaker: if the password check happens inside the crypto-chip, "here we fundamentally can't do anything at the moment" (00:31:23). The 2026 talk contains no performance figures at all — they have stopped being relevant.
  2. The bottleneck in mobile forensics is no longer hardware but the vendor's release pace. 2025 — the memory controller and scrypt. 2026 — since the May conference, two significant security patches came out for MTK in 2 to 4 months, "and that's not the most serious manufacturer. So, essentially, that pace is far scarier than wireless interfaces" (00:41:53).
  3. The object of examination moved from the file to the journal. Moskvichev in 2025 found the trojan vtb1 itself and its manifest (02:02:36). Moskvichev in 2026 found nothing: the malicious-objects scan came back empty, the files were already gone from the devices, and the whole evidentiary chain was assembled from other people's journals — the WAL of Sber's antivirus, Play Protect's gass.db, the service logs of budget Android handsets, the Telegram database (00:49:43). The cases are the same (an APK delivered through a messenger); what supports them is not.
  4. AI: the axis of the argument moved from "may we embed it" to "will a court accept it." 2025: "building artificial intelligence into Mobile Criminalist is prohibited. The legislation would object" (Vakhrushina, 00:45:14) — even though partners were using AI without a single procedural objection from the audience. 2026: Boroshchuk rejects AI not on quality grounds but because the result is not reproducible (01:56:45); asked whether AI output gets filed in a case, the audience answers "Well, of course not" (01:53:46); ELETEK admits the model's fabrication — "it's not switched off, you can't switch it off, right? But it's heavily restricted" (01:50:57); Azersky shows AI as a source of disinformation inside the reports themselves — "neural slop" (03:53:52).
  5. Windows artifacts: the trace picture got worse. Azersky in 2025 listed what UWP/MSIX leaves behind (BlockMap, StateRepository-Deployment, event 9545, winget logs). Azersky in 2026 opens on WSL with an admission: "there are no forensic artifacts specifically related to this component" (03:44:41) — no ETW providers, no text logs, no databases. On top of that, the WSL 2 network stack is invisible to the host's Sysmon and EDR (03:50:01).
  6. Bederov's OSINT: from deanonymizing a website to following a person, in a military frame. 2025 — WHOIS, Cloudflare, Yandex.Metrica, and the conclusion that "for reconnaissance on domain names and sites it's, of course, a huge minus" (04:06:24). 2026 — ADINT: advertising audiences expose the number and composition of devices in a chosen area, and if you "walk along the line of contact," "that already exposes actual troop positions" and is "used perfectly for guiding precision weapons" (02:42:21). The method is the same; the scale of the consequences claimed for it has grown radically.
  7. Corporate security: from "buy the right tools" to "the tools may not be there." In 2025 Vyugin walked through the line-up — antivirus, DLP, EDR, SIEM, SOAR, SOC, DFIR — with the refrain "count, count, don't be lazy." In 2026 Pavensky: a full arsenal of security tools "in no way guarantees that, if you face a serious cyberattack, you will necessarily keep access to your usual security tools and their telemetry" (04:11:45), and then "the only key instrument for restoring the full picture of the incident is exclusively digital forensics" (04:20:41).
  8. The state forensic expert has left the stage. 2025: three of nineteen speakers came from state bodies (Tushkanova, GUK SK; Shavlovsky, SEC SK; Kotova, EKC UMVD for the Yaroslavl Region), and they were the ones carrying the procedural layer. In the 2026 recording: none. Tushkanova and Shavlovsky are on the 2026 program — in the closed, unstreamed part (§ 2). This is a fact about the broadcast, not about the conference.
  9. The procedural layer moved from the stage into the audience. With nobody left to read out the methodology, the requirements are put to the vendors from the floor: certification of the tool as trusted software under FSTEC (01:02:05), reproducibility of AI output — "this is very important for expert examination and analysis results" (01:50:10), whether antivirus logs can be tampered with (01:07:39), and on what legal basis a non-state organization collects personal data (02:51:22). More in § 4.
  10. The mechanism for public criticism of the vendor was removed from the program. 2025 — the "roast": a year's worth of accumulated complaints about Mobile Criminalist, and "you can say it straight to the CEO" (00:05:26); it was not streamed. 2026 — "today there won't be a roast" (00:03:26), replaced by the 2021 time capsule (also in the closed part). The criticism did not disappear; it moved into ordinary Q&A, where two defects of MK were named publicly (§ 6).

What didn't change

  1. For hardware vendors, import substitution is pragmatic rather than ideological. ELETEK states its advantage the same way in both years: E01 on Astra Linux (00:21:4001:44:45, answering a direct question about what makes the product better than competitors apart from being Russian). Foreign products remain the audience's yardstick: in 2026 the speaker is contradicted with a reference to Belkasoft and Tableau, and he agrees to take a look.
  2. Telegram is the universal channel. 2025: APK delivery, a call from a "law enforcement officer," reselling card data. 2026: APK delivery in all three of Moskvichev's cases, extortion in Pavensky's, plus something new — live location sharing left running on someone else's phone as a surveillance technique (02:26:33).
  3. The estimate of corporate security maturity has not moved, and it comes from one and the same source, the pentester Dmitriev: in Vyugin's retelling in 2025, one company out of 200 pentests (06:28:48); in the 2026 debate, "less than 1%" (03:35:30). In 2026 he was on the program himself — in the unrecorded tail of day 2.
  4. The engineering honesty of the vendor speakers. Chikin, Vakhrushina, Greshnov and Azersky are, in both years, the first to say what their tool cannot do, and they do not hide it behind "work is under way."
  5. The density of questions from the floor. 60 questions across 19 talks in 2025 and 29 across 9 segments in 2026 — 3.2 per appearance in both cases [counted from the summaries' own markup, not a measurement]. What changed is not the number but the subject (§ 4).

2. The basis for comparison: what was recorded and what wasn't

2025. 19 talks out of 20, both days, ≈9 h 33 min. Missing: Igor Zaitsev's closed-door talk (Account-Best, UAVs, general partner), the "roast," the prize draw and the evening networking of day 1 — the stream closed right after Bederov; the breaks are cut.

2026. 9 segments out of the program's 18 items, ≈4 h 47 min, four discontinuities, and the last talk breaks off mid-sentence inside Pavensky's (his ending and Q&A are lost). Not recorded: SEUS (Mingaraeva); the whole closed part of day 1 — Maxim Zaitsev (brokerage apps), Shavlovsky (WhatsApp on Windows), Tushkanova (macOS), Drozd (AI in security), the opening of the time capsule; and the whole tail of day 2 — Sukhanov (Linux during cyberattacks), Dmitriev (external perimeter), Alyushin ("What a fake iPhone hides"), Igityan (GSM equipment), the closing.

The asymmetry. 19 talks against 9 is not "the conference got smaller" but a different streaming policy: in 2026 only the open part of each day went out, and the rest was declared closed, as a more closed and more practical part. Any conclusion of the form "the topic disappeared" is untenable on this basis, and is flagged as such everywhere below.

The difference in format. 2025 — two days split by theme (forensics / information security), 20 solo talks, the "roast" as the finale of day 1, opening and closing by Olga Gutman. 2026 — the tenth, anniversary edition; the recording never states a split of the days by audience; instead of Vyugin's solo talk there is a moderated debate with three guests; instead of the roast, a time capsule; and a new information portal (articles, a video archive replacing Rutube, a training challenge). Gutman does not appear in the 2026 recording.


3. The seven speakers common to both years: what changed for each

Seven slots match exactly: Vakhrushina, Chikin, Moskvichev, Greshnov (ELETEK), Bederov, Vyugin, Azersky. Four more (Tushkanova, Shavlovsky, Drozd, Sukhanov) were announced in both years but not recorded in 2026, so no comparison is possible for them.

3.1 Valeria Vakhrushina (MKO Systems): "Dictionary or mask" → "A special edition for the tenth MFD"

2025 — a methodological talk: two methods plus a third of her own (a dictionary built from the personal data in the extraction), a demo on a zip file (7.5 hours for a head-on mask against 11 seconds for a partial one), and the rule "a head-on mask — I'll say it right away, don't use a mask head-on" (00:33:30). 2026 — release notes without methodology: hashcat 7.0 is in, Samsung Smart Switch, Telegram for macOS and Threema have been added; on scrypt — "our measurements showed that in some places the speed increased tenfold, in others it's not so rosy, of course. FDE won't crack fast" (00:08:47); and "now you can safely load a 20-gig dictionary, a 40- or 100-gig dictionary" (00:10:53).

What shifted. The genre: teaching a method → listing the changes. The bet: a meaningful hypothesis (a dictionary built from the device's own data) → the size of the dictionary and the speed of the engine. That is, from narrowing the search space to running through a larger one.

What didn't shift. Naming the limits outright: FDE has not got faster, the free edition is cut down and has not been updated in a while, Windows Hello is still only being researched.

What got worse. In 2025 there were at least demo measurements. In 2026 there are none: "tenfold" and OpenCL being "usually a bit faster" come with no statement of what was measured or how. And not a single question followed, though the speaker invited them twice.

3.2 Vyacheslav Chikin (ACE Lab): brute-forcing scrypt → crypto-chips

2025 — computational economics: scrypt is memory-hard, top-end CPUs run into the memory controller, and the way forward is more machines, up to ten on one job. 2026 — architecture: where the crypto-chip only stores a block of data (Tab A8, Unisoc, SPI), the brute force can in theory be moved outside; where the chip checks the hash and hands out the keys itself — "this crypto-processor, the crypto-chip, is a gatekeeper" (00:28:18) — nothing can be done: the brute force cannot be offloaded, and inside there may be an attempt counter, a delay and a wipe.

What shifted. The barrier became qualitative rather than quantitative. The forecast reversed: the brute force of the future will run on the phone itself. And a procedural warning came to the fore that was absent in 2025: unlocking the bootloader or flashing unverified firmware changes state that is part of the key — "the encryption keys change at once and all the data effectively disappears" (00:21:30).

What didn't shift. The engineering tone, with hypotheses labeled as hypotheses: "for us, the crypto-chip is a black box. We don't know what's inside."

A caution about cross-year comparison. Chikin in 2025 says scrypt is hard to speed up; Vakhrushina in 2026 reports a tenfold speed-up. Formally this is not a contradiction: she is talking about optimizing an implementation for specific targets and says herself that FDE has not got faster, while he is talking about poor parallelizability in principle. The two statements never met in the recording.

3.3 Alexey Moskvichev (MKO Systems): NFC thefts → SQLite journals

2025 — NFC relaying (NFCGate/NGate, GhostTap, SuperCard X), statistics without sources (×35 against 2024, ~400 cases, ~100,000 roubles on average), one borrowed case worth 230,000 roubles, and an examination that starts from the file that was found. 2026 — three cases of loans taken out in the victims' names; there are no files, and the method is inverted to journal-first. The limitation is stated plainly: "the lawyers might think right now that we can find and view all the deleted stuff, that it'll definitely be there. No. All these journals get overwritten" (00:47:33).

What shifted. (1) The anchor artifact: the manifest and the body of the malware → SQLite journals and other vendors' antivirus verdicts. (2) The theft scheme: NFC relaying, capped by the contactless payment limit, → an APK with SMS permissions and a loan in the victim's name, capped by the bank: technically simpler, economically better. (3) The legal outcome is stated outright: the findings went into the expert report and "they were admitted as evidence in court" (01:08:31). (4) What the audience presses him on: in 2025 payment cryptography and the tool's capabilities, in 2026 regulation; the answers are "on certification, I think that's more a question for a lawyer, it's hard for me to answer, I can't say" and "honestly, I'm not sure" (01:06:42).

A separate detail from 2026: the delivery pretext was a chat called "Missing in Action in the SVO" (00:53:23), and the speaker's conclusion is that fraudsters pick socially charged subjects. In 2025 the pretexts were mundane (renewing a mobile contract, a hacked Gosuslugi account, a health insurance policy).

What didn't shift. Separating his own work from other people's in both years ("we didn't do that examination ourselves" in 2025; "we weren't the ones who did that examination, so effectively we worked with clean data the expert provided to us" in 2026); statistics without sources in both years; and answering a product complaint with an undated promise: "we'll try, but we're not promising" (2025) → "yes, of course, this task will be on the agenda… when exactly, I can't say" (2026).

A consequence of dropping the roast. Complaints about MK were voiced in ordinary Q&A: WAL entries are not flagged as deleted (01:00:11); because both the database and the journal are parsed, WhatsApp and Telegram chats come out doubled and tripled, and investigators ask "why the crook sent the victim messages three times" (01:01:00) — a defect that directly distorts the record of a conversation in an expert report. The channel for criticism changed; the criticism itself did not.

3.4 ELETEK (Greshnov; joined in 2026 by Savinkov): duplicators → "When there are too many terabytes"

2025 — a catalog of the product line with no performance figures; the limits surface only under questioning ("no, we don't work with RAM yet. That's bad… we're, so to speak, on the verge of starting to work on that"; of encryption, only BitLocker detection, the rest "in progress"; on TPM, "it's hard to say off the top of my head"). 2026 — the same hardware in a more mature state (the duplicator is "going into series production" this month, the flash copier "is supplied to the Interior Ministry… for about the second year now") plus a subject new to the company: an analysis pipeline — text classifiers, transcription with fine-tuning, video parsing, and a summary instead of watching: "from the first hour to the eighth you've got trees, wind. A fence, and five cars drive past" (01:33:31).

What shifted. What is being sold: "how to acquire the data" → "what to do with the data once acquired." The argument: made at the request of operational units → "supplied to the Interior Ministry… for about the second year now" — from intent to a fact of deployment. The attitude to AI: in 2025 ELETEK has none at all; in 2026 it has some, and immediately with a reproducibility caveat, with the classical classifiers deliberately kept running in parallel because on a tightly defined rubric they work "both faster and with better quality."

What didn't shift. Limits are admitted only in response to a question from the floor; there are no performance figures in either year.

What got worse. The new USB blocker: blocking is done in software, "inside the device" (01:44:05) — whereas in 2025 a hardware blocker was presented as the distinguishing feature of the SATA copier. Passing through the drive's own parameters (serial number, SMART) is not supported in SATA and is "partially implemented" in USB. And a new unverified claim: "the E01 format itself simply doesn't support interruptions" — contradicted from the floor with specific products, after which the speaker backed off: "we'll look into it, alright" (01:45:24). Nothing he said in 2025 was publicly refuted.

Gaps not closed in a year. The RAM dump (2025: "we're, so to speak, on the verge of starting to work on that," with a "that's bad" from the floor) is not mentioned at all in 2026. Encryption: in 2025 only BitLocker detection, the rest "in progress"; in 2026, on finding encrypted containers disguised as ordinary files, "honestly, we haven't worked in that direction yet" (01:41:07).

3.5 Igor Bederov: owners of web resources → advertising intelligence

2025 — a checklist for deanonymizing a site (WHOIS and its archives, Cloudflare, EXIF, Yandex.Metrica, payment acquiring), packaged in a portable Opera build with "more than 2,000 sources." And a forecast made at the same time: once phones lose the wired port, forensics will have nothing left to plug into — "when there's simply nothing left to plug forensic software and hardware into" (03:54:45). 2026 — exactly that: working without access to the device. Until April 2018, base-station coordinates came from SMS centers — "they sold all that to their clients. For 10 or 15 thousand rubles, some for 20… We did it for 29 kopecks" (02:25:15). Then HTML5 GeoAPI, logging into a "find my lost phone" service with a leaked password, radio emissions and MAC addresses, trackers — and ADINT at the center.

What shifted. (1) The object: a web resource → a person and the set of devices around them. (2) The stakes claimed: a home address from EXIF → guiding weapons along the line of contact. (3) The complaint against the platforms: privacy → national security, with an asymmetry — domestic advertising services hand the data over "completely free of charge, after the simplest registration, or not registering in those services at all," while a foreign platform's barrier is incomparably higher (02:43:32). (4) A political frame appeared: "there's the Renaissance, and we have the Age of Return" (02:48:46). (5) The line of defense: in 2025 he defended OSINT as a verification methodology fit to be used as evidence (arguing with Barkalov); in 2026 the first thing he says is "I'm not law enforcement, and I'm in no way encroaching on that delicate, mostly unnecessary domain" (02:22:59). The emphasis moved from the quality of the method to the legitimacy of the person using it.

What didn't shift. The core claim: advertising infrastructure is the main source of leakage about a person, and privacy settings cannot fix it ("and you trust those settings? No, of course I don't"). The tone and the appetite for provocation are the same.

A discrepancy. The number of sources in his own browser: 2,000+ ('25) and 1,000+ ('26). No reason is given; it cannot be asserted that the figure has fallen.

Heard only in 2026 — a direct question from the floor about the legality of his own practice: for legitimate collectors of personal data "there are draconian laws," "and you're collecting it illegally on top" (02:51:22). The answer rests on status (academic work, R&D at departmental academies, teaching, work on reasoned requests) rather than on which specific actions are permissible.

3.6 Nikita Vyugin (MKO Systems): "The value of security tools" → a debate on corporate forensics

2025 — a solo tour of the security line-up with subjective estimates that are honestly labeled as such ("up to 30% of data leaks are cut by using DLP in a company… some say 90–100 in the marketing brochures," 05:59:38; "it's not SOAR, not some kind of artificial intelligence. It's simply this: SIEM screams, and the IT guy cries"), plus a separate stand against selling through fear: "from a business-ethics standpoint, scaring people is not good" (06:32:30). 2026 — he is the moderator, not a speaker: few claims of his own, and those are empirical (of his ten corporate clients only three have COPE — against 7 or 8 out of 10 reported by one of the guests, 02:58:49).

What shifted. The role: expert reviewer → organizer of someone else's argument. The subject: the purchasing logic of security → the operational practice of investigations.

What didn't shift. Relying on arithmetic instead of generalities.

Cannot be established. Vyugin's 2026 position on "selling through fear" — the debate never covered it; and the 2026 DLP estimates cannot be attributed to him, they are the guests' remarks.

And, honestly, about the format: it barely became a debate. On three of the four topics the participants agree with each other; arguments for BYOD appear only as "you don't have to buy" and are immediately knocked down — "there is not a single advantage to BYOD that I know of… just not one" (03:00:13).

3.7 Vladislav Azersky (F6): UWP/MSIX → WSL

2025 — UWP's isolation vanished with Desktop Bridge, but the artifacts are plentiful: AppxManifest and BlockMap, StateRepository-Deployment, the Organization ID as a ready-made indicator, event 9545, winget traces. 2026 — the same angle, the opposite result: no artifacts, no ETW providers, only the registry, winget logs and the ext4.vhdx file; the WSL 2 network is invisible to Sysmon and EDR; and in any distribution "there's no situation here where a password is prompted" for root. The cases: an ELF ransomware run by Qilin affiliates encrypts NTFS through /mnt (03:54:44); npm typosquatting with a stealer.

What shifted. (1) The quality of the trace picture: "isolation is gone, but there are plenty of artifacts" → "isolation holds, and there are no artifacts" — a deterioration on both axes at once. (2) The conclusion: not a set of indicators but "so we come back to the standard" — Windows forensics on the host plus Linux forensics inside the image (04:03:07). (3) A new methodological motif: two or three publications claimed that Turla, FIN7 and Ryuk had used WSL, and nothing anywhere confirms it — "it turned out to be just some kind of neural slop, where the person didn't actually check what was written."

What didn't shift. The method (architecture → what it gives an attacker → residual artifacts → monitoring) and the willingness to say "I don't know": in 2025 he admitted he had not found a description of the CVE; in 2026, asked whether EDRs look inside a Linux VM, "honestly, I don't have that kind of analytics or statistics." The technical thread running through both years is winget: in 2025 a way to install interpreters and tunnels without administrator rights, in 2026 a way to deliver a distribution — and a source of logs for the defense.


4. What changed in the audience

This is the one layer visible only at the level of the per-talk summaries: every talk has a "questions from the audience" section.

The number did not change — 3.2 questions per appearance in both years. The subject did.

2025: "can your tool do X, and when will Y ship." Greshnov is asked about RAID, RAM dumps, encrypted drives, Secure Boot and TPM, several flash drives at once; Vakhrushina about FBE/FDE in the free edition and the timeline for distributed cracking; Moskvichev about traces left in Clone and Relay modes, NFC amplifiers on public transport, cloning Mir Pay; Eremin about the gyroscope, GPS and object speed; Inkin about other deepfake techniques, prompt injection and transcription speed. The speakers' refusals are about capability too: "no, we don't work with RAM yet," "as for the TPM module specifically, it's hard to say off the top of my head," "in theory it's possible, but in practice we haven't tried it."

There was a procedural line in 2025 as well — but it came from the stage: the whole of Tushkanova's standard methodology, Kotova's "that's the only correct wording of the question" (03:07:00), Art. 57 and the appointing party's permission in Shavlovsky's talk, Bezik's argument with a former EKC staffer about the boundaries of an examination. Those requirements were addressed to the expert.

2026: "will your result survive scrutiny." Six questions out of twenty-nine are exactly that, and all of them are addressed not to an expert but to the tool and the speaker:

Answers in this category, in 2026, are almost always "I don't know": "I think that's more a question for a lawyer, it's hard for me to answer, I can't say," "honestly, I'm not sure," "honestly, we haven't worked in that direction yet," "I don't have that kind of analytics or statistics." The parallel is neat: in 2025 the vendor did not know what his hardware could do; in 2026 he does not know whether his result will be accepted.

A second new line in 2026 — "what will actually happen to the data." Four of the seven questions to Chikin: why data dies because of the phone's state, whether it can be put back, whether it is physically erased or the keys merely change, and what happens once wired interfaces are gone. There are no such questions in 2025: there, people asked how to go faster, not how to avoid destroying things.

Where the floor outdid the talk. 2025: Drozd objects to Pavlov about interface customization, a former EKC staffer objects to Bezik about the boundaries of an examination, Bederov objects to Barkalov about verification. 2026: the floor refutes ELETEK's claim about E01 interruptions, and a former forensic audio examiner tells Boroshchuk outright that "what you've presented is roughly the level of maybe 2006 or 2007" (02:16:43) — and then adds what the talk did not have (removing harmonic components without damaging speech, reconstructing a shootout from some 45 recordings). The speaker agrees — "yes, 2006 to 2008, absolutely" — but reframes his own task: the talk is for people who have nothing at hand.

Who is in the room. In 2025 the moderator often names the people asking, and some are recognizable from the program (Bederov questions Barkalov, Drozd questions Pavlov). In 2026 names are almost never heard. Partly that is recording quality, partly a different format; no reliable conclusion can be drawn from it.


5. Technologies and methods

5.1 Password cracking and encryption

2025 2026
How the problem is framed how many passwords per second, and how many years that is can the brute force be moved off the device at all
The barrier memory-hard scrypt, the memory controller, DDR5 a crypto-chip that checks the hash internally; attempt counter, throttling, wipe
Metrics ~20,000 p/s; RTX 4060 Ti ~1,500 p/s; 8 characters ≈ 10,000 years no metrics at all
The way forward more machines ("up to 10"); distributed cracking in MK by H1 2026 brute force "on the phone itself"; in MK, a faster engine and dictionaries up to 100 GB
The role of the dictionary central: dictionary before mask, dictionary from personal data central in a different way: a library of large dictionaries
The main threat the physics of memory the vendor's patch cadence

A separate thread between the years: in 2025 Shavlovsky publicly recorded a gap — MK Brute Force does not support hashcat mode 7100 (the macOS account hash), and Mobile Criminalist does not convert that hash (03:45:24). In the recorded part of 2026 no closure is claimed: the Telegram for macOS passcode was added, which is a different object. Whether the gap was closed cannot be established from the recording.

5.2 Mobile forensics: from the file to the journal

The level of extraction. 2025 — the MTK Android method. 2026 — Unisoc/Spreadtrum and Samsung, full file system via "vulnerability 31317" (the number was not recovered from the recording). Access is increasingly obtained through a vulnerability in a particular platform rather than a universal method; in parallel Chikin shows that on recent handsets the password cannot be recovered either. The two trends converge: the expert's window of opportunity is narrowing from both sides.

What gets examined inside. The move of "someone else's antivirus becomes the source of evidence" was already there in 2025: Kotova's 30.db from Sberbank's built-in antivirus proved malware had been there without the malware itself — "we can prove a malicious app's presence without it being present" (03:24:25). In 2026 this became Moskvichev's main technique. That is not a shift but the development of a 2025 move — and, correspondingly, a new weakness: the floor asked precisely the right question, namely whether those logs were tampered with.

5.3 Windows artifacts

2025 gave Windows three talks: Azersky (UWP/MSIX), Sukhanov (NTFS, shadow copies, FAT, Prefetch — with the claim that a vendor's documentation cannot be trusted and the source of truth is the code: "but let's try to take the hardest route, straight from the code," 06:50:58), Shulmin (batch files and legitimate utilities in an APT chain). 2026 — only Azersky (WSL) and Pavensky's list of logs. The shift visible through the common speaker is from a subsystem rich in artifacts to a subsystem with none. What cannot be claimed: that reverse engineering and distrust of documentation have left the agenda — Sukhanov is on the 2026 program but was not recorded.

5.4 Volume: from "process it faster" to "what to take into work at all"

2025 attacked the problem three ways: speed up processing of the object (carving a terabyte took ~3 weeks for Eremin, and his AI module handled a 30-minute video in 3 minutes on a GPU against 25 on a CPU), speed up the human (Pavlov: indexing and highlighting logs means "we would basically cut the work down by tens, if not hundreds of times," 07:40:44), and summarize (Inkin: LLM digests over a body of audio).

2026 moves the emphasis to selection. ELETEK: "200 gigabytes of photos and files is just impossible to look through" (01:35:08), so don't watch the video, read its description — out of 24 hours of street camera footage "we get three two-minute fragments." Pavensky argues outright against collecting everything: with 2,000, 10,000 or 100,000 hosts, "I'm afraid we'll be collecting information until our company shuts down because of this incident" (04:25:13), and then gives a decision procedure for each node. This is no longer about throughput but about triage as a methodological position.

5.5 AI

2025. Three positions coexisted without an argument: a vendor ban on embedding it (Vakhrushina, justified architecturally — no data comes back to the vendor; she could not name the legal provision); industrial use by partners (Eremin: PyTorch, object and license-plate detection; Inkin: LLM digests, "99.6%" on ElevenLabs, 97% on a video deepfake — all figures from demos run on the company's own datasets); and the expectation that LLMs would patch DLP's weaknesses (Drozd). Only Inkin raised the procedural side, and gently: "the conclusions of any automatic system need expert confirmation" (08:53:17).

2026. The argument has moved inside forensics and sharpened into admissibility: refusal on procedural rather than technical grounds (Boroshchuk: "when we have a 64 by 64 pixel image, at best the artificial intelligence starts fantasizing… unfortunately they have no connection to reality whatsoever," 02:04:28); conditional use with parameters locked down for reproducibility (ELETEK); and AI as a source of contamination in the reports themselves (Azersky).

How to state the shift. 2025: "should AI be embedded in a forensic product." 2026: "will a result obtained with AI survive challenge in court." The asymmetry matters: in 2025 nobody using AI met a public procedural objection; in 2026 one was voiced, and the room agreed with it.

5.6 OSINT

2025: OSINT existed in two guises — instrumental (Bederov) and ideological (Barkalov: where there is intelligence there is counterintelligence, that is, disinformation; "launch some disinfo, see who leaks what," 04:39:36). Their argument about verification was never settled and ended on "but we're not in the West, thank God" (04:46:04).

2026: the ideological line is gone from the recording (Barkalov is not there), while the instrumental one has grown into a class of its own (ADINT, radio emissions, MAC addresses, trackers). At the same time OSINT stopped being a topic in itself and became a link in other people's storylines: in Pavensky's case, OSINT enrichment from one leaked password is the second step of the attack; at ELETEK, open sources are indexed alongside seized data; in Moskvichev's cases, social engineering is built on whatever is topical.


6. Vendor promises: 2025 → 2026

MKO Systems

2025 In the 2026 recording
hashcat 7.0, "we'll soon build it into MK Brute Force" Done — shipped; already announced at the spring conference
Distributed cracking, H1 2026, "I'm not promising anything" Never mentioned
"…building artificial intelligence into Mobile Criminalist is prohibited" Not repeated; no AI in MKO products is claimed in the recording
No FBE/FDE in the free edition — "that's my pain point" Of the free edition: "I haven't updated it in a while"; it supports fewer hashes
"A dictionary based on personal data" as a third method Not mentioned; in its place, a dictionary library of 20–100 GB
No mode 7100 / macOS account hash (Shavlovsky's remark) Neither closure nor persistence of the gap is stated
A reference guide of which file stores what — "we'll try, but we're not promising" Not mentioned
New: Samsung Smart Switch, Telegram for macOS, Threema, faster scrypt, a pause on overheating; plans for KeePass, Kims, Windows Hello
New: the anniversary portal — articles, a video archive replacing Rutube, a training challenge. The flip side: "you won't find our videos on Rutube anymore" (00:14:57), access only for clients after authorization
New defects aired publicly: WAL entries are not flagged as deleted; chats come out doubled in reports

ELETEK

2025 In the 2026 recording
The duplicator workstation shown as part of the product line "Last year we already presented it for the first time," "this month, it's going into series production"
The flash copier — "at the request of field operatives" "…supplied to the Interior Ministry, that's the main customer, for about the second year now"
SATA copier with a hardware blocker SATA is in production; USB 3.0 "hasn't gone on sale yet," and blocking is in software
Live-acquisition software: Windows, Linux, Astra Linux "planned" "Element-P," Windows and Linux — in final testing
RAW/E01 image viewer with partition recovery The image-handling program — in final testing
File selection by signature instead of by mask Selection by MIME type (catches a substituted extension)
RAM dump — "on the verge of starting to work on that" Not mentioned
Encryption — BitLocker detection only, the rest "in progress" Finding disguised crypto containers — "we haven't worked in that direction yet"
New: an analytics platform (classifiers, transcription with fine-tuning, video parsing, a single portal)

Two programs shown in the 2025 catalog with no caveat about readiness are, a year later, still "in final testing," and the new blocker is not on sale — meaning a noticeable share of what was shown in 2026 cannot be checked by anyone.

"Not mentioned" ≠ "not done." Only part of the conference was recorded, and the MK Bruteforce talk was a special edition covering changes since the spring, not a full product review. For LAN PROJECT, STC and Zero eDiscovery no comparison is possible at all — they did not take part in 2026.


7.1 Where the nature of the threat really did change

Mobile fraud: from bypassing the payment protocol to bypassing the loan approval process. 2025 — NFC relaying, which requires the victim to tap the card and enter the PIN; the ceiling is set by the terminal (a 3,000-rouble contactless limit, in places 1,000). 2026 — an APK with permissions to receive and send SMS, making itself the default SMS app, and a loan taken out in the victim's name; the ceiling is set by the bank. What is common: the channel (Telegram), a pretext taken from the news agenda, and deletion of the app once the job is done. NFC schemes simply were not discussed in the 2026 recording — which does not mean they have stopped.

Attacks on infrastructure: from "ransomware and a ransom" to "a wipe and loss of control." In 2025 Titkov described the economics of extortion (double extortion, repeated fake leaks, a dwell time of "3, 6, or even 9 months") and insisted on the order of operations: "you do need to kick the attacker off the infrastructure first and only then fix and restore it" (07:01:15). In Pavensky's 2026 case the ransom is an afterthought: backups destroyed, core switch configs changed, connectivity and access to the security tools themselves gone, and "a rapid reconstruction of the attack with standard tools was no longer possible." The debate points the same way: restoring a fully encrypted infrastructure is usually pointless, "especially now, when it's not encryption but wiping, for geopolitical reasons" (03:39:26).

The entry point: from a phishing email to a trusted contractor. 2025 — spear phishing delivers "something like 90-95% of threats" (Shulmin, 05:16:47), and "people still run .pdf.exe attachments." 2026 — entry through the personal mailbox of an employee at the company that develops an IDM system, a password reused from a public leak, a legitimate email thread with the customer continued, and remote access to a jump host; for the first week the attackers "behaved as if they really were a contractor" (04:14:53).

The personal device as leverage. A motif new to 2026 and sounded twice: an unencrypted backup of a personal phone on an IT employee's workstation became both a source of credentials and the means of blackmailing that employee personally (04:16:23); and in the debate a key subject "forgot the password" to the personal laptop he had brought to work — "there's no trick against BitLocker" — and, as the owner of a personal device, he could have refused outright.

Living off the land continues; the carrier changes. 2025 — batch files and legitimate utilities with no binary implants (RAR 3.8 disguised as driver.exe, blat.exe, AnyDesk renamed svchost, Defender Control, scheduled tasks at night) plus the Store and winget as a source of tooling without administrator rights. 2026 — WSL as the "legitimate subsystem": ELF ransomware through /mnt, npm lookalikes with a stealer, persistence through /etc/wsl.conf. The logic is the same: what must be detected is not the tool but its illegitimate use.

Heard in 2025. A heavy procedural layer: the Investigative Committee's 2025 standard methodology for examining mobile devices and its lineage (FSKN 2011, restricted → EKC MVD 2014 → the 2023 revision), functional rather than vendor-specific requirements for the hardware-software complex, template petitions for a password and PIN/PUK, the procedure for cloud tokens found during an examination (tell the investigator, do not log in yourself, otherwise "this is probably already exceeding our authority," 01:22:49); Federal Law 73-FZ; Art. 57 (examination that alters the object only with the appointing party's permission); the only admissible wording of the question put to an expert; the GAS "Pravosudie" system, Federal Law 44-FZ, acceptance testing, contracts from 150 million to billions of roubles, and "the court pays us, not a party" (08:49:33); the register of Russian software; Federal Law 152-FZ and the Information Security Doctrine; the 24-hour notification to Roskomnadzor and the 72-hour report, anti-money-laundering rules and a ransom as possible terrorist financing, GosSOPKA/NKTsKI/FinCERT.

Heard in 2026. The layer moved into financial anti-fraud and corporate law, and almost all of it came from the floor: "Anti-Fraud 2" and the forthcoming "Anti-Fraud 3," "Federal Law No. 210" (the number as heard in the recording, needs checking), a doctrine for countering ICT crime, and the demand from the Bank of Russia and FSTEC that an expert result not be produced automatically. Then: the law on trade secrets and the documents an employee signs on hiring as the basis for monitoring; Federal Law 73-FZ now as a requirement for a non-state investigation — completeness, integrity and reproducibility, otherwise the evidence "won't be accepted as evidence" (03:39:58); retention of forensic images — "law enforcement has it written down, we also try to keep it all six months"; the personal data law and the status of "not law enforcement"; and the admissibility of a processed media recording, with the distinction between an "expert" and a "specialist."

No longer discussed in the recording. Expert methodologies and the procedural boundaries of the expert; cloud tokens; Art. 57; public procurement and Federal Law 44-FZ; critical infrastructure, GosSOPKA, NKTsKI, FinCERT; Roskomnadzor notification deadlines. The caveat without which this list misleads: the people who carried the first group of topics — Tushkanova and Shavlovsky — were on the 2026 program, in the closed part. The correct statement is that these topics did not make it into the open stream, not that they "left the conference."

Reframed.


8. Tone, conflicts, genre

The "negative result" genre became prominent. In 2026 two talks out of nine are built on what cannot be done: Chikin's "here we fundamentally can't do anything at the moment" and Azersky's "there are no forensic artifacts… related to this component." A third — Boroshchuk — rejects the most powerful available tool in advance on procedural grounds. A fourth — Pavensky — opens by saying that the whole security stack does not guarantee access to the security stack. In 2025 there was one such talk (Chikin and his 10,000 years); the rest showed how to do things.

Whose cases get shown. 2025: Kotova works through the SpyNote builder by hand ("all of this without any user confirmation. I tested it myself"), Shavlovsky walks his own route to the macOS hash, Sukhanov digs into ntoskrnl.exe, Bezik counts 1,041 requirements in an examination he is running, Titkov describes cases from July 2025. 2026: Moskvichev's cases were handed to him by another expert ("we worked with clean data the expert provided to us"), all three of Azersky's cases are public and other people's, and Pavensky's case is fully anonymized and introduced with "let's say." Original work is shown by Chikin (two benches, soldering, a logic analyzer) and ELETEK (hardware). This is not a clean shift — in 2025 Moskvichev also said "we didn't do that examination ourselves" — but in the recorded part of 2026 the share of second-hand material is higher.

Import substitution: pragmatism in hardware, geopolitics in OSINT. ELETEK is pragmatic in both years, and in 2026 the audience still names foreign products as the benchmark. Bederov's tone in 2026 is harder: the "Age of Return," a call to build domestic products "out of reach of surveillance from outside." The other side of that was heard only in 2026 and only in the debate: after sanctions several hundred Macs were left unmanaged, and the DLP products available in Russia work on Macs so badly that "you have to reboot them four times, disconnect everything, then reconnect it."

Law enforcement as the customer. In 2025 this is the organizing frame of the first half of the conference. In 2026 no such frame exists in the recording — only isolated facts (the flash copier "supplied to the Interior Ministry… for about the second year now") and training. The most candid admission comes from Boroshchuk: the licensed software people need is usually not there, so "mostly the detectives wrap up the whole investigation like that… well, can't see anything" (01:55:37), and everything he shows is chosen so that "you can download them freely, without cracking anything." Indirectly this records that the practical alternative is pirated software; nothing like it was said aloud in 2025.

The atmosphere. 2025 — hard arguments: Barkalov against Bederov on OSINT, Bezik against a former EKC staffer on the boundaries of an examination, Drozd against Pavlov on interfaces. 2026 — an anniversary, and the advertised debate barely became one. There are two real clashes, and both are the floor against the stage: over E01 interruptions and over the level of the media-processing methods. Whether that follows from the anniversary format or from the fact that the sharp part of 2026 was not streamed cannot be established from the recording.

The day openings as an indicator. 2025: partners named from the stage, a promise of "some real meat" and the announcement of the roast. 2026: not a single figure, the partners named by someone other than the host, no walk-through of the day's program, and not a word about the time capsule on the second day. The one substantive moment is the admission about bugs: "only those who do nothing never have any" and "as our tech support always writes: send us the logs" (00:04:14).


9. What this comparison does not show

  1. Incomparable volumes: 19 recorded talks against 9. Only comparisons across the seven common speakers and across topics present in both years are sound.
  2. The unrecorded parts of both years. The content of the 2025 roast and of the entire closed part of 2026 is unknown. Judging by the programs, that is precisely where the most procedurally loaded part of 2026 sits — so the "no longer discussed" list in § 7.2 describes the broadcast, not the conference.
  3. The 2026 recording breaks off inside Pavensky's talk: his section on persistent data, the promised reconstruction of the attack and the Q&A are lost.
  4. The 2026 debate has no speaker labels; the guests' surnames are by ear, their companies unnamed, and some remarks are attributed by sense. Their positions are therefore not personified here, and the discrepancy "COPE in 7–8 out of 10 versus 3 out of 10" remains unresolved.
  5. Figures in both years come from the speakers, without sources (2025: ×35 for NFC, ~400 cases, 90–95% spear phishing, "up to 30%" for DLP, a dwell time of 3–9 months, 99.6/97/98% in STC's demos; 2026: a tenfold scrypt speed-up, two MTK patches, ~40–50 npm packages, "less than 1%"). They cannot be compared as measurements.
  6. Recognition errors exist in both years (2025: TSFS/TESAM, event 9545, mode 7100, wikpass.com; 2026: "Kims," "vulnerability 31317," "Justiphone," "Federal Law 210," the guests' surnames). No comparison above rests on such a word as a hard fact.
  7. Timecodes are not comparable between the years and do not equal the schedule: the 2026 recording is edited from two streams with the pauses cut out.
  8. What cannot be claimed: that a vendor abandoned a position merely because it was not repeated (the AI ban, distributed cracking); that a promise was broken — only that it is "not confirmed in the recording"; that NFC fraud has subsided, that deepfakes have stopped being a problem, or that the subject of expert methodologies is closed; that the conference got less sharp — the sharp part of 2026 was not streamed.
  9. Speakers almost never named the reasons for the changes. The exception is Chikin, who explains directly why brute force can no longer be moved off the device and why this will get worse. The other explanations here are mine, and are marked as assumptions.

Sources: the per-talk summaries of both years. Where they disagree with the overall conference summaries, the per-talk summaries are correct: they were compiled later and from the proofread transcripts. Quotes come from the published English subtitle tracks of the two videos. The Russian original of this document is the Russian version of this page.