In brief

The WAL journal as a source of "deleted" data: the main database shows only the final state, while the journal — all the intermediate ones, including deleted records and drafts. Then three cases from a single region where loans were taken out in the victims' names: the APKs themselves were no longer on the phones, but from the log of Sber's antivirus, the system logs of budget Android devices, the Google Play Protect database and the Telegram database the examiner assembled a timeline — from the file being received in a chat to the app being deleted. An important caveat from the speaker: the journals get overwritten, there is no point looking there for "all the deleted stuff", and the point is to capture the journal before the checkpoint. The cases are not his own — they were handed over by a working examiner, which is why some of the questions from the audience had no answer, including two regulatory ones.

Key points

Tools, artifacts, technologies

The most substantial legal part of the day — in the questions. Mentioned were Federal Law No. 210 ("Anti-Fraud 2", already in force), the "Anti-Fraud 3" now in preparation and the doctrine for developing a system to counter ICT crime, as well as the demands of the regulators — the Bank of Russia and FSTEC — that the expert result not be "automatic", that is, that the conclusions be drawn by a human. Hence two requirements for tools: certification as trusted software for departmental systems and a technical (not textual) record that the objects passed an antivirus scan — because in court defense lawyers ask the expert how he made sure that he did not corrupt anything himself. The procedural outcome of the cases: the information formed the basis of the expert report and was admitted as evidence in court. The seizure and the forensic examination went through the regional EKC.

Questions from the audience

The speaker's position

The speaker consistently separates what is his from what is not: the cases were handed over by the examiner, the third-party tool — his choice, "we worked with clean data". This is honest, but the price is this: half of the questions from the audience have nothing to answer them with. The limits of the technology are stated outright (the journals get overwritten, permissions do not equal actions, data can be tampered with), and the product is sold softly — through method, not through promises. To the regulatory questions the answer is a frank "I don't know", with no attempt to talk his way out of it.

Quotes