In brief
Two talks in one. Greshnov shows the hardware and software for acquisition: a duplicator going into series production this month, a compact copier for flash drives that has been supplied to the Interior Ministry for a second year, SATA write blockers and a new USB 3.0 one, plus two programs at the final testing stage — "live" acquisition of files by extension, path and MIME type, and work with images, including recovering deleted partitions. Savinkov — on the pipeline for analyzing heterogeneous data: text classifiers, audio transcription with fine-tuning and a dictionary of their own, video parsing with search for faces and emblems, a description of what happens in a recording instead of watching it, a single portal for searching across all data types. The liveliest part — the questions: the audience presses on the reproducibility of AI results, interruptions while creating an E01 image and the search for disguised crypto containers, and on two of those three points the answer is "we haven't worked in that direction yet" or "we'll look into it".
Key points
- ELETEK — integration projects and in-house development: specialized hardware-software complexes and secure-execution systems, tools for collecting and analyzing data, tools for forensic and operational acquisition, server systems built to the customer's order. The talk covers two of the topics on that list.
- Duplicator: it was in development for a long time, it was shown last year, "this month, it's going into series production" and is starting to ship. The purpose — to acquire data from the drives under examination quickly and safely, both in the lab and in the field: powered from 220 V mains or from a power bank.
- Sources — HDDs, SSDs, flash drives; NVMe only through an adapter to USB. Inside there is a full-fledged microcomputer: they take the "brains" of a ready-made module, and lay out the boards with the ports they need and built-in hardware write blockers themselves.
- Copying is either pass-through (to a trusted drive) or to internal storage — a fast NVMe disk; right now they fit 2 TB, 4 TB at the customer's request.
- Compact copier: it has been supplied to Interior Ministry agencies for a second year. Flash drives only — that is what operational units asked for originally: a self-contained device that "would fit in your fist". A 2000 mAh battery, about 2 hours of copying over USB 3.0, longer with 2.0.
- Storage — microSD: the card is removed and connected to a computer through an adapter. Modes: sector-by-sector, file-based and by masks; the main one — file-based, "copying files is faster for us in some kind of operational conditions".
- The mobile app — "not so much control as pre-configuration": choosing the mode, monitoring the copying status and the remaining storage, working with dumps and file containers.
- Write blockers: the SATA one has been in production for a long time (2.5-inch and 3.5-inch HDDs with additional power, SSDs, everything on SATA); the USB 3.0 one — new, it "hasn't gone on sale yet", finishing its final tests: flash drives directly, NVMe through an adapter, but without maximum NVMe speeds.
- Element-P — acquiring data "live" from computers running Windows and Linux: the program is launched from a flash drive, and a copying task is created. The most interesting part is the selection: by extension, by path and by MIME type — the last one catches a file whose extension has been stripped or swapped.
- A program for working with images: load a sector-by-sector image, browse and sort files, recover deleted information — deleted files and partitions, with the file system of each deleted partition identified, search by signatures and MIME types. Both programs are in final testing, demos "in the near future".
- The second part (Savinkov): a modular analysis system — collectors of data from the internet and from internal closed systems, processors, a single closed perimeter and multi-user analyst portals with access controls. The data is split into text, audio and visual data.
- Text: 20 years of work; classical classifiers for precise classification (topics such as physics or extremism, factual data — names, company names, addresses, the tone and the type of text) are applied as a set — a sequence gives the result you need. AI adds searching after the fact across the indexed archive.
- Audio: transcription — a task that "on the one hand is already solved these days, but on the other always needs an individual approach": noise, foreign languages, many speakers, switching between languages. Fine-tuning and a subject dictionary of your own help: with specialized vocabulary, off-the-shelf tools "pull the transcription towards a more common word".
- Speakers are only separated (speaker 1, speaker 2) — as for identification, "we haven't gone into that area yet", partners do it. Next come translating the transcript, a summary of a long recording or a set of recordings, and questions about the content.
- Video and images: splitting into frames and a stack of tasks of their own — classifying the frame (vehicles, people, landscapes, military, documents), working with faces (searching for specified ones or clustering all of them), searching for emblems, flags, signs, objects; the output is an indexed array with markers showing where what was found.
- A separate block — document recognition, printed and handwritten; for handwritten ones "the quality is a bit lower".
- The specifics of the audio solution: recordings of any length and streams, stable memory consumption ("we don't try to pull the whole recording into memory at once… like some solutions do"), multimodality — the pieces of a mixed dialogue are routed to the recognizer for their own language, adaptability through a dictionary: on radio intercepts of surveyors the quality "improves several times over just because of that".
- The scale — from a laptop (one language at any given moment, a multilingual recording takes longer to process) to a workstation with parallel multilingual processing and server configurations.
- The key idea for practice: do not watch the video, read its description. A summary of a nine-hour recording — "from the first hour to the eighth you've got trees, wind, a fence, and five cars drive past", and the events start from the eighth hour; out of 24 hours of a street camera "three two-minute fragments" remain. It works on predefined topics — hacker ones, suicides, fights.
- The motivation is volume: "200 gigabytes of photos and files is just impossible to look through" — even the data from a single phone is not gone through by eye.
- The text archive — "tens of terabytes" of indexed texts with search in seconds and filters by time, file type and source. Classical algorithms deliberately work in parallel with AI: on a rigidly defined category they work "both faster and with better quality"; the classifiers are built for the customer, with linguists involved.
- The portal brings all the data types together: end-to-end search regardless of the source, each analyst has their own set of classifiers, collections and reports (current, quarterly, annual), presentation as cards, text, maps and graphs, fine-tuning for a specific department.
Tools, artifacts, technologies
- Duplicator (series production from September 2026): HDD/SSD/flash, NVMe through an adapter, internal NVMe of 2–4 TB, powered from 220 V or a power bank, built-in hardware write blockers.
- Compact copier (a second year at the Interior Ministry): flash drives, a 2000 mAh battery (~2 h over USB 3.0), microSD as storage, sector-by-sector / file-based / by-mask modes.
- Write blockers: SATA (in series production) and USB 3.0 (in final testing; the blocking is done in software, a microcomputer inside).
- Element-P — "live" acquisition from Windows and Linux by extension, path, MIME type.
- A program for working with images — sector-by-sector images, recovery of deleted files and partitions, file system identification, search by signatures and MIME; the E01 format, the Astra Linux OS.
- Data analysis: text classifiers (topical, factual, tone, type), transcription with fine-tuning and a subject dictionary, speaker separation, translation, summarization, frame classification, face search and clustering, search for emblems and objects, recognition of printed and handwritten documents, description of what is happening in a video.
- Infrastructure: local deployment, a two-tier perimeter (open and closed), from a laptop to a server cluster, "two GPUs" for the model, an indexed archive of tens of terabytes, a multi-user portal.
Legal and organizational context
There are no direct references to laws, but the context is departmental: the compact copier is supplied to Interior Ministry agencies, the systems are made in a secure execution and deployed locally — "naturally, not in the cloud". The key requirement formulated by the audience — the reproducibility of the AI's result as a condition for it being usable in a forensic examination. Import substitution comes up separately: the program's main advantage over its competitors — Russian software and working with E01 on Astra Linux.
Questions from the audience
- 1 (name not given): a blocker is needed that passes through the parameters of the drive itself — the interface, the serial number, SMART — and not those of the blocker's controller. → In the new USB 3.0 one this is "partially implemented and is being implemented further", in the SATA blocker it is not. From the same person: will MIME analysis find a crypto container disguised as a different format? → Yes, there are ready-made groups of MIME types and a custom group; but as for a search for all encrypted objects posing as ordinary files — "we haven't worked in that direction yet", they promise to raise the topic.
- 2 (name not given): a local model or an online service? What specs does the rig need, which models are used and how is the context issue handled? → Locally only, a two-tier perimeter is possible. The hardware runs "from a laptop on up" depending on the task; the search runs over an archive indexed in advance, and the model has its schema; "as a rule, it's, for example, two GPUs that run a model of 38 or 72 in size"; the query context is limited in the usual way, "but for analyzing an archive that's already structured… that's quite enough".
- 3 (name not given): the USB blocker — a microcomputer or a signal processor, and is the blocking done in software? → A microcomputer plus a board of their own; yes, the blocking is done in software, inside the device.
- 4 (name not given): how is the program better than its competitors, apart from being Russian? → That is exactly what makes it better: Russian software, running on Astra Linux and working with E01 files — "that was our main, large-scale task".
- 5 (name not given, continuing an earlier conversation): what about interruptions while creating an E01 image — if the drive drops out you have to start over, although there are products on the market that can resume. → The answer: the E01 format "simply doesn't support interruptions", because checksums are calculated inside it. The questioner names specific products (Belkasoft, Tableau) → "We'll look into it, alright".
- 6 (name not given): how is the emotional state in audio assessed and in what words is, say, a fight described? → By timbre, pauses, volume; "scientific work was done, there are already standard solutions for this". On video: the system does not break down the type of fight, so the search is built not around a word but around a linguistic query — a query library, "a mini-classifier, in effect", because the description may contain neither "strike" nor "fight". Linguists should be the ones to tune it: "they better understand the semantics". The dictionary of terms is set as plain text — a word, Enter, a word.
- 7 (name not given): how is the reproducibility of AI results ensured — "this is very important for expert examination"? → The parameters are hard-set, the reproducibility "will be very high"; the "making things up" cannot be switched off completely, but it is heavily restricted, otherwise transcription would produce arbitrary text; preprocessing, slicing and a set of models of their own for each language are used — "a stack of models".
The speakers' positions
Greshnov speaks like a production engineer: what is already in series production, what is still in testing, where the limits are (NVMe only through an adapter and without full speed, the copier only for flash drives). Savinkov — like a systems architect, and a deliberate restraint about AI is noticeable in him: the classical algorithms have been kept precisely because they work better on rigidly defined categories; speaker identification is honestly handed over to partners; the model's "making things up" is called by its name. But where the audience demands verifiability — reproducibility, the search for encrypted data, E01 interruptions — the answers become generic, and two of the points are closed outright with a promise to "look into it".
Quotes
- "…officers from operational units asked for the most compact, self-contained solution… one that would literally fit in your fist".
- "From the first hour to the eighth you've got trees, wind. A fence, and five cars drive past".
- "…200 gigabytes of photos and files is just impossible to look through".
- "Honestly, we haven't worked in that direction yet".
- "It's like this making things up, the imagination of the neural net… well, it's not switched off, you can't switch it off, right? But it's heavily restricted".