# MK Bruteforce: a special edition for the tenth MFD Valeria Vakhrushina · MKO Systems MOSCOW FORENSICS DAY ’26 · Day 1 — Thursday, 3 September 2026 · Scheduled 10:15–10:40 · In the recording 00:05:06–00:16:49 Talk transcript · https://2026.moscow-forensics-day.workers.dev/en/transcript/01-vakhrushina Summary: https://2026.moscow-forensics-day.workers.dev/en/summary/01-vakhrushina · Slides: https://2026.moscow-forensics-day.workers.dev/en/slides/01-mk-bruteforce · Watch from 00:05:06: https://youtu.be/WuMIv5sFPRs?t=306 --- ## Moderator's introduction So let's open today's conference. And for that I invite our marketing director, the wonderful Valeria Vakhrushina. Let's welcome her with a round of applause. ## Conference opening: partners and ten years of MFD — Good afternoon, colleagues. I'm very glad to see you all in the hall today. There are a lot of us today, and today will be interesting. And my clicker, as usual, isn't working. Right, oh well, technical hiccups. I'd also like to introduce the partners of today's conference. Thanks, Zhenya. Dmitry, who's taking part with us today at the 10th MFD? Who's supporting us? Today we're supported by companies such as Account Best, ELETEK, Ester Solutions, Amplicom, ACE Lab and SearchInform. But I deliberately didn't do a teaser, because I know the guys will tell you everything far better than me. The guys will tell you everything, but again, besides our booth, where you can talk to our specialists, there are our partners' booths too, where you can ask them tricky questions and find out what's new. And of course, look for them after the talks. It'll be interesting, I hope. I have a question for the hall. Was anyone here at the first MFD? We're ten today. I'm curious, was anyone there? Wonderful. So they exist, the ones with us all ten years. Great! Well then, let's start our talks. ## MK Bruteforce: new hashes, faster scrypt, dictionaries, plans Excellent. And we'll start with our MK Bruteforce. I think you're all familiar with it. I hope you've known it a long time. Zhenya, my clicker isn't working. One more slide. Wonderful. So, here we go. I think you're all familiar with it. It's our product built on hashcat. I think those of you at the spring conference remember we already updated to hashcat version 7.0. Overall, what Bruteforce can do you've all known for a long time, I think. But let's look at what new things we've added. These are basically all the hashes we currently support. I urge you: if something's missing, some applications, some hashes that hashcat supports, or that aren't supported at all, you can come up to me any time, or to the guys at the booth, and request it. We'll definitely try to add them. A bit later I'll tell you what's in development now. So, what's fresh? We've added Samsung Smart Switch Backup for you. Telegram for macOS, the passcode for the desktop version, and Threema. Every time, users ask me where to get the hash. Just in case, I'll show you: we load it straight into the Bruteforce UI. With Samsung Smart Switch, we load two files. Make sure they're from the same backup. That's important, otherwise something may glitch and it'll recover some wrong password. It's exactly the same with Telegram for macOS. You can paste the hash or upload the file so it gets recognized. And Threema works exactly the same way. Let's see what else we've updated. We've improved the scrypt algorithms, specifically for Android physical images, both FBE and FDE, Apple Notes, Huawei HiSuite backups, Threema and Telegram for macOS. That means everything should now be recovered somewhat faster. Our measurements showed that in some places the speed increased tenfold, in others it's not so rosy, of course. FDE won't crack fast, as all of us who use it know. But still, try it, test it. I hope everything works for everyone. Again, if anyone has problems, write to our support or write to me directly, catch me in the hall. What else have we done? We all remember that MK Bruteforce runs both on GPU and on CPU. But a lot of people get confused. I often get screenshots saying, look, I have one graphics card and it shows up twice. Note that this depends on which drivers you have. So with this screenshot from my laptop, I have both the CUDA driver and the OpenCL driver. That's why the graphics card shows up twice. In the next release, I promise, the graphics card will show up once, and there'll just be a driver switch. But in any case, I recommend everyone use OpenCL. It's usually a bit faster, but you can test that yourself on your own device and see which is faster for you. Also, at your request, dear users, we added showing every graphics card separately, so you can see the temperature breakdown. You asked us to add that to the UI. And we added a notification that the attack has been paused on reaching a critical temperature, so it's clear what happened to me, what kind of bug this is, why it's paused, why it isn't working. It all works, everything's fine, we're just trying not to burn out your devices. Okay, what else did we add? We added a dictionary library. Now you can get in through an interface like this. There are preinstalled dictionaries. You can see they can't be deleted, you can't do anything with them. Here you can add new dictionaries, delete them, edit all of this for yourself somehow. But most importantly, there were a lot of requests to start supporting large dictionaries. So now you can safely load a 20-gig dictionary, a 40- or 100-gig dictionary. It will work, everything's fine, now it's actually possible. The only thing is, keep them where you won't accidentally delete them. Because they're saved here in the interface, and if you edit something, it will sync seamlessly. So if you deleted a dictionary or wiped something out of it, there could be a problem. Keep a close eye on that. Plans for the future. I promised teasers. What are we preparing now? We're preparing the KeePass application. It'll be out soon. We're preparing the Kims application. It'll also be out soon. And there were a lot of requests for password recovery for Windows Hello. That's in research now, but I think within the next six months, that is, a release from now, give or take, we'll be able to add it. The team is working really hard to make sure everything works for you. So if you have any wishes, if you have any suggestions for improving Bruteforce, we're always open, we'd be glad to hear it. For those who haven't used it for those who for some strange reason don't have Mobile Criminalist, first, you can come to our booth and ask the guys what it's for. Maybe they'll even share a demo. And second, you can follow the QR code. There's a free version of MK Bruteforce. I know, I haven't updated it in a while. The update will come with the next release of Mobile Criminalist. All the fresh, tasty new stuff will make its way in there. Of course, it's a slightly cut-down version. It supports fewer hashes than the Bruteforce built into MK. But still, you can use it. It's there. And if it has any bugs, we try not to code them in. But in any case, write to our support too. We'll definitely keep track and improve it. Well, I'm quick today. If you have any questions, I'm ready to answer them. Where's my Dmitry Yankovoy? With the microphone. We lost our moderator. He's been found. He wasn't lost. Guests keep arriving, pulling me every way. So, colleagues, I'm looking for raised hands, right? I think they'll grill me later, I know from experience, they'll grill me in the hall. ## The 10th-anniversary MFD portal: articles, video archive, a training exercise — All good overall, but in that case I suggest the next slide. I'll give you the great honor of telling everyone about the first gift we've prepared for today's conference. Then I'll add to it. — Well then, I suggest you all scan this QR code, there won't be anything indecent there, I promise. It's a small information portal we opened in honor of the 10th Moscow Forensics Day, which we're holding with you today. You need a short registration, and I promise no spam mailings will come to you after that. What have we prepared for you there? Our friends, both forensic and infosec specialists, wrote several articles there. I hope you'll find them interesting to read. Check them out. If, again, you have any wishes, maybe something is missing, maybe someone wants to take part and write something too, some article on their own or together with us, you're welcome at our booth. We'll be glad to work with you. But that's far from all. Because it's on this very information portal that we finally got around to structuring all the information we have. You won't find our videos on Rutube anymore, but if you're a client of MKO Systems, all you need is a short authorization. As soon as you register on the portal, it'll all be spelled out, what you need to do. I won't dwell on that now. And then you'll again have access to fresh materials, to a large number of manuals, to videos and everything else. But in honor of our tenth event, my colleagues and I thought for a very long time about what interesting and cool thing we could do. And so we implemented the ability, this will actually be of most interest, probably, to universities, to complete a challenge. So now on the portal you'll also be able to find a challenge. There's a short preamble to the challenge there. A test image is already ready, easy enough to download. And you'll be able to actually solve it. Then it'll say what we want from you. You don't need to upload anything. But you can solve this case, write us your answer, and our colleagues check it. The only thing I'll say right away: I know that before our conference, already underway today, 50 people had registered on the platform. You won't be able to register with the same email, unfortunately, so down below there'll be a small button that just says "Log in". So you log in with the credentials you already entered on the site earlier, and that's it, it all shows up. If you scan this QR code here, the articles will show up on top of that too. So go ahead, give it a try, write to us, and if anything comes up, we're always here in touch.