Open Source Signal logo
Open Source SignalСигнал відкритих джерел
Issue #073 5 August 2026 Daily Signal EN + UKR

Open Source Signal

Сигнал відкритих джерел

Bilingual OSINT radar for Ukrainian accountability work, verification, war-crimes documentation, losses, captivity and missing-persons research, maps, platforms, surveillance and researcher safety.

Daily issue #073: a drone attack on a civilian seller in Kherson as a verification chain that separates location, date, protected status, attribution and legal assessment; an open satellite method for screening conflict-related damage in Ukraine without turning model output into a casualty or attribution record; Google Earth’s brief experiment with generated overlays as a warning that a familiar map interface can launder synthetic imagery; a Puerto Rico cadastral service that exposed roughly one million Social Security numbers through an unprotected data path; forensic evidence that Russian investigators used Cellebrite against an opposition activist’s seized phone; an autonomous agent used for reconnaissance inside Thailand’s finance ministry while exfiltration and attribution remained unresolved; and Android intrusion logs designed for consensual, user-controlled forensic analysis.

Editorial frame

What this is: A bilingual editorial filter for public-interest OSINT. Each item explains what happened, why it matters, how a reader can use the insight, and where the method or evidence has limits.

What this is not: Doxxing, live targeting, stolen-data workflows, private-person deanonymization, credential hunting, revenge calls, unsafe operational guidance or unverified accusations against private people.

Rubric map

🇺🇦 Ukraine Lens
🛰️ Conflict Mapping
🤖 AI Verification
🗺️ Data Exposure
🛡️ Investigator OPSEC
⚠️ Risk Watch
🔬 Forensic Methods
🇺🇦Ukraine LensУкраїнська оптика
#01

A drone-attack video needs location, date, civilian status, attribution and legal assessment kept separate

Source: Reuters · 4 August 2026

What happened

Reuters reported on footage released by Ukrainian police that showed a drone pursuing a man around a van used as a vegetable stand in Kherson and exploding nearby. Police said the 52-year-old seller, identified only as Yurii, survived with shock and shrapnel wounds. Reuters verified the location by matching buildings, road layout and vegetation with satellite and archival imagery, but could not independently confirm the date. Ukrainian officials described the incident as a Russian war crime; Russia’s Defence Ministry did not immediately comment.

Why it matters

The video can support several findings, but not all at once. Geolocation, capture date, continuity of the original file, the victim’s protected status, the absence or presence of a military objective, the platform’s origin, operator attribution, intent and legal classification require different evidence. Keeping those layers separate prevents a verified location from being silently upgraded into a verified date, perpetrator or final legal conclusion.

How to use it

Preserve the earliest available file, its hash, upload history and every recompression. Record frame-level geolocation anchors, shadows and weather only as dated observations, and compare them with archival imagery. Create separate records for the victim interview, medical evidence, witness accounts, official statements, possible military objects, drone characteristics and attribution claims. Mark each conclusion with its source class, reviewer, confidence level and unresolved alternatives.

Limits

A verified location does not independently prove the recording date, operator, command chain, intent or legal classification. Do not publish the victim’s current location, routine, private contacts, medical details beyond public-interest need, or technical information that could assist targeting or evasion. Treat official allegations and denials as attributed claims until corroborated.

Відео удару дроном потребує окремої перевірки місця, дати, цивільного статусу, виконавця та правової оцінки

Джерело: Reuters · 4 серпня 2026

Що сталося

Reuters повідомило про відео, оприлюднене українською поліцією: дрон переслідує чоловіка навколо автомобіля, з якого продавали овочі в Херсоні, а потім вибухає поруч. За даними поліції, 52-річний продавець, названий лише Юрієм, вижив і дістав осколкові поранення та гостру реакцію на стрес. Reuters підтвердило місце за будівлями, плануванням дороги, рослинністю, супутниковими й архівними зображеннями, однак не змогло незалежно встановити дату. Українські посадовці назвали подію російським воєнним злочином; Міністерство оборони Росії не надало негайного коментаря.

Чому це важливо

Відео може підтверджувати кілька обставин, але не всі одночасно. Геолокація, дата знімання, безперервність походження первинного файла, захищений статус потерпілої людини, наявність або відсутність військової цілі, походження носія, встановлення оператора, умисел і правова кваліфікація потребують різних доказів. Їхнє розмежування не дає непомітно перетворити підтверджене місце на нібито підтверджену дату, виконавця або остаточний юридичний висновок.

Як це застосувати

Збережіть найраніший доступний файл, його контрольну суму, історію оприлюднення та всі повторні стиснення. Фіксуйте орієнтири геолокації в окремих кадрах, тіні й погоду лише як датовані спостереження та порівнюйте їх з архівними зображеннями. Створіть окремі записи для розповіді потерпілого, медичних відомостей, свідчень, офіційних заяв, можливих військових об’єктів, ознак дрона й тверджень про виконавця. Для кожного висновку зазначайте тип джерела, перевіряльника, рівень упевненості та невирішені альтернативи.

Обмеження

Підтверджене місце саме собою не доводить дати знімання, оператора, ланцюга командування, умислу або правової кваліфікації. Не публікуйте поточне місце перебування потерпілого, його звичні маршрути, приватні контакти, надмірні медичні подробиці чи технічні дані, здатні допомогти наведенню або ухиленню. Офіційні звинувачення та заперечення залишайте підписаними твердженнями, доки їх не підтверджено іншими джерелами.

ukrainekhersoncivilian-protectionvideo-verificationwar-crimes-documentation
🛰️Conflict MappingКартографування наслідків
#02

A satellite damage model is a screening layer, not a casualty or attribution record

Source: Scientific Reports · 8 March 2026

What happened

A Scientific Reports paper presented an automated method for detecting conflict-related changes in Ukraine using open Sentinel-1 radar and Sentinel-2 optical imagery. The workflow adapts processing to urban and non-urban land cover, combines radar change signals with optical classification and applies context-aware smoothing. Against a UNOSAT reference set, the authors reported detection of more than 80% of damaged buildings, with 78.8% recall, 87.5% precision and an F1 score of 0.828.

Why it matters

The method can prioritise places for human review where access is restricted and cloud cover or acquisition gaps make one sensor insufficient. But a change pixel is not a destroyed building, a damaged building is not a casualty, and neither establishes weapon, perpetrator or intent. The useful product is a review queue linked to source scenes, model version, thresholds, validation data and later corrections.

How to use it

Store the before-and-after scene identifiers, acquisition times, sensor, orbit, processing level, cloud and layover conditions, land-cover class, algorithm version, thresholds and output geometry. Route detections to analysts who compare high-resolution imagery, verified ground material and official or humanitarian records. Preserve false positives, false negatives and reviewer decisions so performance can be recalculated by settlement type.

Limits

Published benchmark performance does not guarantee equal accuracy across seasons, sensors, settlement types or new areas. Radar geometry, vegetation, construction, fire, demolition and ordinary land-use change can imitate conflict damage. Do not publish sensitive current imagery, exact military positions or automated casualty and attribution claims.

Супутникова модель руйнувань є засобом попереднього відбору, а не обліком жертв чи доказом відповідальності

Джерело: Scientific Reports · 8 березня 2026

Що сталося

У статті Scientific Reports представлено автоматизований спосіб виявлення пов’язаних із війною змін в Україні за відкритими радарними знімками Sentinel-1 та оптичними знімками Sentinel-2. Оброблення пристосовано до міської й неміської місцевості, радарні сигнали змін поєднано з оптичною класифікацією та просторовим згладжуванням із урахуванням оточення. Порівняно з еталонними даними UNOSAT автори повідомили про виявлення понад 80 відсотків пошкоджених будівель: повнота становила 78,8 відсотка, точність — 87,5 відсотка, узагальнений показник F1 — 0,828.

Чому це важливо

Метод допомагає визначати ділянки для людської перевірки там, де доступ обмежений, а хмарність або прогалини знімання роблять одного сенсора недостатнім. Проте змінений піксель не дорівнює зруйнованій будівлі, пошкоджена будівля не дорівнює потерпілій людині, а жоден із цих сигналів не встановлює зброю, виконавця чи умисел. Корисним результатом є черга перевірки, пов’язана з первинними сценами, версією моделі, порогами, перевірними даними й подальшими виправленнями.

Як це застосувати

Зберігайте ідентифікатори сцен до й після події, час знімання, сенсор, орбіту, рівень оброблення, хмарність, геометричні спотворення, клас покриву, версію алгоритму, пороги та контур результату. Передавайте спрацювання аналітикам для порівняння зі знімками вищої роздільності, перевіреними наземними матеріалами та офіційними чи гуманітарними записами. Не видаляйте хибні спрацювання, пропуски й рішення перевіряльників, щоб повторно оцінювати якість для різних типів населених пунктів.

Обмеження

Опублікована якість на еталонній вибірці не гарантує такої самої точності в інші пори року, для інших сенсорів, типів поселень або нових територій. Геометрія радарного знімання, рослинність, будівництво, пожежа, знесення та звичайна зміна землекористування можуть бути схожими на воєнну шкоду. Не публікуйте чутливі поточні знімки, точні військові позиції або автоматичні твердження про жертви й відповідальність.

ukrainesatellite-imagerysentinel-1sentinel-2damage-screening
🤖AI VerificationШІ та верифікація
#03

A familiar map interface can make generated imagery look like satellite evidence

Source: The Guardian · 4 August 2026

What happened

The Guardian reported that Google Earth briefly allowed users to create generated images over real locations. Researchers quickly produced scenes involving refugees, a nuclear facility and a fabricated hospital and crater. Google withdrew the feature to add safeguards after screenshots of generated imagery appeared to violate its policies. The underlying concern is not only realism: the trusted Google Earth frame can lend synthetic content the authority normally associated with satellite evidence.

Why it matters

Investigators often inherit screenshots without the original project, imagery identifier or interface state. When a platform can mix base imagery and generated overlays, the platform logo, coordinates and map furniture no longer authenticate every pixel. Provenance must therefore include which layer was displayed, whether generation was available, who exported the image and whether the same view exists in independent imagery.

How to use it

Treat every screenshot as a derived object. Request the original export or project link, capture the full interface, record account and feature state, base imagery date, layer list, coordinates, zoom and retrieval time. Compare the scene with an independent provider and earlier imagery, inspect edges and repeated textures, and preserve any generation labels or metadata. Publish the base image and the questioned overlay as separate exhibits.

Limits

Visual artefacts can raise questions but rarely prove generation by themselves, and a clean-looking image is not necessarily authentic. Do not accuse a person of fabrication from a screenshot alone. Platform statements describe product policy and remediation, not the provenance of every image already shared.

Звичний картографічний інтерфейс може надати синтетичному зображенню вигляд супутникового доказу

Джерело: The Guardian · 4 серпня 2026

Що сталося

The Guardian повідомила, що Google Earth на короткий час дозволив створювати синтетичні зображення поверх реальних місць. Дослідники швидко отримали сцени з біженцями, атомним об’єктом, вигаданою лікарнею та вирвою. Google відкликала можливість для додавання запобіжників після поширення знімків екрана, які, за оцінкою компанії, могли порушувати її правила. Небезпека полягає не лише в правдоподібності: знайома рамка Google Earth надає синтетичному вмісту авторитету, який зазвичай пов’язують із супутниковим доказом.

Чому це важливо

Дослідники часто отримують лише знімок екрана без первинного проєкту, ідентифікатора знімка чи стану інтерфейсу. Коли сервіс може змішувати основу із синтетичним накладенням, логотип, координати й елементи карти вже не засвідчують походження кожного пікселя. Тому слід фіксувати показаний шар, доступність створення зображень у той момент, автора вивантаження та наявність того самого виду в незалежних джерелах.

Як це застосувати

Вважайте кожен знімок екрана похідним об’єктом. Запитуйте первинне вивантаження або посилання на проєкт, зберігайте повний інтерфейс, стан облікового запису й функції, дату основного знімка, перелік шарів, координати, масштаб і час отримання. Порівнюйте сцену з незалежним постачальником та давнішими знімками, перевіряйте краї й повторювані текстури, зберігайте позначки або метадані створення. Основний знімок і сумнівне накладення публікуйте як різні матеріали.

Обмеження

Візуальні вади можуть викликати сумнів, але рідко самі доводять синтетичне походження; охайне зображення також не обов’язково справжнє. Не звинувачуйте людину у підробленні лише за знімком екрана. Заяви сервісу описують правила продукту й виправлення, а не походження кожного вже поширеного зображення.

ai-verificationgoogle-earthsatellite-provenancesynthetic-imagerymap-evidence
🗺️Data ExposureРозкриття даних
#04

A public map can expose fields that its visible interface never displays

Source: ProPublica and Centro de Periodismo Investigativo · 9 July 2026

What happened

ProPublica and Centro de Periodismo Investigativo reported that Puerto Rico’s Municipal Revenue Collection Center inadvertently exposed the Social Security numbers of about one million people through its Catastro Digital property map. The sensitive fields were not shown in an ordinary map search, but could be retrieved without a username or password through the way the website requested data. The newsrooms notified the agency in mid-June and later observed that the access paths had been patched, while the agency denied that protected information had been at risk.

Why it matters

Open-data review must examine the data returned to the browser, not only the fields drawn on the screen. A map can legitimately publish parcels, assessments and owner names while its underlying responses unintentionally include identifiers that create identity-theft and source-protection risks. The evidence record should distinguish potential accessibility, confirmed retrieval, observed misuse, remediation and legally required notification.

How to use it

For an authorised or responsibly disclosed assessment, document the visible field, returned field, endpoint class, authentication requirement, sample size needed to confirm the issue, notification time, agency response and patch status. Minimise collection: retain only redacted proof, hashes and request-response structure sufficient to establish exposure. Build a field-level publication review for every map and download service before release.

Limits

Do not reproduce the access path, enumerate records, download the dataset, retain unredacted identifiers or contact affected people using exposed data. Accessibility does not prove that criminals obtained or used the records. Agency denial and later patching should be recorded separately rather than treated as proof of either absence or misuse.

Відкрита карта може розкривати поля, яких її видимий інтерфейс ніколи не показує

Джерело: ProPublica and Centro de Periodismo Investigativo · 9 липня 2026

Що сталося

ProPublica та Centro de Periodismo Investigativo повідомили, що Центр збору муніципальних доходів Пуерто-Рико ненавмисно відкрив через кадастрову карту Catastro Digital номери соціального страхування близько мільйона людей. Звичайний пошук на карті не показував чутливих полів, однак спосіб запиту даних вебсторінкою давав змогу отримувати їх без імені користувача й пароля. Редакції повідомили установу в середині червня й згодом побачили, що шляхи доступу закрито, тоді як установа заперечила, що захищені відомості перебували під загрозою.

Чому це важливо

Перевірка відкритих даних має охоплювати відомості, які сервер повертає браузеру, а не лише поля на екрані. Карта може правомірно показувати ділянки, оцінку й імена власників, але у внутрішній відповіді ненавмисно передавати ідентифікатори, що створюють ризик викрадення особи та розкриття джерел. У записі слід розрізняти можливість доступу, підтверджене отримання, виявлене зловживання, усунення проблеми й обов’язок сповістити потерпілих.

Як це застосувати

Під час дозволеної перевірки або відповідального повідомлення фіксуйте видиме поле, фактично повернуте поле, клас шляху доступу, вимогу входу, мінімальний зразок для підтвердження, час сповіщення, відповідь установи й стан виправлення. Зводьте збирання до мінімуму: залишайте лише знеособлений доказ, контрольні суми та будову запиту й відповіді, достатню для встановлення розкриття. Перед оприлюдненням кожної карти чи служби вивантаження проводьте перевірку на рівні полів.

Обмеження

Не відтворюйте шлях доступу, не перебирайте записи, не завантажуйте набір, не зберігайте незнеособлені ідентифікатори й не зв’язуйтеся з людьми за розкритими відомостями. Доступність не доводить, що зловмисники отримали або використали записи. Заперечення установи й подальше виправлення фіксуйте окремо, не подаючи жодне з них як доказ відсутності проблеми або фактичного зловживання.

public-datacadastrepersonal-dataresponsible-disclosureprivacy
🛡️Investigator OPSECБезпека дослідника
#05

A seized phone investigation needs a custody timeline and tool-specific traces

Source: The Citizen Lab · 25 June 2026

What happened

Citizen Lab reported high-confidence forensic traces showing that Russian authorities used Cellebrite’s Universal Forensic Extraction Device against the iPhone of opposition activist Andrey Pivovarov while it was in state custody in June 2021. A Russian forensic document also identified the tool and described searches for political and personal information. The case indicates continued operational use after Cellebrite said it had stopped selling to Russia.

Why it matters

A vendor’s current sales policy does not establish whether licensed, offline, legacy or transferred tools remain in use. For the device owner, the decisive record is the custody interval, lock state, operating-system version, physical access, extraction artefacts, forensic report and subsequent account activity. Tool attribution should rest on several independent traces rather than a generic assumption that any seized phone was unlocked.

How to use it

Before high-risk travel, record device model, operating-system version, enabled protections and recovery contacts without creating an unsafe public inventory. After seizure, preserve return time, photographs, power and lock state, unexpected reboots, account alerts and a consensual forensic image where lawful. Compare device artefacts with official paperwork and known tool signatures, and document every analyst, copy, hash and interpretation.

Limits

The case concerns one device and one custody episode; it does not establish the prevalence of the tool across Russia or prove a live vendor relationship. Do not publish extraction artefacts that expose the activist’s private data, account tokens, contacts or defensive weaknesses. Forensic absence is not proof that no access occurred.

Дослідження вилученого телефона потребує часової лінії зберігання та ознак конкретного засобу

Джерело: The Citizen Lab · 25 червня 2026

Що сталося

Citizen Lab повідомила про криміналістичні ознаки високої впевненості, за якими російські органи застосували Universal Forensic Extraction Device компанії Cellebrite до iPhone опозиційного активіста Андрія Пивоварова, коли телефон перебував під контролем держави в червні 2021 року. Російський експертний документ також називав цей засіб і описував пошук політичних та особистих відомостей. Випадок указує на подальше практичне використання після заяви Cellebrite про припинення продажів у Росії.

Чому це важливо

Чинна політика продажів постачальника не встановлює, чи залишилися в роботі ліцензовані, автономні, застарілі або передані засоби. Для власника визначальними є проміжок перебування телефона під чужим контролем, стан блокування, версія системи, фізичний доступ, сліди вилучення, експертний документ і подальша активність облікових записів. Встановлення засобу має спиратися на кілька незалежних ознак, а не на припущення, що будь-який вилучений телефон зламали.

Як це застосувати

Перед ризикованою поїздкою зафіксуйте модель пристрою, версію системи, увімкнені засоби захисту й контакти для відновлення, не створюючи небезпечного відкритого переліку. Після вилучення збережіть час повернення, фотографії, стан живлення й блокування, несподівані перезапуски, сповіщення облікових записів і, де це законно, добровільно надану криміналістичну копію. Зіставляйте сліди на пристрої з офіційними документами та відомими ознаками засобів; фіксуйте кожного аналітика, копію, контрольну суму й тлумачення.

Обмеження

Випадок стосується одного пристрою й одного періоду вилучення; він не визначає поширеність засобу в Росії та не доводить чинних відносин із постачальником. Не публікуйте сліди вилучення, які розкривають приватні відомості активіста, ключі доступу, контакти або слабкі місця захисту. Відсутність знайдених слідів не доводить, що доступу не було.

russiacellebritedevice-seizuremobile-forensicssource-protection
⚠️Risk WatchМежі й ризики
#06

An autonomous-agent intrusion should be recorded by observed actions, not by a dramatic label

Source: The Record · 27 July 2026

What happened

The Record reported that Hunt.io researchers found a publicly accessible attacker server containing malware, credentials, scripts and logs from an open-source Hermes agent used during an intrusion into Thailand’s finance ministry. The agent was configured to execute commands without human approval and was observed exploring the network, collecting system information, searching files and looking for paths to higher privileges. Researchers found no evidence of data exfiltration and did not attribute the operation to a known group.

Why it matters

The presence of an agent does not reveal how much autonomy the operation actually had. Prompts, tool calls, command results, pauses, human interventions and failed actions are needed to distinguish automated execution from planning or operator assistance. Reconnaissance, credential access, persistence, collection and exfiltration are separate incident stages and should not be collapsed into a claim that the agent completed the attack.

How to use it

Create a timestamped action ledger with the host, account, command class, agent prompt, tool response, human approval state, success or failure, resulting artefact and defensive detection. Preserve the server image and logs through authorised channels, separate researcher observation from victim confirmation, and map only observed behaviour to a defensive technique framework. Track exfiltration and attribution as unresolved unless supported by independent evidence.

Limits

Do not reproduce credentials, malware, prompts, command sequences, server addresses or privilege-escalation paths. A public attacker server may contain planted, incomplete or unrelated material. Language indicators do not establish nationality, and absence of observed exfiltration does not prove that no data left the network.

Вторгнення з автономним агентом слід описувати за спостереженими діями, а не гучною назвою

Джерело: The Record · 27 липня 2026

Що сталося

The Record повідомило, що дослідники Hunt.io знайшли відкритий сервер нападників із шкідливими програмами, обліковими даними, сценаріями та журналами роботи агента Hermes із відкритим кодом, застосованого під час проникнення до мережі Міністерства фінансів Таїланду. Агент був налаштований виконувати команди без підтвердження людиною; спостерігали дослідження мережі, збирання відомостей про системи, пошук файлів і можливостей розширити права. Доказів викрадення даних дослідники не виявили й не пов’язали операцію з відомою групою.

Чому це важливо

Наявність агента не показує фактичного рівня самостійності операції. Для розмежування автоматичного виконання, планування й допомоги операторові потрібні запити до системи, виклики засобів, результати команд, паузи, втручання людини та невдалі дії. Розвідка, доступ до облікових даних, закріплення, збирання й викрадення є різними стадіями; їх не можна зливати в твердження, що агент самостійно завершив напад.

Як це застосувати

Створіть датований журнал дій із вузлом, обліковим записом, класом команди, завданням агентові, відповіддю засобу, станом підтвердження людиною, успіхом або помилкою, створеним слідом і спрацюванням захисту. Зберігайте образ сервера та журнали лише через дозволені канали, відокремлюйте спостереження дослідників від підтвердження потерпілої установи й наносіть на захисну схему тільки фактично зафіксовану поведінку. Викрадення даних і виконавця залишайте невстановленими без незалежних доказів.

Обмеження

Не відтворюйте облікові дані, шкідливі програми, завдання, послідовності команд, адреси серверів або шляхи розширення прав. Відкритий сервер нападників може містити підкладені, неповні чи сторонні матеріали. Мовні ознаки не встановлюють національності, а відсутність спостереженого викрадення не доводить, що жодні дані не залишили мережу.

ai-agentscyber-incidentthailandincident-timelinedefensive-analysis
🔬Forensic MethodsКриміналістичні методи
#07

Android intrusion logs shift mobile forensics from incidental traces toward user-controlled evidence

Source: Amnesty International Security Lab · 12 May 2026

What happened

Amnesty International’s Security Lab described Android Intrusion Logging, introduced within Android Advanced Protection Mode, as a new source for consensual forensic analysis of sophisticated attacks. The opt-in mechanism records security-relevant events, encrypts the archives with a user-generated key and stores them in the user’s Google account; the owner must explicitly share and decrypt them for an analyst. Amnesty also added initial collection and analysis support to AndroidQF and the Mobile Verification Toolkit.

Why it matters

Mobile investigations have often depended on short-lived crash records and troubleshooting logs that were never designed to preserve evidence. Purpose-built logging can retain context about unlocking, debugging access, application changes and network activity after an incident. Its evidentiary value comes from advance enablement, owner consent, key custody, time integrity and preservation of the raw archive—not from a tool declaring that an infection occurred.

How to use it

For high-risk users, document whether the protection was enabled before the suspected event and preserve the device time, account state and export procedure. Obtain explicit informed consent, export the encrypted archive, hash both the raw and working copies, keep the decryption key separate and analyse a copy with a recorded tool version. Link each alert to its underlying event, alternative explanations and corroborating device or network evidence.

Limits

The feature is not retroactive and cannot recover events that were never logged or have already been lost. Logging coverage varies by Android version and device support, and attackers may still evade or corrupt traces. Do not collect archives without consent, upload them to untrusted services, publish private communications or treat one event as conclusive proof of spyware.

Журнали вторгнень Android переводять мобільну криміналістику від випадкових слідів до доказів під контролем власника

Джерело: Amnesty International Security Lab · 12 травня 2026

Що сталося

Security Lab Amnesty International описала журналювання вторгнень у розширеному режимі захисту Android як нове джерело для добровільного криміналістичного дослідження складних нападів. Увімкнений власником механізм записує події, важливі для безпеки, шифрує архіви створеним користувачем ключем і зберігає їх в обліковому записі Google; для дослідження власник має явно передати й розшифрувати їх аналітикові. Amnesty також додала початкову підтримку збирання й аналізу до AndroidQF та Mobile Verification Toolkit.

Чому це важливо

Дослідження телефонів часто залежало від короткочасних записів збоїв і службових журналів, не призначених для збереження доказів. Спеціальне журналювання може залишати контекст про розблокування, налагоджувальний доступ, зміни застосунків і мережеву активність після події. Доказова цінність виникає завдяки завчасному ввімкненню, згоді власника, контролю ключа, цілісності часу й збереженню первинного архіву, а не через повідомлення програми про нібито зараження.

Як це застосувати

Для користувачів під підвищеним ризиком зафіксуйте, чи було захист увімкнено до ймовірної події, а також час пристрою, стан облікового запису й порядок вивантаження. Отримайте явну поінформовану згоду, вивантажте зашифрований архів, обчисліть контрольні суми первинної та робочої копій, зберігайте ключ окремо й аналізуйте копію засобом із записаною версією. Пов’язуйте кожне попередження з первинною подією, іншими можливими поясненнями та підтвердними відомостями з пристрою або мережі.

Обмеження

Функція не діє заднім числом і не відновлює події, які не були записані або вже втрачені. Повнота залежить від версії Android і підтримки пристрою, а нападники можуть уникати запису або пошкоджувати сліди. Не збирайте архіви без згоди, не передавайте їх ненадійним сервісам, не публікуйте приватне листування й не подавайте одну подію як остаточний доказ шпигунської програми.

androidintrusion-loggingconsensual-forensicsmobile-securityevidence-custody