There is a good article about Drone Forensics in eForensics Magazine. The synopsis for the article states:
"The project begins to look into the broad range of UAVs that are likely to be encountered by police forces in the UK, specifically targeting the more budget end of the spectrum whilst still having all the functionality required to commit a range of crimes. The project focuses on post criminal activity analysis of the UAV and controller and while there is some discussion of commercial counter UAV tools it is not the focus of this project. One example of this analysis comes from media files stored on the drone and the kind of information that can be gathered from them through metadata. Using a purely practical, experimentation and analysis based approach, a thorough examination was made of both the UAV and its controlling Android and iOS devices. The project concludes that metadata is the best way to obtain information regarding flights, particularly where the Bebop’s “Drone Academy” feature is disabled as it specifically states that this will track your drone’s flights, though there is an analysis of the files created by the “Drone Academy” feature."
https://eforensicsmag.com/product/drone-forensics/
However, there a huge range of technology to consider with evidential value and later on I will present additional supporting info to the community. In the meantime here is a great Infographics by (c) Jethro Hazelhurst of the Pixhawk PX4 autopilot.
Investigations, Practices and Procedures: Seizure-Forensic Examination-Evidence. Cellular and Satellite Telephones, Call Records-Billing Data, Cell Site Analysis. Telecomms. Computer and Network Analysis. GPS devices & Jammers, Cyber, IoT forensics.
Showing posts with label evidence. Show all posts
Showing posts with label evidence. Show all posts
Tuesday, May 21, 2019
Saturday, July 08, 2017
What's happening with Contemporaneous Notes
Contemporaneous note (CN) taking is an essential process and procedure. The title is often used as a widely applied statement to include other associated processes and procedures, such as Simultaneous Notes (SN), etc.; as some of you know CN, SN, IN and VN are covered in my training courses for e-Discovery, (forensic) examination and evidence E3.
I have taken the opportunity to bring on board Robert Merriott, Founder of Forensic Notes, to provide an overview of some of the methods and tools out there for preparing and producing Contemporaneous Notes. From Robert's well informed discussion (below) this clearly is a subject where strong opinions are held and a subject which we will return in future discussions.
Robert Merriott
Digital Forensic Examination Notes
The purpose of this post isn’t to provide a
singular and definitive answer to the question of what ‘examination notes’
should look like. In fact, every
country or region will have its own accepted practices developed to satisfy the
laws of the land. Instead, this article
is presented to discuss the many facets of this important subject and to help
you find a solution that will best meet your needs.
A recent
discussion regarding Contemporaneous Notes on Forensic Focus showed that
there are differing views on how strict guidelines should be in relation to
examination notes. This difference of
opinion reveals how much the process of conducting digital forensic
examinations can vary from one office to the next.
Importance of Documentation
The importance of documenting your
examinations can not be understated.
Although you may never need to defend your case in court, you should
complete every case as if you would be testifying as an expert in Supreme
Court.
Recently, experts and influential leaders
in Digital Forensics provided quotes on the Importance of Documentation.
As Greg stated…
“Contemporaneous
Notes are unavoidable, thus inescapable, when it comes to examining evidence
and are akin to the standard of Ethics.
They hold the
examiner to their own account of conduct when no one else is around to witness
what is happening.”
Examination Notes – Current Solutions
Investigators dealing with digital evidence
will document their examinations in one of several ways:
-
Traditional paper notebook and
pen
-
Word processors such as MS Word
or OneNote
-
Purpose built electronic note-taking
system
-
Scrap pieces of paper
-
Do not document!
Paper Notebook and Pen
The classic way of writing contemporaneous
notes.
This form of documentation has been relied upon
in law enforcement and scientific labs for decades and has continued to standup
to the scrutiny of the courts when properly completed.
Although widely accepted in courts, writing
your notes in a paper notebook can be slow and result in notes that are
illegible and incomplete. For many young
examiners that can quickly type out long messages on a virtual mobile keyboard,
the idea of handwriting notes seems like a step back in productivity.
Attempts to correct spelling and grammatic
mistakes only further complicate the process of writing and disclosing notes.
MS Word or OneNote
Electronic documentation is becoming more
common even in traditional settings like law enforcement were only paper notebooks
and pens were previously trusted.
Electronic documentation offers many
advantages including the ability to edit and modify the content of the notes as
required.
Being able to edit the content of an
electronic note allows the examiner to correct any spelling, grammatical errors
or omissions. As a result, some examiners feel electronic documentation provides
a more professional form of their notes as they are able to correct these
issues prior to providing them to colleagues or the courts.
But if notes can be changed at a later date
with no previous history of the contents originally entered, can they really be
considered contemporaneous?
And does this open up Pandora’s Box for defense
lawyer questioning?
If you admit you modified some of your
notes for “grammar” and “typos”, will defense begin to argue you changed other
aspects of your notes as well? And what
if you did change something else for reason beyond simple grammar or typos, how
will you explain that change in court?
Criminal courts would never allow a law
enforcement officer to wite-out® portions of
his notes in a paper notebook and then overwrite that information with new information.
So why should the courts trust electronic notes to be a true representation of
your thoughts at the time stated if they can be edited without including the
previous entries?
Although many Digital Forensic Examiners
are using MS Word and OneNote successfully in courts throughout North America
and Europe, we as examiners know that the majority of courts have failed to
keep up with the complexities of digital data and how easily files can be
manipulated.
Of course, there are ways to make
electronic notes immutable with the use of Digital Signatures and digital
timestamps, but few organizations are properly setup to implement this solution.
Will you be able to defend the authenticity of
your MS Word or OneNote examination notes in court if questioned? Electronic Note-Taking Application
Electronic Note-Taking applications offer
the best of both worlds if designed and used properly. But remember, not all applications are
created equal.
When deciding on what electronic
note-taking application you want to use, you will have to consider your
specific needs and requirements not only now, but in the future when your cases
finally go to trial.
-
Can you easily print notes in
sequential order for court?
-
Can you edit existing notes
while retaining the original note for Full Disclosure?
-
Can you arrange your notes in a
logical manner during the investigation to keep your information organized?
-
Can you search through your
notes to find answers quickly?
-
Is your information securely
saved and encrypted?
-
Do Audit Logs exist allowing
you to clearly see who else accessed a particular note or notebook?
-
Is the application able to
timestamp individual notes from a trusted and independent Timestamping
Authority (TSA)?
-
Will the courts be able to
authenticate your notes if required without calling in another expert?
-
Can you access your notes on
multiple devices, including mobile, so that you can take notes outside of your
office such as during live analysis at the scene or meetings with other
investigators?
-
If you include screen captures
and images in your notes, will you be able to print the image in a high-quality
format at a later date if it becomes a key piece of evidence?
-
Are the owners of the
application trusted members of the digital forensic community?
When choosing an Electronic Note-Taking Application,
you should select an application that works the way you work instead of being
forced to work within the constraints of the application they provide.
Scrap Pieces of Paper
Although it’s common to use scrap pieces of
paper to quickly jot down information, they should not be used as a place to
write notes during an examination unless other options discussed above are not
available.
If scrap pieces of paper are used to
document important information, this should be transcribed into your proper
notes as soon as possible. Often, if done in a reasonable time frame, these
transcribed notes will be considered contemporaneously written.
Do Not Document Examination
Some examiners do not see a need to
document their examinations. This is often as result of poor training,
inexperience or laziness. If your examination involves criminal or civil
litigation, then it’s imperative that you conduct your examinations in a
professional manner. Poorly documented
investigations can lead to bad caselaw that affects us all.
Should Standards Exist for Examination Notes?
Preston Coleman provides a valid and well
thought out response to the idea of standards for examination notes.
As Preston points out, if standards were to
be created for examination notes, then they should be general in nature to
allow for the flexibility needed within most examinations. At a minimum, the following “universal
elements should be observed”
-
Contemporaneous Notes
Document actions and results sequentially as they occur
Document actions and results sequentially as they occur
-
Timestamp Notes
Include Date & Time with every note made
Include Date & Time with every note made
-
Immutability
Notes should be fixed and non-editable upon completion of the examination
Notes should be fixed and non-editable upon completion of the examination
-
Available
Provide to others, including the courts, if required
Provide to others, including the courts, if required
Depending on your particular circumstances
and the types of files that you are investigating, you may decide on more
stringent requirements for your own note taking.
Odds n’ Ends
Now let’s discuss a few more questions
regarding examination notes…
Simultaneous Notes
As discussed within the “Forensic Chip Off
– Notes in Progress” post,
Greg asked the question “how would you keep contemporaneous notes (CN)
simultaneously whilst removing a chip?”
If Simultaneous Notes (SN) were required
during a technical hands-on examination, then a video of the examination (as
shown in the blog post) could be used to allow the examiner to concentrate on
the task at hand while still properly documenting the actions being taken. Upon
completion, the video file could be hashed with the resulting hash being noted
within your Contemporaneous Notes.
A purpose-built forensic Electronic
Note-Taking application would allow you to attach the original video to the note
and automatically Hash and Timestamp the video in only a couple steps.
Destroy Notes After an Examination Is Complete?
In some American states, it is apparently
common practice to destroy both paper and electronic notes once a final
examination report has been written.
If the destruction of examination notes is
currently allowed where you work, you should ask yourself:
-
What happens if the accuracy or
credibility of the report is questioned?
-
What reasoning will you provide
if questioned on why you felt it was necessary to destroy your notes?
o
The opposing party may ask
“What were you trying to hide in those notes that it was so important that you
destroy them prior to court?”
Restrictive Warrants
In many regions, warrants authorizing
forensic examinations are becoming restrictive with respect to the type of data
that can be analyzed and included in forensic reports. In practice, you may observe other evidence
in plain view (eg: Child abuse material) that does not fit within the
restrictions of the warrant.
In this case, it is suggested that you
immediately stop your current examination and re-apply for a warrant that
includes the evidence you observed in plain view.
If you fail to take proper contemporaneous
notes or destroy your notes upon completion of a report, would you be able to
properly articulate how you came to observe the images or data that you weren’t
authorized to have searched which resulted in a more comprehensive warrant
being sought?
If not, you risk having all your evidence
excluded from the trial.
Many investigators fail to recognize that
obtaining a new warrant is easy in comparison to defending the merits of the
new warrant at trial. Are you willing to lose all that hard work due to a lack
of proper documentation?
Conclusion
The digital forensic community needs a “Best
Practice” guideline in creating contemporaneous notes during an examination.
Without a clear guideline, Digital Forensic Examiners are left to rely on
potentially false or misleading information from fellow members who do not
fully recognize the need or value in creating proper notes during an
examination.
At a minimum, all professional Digital
Forensic Examiners should use the following list as the current “Best Practice”
guideline:
-
Contemporaneous Notes
-
Timestamp Notes (Date &
Time)
-
Immutability
-
Available
By continuing to discuss this important
subject, we as a community can further improve “Best Practice” guidelines that
will help ensure existing and new examiners take the necessary steps during
digital forensic examinations.
After evaluating the “Best Practice”
guidelines, you can make an informed decision on what is the best solution for
recording Examination Notes given your particular circumstances and needs.
Will you stick with the classic pen and
paper, utilize a word processing application such as MS Word or OneNote or go
with a more forensic solution such as a purpose-built electronic
note-taking system like Forensic Notes?
About
Author:
Robert Merriott founded TwiceSafe Software
Solutions Inc. (Forensic Notes) after realizing the need for a digital
note-taking application that would meet the high standards of digital forensic
evidence in the courts. Robert has a Degree in Computer Information Systems and
obtained both Microsoft MVP and ASPInsider status during the infancy of
ASP.Net. He now works as a Digital Forensic Examiner.
DISCLAIMER:
This article is not meant to provide legal advice or information. Legal
statements made are only provided as guidance for the reader to seek
professional legal advice within their jurisdiction. No information contained
within this article should be acted upon without discussing the merits of such
information with a legal professional. The author of this article is NOT A
LAWYER and takes no legal responsibility for the information presented. In
addition, the information provided is based on personal beliefs and ideas and
does not represent his employer.
Wednesday, June 28, 2017
U-N-I update on posts
- Diameter - Online Charging Systems (OCS)
- Big / Fresh / Deep - Data : Huaewi overview
- Hot technologies to know about
- ARP.pcap
- bgp.pcap
- https.pcap
- ICMP-ARP-OpenFlow1.0.pcap
- ICMP-DHCP-DNS.pcap
- Russians target Telegram App
- Wireshark
- Protocols Relevant to U-N-I
- Industrial Networks Hit By WannaCry
- IM Telegram Replay Attack - Android
- Whisper Signal WhatsApp
- Subpico Intelligent Appication Layer Software
- Subpico LI with evidential integrity
- TraceWrangler
- old_GUTI_IMSI_Critical_Reject (updated)
https://www.linkedin.com/groups/13536130
- Big / Fresh / Deep - Data : Huaewi overview
- Hot technologies to know about
- ARP.pcap
- bgp.pcap
- https.pcap
- ICMP-ARP-OpenFlow1.0.pcap
- ICMP-DHCP-DNS.pcap
- Russians target Telegram App
- Wireshark
- Protocols Relevant to U-N-I
- Industrial Networks Hit By WannaCry
- IM Telegram Replay Attack - Android
- Whisper Signal WhatsApp
- Subpico Intelligent Appication Layer Software
- Subpico LI with evidential integrity
- TraceWrangler
- old_GUTI_IMSI_Critical_Reject (updated)
https://www.linkedin.com/groups/13536130
Labels:
CDR,
cell details,
cyber,
evidence,
fault-finding,
fixed,
forensics,
large-scale computer networks,
mobile,
network,
PCAP,
switch data,
traffic logs,
universal network investigations
Friday, June 23, 2017
Universal Network Investigations
Just started a new LinkedIn group called 'Universal Network Investigations (UNI)'. It is a group only for those involved in the wider area of fixed, mobile and large-scale computer networks. The group exists to assist cyber, forensics and fault-finding investigations: to exchange observations and sharing 'intel' in a closed forum discussing fixed and mobile network investigations - trace data and other forms of evidence (including but not limited to PCAP, CDRs, traffic logs, exchange and switch data, cell details, dumps, etc.) If you are a member of LinkedIn and want to participate in the group here is the link: https://www.linkedin.com/groups/13536130
Labels:
CDR,
cell details,
cyber,
evidence,
fault-finding,
fixed,
forensics,
large-scale computer networks,
mobile,
network,
PCAP,
switch data,
traffic logs,
universal network investigations
Thursday, February 23, 2017
Secrets and Evidence of Older Mobiles
It is good to learn that the Nokia 3310 may make a return, albeit with an Android operating system. The nostalgia for these types of mobile phones has clearly not been lost. What it might suggest is that consumers still want a mobile telephone to remain a mobile telephone and to look like one.
The older mobile phones I have in mind though are the ones that are still used in examinations, investigations and research. Since there is nostalgic sentiment in the air I thought you might be interested in some examples of older mobile phones from my lab toolkit.
Now these old buzzards are used for basic GSM telephony services. There isn't a universal SIM that will work with these as some from my collection operate with a 5-volt SIM and so on. Importantly they are used due to the fact they have an external antenna and extendable external antenna. In some investigation instances RSSI will show network detection and a small amount of RF power whereas mobiles/smartphones with embedded antennas show Emergency Calls Only.
You might recall I have written numerous articles on radio surveys and two that may seem appropriate to this discussion are:
CSA: Mobile Phones and Fringe Coverage
http://trewmte.blogspot.co.uk/2010/06/csa-mobile-phones-and-fringe-coverage.html
GSM Radio Test Measurements
http://trewmte.blogspot.co.uk/2010/06/gsm-radio-test-measurements.html
The next selection of mobiles/smartphones each provide different radio characteristics due to the manufacturer's selection of RF chipset and functionality.
My five beauties, as I call them, are my Nokia 3210s. Great phones and they still operate perfectly well today. You can also see in the photo that all bar one mobile have embedded antenna. Some are mobile phones and some are smartphones. Combined they offer the ability for RF surveys and testing voice telephony, data downloads, instant messaging etc. The common laptop application Network Monitor (NMonitor/NetMonitor) still provides good feedback when connected to the Nokia 3210 (nmon activated). Blackberry requires a bit of setting up with applications such as MagicBerry, BBHTool, etc., and creating JAD-files (depending on what you want to achieve). Now with the Samsung models GT-I8160 and GT-I9100 both are used with 2G and 3G networks and illustrates the point that two models of smartphone from the same manufacturer display didn't RF survey details.
Now I wont bore you with an explanation of the details just to say these investigation RF surveys require knowing the various ServiceMode states. In particular, if you are conducting a PRACH and RACH survey, relevant to investigations for Access Requests (e.g. the phone is not in idle mode but seeking a service), then the GT-I9100 is useful in that it displays not just the LAC but also the Cell ID the RACH (access) request was made. Quite a few mobiles do not do this when looking into the ServiceMode states. You have to be quick, mind you, as the ServiceMode screen changes fairly quickly if you are not ready to take a photo.
Yet another, quite old-ish, mobile phone that I haven't shown so far is the Nokia 6303. The photo shown below should explain everything. But for those not familiar to testing and examination; where a charge in the billing appears for an SMS or at least details of a called number sent an SMS (even if sent message is free) it is quite possible the party receiving the message can read it but the message wont be saved. This is known as a Class 0 message (commonly referred to as a Flash Message). Depending on make and model of mobile phone, part or all of the message which is only held in RAM might still be recoverable, provided seizure and examination is undertaken and completed fairly quickly, as RAM is updating perpetually.
The Nokia 6303 is one of those mobiles that the handset manufacturer in combination with mobile network operator enabled this feature as they foresaw revenue generation from it and also recognised that a reasonable memory storage capacity in handset and SIM card need not be blocked up with trivial messages.
The 6303 came with a 940 MB memory card for downloaded applications etc. This proved to be useful in an investigation where text messages didn't have alphabet characters but a series of dots and dashes. At first it was thought this was incomplete text chat messages or some sort of smiley face that didn't form properly when typed on the screen.
When reviewing hundreds of text messages recovered from a mobile or smart phone it is quite easy to overlook or ignore a message as being meaningless. However, I researched the matter and following testing the message turned out to be Morse Code. I tracked down the application for this and cross-checked with the device that had been examined.
So next time you see a text message with an odd presentation look closely to see if it has relevance and whether your mobile phone forensic suite software has the capability to either identify the message contains additional features or can translate the message.
Hope you have enjoyed this brief look at older mobile phones used in and for mobile forensic examination, investigations and research.
The older mobile phones I have in mind though are the ones that are still used in examinations, investigations and research. Since there is nostalgic sentiment in the air I thought you might be interested in some examples of older mobile phones from my lab toolkit.
Now these old buzzards are used for basic GSM telephony services. There isn't a universal SIM that will work with these as some from my collection operate with a 5-volt SIM and so on. Importantly they are used due to the fact they have an external antenna and extendable external antenna. In some investigation instances RSSI will show network detection and a small amount of RF power whereas mobiles/smartphones with embedded antennas show Emergency Calls Only.
You might recall I have written numerous articles on radio surveys and two that may seem appropriate to this discussion are:
CSA: Mobile Phones and Fringe Coverage
http://trewmte.blogspot.co.uk/2010/06/csa-mobile-phones-and-fringe-coverage.html
GSM Radio Test Measurements
http://trewmte.blogspot.co.uk/2010/06/gsm-radio-test-measurements.html
The next selection of mobiles/smartphones each provide different radio characteristics due to the manufacturer's selection of RF chipset and functionality.
My five beauties, as I call them, are my Nokia 3210s. Great phones and they still operate perfectly well today. You can also see in the photo that all bar one mobile have embedded antenna. Some are mobile phones and some are smartphones. Combined they offer the ability for RF surveys and testing voice telephony, data downloads, instant messaging etc. The common laptop application Network Monitor (NMonitor/NetMonitor) still provides good feedback when connected to the Nokia 3210 (nmon activated). Blackberry requires a bit of setting up with applications such as MagicBerry, BBHTool, etc., and creating JAD-files (depending on what you want to achieve). Now with the Samsung models GT-I8160 and GT-I9100 both are used with 2G and 3G networks and illustrates the point that two models of smartphone from the same manufacturer display didn't RF survey details.
Now I wont bore you with an explanation of the details just to say these investigation RF surveys require knowing the various ServiceMode states. In particular, if you are conducting a PRACH and RACH survey, relevant to investigations for Access Requests (e.g. the phone is not in idle mode but seeking a service), then the GT-I9100 is useful in that it displays not just the LAC but also the Cell ID the RACH (access) request was made. Quite a few mobiles do not do this when looking into the ServiceMode states. You have to be quick, mind you, as the ServiceMode screen changes fairly quickly if you are not ready to take a photo.
Yet another, quite old-ish, mobile phone that I haven't shown so far is the Nokia 6303. The photo shown below should explain everything. But for those not familiar to testing and examination; where a charge in the billing appears for an SMS or at least details of a called number sent an SMS (even if sent message is free) it is quite possible the party receiving the message can read it but the message wont be saved. This is known as a Class 0 message (commonly referred to as a Flash Message). Depending on make and model of mobile phone, part or all of the message which is only held in RAM might still be recoverable, provided seizure and examination is undertaken and completed fairly quickly, as RAM is updating perpetually.
The Nokia 6303 is one of those mobiles that the handset manufacturer in combination with mobile network operator enabled this feature as they foresaw revenue generation from it and also recognised that a reasonable memory storage capacity in handset and SIM card need not be blocked up with trivial messages.
The 6303 came with a 940 MB memory card for downloaded applications etc. This proved to be useful in an investigation where text messages didn't have alphabet characters but a series of dots and dashes. At first it was thought this was incomplete text chat messages or some sort of smiley face that didn't form properly when typed on the screen.
When reviewing hundreds of text messages recovered from a mobile or smart phone it is quite easy to overlook or ignore a message as being meaningless. However, I researched the matter and following testing the message turned out to be Morse Code. I tracked down the application for this and cross-checked with the device that had been examined.
So next time you see a text message with an odd presentation look closely to see if it has relevance and whether your mobile phone forensic suite software has the capability to either identify the message contains additional features or can translate the message.
Hope you have enjoyed this brief look at older mobile phones used in and for mobile forensic examination, investigations and research.
Labels:
blackberry,
cell site analysis,
embedded antenna,
Ericsson,
evidence,
examination,
external antenna,
investigation,
Nokia,
phillips,
Research,
RF survey,
Samsung,
secrets,
Sony Ericsson,
text messages
Wednesday, June 22, 2016
Vacancy - Senior Evidence Handling Analyst
If you are interested in getting into Corporate investigations evidence handling, here is a good opportunity. Contact: Scott Barlow Corporate Recruiter at Epiq Systems.
https://epiqsystems.tms.hrdepartment.com/jobs/1103/Senior-Evidence-Handling-AnalystLondon-London
Senior Evidence Handling Analyst
The Senior Evidence Handling Analyst works as a member of the Operations team within Epiq's Electronic Discovery division in London, UK. This is a role for someone who has developed a high level of expertise and experience particularly in the left-hand side of the EDRM operational workflow as practiced at Epiq Systems. The purpose of this position is to provide hands-on operational support, pass on expertise to associates, support learning and development, ensure best practices and quality standards are applied and adhered to, whilst also acting as an individual contributor within Operations on the full range of activities and tasks applicable to evidence collection, handling and management.
Essential Job Responsibilities
Requirements for the role include:
Epiq Systems solves problems faced by the legal profession in managing high volume, complex electronic data. We serve corporations and law firms around the world in practice areas spanning bankruptcy, litigation, class action, mass tort, antitrust, investigations and regulatory compliance.
Epiq combines proprietary software, deep subject matter expertise and a global infrastructure to assist clients with the technology requirements for their most important and complex matters. Our clients include top worldwide law firms, corporate legal departments, government agencies and trustees.
We strive for a cohesive, collaborative environment that focuses on group achievement.
Epiq is a NASDAQ listed company (EPIQ) with over 1400 associates worldwide. Epiq operates globally with key offices in Hong Kong, Kansas City (corporate headquarters), London, New York, Phoenix, Shanghai (data center only), Tokyo, Toronto and Washington, D.C.
https://epiqsystems.tms.hrdepartment.com/jobs/1103/Senior-Evidence-Handling-AnalystLondon-London
Senior Evidence Handling Analyst
Job Code : 1103
Division : Epiq eDiscovery Solutions (EDS)
Location : London London UK EC2R 8DU
Job Type : Full Time
Career Level : Experienced (Non-Manager)
Education : Bachelor's Degree
Category : Legal
Job Description :
The Senior Evidence Handling Analyst works as a member of the Operations team within Epiq's Electronic Discovery division in London, UK. This is a role for someone who has developed a high level of expertise and experience particularly in the left-hand side of the EDRM operational workflow as practiced at Epiq Systems. The purpose of this position is to provide hands-on operational support, pass on expertise to associates, support learning and development, ensure best practices and quality standards are applied and adhered to, whilst also acting as an individual contributor within Operations on the full range of activities and tasks applicable to evidence collection, handling and management.
Essential Job Responsibilities
- Utilise proprietary software applications, 3rd party forensic and eDiscovery applications, electronic discovery and data recovery processes.
- Participate in evidence collections; handle and create evidential media in a legally defensible manner.
- Work closely with team members to troubleshoot issues (prior to escalation to operations senior management and/or IT/Development), research software and/or techniques to solve problems, and carry out complex data analysis tasks.
- Communicate and collaborate with other company departments.
- Generate reports from various database platforms for senior management.
- Become a subject-matter expert (SME) in the left-hand side of the EDRM as practiced at Epiq Systems. Make SME available by consulting on projects, planning meetings, client requirements and solution design as required.
- Create and lead training sessions for Associates in SME areas as requested by Management. Be responsible for the creation and management of Standard Operating Procedures (SOPs) for their SME areas, including but not limited to policies, procedures, workflows and work instructions. Ensure reference documentation is maintained and easily findable. Contribute to the development and implementation of a Knowledge Management (KM) strategy.
- Manage, drive, and implement department initiatives around planning, documentation, procedures and Continuous Improvement, and ensure compliance with policies, procedures and work instructions.
- Promote the company’s culture and values through leadership-by-example, group interaction, and frequent one-on-one coaching with associates at every level.
Job Requirements :
Requirements for the role include:
- At least three years’ experience working in an industry-related role that is review-based, deadline driven and outcome oriented including a solid understanding of the data collection, processing, litigation support and document review processes.
- Hands-on experience with industry standard forensic software, maintenance of chain of evidence and handling of evidential media.
- Willingness to travel up to 25% of the time in support of onsite evidence collections, including overseas.
- Must possess a strong desire to learn new skills.
- Must display excellent verbal and written communication.
- Must work well in a team environment but also independently.
- Demonstrable experience implementing process improvement and compliance.
- Must have a demonstrable ability to effectively lead and manage the productivity of the team, incidents, and drive to problem resolutions.
- Must be able to facilitate solutions across departments and teams in a collaborative manner.
- Must be able to anticipate and prevent problems while assisting in managing incidents to resolution.
- Experience of working under tight deadlines in a fast-paced environment.
- Strong communication, situational awareness and organizational agility skills.
- Must be self-directed and foster initiative in others.
- Must be able to translate larger business goals into actionable items for their team.
- Demonstrable experience with training and developing team members using an inspirational and motivational approach that aligns with Epiq’s unique organizational culture.
- Bachelor’s degree in Computer Science, Business Management or a closely related field of study or an equivalent combination of education and experience, OR;
- A degree or certification in law or a legal field (complemented by suitable technical expertise)
- Experience of collaborating across shifts is desirable.
- A solid understanding of all Microsoft Office applications, Windows, Mac, Linux, server OS, hardware & networking.
- Familiarity with the eDiscovery industry – Electronic Discovery Reference Model (EDRM), technology, global legal framework and competitive landscape.
- Knowledge of litigation support software, including any of the following: DocuMatrix, Relativity, Concordance, Summation, Ipro, Ringtail, and Introspect.
- Deep experience of computer forensics, collections and evidence handling – including formal certifications if available.
- Coaching for Results - Provides timely guidance and feedback to help others strengthen specific knowledge and/or skill areas necessary to accomplish specific objectives or tasks; helps to clarify the situation and expected behaviors; provides instruction and opportunities for observation; provides on-going feedback and reinforcement
- Managing Performance - Ensures that associates have clear goals and objectives, expectations and measures of success for projects and tasks; clearly assigns or delegates responsibility for tasks and assignments; monitors the process of work as well as progress toward completion and final results; provides specific performance feedback, both positive and corrective, as soon as possible after event
- Developing Others - Provides support and direction towards the development of individuals’ knowledge and skills to effectively facilitate their accomplishment of both current and future job responsibilities; partners with individuals on identifying and setting development goals; helps to identify development opportunities as part of the plan; provides continuous feedback on performance and progress and assists in the adjustment of development plans; ensures management team adheres to business defined talent management practices and procedures
- Fosters Teamwork - provides opportunities for people to learn to work together as a team; promotes cooperation with other departments; recognizes and encourages the behaviors that contribute to teamwork, continuous support and removal of barriers, appropriately involves team members in decisions and leverages unique talents of the team
- Empowering Others - Gives people latitude to make decisions based on their level and area of responsibility and level of knowledge and skills; encourages individuals and groups to set their own goals, consistent with business goals; expresses confidence in the ability of others to be successful; encourages groups to resolve problems on their own; avoids prescribing a solution
Epiq Systems solves problems faced by the legal profession in managing high volume, complex electronic data. We serve corporations and law firms around the world in practice areas spanning bankruptcy, litigation, class action, mass tort, antitrust, investigations and regulatory compliance.
Epiq combines proprietary software, deep subject matter expertise and a global infrastructure to assist clients with the technology requirements for their most important and complex matters. Our clients include top worldwide law firms, corporate legal departments, government agencies and trustees.
We strive for a cohesive, collaborative environment that focuses on group achievement.
Epiq is a NASDAQ listed company (EPIQ) with over 1400 associates worldwide. Epiq operates globally with key offices in Hong Kong, Kansas City (corporate headquarters), London, New York, Phoenix, Shanghai (data center only), Tokyo, Toronto and Washington, D.C.
Saturday, March 19, 2016
Exploration - missing the micro-evidence
If you are new to or have all but forgotten the humble (U)SIM Card now maybe as good time as any to refresh on the physical state of (U)SIM Card, in particular the hardware, so to speak.
To assist that refresh process, below are links to previously published materials that investigators and examiners might find useful:
http://trewmte.blogspot.co.uk/2013/09/usim-examination-physical-pt1.html
http://trewmte.blogspot.co.uk/2013/09/usim-examination-physical-pt2.html
It has been noted that such is the sophistication of attackers skillsets in areas, e.g. in-card listening devices, the skillsets applied borders on high-academic results that to the untrained eye could miss a forgery. [Images courtesy of Houda Ferradi, Rémi Gérau d, David Naccache, and Assia Tria: When Organized Crime Applies Academic Results. A Forensic Analysis of an In-Card Listening Device]
To assist that refresh process, below are links to previously published materials that investigators and examiners might find useful:
http://trewmte.blogspot.co.uk/2013/09/usim-examination-physical-pt1.html
http://trewmte.blogspot.co.uk/2013/09/usim-examination-physical-pt2.html
It has been noted that such is the sophistication of attackers skillsets in areas, e.g. in-card listening devices, the skillsets applied borders on high-academic results that to the untrained eye could miss a forgery. [Images courtesy of Houda Ferradi, Rémi Gérau d, David Naccache, and Assia Tria: When Organized Crime Applies Academic Results. A Forensic Analysis of an In-Card Listening Device]
Hope this helps
Saturday, April 04, 2015
Android Botnet for SMS
Another area where SMS text messages may not have received as much scrutiny is regarding messages sent by mobile botnets. If I may I will re-emphasise the following point, the purpose of the discussions here and below are not as a criticism about tools or processes that are used in extracting, harvesting and/or treating recovered data but that data analysis is still required and cannot be rushed. If the examiner doesn't perform the analysis task does the officer or investigator (who may have considerably less experience) left to perform that role?
To avoid confusion a starting point about reference to botnets is required. One contribution is this intro into botnets: https://www.usenix.org/legacy/event/leet11/tech/slides/xiang.pdf
The video below shows how one hacker, Georgia Weidman (2011), developed an Android Smartphone Botnet to send SMS text messages.
A brief description of the code (botPoCrelease-android.c) that use the smartphone to spawn messages using a Master/Slave/Target combination to hide the identity of the Master to the Slave.
==============================================================
Compile with arm-gcc with the -static flag set
Copy to anywhere on the underlying OS that is writable (/data/ is good).
Rename /dev/smd0/ to /dev/smd0real/
Start the bot application
Kill the radio application (ps | grep rild)
The radio will automatically respawn and now the bot proxy will be working
==============================================================
The original botnet code has been in the hacking community since 2011 but currently the code is hard to find. There is a sanitised version available though.
This proof of concept mobile botnet to generate SMS text messages still relies upon knowing the target's mobile number. The analysis thus focussing on the sending party (Master) knowing the recipient mobile number (Target) to hand to the donor (Slave). In the alternative, harvested mobile numbers returned from ICMP (or similar) pings via the internet could generate a high harvest of returned MSISDNs without the Target knowing his/her MSISDN has been acquired to send messages(SMS spam, etc.).
To avoid confusion a starting point about reference to botnets is required. One contribution is this intro into botnets: https://www.usenix.org/legacy/event/leet11/tech/slides/xiang.pdf
The video below shows how one hacker, Georgia Weidman (2011), developed an Android Smartphone Botnet to send SMS text messages.
A brief description of the code (botPoCrelease-android.c) that use the smartphone to spawn messages using a Master/Slave/Target combination to hide the identity of the Master to the Slave.
==============================================================
Compile with arm-gcc with the -static flag set
Copy to anywhere on the underlying OS that is writable (/data/ is good).
Rename /dev/smd0/ to /dev/smd0real/
Start the bot application
Kill the radio application (ps | grep rild)
The radio will automatically respawn and now the bot proxy will be working
==============================================================
The original botnet code has been in the hacking community since 2011 but currently the code is hard to find. There is a sanitised version available though.
This proof of concept mobile botnet to generate SMS text messages still relies upon knowing the target's mobile number. The analysis thus focussing on the sending party (Master) knowing the recipient mobile number (Target) to hand to the donor (Slave). In the alternative, harvested mobile numbers returned from ICMP (or similar) pings via the internet could generate a high harvest of returned MSISDNs without the Target knowing his/her MSISDN has been acquired to send messages(SMS spam, etc.).
Thursday, March 19, 2015
Emotion Icons
From a recent discussion about knowledge/skills and experience and operators of forensics tools having a range of training, contributors comments varied as to exactly where the demarcation line lay regarding 'competence'. That is how far should an examiner go to valid the extracted and harvested data from a mobile phone. Bits and Bytes levels, carving out etc. brought some responses suggesting these were not seen as paramount to know, which seemed to me to suggest, at any rate, reliance on the forensic tool to get it right.
A couple of observations I raised were these:
Some examples of required technical competence
(c) Good example of checking the tool's output can be seen when cross-checking the output on the physical mobile handset device. Take the standard Smart Messaging which can contain images. The tool extracts and the output is harvested. The image shown by the tool is not always the same as shown on the mobile phone. Why? Proprietary applications that reside on the handset are not the same as on the tool? A smart messaging image can be interpreted differently by another make/model of handsets? Or did the tech / examiner incorrectly perform the extract and harvesting properly? So where would blame lay in a situation like this?
I have added an example for a Phillips Savvy mobile phone 1999 (from 15 years ago) when it was known makes/models handle emotion icons (emoticons) differently.
A couple of observations I raised were these:
Some examples of required technical competence
(c) Good example of checking the tool's output can be seen when cross-checking the output on the physical mobile handset device. Take the standard Smart Messaging which can contain images. The tool extracts and the output is harvested. The image shown by the tool is not always the same as shown on the mobile phone. Why? Proprietary applications that reside on the handset are not the same as on the tool? A smart messaging image can be interpreted differently by another make/model of handsets? Or did the tech / examiner incorrectly perform the extract and harvesting properly? So where would blame lay in a situation like this?
I have added an example for a Phillips Savvy mobile phone 1999 (from 15 years ago) when it was known makes/models handle emotion icons (emoticons) differently.

(d) Remaining with SMS text you may know about 7-bit, 8-bit and 16-bit encoding for SMS text messages. But how about variations such as Fernschreiber 5-bit encoding that can be used in SMS PDU mode allowing one single message to contain 244 characters. A user may send one text but with 7-bit encoding (244 characters) but the mobile phone sends this as a GSM concatenated text message e.g. in say 2 messages (concatenation of messages can be up to max: 255 messages). Does the tech / examiner immediately mistake the 5-bit 244 character message as a concatenated message?
I choose these observations because they highlight how deceptive recovered data can be when viewed through the GUI of the tool used to extract and harvest data. Viewing recovered data can be a trompe l'oiel (a lie to the eye) if as examiners we merely accept on the face of it what the tool tells us. Additionally, a tool cannot encompass all a mobile's features or its interpretation libraries associated with particular data.
The emotion icons discussion interested me because on first blush emoticons may be perceived as simple smiley faces and different Unicode characters etc. However, with Emotion Icons and Emoji widely in use on mobile devices Emoji can also e.g. be used for encrypting messages; which takes these icons into a completely different ball park when it comes to evidence. Another example for the potential for mistaken identity about the meaning of the data.
https://itunes.apple.com/us/app/hidemessage-pro-send-private/id648699383?mt=8
http://www.quora.com/Some-mobile-apps-allow-you-to-encrypt-text-messages-in-emojis-I-need-to-decipher-a-long-sequence-of-seemingly-random-black-white-red-and-blue-circles-Is-it-likely-that-this-message-is-encrypted-in-emojis-If-it-is-how-should-I-go-about-trying-to-decrypt-this-and-other-emoji-encrypted-messages
http://www.appszoom.com/iphone-apps/business/hidemessage-encrypt-secret-private-messages-into-emoticons-for-chat_ghosb.html
Wednesday, January 01, 2014
Cell Site Analysis Discussions
Cell Site Analysis Discussions
CSA related items
http://cellsiteanalysis.blogspot.co.uk/2013/12/csa-related-items.html
Location Tracking in the US
http://cellsiteanalysis.blogspot.co.uk/2013/12/location-tracking-in-us.html
CSA related items
http://cellsiteanalysis.blogspot.co.uk/2013/12/csa-related-items.html
Location Tracking in the US
http://cellsiteanalysis.blogspot.co.uk/2013/12/location-tracking-in-us.html
Monday, December 30, 2013
Location Tracking in the US
We have all read various views expressed by those involved in the US that location data are not kept and it is all too difficult to get any sort of data. Have a read of the article below and maybe ask yourself if the authors of this article are aware that such location data does exists and are retained why others have expressed in other forums such data doesn't exist or if the data did exist the location data isn't retained.
Government Location Tracking: Cell Phones, GPS Devices, and License Plate Readers:
https://www.aclu.org/government-location-tracking-cell-phones-gps-devices-and-license-plate-readers
Government Location Tracking: Cell Phones, GPS Devices, and License Plate Readers:
https://www.aclu.org/government-location-tracking-cell-phones-gps-devices-and-license-plate-readers
Sunday, November 03, 2013
Directed Retry
A fundamental and vital goal of any mobile communication network is to maintain communications between the network and the mobile station (MS), whether the MS is dwelling in an area or on the move. To assist the aims and objectives GSM is commonly known to use 'Handover' for which there is a specific GSM standard TS03.09 [cf W-CDMA see 3GPP TS23.009].
The assumption being made for these cause values is that the MS is seeking to obtain a service for speech calls
│7 6 5│ 4 3 2 1│ │
│
│0 0 0│0 0 0 0│ │Radio interface message failure │
│
│0 0 0│0 0 0 1│ │Radio interface failure │
│
│0 0 0│0 0 1 0│ │Uplink quality │
│
│0 0 0│0 0 1 1│ │Uplink strength │
│
│0 0 0│0 1 0 0│ │Downlink quality │
│
│0 0 0│0 1 0 1│ │Downlink strength │
│
│0 0 0│0 1 1 0│ │Distance │
│
│0 0 0│0 1 1 1│ │O and M intervention │
│
│0 0 0│1 0 0 0│ │Response to MSC invocation │
│
│0 0 0│1 0 0 1│ │Call control │
│
│0 0 0│1 0 1 0│ │Radio interface failure, reversion to old channel │
│
│0 0 0│1 0 1 1│ ││
│
│0 0 0│1 1 0 0│ │Better Cell │
│
│0 0 0│1 1 0 1│ │Directed Retry │
│
│0 0 0│1 1 1 0│ ││
│
│0 0 0│1 1 1 1│ │Traffic
Key and germane to handover being successful is that operators can use various handover techniques controlled by handover triggering algorithms. These triggers activiate when detection mechanisms identify propagation or network conditions at the existing cell or for the target cell where neither meet a set criteria for usage. One such condition is referred to by Professor Sami Tabbane in Management of Radio Mobility: The Handover Procedure - 8.1.4.2 Intercell and Intra-BSC Handover "A handover that is triggered for reasons of traffic loading and occurs during call setup is called directed retry."
Examiners are expected to know about Directed Retry, to take account of its possibility when conducting CSA (cell site analysis) investigations and understand its influence and impact on evidence record in call records and associated cell data. A point of contention in evidence for often arises where a defendant states "I was not at the location claimed by the prosecution but was in a different area". Invariably this receives a response "Why does your mobile use the radio coverage from a particular sector (azimuth) from a particular fixed mast (BTS)?" Directed retry makes possible the scenario of having a mobile phone in an adjacent cell from the one shown in the call records. Directed Retry is not a trigger simply triggering every few minutes but arises as Professor Tabbane records, due to traffic loading at the time of call setup.
A mistake that experts and investigators could make would be to ignore the existence of Directed Retry and, even more problematical, not to have asked the question was Directed Retry active at cell/BSC level at the material time of the calls, apart from any intervention within the network.
GSM standards make Directed Retry explicit that which might be implicit to for a GSM radio location area. This logically raises questions how can Directed Retry be configured and activated? Mobile network radio equipment manufacturers offer the capability in their equipment for mobile network engineers to radio fine tune post-installation, and the parameters that can be fine tuned are the Handover triggers of which Directed Retry is one such trigger:
As each equipment manufacturer vary the way fine tuning may be implemented using a GUI to input the trigger parameters is one methiod. Another is to incorporate data into the .mdb or .xls file which has been scripted to produce e.g. an .xml output for uplifting to the radio base station database. This means Directed Retry can be checked that it is active in a particular GSM radio location area. Furthermore, due to continuing radio fine tuning updates to the trigger parameters can occur and older versions of .mdb/.xls maybe recovered from archive.
Experts and Investigators will need to be aware of the triggers Directed Retry (DR) and Forced Directed Retry (FDR) and identify when, in a mobile network, either of these triggers would be implemented and activated for the radio network. This equally means tracking down the equipment manufacturers that offer one form or another or both forms of Directed Retry.
The assumption being made for these cause values is that the MS is seeking to obtain a service for speech calls
│7 6 5│ 4 3 2 1│ │
│
│0 0 0│0 0 0 0│ │Radio interface message failure │
│
│0 0 0│0 0 0 1│ │Radio interface failure │
│
│0 0 0│0 0 1 0│ │Uplink quality │
│
│0 0 0│0 0 1 1│ │Uplink strength │
│
│0 0 0│0 1 0 0│ │Downlink quality │
│
│0 0 0│0 1 0 1│ │Downlink strength │
│
│0 0 0│0 1 1 0│ │Distance │
│
│0 0 0│0 1 1 1│ │O and M intervention │
│
│0 0 0│1 0 0 0│ │Response to MSC invocation │
│
│0 0 0│1 0 0 1│ │Call control │
│
│0 0 0│1 0 1 0│ │Radio interface failure, reversion to old channel │
│
│0 0 0│1 0 1 1│ ││
│
│0 0 0│1 1 0 0│ │Better Cell │
│
│0 0 0│1 1 0 1│ │Directed Retry │
│
│0 0 0│1 1 1 0│ ││
│
│0 0 0│1 1 1 1│ │Traffic
Key and germane to handover being successful is that operators can use various handover techniques controlled by handover triggering algorithms. These triggers activiate when detection mechanisms identify propagation or network conditions at the existing cell or for the target cell where neither meet a set criteria for usage. One such condition is referred to by Professor Sami Tabbane in Management of Radio Mobility: The Handover Procedure - 8.1.4.2 Intercell and Intra-BSC Handover "A handover that is triggered for reasons of traffic loading and occurs during call setup is called directed retry."
Examiners are expected to know about Directed Retry, to take account of its possibility when conducting CSA (cell site analysis) investigations and understand its influence and impact on evidence record in call records and associated cell data. A point of contention in evidence for often arises where a defendant states "I was not at the location claimed by the prosecution but was in a different area". Invariably this receives a response "Why does your mobile use the radio coverage from a particular sector (azimuth) from a particular fixed mast (BTS)?" Directed retry makes possible the scenario of having a mobile phone in an adjacent cell from the one shown in the call records. Directed Retry is not a trigger simply triggering every few minutes but arises as Professor Tabbane records, due to traffic loading at the time of call setup.
A mistake that experts and investigators could make would be to ignore the existence of Directed Retry and, even more problematical, not to have asked the question was Directed Retry active at cell/BSC level at the material time of the calls, apart from any intervention within the network.
GSM standards make Directed Retry explicit that which might be implicit to for a GSM radio location area. This logically raises questions how can Directed Retry be configured and activated? Mobile network radio equipment manufacturers offer the capability in their equipment for mobile network engineers to radio fine tune post-installation, and the parameters that can be fine tuned are the Handover triggers of which Directed Retry is one such trigger:
As each equipment manufacturer vary the way fine tuning may be implemented using a GUI to input the trigger parameters is one methiod. Another is to incorporate data into the .mdb or .xls file which has been scripted to produce e.g. an .xml output for uplifting to the radio base station database. This means Directed Retry can be checked that it is active in a particular GSM radio location area. Furthermore, due to continuing radio fine tuning updates to the trigger parameters can occur and older versions of .mdb/.xls maybe recovered from archive.
Experts and Investigators will need to be aware of the triggers Directed Retry (DR) and Forced Directed Retry (FDR) and identify when, in a mobile network, either of these triggers would be implemented and activated for the radio network. This equally means tracking down the equipment manufacturers that offer one form or another or both forms of Directed Retry.
Sunday, October 06, 2013
(U)ICC/(U)SIM Script Commands and Responses
(U)ICC/(U)SIM Script Commands and Responses
The discussion under (U)ICC/(U)SIM Script Commands and Responses is one of a number that will appear to assist Diploma students with their course work.
http://sim2usim.blogspot.co.uk/2013/10/uiccusim-script-commands-and-responses.html
The discussion under (U)ICC/(U)SIM Script Commands and Responses is one of a number that will appear to assist Diploma students with their course work.
http://sim2usim.blogspot.co.uk/2013/10/uiccusim-script-commands-and-responses.html
Labels:
3GPP/3GPP2,
ARIB,
CCSA,
Dedicated File,
Diploma,
Elementary Files,
EU,
evidence,
examination procedure,
GSMA,
ICC,
Master File,
SIM,
TIA TTA,
TTC,
UICC,
US,
USIM
(U)ICC/(U)SIM Script Commands and Responses
(U)ICC/(U)SIM 3F00 7F10 6F4A
3GPP UICC/USIM script selecting Master File, Dedicated File and Elementary File
GSM ICC/SIM script selecting Master File, Dedicated File and Elementary File
Reason for script test : defining an examination procedure to isolate and test a single elementary file; determine the EF's status, file structure, coding etc; conrroborate the ability of the (U)ICC/(U)SIM to action responses from commands sent to card; provide corroborating evidence of commands sent to the card to demonstrate evidential integrity (transparency of practices and procedures); testing the examination card reader is functioning correctly; QA procedures.
Script examination tool used : USIM Commander - http://www.quantaq.com/usimcommander.htm
Relevant Core Diplomas:-
Aims : MTEB Diploma for Mobile Evidence QA and Evidence Handling - Mobile Telephone Diploma Core CQAE1
Objectives : Device Maintenance and Calibration; Examination Procedure
Aims : MTEB Diploma for SIM and USIM Technology Examination - Mobile Telephone
Diploma Core CSUT2
Objectives : Your understanding of roles and responsibilities and the importance of
appropriate practices and procedures for SIM and USIM Technology
Examination for acquiring evidence.
Reference Standards :
GSM11.11/3GPP TS51.011/3GPP TS31.102,
GSM11.12,
GSM11.17/3GPP TS51.017/3GPP TS31.120/3GPP TS31.121/3GPP TS31.122,
GSM11.18/3GPP31.101,
EU MTEB Diploma Student Note : Remember to check with ETSI Standards e.g. TS102.221 etc
US MTEB Diploma Student Note : Diploma Students remember to check e.g. C.S0065-0 v1.0, C.S0074-0 v1.0, C.S0074-A v1.0, N.S0009-0 v1.0, S.R0095-0 v1.0 etc
Generically speaking, apart from GSMA and 3GPP, there is also 3GPP2 which also includes ARIB, CCSA, TIA TTA, TTC that all have conditions that can impact/influence results on (U)ICC/(U)SIM.
The discussion under (U)ICC/(U)SIM Script Commands and Responses is one of a number that will appear here to assist Diploma students with their course work.
The latest MTEB Diploma Modules Guide MTEdipl 2.2 can be downloaded here:
https://dl.dropboxusercontent.com/u/84491783/MTEdipl%202.2.pdf
Labels:
3GPP/3GPP2,
ARIB,
CCSA,
Dedicated File,
Diploma,
Elementary Files,
EU,
evidence,
examination procedure,
GSMA,
ICC,
Master File,
SIM,
TIA TTA,
TTC,
UICC,
US,
USIM
Subscribe to:
Posts (Atom)














