Carving JSON in heap dumps
- Track: Open Source Digital Forensics
- Room: UB4.132
- Day: Sunday
- Start: 09:00
- End: 09:20
- Video only: ub4132
- Chat: Join the conversation!
There are lots of carving tools out there, but surprisingly there's no open-source one for carving JSON objects. Reporters United, a network of investigative reporters in Greece, wrote json-carver as part of our investigation into the Telemessage leaks. json-carver is a FOSS tool written in Rust, that can recover JSON objects from any binary stream, even partially-corrupted ones.
We'll discuss the role of this tool in our investigation, compare its accuracy and speed against strings(1), and show how to use this tool in any of your future investigations.
Speakers
| Hunter Domson |