Pegasus Detection and Analysis 26 Workshop: Difference between revisions
No edit summary |
|||
| (36 intermediate revisions by the same user not shown) | |||
| Line 1: | Line 1: | ||
= Pegasus Detection and Analysis | = Pegasus Detection and Analysis Lab = | ||
[[File:Amnesty-international.png|thumb]] | |||
[[File:Mvt.png|thumb]]<br> | |||
== Abstract == | == Abstract == | ||
This | This lab will be using Amnesty International’s '''Mobile Verification Toolkit''' (MVT) to see if your Android or iOS has been compromised by Pegasus. The lab will open with a short overview on mobile spyware and general principles of communications security. Note: The presenters of this lab do not consent to mechanical recording of their presentation, but feel free to take notes. | ||
== Day / Time / Location == | == Day / Time / Location == | ||
| Line 9: | Line 12: | ||
Day 3, Sunday, 16-August-2026, 12:30pm - 3:30pm<br> | Day 3, Sunday, 16-August-2026, 12:30pm - 3:30pm<br> | ||
Workshop A (Sutton Place, third floor) | Workshop A (Sutton Place, third floor) | ||
== Registration -- NOT required == | == Registration -- NOT required == | ||
| Line 18: | Line 17: | ||
<span style="color:orange">'''NOTE: You do NOT need to register to take this workshop<br>-- please show up early to ensure a seat at the WORKSHOP A room (in Sutton Place, on the third floor).'''<br> | <span style="color:orange">'''NOTE: You do NOT need to register to take this workshop<br>-- please show up early to ensure a seat at the WORKSHOP A room (in Sutton Place, on the third floor).'''<br> | ||
== | == Expected Skill Level or Experience == | ||
Open to all skill levels, provided you are comfortable navigating your Linux or BSD laptop. There will be assistants present to provide help. | |||
== '''<span style="color:red">Required Software and Hardware / What to bring</span>''' == | |||
* A fully-charged laptop that uses an open source operating system (Linux or BSD...) that you have the root password for. Updates should have been applied before the lab and the laptop's personal firewall (like "ufw"...) should be enabled. | |||
* DNS for the laptop operating system should be using either '''DNS over https''' ("'''DoH'''") or "'''unbound'''" using a trusted DNS server. C.f., [https://oneuptime.com/blog/post/2026-03-20-setup-dns-over-https-linux/view '''''How to Set Up DNS over HTTPS (DoH) on Linux'''''] or [https://unbound.docs.nlnetlabs.nl/en/latest/getting-started/installation.html '''the unbound documentation'''] | |||
''' | |||
''' | |||
* Installation of python 3.X and pip 3 (or an equivalent python module installer that works for you...) on the laptop to be used. | |||
* A fully-charged Android or iOS phone that you want to diagnose and that you have the password for. | * A fully-charged Android or iOS phone that you want to diagnose and that you have the password for. | ||
* A USB DATA cable (not a charging one...) of '''''KNOWN PROVENANCE!''''' (a commercial brand you bought from microcenter, etc.) Check that the gender and USB types will be appropriate for connecting the laptop to the phone (e.g., male A to male C, male C to male C, etc. '''It is recommended that you make sure you have a ''data'' cable by attempting a file transfer to/from your laptop to the phone.''' | * A USB '''''DATA''''' cable (not a charging one...) of '''''KNOWN PROVENANCE!''''' (a commercial brand you bought from microcenter, etc.) Check that the gender and USB types will be appropriate for connecting the laptop to the phone (e.g., male A to male C, male C to male C, male micro to male A, etc.) '''It is recommended that you make sure you have a ''data'' cable by attempting a file transfer to/from your laptop to the phone before attending.''' | ||
'''Note: Since pegasus uses a "zero-click" attack vector, aluminum foil will be provided for the more paranoid attendees, allowing them to construct a makeshift Faraday cage for their phones.''' Of course if you are a pro and have a Faraday bag, you are welcome to bring that. | |||
== '''Recommended Videos''' == | |||
* [https://www.youtube.com/watch?v=Pc-rWN-k4Xo '''60 Minutes Archive: NSO Group's "Pegasus"'''] | * [https://www.youtube.com/watch?v=Pc-rWN-k4Xo '''60 Minutes Archive: NSO Group's "Pegasus"'''] | ||
| Line 55: | Line 45: | ||
* [https://www.youtube.com/watch?v=I5WjTTi67BE '''Snowden on Pegasus spyware: 'This is an industry that should not exist''''] | * [https://www.youtube.com/watch?v=I5WjTTi67BE '''Snowden on Pegasus spyware: 'This is an industry that should not exist''''] | ||
== Presenter == | |||
'''Steve B.:''' Steve is a software developer of over 30 years and has a fair amount of experience with Linux (including Linux firewalls...). A friend who is an activist came to him with their phone and asked if he could use Amnesty International's Mobile Verification Toolkit (MVT) to see if it was compromised -and it was! And that's why he is offering his services to conduct this lab. | |||
== Assistants == | |||
'''Matt H.:''' Matt is currently a comp sci major at CUNY Brooklyn, and has a fair amount of experience with python and django (the MVT is written in python...)<br><br> | |||
<!-- | |||
'''Gabe R.:''' Gabe spends much of his time exploring the latest distros. He also loves meshtastic, which offers superior privacy to android. He feels it is a promising alternative to traditional text messaging as it's a decentralized platform that can be used with no registration and has a strong potential to not have personal information tied to senders and recipients.<br> | |||
--> | |||
'''Steven S.''': Steve is a cybersecurity researcher who has a lot of Linux experience. | |||
== Links == | |||
* '''<span style="font-size: 110%">Hope Pegasus Detection and Analysis Lab git</span>''' | |||
==== '''Android''' ==== | |||
* [https://github.com/mvt-project/mvt '''Mobile Verification Toolkit'''] | |||
* [https://github.com/mvt-project/androidqf/releases/latest '''Android Quick Forensics'''] | |||
==== '''iOS''' ==== | |||
* [https://libimobiledevice.org '''libimobiledevice'''] | |||
* [https://github.com/securitywithoutborders/guide-to-quick-forensics/blob/master/ios/extract.md '''Guide to iOS quick Forensics'''] | |||
=== '''Hardware-based Data Recovery''' === | |||
'''<span style="color: red;">NOTE: Not an endorsement! Research these labs on your own.</span>''' | |||
[https://mdrepairs.com/cell-phone-data-recovery-palo-alto-california '''MD Repairs'''] | |||
==== '''Android''' ==== | |||
* [https://www.youtube.com/watch?v=nXDUhhyY2rE '''HDD Recovery Services: recover data Samsung Galaxy directly from phone memory (video)'''] | |||
* [https://www.datarecovery.net/android-data-recovery.aspx '''Ace Data Recovery'''] | |||
* [https://www.datarescuelabs.com/data-recovery-toronto/android-data-recovery '''DRL Data Rescue Labs'''] | |||
* [https://www.gillware.com/data-recovery-lab '''Gillware'''] | |||
Latest revision as of 02:11, 7 August 2026
Pegasus Detection and Analysis Lab


Abstract
This lab will be using Amnesty International’s Mobile Verification Toolkit (MVT) to see if your Android or iOS has been compromised by Pegasus. The lab will open with a short overview on mobile spyware and general principles of communications security. Note: The presenters of this lab do not consent to mechanical recording of their presentation, but feel free to take notes.
Day / Time / Location
Day 3, Sunday, 16-August-2026, 12:30pm - 3:30pm
Workshop A (Sutton Place, third floor)
Registration -- NOT required
NOTE: You do NOT need to register to take this workshop
-- please show up early to ensure a seat at the WORKSHOP A room (in Sutton Place, on the third floor).
Expected Skill Level or Experience
Open to all skill levels, provided you are comfortable navigating your Linux or BSD laptop. There will be assistants present to provide help.
Required Software and Hardware / What to bring
- A fully-charged laptop that uses an open source operating system (Linux or BSD...) that you have the root password for. Updates should have been applied before the lab and the laptop's personal firewall (like "ufw"...) should be enabled.
- DNS for the laptop operating system should be using either DNS over https ("DoH") or "unbound" using a trusted DNS server. C.f., How to Set Up DNS over HTTPS (DoH) on Linux or the unbound documentation
- Installation of python 3.X and pip 3 (or an equivalent python module installer that works for you...) on the laptop to be used.
- A fully-charged Android or iOS phone that you want to diagnose and that you have the password for.
- A USB DATA cable (not a charging one...) of KNOWN PROVENANCE! (a commercial brand you bought from microcenter, etc.) Check that the gender and USB types will be appropriate for connecting the laptop to the phone (e.g., male A to male C, male C to male C, male micro to male A, etc.) It is recommended that you make sure you have a data cable by attempting a file transfer to/from your laptop to the phone before attending.
Note: Since pegasus uses a "zero-click" attack vector, aluminum foil will be provided for the more paranoid attendees, allowing them to construct a makeshift Faraday cage for their phones. Of course if you are a pro and have a Faraday bag, you are welcome to bring that.
Recommended Videos
Presenter
Steve B.: Steve is a software developer of over 30 years and has a fair amount of experience with Linux (including Linux firewalls...). A friend who is an activist came to him with their phone and asked if he could use Amnesty International's Mobile Verification Toolkit (MVT) to see if it was compromised -and it was! And that's why he is offering his services to conduct this lab.
Assistants
Matt H.: Matt is currently a comp sci major at CUNY Brooklyn, and has a fair amount of experience with python and django (the MVT is written in python...)
Steven S.: Steve is a cybersecurity researcher who has a lot of Linux experience.
Links
- Hope Pegasus Detection and Analysis Lab git
Android
iOS
Hardware-based Data Recovery
NOTE: Not an endorsement! Research these labs on your own.
