Pegasus Detection and Analysis 26 Workshop: Difference between revisions

From HOPE Wiki
Steveb (talk | contribs)
Steveb (talk | contribs)
No edit summary
 
(4 intermediate revisions by the same user not shown)
Line 33: Line 33:


'''Note: Since pegasus uses a "zero-click" attack vector, aluminum foil will be provided for the more paranoid attendees, allowing them to construct a makeshift Faraday cage for their phones.''' Of course if you are a pro and have a Faraday bag, you are welcome to bring that.
'''Note: Since pegasus uses a "zero-click" attack vector, aluminum foil will be provided for the more paranoid attendees, allowing them to construct a makeshift Faraday cage for their phones.''' Of course if you are a pro and have a Faraday bag, you are welcome to bring that.
== '''Recommended Videos''' ==
* [https://www.youtube.com/watch?v=Pc-rWN-k4Xo '''60 Minutes Archive: NSO Group's "Pegasus"''']
* [https://www.youtube.com/watch?v=lfOgm1IcBd0 '''Al Jazeera: How Israeli technology became one of the world’s most feared spyware''']
* [https://www.youtube.com/watch?v=6ZVj1_SE4Mo '''Frontline: Exposing Pegasus Part One''']
* [https://www.youtube.com/watch?v=xYMWTXIkANM '''Frontline: Exposing Pegasus Part Two''']
* [https://www.youtube.com/watch?v=I5WjTTi67BE '''Snowden on Pegasus spyware: 'This is an industry that should not exist'''']


== Presenter ==
== Presenter ==
Line 47: Line 59:
== Links ==
== Links ==


* '''Hope Pegasus Detection and Analysis Lab git'''
* '''<span style="font-size: 110%">Hope Pegasus Detection and Analysis Lab git</span>'''


===== '''Android''' =====
==== '''Android''' ====


* [https://github.com/mvt-project/mvt '''Mobile Verification Toolkit''']
* [https://github.com/mvt-project/mvt '''Mobile Verification Toolkit''']
Line 55: Line 67:
* [https://github.com/mvt-project/androidqf/releases/latest '''Android Quick Forensics''']
* [https://github.com/mvt-project/androidqf/releases/latest '''Android Quick Forensics''']


==== '''Hardware-based Data Recovery''' ====
==== '''iOS''' ====
 
* [https://libimobiledevice.org '''libimobiledevice''']
 
* [https://github.com/securitywithoutborders/guide-to-quick-forensics/blob/master/ios/extract.md '''Guide to iOS quick Forensics''']
 
=== '''Hardware-based Data Recovery''' ===


'''<span style="color: red;">NOTE: Not an endorsement! Research these labs on your own.</span>'''
'''<span style="color: red;">NOTE: Not an endorsement! Research these labs on your own.</span>'''
Line 61: Line 79:
[https://mdrepairs.com/cell-phone-data-recovery-palo-alto-california '''MD Repairs''']
[https://mdrepairs.com/cell-phone-data-recovery-palo-alto-california '''MD Repairs''']


===== '''Android''' =====
==== '''Android''' ====
* [https://www.youtube.com/watch?v=nXDUhhyY2rE '''recover data Samsung Galaxy directly from phone memory''']
* [https://www.youtube.com/watch?v=nXDUhhyY2rE '''HDD Recovery Services: recover data Samsung Galaxy directly from phone memory (video)''']


* [https://www.datarecovery.net/android-data-recovery.aspx '''Ace Data Recovery''']
* [https://www.datarecovery.net/android-data-recovery.aspx '''Ace Data Recovery''']
Line 69: Line 87:


* [https://www.gillware.com/data-recovery-lab '''Gillware''']
* [https://www.gillware.com/data-recovery-lab '''Gillware''']
===== '''iOS''' =====
* [https://libimobiledevice.org '''libimobiledevice''']
* [https://github.com/securitywithoutborders/guide-to-quick-forensics/blob/master/ios/extract.md '''Guide to iOS quick Forensics''']
===== '''Recommended Videos''' =====
* [https://www.youtube.com/watch?v=Pc-rWN-k4Xo '''60 Minutes Archive: NSO Group's "Pegasus"''']
* [https://www.youtube.com/watch?v=lfOgm1IcBd0 '''Al Jazeera: How Israeli technology became one of the world’s most feared spyware''']
* [https://www.youtube.com/watch?v=6ZVj1_SE4Mo '''Frontline: Exposing Pegasus Part One''']
* [https://www.youtube.com/watch?v=xYMWTXIkANM '''Frontline: Exposing Pegasus Part Two''']
* [https://www.youtube.com/watch?v=I5WjTTi67BE '''Snowden on Pegasus spyware: 'This is an industry that should not exist'''']

Latest revision as of 02:11, 7 August 2026

Pegasus Detection and Analysis Lab


Abstract

This lab will be using Amnesty International’s Mobile Verification Toolkit (MVT) to see if your Android or iOS has been compromised by Pegasus. The lab will open with a short overview on mobile spyware and general principles of communications security. Note: The presenters of this lab do not consent to mechanical recording of their presentation, but feel free to take notes.

Day / Time / Location

Day 3, Sunday, 16-August-2026, 12:30pm - 3:30pm
Workshop A (Sutton Place, third floor)

Registration -- NOT required

NOTE: You do NOT need to register to take this workshop
-- please show up early to ensure a seat at the WORKSHOP A room (in Sutton Place, on the third floor).

Expected Skill Level or Experience

Open to all skill levels, provided you are comfortable navigating your Linux or BSD laptop. There will be assistants present to provide help.

Required Software and Hardware / What to bring

  • A fully-charged laptop that uses an open source operating system (Linux or BSD...) that you have the root password for. Updates should have been applied before the lab and the laptop's personal firewall (like "ufw"...) should be enabled.
  • Installation of python 3.X and pip 3 (or an equivalent python module installer that works for you...) on the laptop to be used.
  • A fully-charged Android or iOS phone that you want to diagnose and that you have the password for.
  • A USB DATA cable (not a charging one...) of KNOWN PROVENANCE! (a commercial brand you bought from microcenter, etc.) Check that the gender and USB types will be appropriate for connecting the laptop to the phone (e.g., male A to male C, male C to male C, male micro to male A, etc.) It is recommended that you make sure you have a data cable by attempting a file transfer to/from your laptop to the phone before attending.

Note: Since pegasus uses a "zero-click" attack vector, aluminum foil will be provided for the more paranoid attendees, allowing them to construct a makeshift Faraday cage for their phones. Of course if you are a pro and have a Faraday bag, you are welcome to bring that.

Recommended Videos

Presenter

Steve B.: Steve is a software developer of over 30 years and has a fair amount of experience with Linux (including Linux firewalls...). A friend who is an activist came to him with their phone and asked if he could use Amnesty International's Mobile Verification Toolkit (MVT) to see if it was compromised -and it was! And that's why he is offering his services to conduct this lab.

Assistants

Matt H.: Matt is currently a comp sci major at CUNY Brooklyn, and has a fair amount of experience with python and django (the MVT is written in python...)

Steven S.: Steve is a cybersecurity researcher who has a lot of Linux experience.

Links

  • Hope Pegasus Detection and Analysis Lab git

Android

iOS

Hardware-based Data Recovery

NOTE: Not an endorsement! Research these labs on your own.

MD Repairs

Android