The Things know What You Did Last Session

Will Baggett (Director of Digital Forensics · Operation Safe Escape)

DEF CON 33 · Day 1 · Main Stage

Overview

Will Baggett's DEF CON talk, "The Things know What You Did Last Session," delves into the critical intersection of digital forensics and the Internet of Things (IoT). Baggett, a seasoned expert with a background spanning NATO, the CIA, and Fortune 25 firms, highlights how seemingly innocuous or overlooked IoT devices are becoming pivotal sources of evidence in complex investigations. The presentation meticulously dissects three distinct, high-impact case studies—a suspicious Chinese voting machine, a sophisticated workplace timecard fraud scheme, and the pervasive issue of North Korean IT worker infiltration—to illustrate the evolving landscape of digital forensics.

Watch on YouTube

Visual summary for The Things know What You Did Last Session by Will Baggett
Visual summary for The Things know What You Did Last Session by Will Baggett

Key moments

  1. 0:00 Speaker introduction, background, and talk overview
  2. 0:37 Talk agenda: Chinese voting machine, fraud, N. Korean IT
  3. 4:00 Debunking voting machine 'hacks' with Rick Astley example
  4. 4:30 Chinese voting machine prototype features: camera, fingerprint, ID scan
  5. 5:40 Non-public manual and problematic thermal paper receipts
  6. 6:50 Discovery of unexpected Android board and chip-off extraction
  7. 8:00 Voting machine's extensive, problematic connectivity (Bluetooth, Wi-Fi, 4G)

The Things know What You Did Last Session

Speakers: Will Baggett, Director of Digital Forensics, Operation Safe Escape

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=HqNgsnO5IoU

Overview

Will Baggett's DEF CON talk, "The Things know What You Did Last Session," delves into the critical intersection of digital forensics and the Internet of Things (IoT). Baggett, a seasoned expert with a background spanning NATO, the CIA, and Fortune 25 firms, highlights how seemingly innocuous or overlooked IoT devices are becoming pivotal sources of evidence in complex investigations. The presentation meticulously dissects three distinct, high-impact case studies—a suspicious Chinese voting machine, a sophisticated workplace timecard fraud scheme, and the pervasive issue of North Korean IT worker infiltration—to illustrate the evolving landscape of digital forensics.

The talk underscores that while the technology and devices may change rapidly, the fundamental principles of forensic investigation remain constant. Baggett emphasizes the importance of meticulous data collection, rigorous analysis, and the ability to adapt traditional forensic methodologies to the unique challenges posed by IoT devices, many of which were never designed with security or forensic traceability in mind. This article will explore the technical nuances and practical implications of Baggett's findings, providing actionable insights for forensic practitioners and organizational defenders alike.

Background

▶ Watch: Speaker introduction, background, and talk overview (0:00)

Digital forensics, at its core, adheres to a structured, four-phase process: collection, examination, analysis, and reporting. This systematic approach ensures the integrity and admissibility of evidence. Collection involves acquiring a complete and forensically sound image of data, ensuring it remains unaltered. Examination then delves into this data, seeking relevant artifacts. Analysis interprets these artifacts to reconstruct events, and finally, a comprehensive report documents the findings. A foundational principle, often likened to Locard's Exchange Principle, posits that a perpetrator will always leave something behind and take something with them from a "crime scene," a concept that extends even to digital interactions with IoT devices.

Crucially, forensic soundness demands that investigations be performed by qualified personnel, follow an auditable trail, and produce reproducible findings. Any deviation from these standards can invalidate evidence in legal proceedings. Baggett humorously, yet pointedly, illustrates common pitfalls, such as the misconception that simply copying data onto a device constitutes "hacking," or the dangers of altering evidence—a scenario he recounts from a previous voting village incident where manipulated data led to serious legal consequences for the perpetrator. The talk also stresses the importance of having backup plans for critical forensic tools, adhering to legal frameworks, and understanding that even seemingly trivial actions, like uploading a Rick Astley song to a voting machine, can generate misleading headlines if not properly contextualized within a forensic framework. The emergence of IoT devices, with their diverse operating systems, network connectivity, and often opaque designs, necessitates a renewed focus on these fundamental principles, challenging forensic practitioners to adapt their techniques to a new generation of "things."

Key Findings

▶ Watch: Debunking voting machine 'hacks' with Rick Astley example (4:00)

Baggett's presentation unveils critical findings across three distinct case studies, each highlighting the unique forensic challenges and opportunities presented by IoT devices.

The first case involved a Chinese voting machine prototype acquired by the DEF CON Voting Village. This device, costing $7,000 plus shipping, was ostensibly designed for US elections but exhibited alarming security and privacy vulnerabilities. Key findings included:

  • Non-Standard Features: The machine incorporated a camera to record voters, a fingerprint scanner, and a driver's license scanner—features that directly violate US election laws regarding voter privacy and anonymity.
  • Opaque Supply Chain: The device manual was only available directly from the manufacturer via Alibaba, preventing public scrutiny or open-source community investigation. Drivers and patches were distributed on a per-precinct basis, hindering independent security audits.
  • Unexpected Hardware/Software: Despite its specialized purpose, the machine ran on a standard Android board with Android 7.1 OS, a surprising finding for a high-security device.
  • Extensive Connectivity: It featured Bluetooth, Wi-Fi, and 4G capabilities, along with a "bevy of ports," raising concerns about unauthorized external communication and control.
  • Forensic Discovery: A chip-off extraction was necessary to acquire data, revealing a massive 1283.8 GB wall of text. Analysis using the National Institute of Standards (NIS) database for known good files allowed investigators to filter out legitimate Android components and identify anomalies, leading to the consensus that the machine was fundamentally untrustworthy for US elections.

The second case detailed a workplace timecard fraud scheme involving an older-generation iPhone. This "theoretical" scenario revealed:

  • "Leave-Behind" Device: An iPhone 4s, powered by a hidden cord, was discovered under a box, continuously connected to the corporate guest Wi-Fi network.
  • Automated Activity: The device was programmed to log into the corporate site at 9:00 AM and log off at 5:00 PM daily, simulating presence for multiple contractors without their physical attendance.
  • OSINT Indicators: The device was registered with the contractor's true name and company, providing immediate leads.
  • Power Source Implications: Being constantly plugged in allowed for continuous data collection and network beaconing, indicating a long-term, high-collection operation.

The third case addressed the pervasive issue of North Korean IT workers infiltrating global companies to bypass sanctions and fund illicit state activities. Key findings included:

  • "Trojan Unicorns": These workers present themselves as ideal candidates with impeccable, yet suspiciously generic, resumes and extensive experience, often operating from laptop farms in third countries.
  • Pi KVM Use: A significant indicator is the use of a Pi KVM (Raspberry Pi-based Keyboard, Video, Mouse switch), an intentional device costing around $800, enabling a single individual to control up to 20 different computers/personas simultaneously. This allows them to manage multiple remote jobs and revenue streams.
  • Linux Emulator Anomalies: While most legitimate users connect with iPhones or Androids, North Korean workers frequently use Linux emulators on their remote devices, creating a distinct anomaly in device connection logs (e.g., in Splunk or Microsoft Defender).
  • 2FA Data Exploitation: Two-Factor Authentication (2FA) logs, often overlooked, provide rich forensic data including geolocation (latitude/longitude), device types, and connection times. Discrepancies between claimed work location (e.g., North Virginia time zone) and actual 2FA geolocation (e.g., Beijing time zone, or VPN usage from the Caribbean) are strong indicators of fraud.
  • Behavioral Red Flags: Beyond technical artifacts, behavioral cues like persistent excuses for non-functional cameras during video calls, inability to perform simple physical actions (e.g., "walk to the window"), or failure to correct misaddressed names (due to managing multiple personas) are critical indicators.

These cases collectively demonstrate how a holistic forensic approach, combining traditional methods with specialized IoT techniques and OSINT, is essential for uncovering sophisticated digital threats.

Technical Deep Dive

▶ Watch: Chinese voting machine prototype features: camera, fingerprint, ID scan (4:30)

The technical depth of Baggett's talk lies in its exploration of how traditional forensic principles are adapted and augmented to tackle the unique challenges posed by IoT devices, alongside specific tools and methodologies for each case study.

For the Chinese voting machine, the initial challenge was data acquisition. Traditional imaging techniques were insufficient given the device's unknown architecture. This necessitated a chip-off extraction, a highly specialized and delicate process where the memory chip is physically removed from the circuit board and then read using a specialized reader. This yielded a massive 1283.8 GB raw data file, a "wall of text" requiring advanced processing. The next step involved using the National Institute of Standards (NIS) database of known good operating system files and their corresponding hash values. Forensic tools like Magnet Axiom, Blacklight, or Celbrite can ingest this database to filter out legitimate Android 7.1 OS components, leaving only anomalous files for deeper investigation. This process, often referred to as "hash filtering," is crucial for narrowing down the scope of a large dataset to focus on potentially malicious or unexpected artifacts. The presence of Bluetooth, Wi-Fi, and 4G capabilities on the voting machine also prompted the use of a "dope scope"—essentially a Kali Linux distribution running on a Raspberry Pi, configured to monitor and analyze wireless network activity (Bluetooth and Wi-Fi beacons) in the vicinity of the device. This tool helps identify any unexpected network broadcasts or connections that the device might be initiating.

In the workplace fraud case, the primary technical focus was on network forensics and device identification. The discovery of an older iPhone 4s (identifiable by its 30-pin connector, distinct from Lightning or USB-C) connected to the corporate guest network triggered a deeper investigation. Splunk, a powerful security information and event management (SIEM) platform, was instrumental in this phase. By querying Splunk logs for connectivity related to "iPhone 4" and correlating beaconing times (9:00 AM and 5:00 PM daily), the forensic team could establish a pattern of automated activity. The fact that the device was constantly powered, rather than battery-dependent, was a significant indicator. Battery-powered IoT devices typically have limited collection and storage capabilities due to power constraints, whereas a continuously powered device can sustain prolonged network activity and data exfiltration. This distinction helps infer the nature and intent of the collection operation. The speaker also mentioned the value of OSINT (Open Source Intelligence), noting that the device was registered with the contractor's true name, which immediately provided a strong lead for internal correlation.

The investigation into North Korean IT workers leveraged a sophisticated blend of network telemetry, device fingerprinting, and behavioral analysis. A key indicator is the Pi KVM, a hardware device that allows remote control of multiple physical machines using a single set of peripherals. Detecting these devices in a corporate environment often involves network traffic analysis, looking for unusual remote access protocols or specific device signatures. Further, the use of Linux emulators by these workers creates a distinct digital footprint. Tools like Microsoft Defender or Splunk can be configured to log and alert on connected device types. While most legitimate users would show connections from iOS or Android devices, a disproportionate number of Linux-based connections from remote workers would stand out as an anomaly.

Beyond device types, 2FA logs are a goldmine of forensic data. Baggett highlights that systems like Duo collect extensive Personally Identifiable Information (PII), including geolocation (latitude, longitude), IP addresses, and device details. Analyzing these logs can reveal discrepancies between a worker's declared location and their actual connection points, especially if VPNs are used. Wigle.net, a popular wardriving database, can then be used to cross-reference IP addresses or Wi-Fi SSIDs with physical locations, potentially exposing connections to known "laptop farms" or unexpected geographic regions. Finally, Splunk badge logs, which record physical access to corporate premises, can be correlated with digital activity. If a worker's badge logs indicate no physical presence, but their digital footprint shows consistent remote work from a suspicious location or using anomalous devices, it strongly points to fraudulent activity. The mention of spydoller.com as a free OSINT tool for phone number analysis (identifying TCON providers, VoIP numbers, or Linux emulators) further illustrates the breadth of resources available to forensic practitioners in these complex investigations.

Demo / Proof of Concept

▶ Watch: Discovery of unexpected Android board and chip-off extraction (6:50)

While the talk did not feature a live, interactive demonstration in the traditional sense, each of the three case studies presented served as a compelling proof of concept for the forensic methodologies discussed. The detailed breakdown of how the Chinese voting machine was acquired, analyzed via chip-off extraction and NIS database filtering, and ultimately deemed untrustworthy, effectively demonstrated the practical application of advanced IoT forensics. Similarly, the workplace fraud scenario, though "theoretical," meticulously outlined how network monitoring, device identification, and correlation with OSINT could uncover automated time card fraud, showcasing a real-world investigative workflow. Finally, the extensive discussion on detecting North Korean IT workers, incorporating the identification of Pi KVMs, analysis of Linux emulator footprints, and the strategic use of 2FA geolocation data and badge logs, provided a comprehensive and actionable framework for identifying and mitigating this sophisticated insider threat. These examples, rich in technical detail and real-world context, functioned as powerful demonstrations of effective IoT forensic techniques.

Defensive Implications

▶ Watch: Voting machine's extensive, problematic connectivity (Bluetooth, Wi-Fi, 4G) (8:00)

The insights gleaned from Baggett's talk offer critical defensive implications for organizations across various sectors, from election security to corporate insider threat mitigation.

For election officials and policymakers, the Chinese voting machine case underscores the paramount importance of supply chain transparency and integrity. Any voting equipment must undergo rigorous, independent, and open-source security audits. Devices with hidden features like cameras, fingerprint scanners, or extensive network connectivity (Bluetooth, Wi-Fi, 4G) should be immediately rejected, as they introduce unacceptable risks to voter privacy and election security. The reliance on proprietary, manufacturer-controlled updates (via Alibaba, per-precinct) is a severe vulnerability, preventing public and expert scrutiny. Defenders must demand open-source software, transparent hardware designs, and robust, verifiable security protocols for all election technology.

Regarding workplace fraud and insider threats, organizations must enhance their network monitoring capabilities to detect anomalous IoT devices. This includes actively scanning for old or unrecognized hardware (e.g., iPhone 4s in a modern environment) on corporate networks, particularly guest Wi-Fi. Endpoint detection and response (EDR) solutions and SIEM systems (like Splunk) should be configured to flag unusual device types, consistent beaconing activity from non-standard devices, and discrepancies between physical access logs (badge swipes) and digital activity. The power source of a device (battery vs. constant power) can also inform risk assessment, with continuously powered, hidden devices posing a higher, long-term threat.

To counter the sophisticated tactics of North Korean IT workers, a multi-layered defense is essential. Enhanced vetting processes for remote contractors are critical, moving beyond superficial resume checks to include deeper background investigations and behavioral assessments. Organizations should monitor for indicators such as the presence of Pi KVMs through network traffic analysis or endpoint forensics, and scrutinize device connection logs for a high prevalence of Linux emulators among remote workers. 2FA data should be actively analyzed for geolocation discrepancies, IP address anomalies, and unexpected device types. Any consistent excuses for non-functional video cameras during virtual meetings or an inability to perform simple, verifiable physical actions (e.g., showing their surroundings) should be treated as major red flags. Furthermore, implementing human social engineering tests (e.g., using incorrect names, making irrelevant small talk) can help identify individuals who are managing multiple personas and may struggle to maintain consistent identities.

In a broader sense, the talk reinforces the need for organizations to maintain robust digital forensic capabilities and to ingrain the "two is one, one is none" principle for critical forensic tools and data acquisition hardware. Proactive monitoring, coupled with the ability to swiftly and forensically soundly investigate anomalies, is paramount. The speaker's closing remarks—"the devices change, the trade craft doesn't, the principles don't"—serve as a reminder that while technology evolves, the fundamental tenets of forensic investigation and proactive defense remain the bedrock of cybersecurity.

Key Takeaways

  • IoT devices are rich forensic data sources: Even seemingly simple or old "things" can harbor critical evidence for investigations, from voting machines to hidden iPhones.
  • Forensic principles remain constant: Meticulous collection, examination, analysis, and reporting, ensuring data integrity and reproducibility, are non-negotiable regardless of the device type.
  • Supply chain transparency is paramount: Organizations must demand open-source software, transparent hardware, and independent audits for critical systems, especially those impacting elections.
  • Network monitoring and 2FA data are powerful defenses: Actively monitor for anomalous device types (e.g., Linux emulators, old iPhones, Pi KVMs) and leverage 2FA logs for geolocation and connection pattern analysis to detect fraud and insider threats.
  • Combine technical and behavioral indicators: While technical artifacts are crucial, behavioral red flags (e.g., video camera excuses, inconsistent personas) are equally vital in identifying sophisticated adversaries like North Korean IT workers.
  • Always plan for contingencies: Critical forensic tools and data acquisition methods require backups; the "two is one, one is none" mantra prevents operational paralysis during investigations.

About the Speaker(s)

Will Baggett is a distinguished expert in digital forensics and cybersecurity with a diverse background across government and corporate sectors. He previously served as a human cyber collection specialist for NATO and a cyber trainer for their Special Operations Forces (SOF). Baggett also dedicated years to the Central Intelligence Agency (CIA), where he honed his skills in intelligence and digital investigation. Currently, he serves as the Director of Digital Forensics for Operation Safe Escape, a volunteer organization providing assistance to victims of domestic violence. In his day job, he leads the insider threat digital forensics team at a Fortune 25 firm, focusing on protecting corporate assets from internal threats. His extensive experience spans traditional digital forensics, iOS forensics (since 2007), and the emerging field of IoT forensics, making him a leading voice in understanding and mitigating complex digital risks.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Baggett brings legitimate field cred and three well-chosen case studies that give the talk real texture — the North Korean IT worker detection angle using Pi KVM fingerprinting and 2FA geolocation data is the most operationally useful material here. It's a competent applied-forensics talk, but the technical ceiling is low: nothing requires novel tooling, the chip-off discussion is surface-level, and experienced forensic practitioners will have seen most of these techniques before.

Heather Calloway (CISO) — SOLID

Baggett brings genuine field credibility and three case studies with real investigative texture, particularly the North Korean IT worker detection work, which has immediate operational relevance for insider threat programs. The talk delivers useful practitioner tradecraft but stops short of the institutional and governance framing that would make it land with security leaders rather than forensic analysts.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33