Foredragsholdere
Veronica (Vee) Schmitt
Biohacker, breaker-of medical things, Bionic Woman, Forensicator and hungry for knowledge, Interim Lead DFIR Noroff University College
Veronica started her forensic career in 2008. Veronica is also the Interim Programme Lead for Digital Forensics and Incident Response at Noroff University in Norway, where she replaced a warm climate with a more adventurous one. Veronica holds a Master in Science at Rhodes University in Information Security with a specialisation in the forensic analysis of malware. She is currently doing her PhD in cybersecurity at the University of Plymouth in the UK. Her PhD is about designing robust logs for medical devices. She prides herself on keeping patients safe, as this is something close to her heart (quite literally). She is also a cyborg, sporting an embedded medical device herself. She is also a DEF CON goon, and she is the founder of DC2751, and the OWASP Kristiansand project. She has a love for all things ransomware and understands the low level details forensically.
Her particular research interests include research into security vulnerabilities in medical devices forming part of the Internet of Things, and how these could be exploited by malicious attackers, as well as what types of forensic artefacts could be identified from any attacks. She believes that incident response should be something that is continuously done and improved on. She is extremely passionate about protecting people whose lives depend on these medical devices, and her passion led her to become a researcher within an MDM. She is also developing a digital forensics and incident response approach dealing specifically with implanted medical devices and medical devices installed within a healthcare setting. At her core, Veronica is a forensicator and hacker, in love with every bit, byte, and nibble of knowledge she has obtained. She has a strong belief that the o in logs stand for observability. Knowing what is a problem is half the battle won she believes.
Emlyn Morgan Butterfield is an experienced academic leader, digital forensics specialist, and cybersecurity educator. Currently serving as Rector at Noroff University College, he has a background in higher education management, curriculum development, and research supervision. With over a decade of experience in academia, he has held key roles such as Head of Computing and Programme Lead for Digital Forensics, contributing to the advancement of forensic education and research.
His research focuses on forensic automation, mobile device forensics, and cybersecurity pedagogy. As a Senior Fellow of the Higher Education Academy, he is dedicated to enhancing teaching practices and fostering student engagement through innovative methodologies.
Beyond academia, he has been involved in research, teaching, and academic leadership, as well as serving as an external examiner and reviewer for universities in the UK. His industry experience includes roles in digital forensics investigations and expert witness services.
He holds an MSc in Forensic Computing from the University of Bradford and a BSc in Computer Science from the University of Hull. His professional training includes certifications in EnCase, XRY, and various forensic analysis tools.
Om sesjonen
Mobile applications often leave behind more data than their designers intend.
In our mobile application research, we conduct structured forensic analysis across the full application lifecycle installation, authentication, routine use, updates, account deletion, and uninstallation. Using systematic filesystem analysis, we examine how data persists within application and operating system storage structures over time.
Across multiple applications, consistent categories of artefacts emerge: persistent authentication tokens, residual SQLite records after account deletion, cached media fragments, background service traces, telemetry remnants, and other filesystem artefacts that survive lifecycle transitions.
This talk presents artefacts identified through this research and outlines the filesystem-focused techniques used to uncover them, including logical extraction, directory mapping, database reconstruction, and structured artefact correlation within application storage areas.
Beyond catalogue and method, we examine the implications of lifecycle persistence. From an application security perspective, these artefacts highlight gaps in storage hygiene and data minimisation. From an incident response perspective, they shape what can be recovered during device investigations. At a broader level, they challenge common assumptions about what “deletion” and “removal” actually mean in practice.
The Forensic Research Pipeline presented here is a research model: independent investigations producing comparable artefact findings over time. The objective is empirical clarity understanding what applications actually retain within their filesystem structures.