What Waze is
From a first glance, Waze, now owned by Google (isn’t
everything?) might look like a typical GPS application. From one perspective it
is. It offers your average garden variety GPS features. From favorite locations, to restaurants, to
even cheapest gas prices in the area, Waze just seems like another typical GPS
app. However, dive a little deeper and
you begin to see that Waze is much more. Waze is an entire community of
users. Waze gives the user the ability
to communicate with other “Wazers” through a variety of methods such as direct
messages.
Map Chat Feature |
Here is a list of some of the other features that are available on the Waze App.
- Native Group Forums
- Pick Up (allows a user to text or email another Wazer their location to get “picked up”)
- Save Parking Location (friends on Waze can see where you parked)
- Link to Facebook, Twitter, and FourSquare.
- Drive Sharing (watching other Waze Friends drive to a location)
- Map Chat and direct messages
- Picture Taking (Built in Camera)
As their motto goes, the goal of Waze it to outsmart traffic together. Users can post where they have seen accidents, slow roads, construction, or even where speed cameras and police are located.
Waze and Forensics
The amount of data, and therefore the amount analysis required
for this the App is extensive. To make this project feasible in the amount of
time I have, I decided to solely focus on data that I believe could impact a
digital forensic investigation. I have broken up the potential artifacts into five main categories
- Artifacts relating to the GPS functionality.
- Artifacts relating to unique Waze features found on the device
- Web Browser History (my Waze profile online)
- Social Media data (Waze links to FB, Twitter and FourSqaure)
- SMS and Email Artifacts relating to Waze.
Direct Message Feature |
Questions to be answered
This project will be focused around a few main questions.
- Can I forensically uncover any data?
- Is there any recoverable deleted data?
- Can I create a timeline of events based on GPS coordinates or timestamps?
- Is there any data stored in memory? (Live routes or shared drives?)
Tools
Although I have not finalized the tools I plan on using to uncover this data, currently I plan at least using the following:- Cellebrite UFED touch
- XRY
- Volatility
- Oxygen Forensic Suite
If you would like to read more about Waze in the meantime
here is a link to their manual.