What Waze is
From a first glance, Waze, now owned by Google (isn’t everything?) might look like a typical GPS application. From one perspective it is. It offers your average garden variety GPS features. From favorite locations, to restaurants, to even cheapest gas prices in the area, Waze just seems like another typical GPS app. However, dive a little deeper and you begin to see that Waze is much more. Waze is an entire community of users. Waze gives the user the ability to communicate with other “Wazers” through a variety of methods such as direct messages.
Map Chat Feature
Here is a list of some of the other features that are available on the Waze App.
- Native Group Forums
- Pick Up (allows a user to text or email another Wazer their location to get “picked up”)
- Save Parking Location (friends on Waze can see where you parked)
- Link to Facebook, Twitter, and FourSquare.
- Drive Sharing (watching other Waze Friends drive to a location)
- Map Chat and direct messages
- Picture Taking (Built in Camera)
As their motto goes, the goal of Waze it to outsmart traffic together. Users can post where they have seen accidents, slow roads, construction, or even where speed cameras and police are located.
Waze and Forensics
The amount of data, and therefore the amount analysis required for this the App is extensive. To make this project feasible in the amount of time I have, I decided to solely focus on data that I believe could impact a digital forensic investigation. I have broken up the potential artifacts into five main categories
- Artifacts relating to the GPS functionality.
- Artifacts relating to unique Waze features found on the device
- Web Browser History (my Waze profile online)
- Social Media data (Waze links to FB, Twitter and FourSqaure)
- SMS and Email Artifacts relating to Waze.
Direct Message Feature
Questions to be answered
This project will be focused around a few main questions.
- Can I forensically uncover any data?
- Is there any recoverable deleted data?
- Can I create a timeline of events based on GPS coordinates or timestamps?
- Is there any data stored in memory? (Live routes or shared drives?)
ToolsAlthough I have not finalized the tools I plan on using to uncover this data, currently I plan at least using the following:
- Cellebrite UFED touch
- Oxygen Forensic Suite
If you would like to read more about Waze in the meantime here is a link to their manual.