
Investigating Payment Card Industry (PCI) breaches usually results in the recovery of credit and debit card data such as primary account numbers, expiration dates, cardholder names, and often full magnetic track data. A common challenge investigators often face is organizing and counting this recovered data, especially when dealing with hundreds of millions of records. Traditionally, investigators have had to create their own scripts or databases to process, validate, de-duplicate, count, organize, and query recovered track data, which resulted in inconsistent tools, formats, and methodologies. Say goodbye to weeks spent writing scripts to parse track data, validate account numbers with a Luhn check, and gather statistics. I will be introducing an open source tool, Card Data Processor and Organizer (CDPO), to quickly and efficiently process and validate millions of recovered PCI track records! This tool automatically generates useful information and statistics that
victims and card brands require. This presentation highlights the need for a standardized card processing procedure, useful features of CDPO, performance metrics, and a demonstration.
David Pany (@DavidPany), Senior Consultant, Mandiant