Abstract
Modern gaming consoles contain highly critical forensic evidence within proprietary non-volatile
memory structures. Standard forensic acquisition interfaces are frequently omitted entirely from
these encrypted hardware environments. A forensically sound data acquisition workflow was
specifically developed for the Nintendo Switch console. A hardware-based Tegra processor
vulnerability was exploited to physically bypass the secure boot chain. Custom bootloader
payloads were injected to acquire the raw internal NAND memory bit-stream. These encrypted
virtual volumes were subsequently reassembled and completely decrypted utilizing the
NxNandManager software.