RELEASE NOTES V7.0
Total Page:16
File Type:pdf, Size:1020Kb
RELEASE DATE: W/C 25 APRIL 2016 RELEASE NOTES v7.0 NEWS IN v7.0 18,625 WELCOME TO A BRAND NEW FEATURES FORENSIC PROFILES » Streamlined XRY focused on extractions NEW VERSION OF XRY for Devices, Cloud & Camera WITH 1,117 » Case File concept – multiple extractions APPS! contained within a single case » Cloud support enabled automatically or manually from Internet connected PCs » Camera support enabled for XRY on all Platforms; Kiosk, Office, Field & Tablet » More frequent micro release update schedules for smartphone apps » New XRY 64-Bit platform for more powerful extractions and decoding capability IMPROVEMENTS » Physical support for Samsung Galaxy S5 & S6 with Recovery Mode » Added soft root for Samsung Galaxy S5 and Note III, for physical dumping of unlocked devices » Automatic dumping & decoding in Wizard » Full Disk Encryption Decoder for Android – updated profiles available » Support for iOS 9.3 & improved support for Apple Notes » Security Code extractions now logged in XRY – full audit trail for evidential purposes » Firefox OS phones decoding added XRY has been supplied to law enforcement, military and government agencies » Support for “WebP” image format now available since 2003. With over 12 years of constant development based upon real world » New MediaTek chipset support in XRY & PinPoint testing and feedback, we are proud to introduce the latest incarnation of this » Dumping & decoding for more Spreadtrum devices world famous mobile forensic extraction software. » Increased support for LG devices XRY v7.0 is a lighter, faster, streamlined application designed to focus on extractions in order to make examiners more efficient than ever. As the volume of data and the features of mobile devices expand, changes are required to ensure XRY meets the demands of the modern world. XRY v7.0 has evolved to MOBILE FORENSIC PROFILES v7.0 TOTAL focus solely on extraction and recovery of data. In doing so we have expanded the extraction capabilities to include not just mobiles, but Camera input and Logical Extraction 260 6,380 Cloud based data as well. Physical Dumping 311 3,957 Physical Decoding 341 3,896 Passcode & Bypass 184 1,994 App Versions 137 1,117 XRY Untested 106 1,281 TOTAL 1339 18,625 FREE XAMN SPOTLIGHT LICENSE For each current XRY license held, customers are entitled to receive one free copy of XAMN Spotlight. These XAMN Spotlight licenses will be synchronized To allow greater feature functionality, the review and analysis of XRY reports to the same duration as the XRY license. are being migrated to the XAMN tools. XAMN Viewer & XAMN Spotlight In order to activate XAMN Spotlight, please download facilitate Case File reviews. This allows users to contrast and compare XRY the software from the MSAB Customer Portal and files related to the same case. By separating out the product ranges, MSAB can then either update your license from within XRY or provide quicker updates for new devices and apps. In the future we will be able request a new license from [email protected] to put out monthly micro releases for smartphone apps and cloud support. XRY v7.0 RELEASE NOTES | 2 EXTRACT DATA BEYOND THE DEVICE XRY Cloud enables authorized forensic examiners to recover more data from connected cloud storage solutions. It offers data access to services such as Facebook, Google, iCloud, Twitter, Snapchat and Weibo to name a few. XRY Cloud empowers users to ensure rapid recovery of additional information in a timely manner for authorized forensic examiners. You can use the software in two modes: » Automatic Mode for immediate recovery of cloud data » Manual Mode allows recovery of cloud data without the device XRY CAMERA AVAILABLE FOR ALL MSAB PLATFORMS XRY 7.0 FOCUS ON EXTRACTION This hardware and software combination is already available The new streamlined XRY v7.0 offers users the for the Kiosk & Tablet platforms. XRY Camera is now extended ability to recover the following: to all MSAB platforms for use with Office and Field kits. Users can quickly take and review images of the mobile device and » Logical Data including File System extractions the data displayed on screen. Pictures can be categorized and » Physical Dumping and Decoding extractions examiner notes added to any number of pictures within a » PinPoint extractions for non-standard mobile devices separate XRY file that forms part of the overall case. » Camera images to complement device extractions » Cloud based storage data via online extractions INTRODUCING MICRO RELEASES – FOR QUICKER SUPPORT XRY v7 will allow MSAB to provide more regular updates that meet the growing pace of change with smartphone app development. Instead of releases every quarter, MSAB plans to provide regular monthly updates for app support. These micro releases will be complemented by updates to the graphic user interface and devices at different stages across the calendar. COMBINE EXTRACTIONS INTO A CASE FILE A major new improvement in XRY v7.0 is the Case File concept. Users can now DECODING OF SONY ERICSSON combine different XRY extractions together into a Case File to store related FFS PHONES digital data from an investigation. The FFSFileDecoder has been updated to recover The Case File enables users to store all mobile related forensic extractions Calls, SMS, Contacts & Calendar details from the in one place, such as the SIM, SD Card, Device & Cloud based data retained following devices: Sony Ericsson T250a, T250i and together. Utilizing a standard Windows OS file system structure, Case Files are J132. monitored by XRY to ensure that users are notified if new XRY files are added or removed from the case. IMPROVED SUPPORT FOR LG DEVICES TOTAL COVERAGE FOR MTK CHIPSETS XRY v7.0 has improved dumping XRY v7.0 introduces physical dumping support for the following MTK chipsets: support for newer LG Android 6580, 6595, 6735, 6753, 6795 & 6571. XRY PinPoint have added logical devices and LG Infineon mobile support of the following MTK chipsets: MT6223(C, D & P), MT6225, MT6226M, devices. We now have improved MT6227, MT6228, MT6235B, MT6229, MT6236, MT6239, MT6250, MT6252H, decoding for Calls, SMS, MMS, MT6253D, MT6260M & MT6268B. Contacts & Calendar for around 26 supported devices with Infineon In total XRY v7.0 now has coverage for NOR memory types and other virtually all MTK Chipsets manufactured devices with Infineon chipsets. in the last 3 years and the latest version of XRY has improved decoding for extraction of Web Browsing History, Web Bookmarks and Bluetooth paired devices. XRY v7.0 RELEASE NOTES | 3 PHYSICAL SUPPORT FOR SAMSUNG SUPPORT FOR “WEBP” IMAGE GALAXY S5 & S6 WITH RECOVERY MODE FORMAT NOW AVAILABLE In this release we have added support for two of This image format is now supported in the most popular mobile devices on the market; the FileSignatureDecoder and DelFileDecoder to allow Samsung Galaxy S5 & S6 models. Physical support for WebP images to display correctly in XRY from both Android Dumping with recovery mode is now possible live and deleted files that are processed. for three of the most common chipsets amongst these devices: Exynos 5422 & 7420 and also MSM 8974 chipsets. This new functionality allows for extractions without rooting which thereby enables support even for IMPROVED DUMPING & DECODING locked devices. FOR SPREADTRUM DEVICES This release sees even greater support for Spreadtrum chipsets: SC5735, SC6815, SC6820 IMPROVED FULL DISK ENCRYPTION DECODER FOR (improved), SC6825, SC7701, SC7710, SC7715, ANDROID SC7727, SC7730, SC7731, SC8810 (improved), SC8825 & SC8830 which are used across a variety The “Android MediaTek Generic” & “Android Spreadtrum Generic” profiles of handsets. In addition to this we have improved have been updated and have improved support for devices running up to decoding for Spreadtrum Android devices using the Android 4.4.4. Additionally, MediaTek devices with default encryption are BTCDecoder; which will allow for a more dynamic now supported up to Android 5.0. way of decoding memory partitions on these Android Agent extractions have also been improved, to recover more phones. information regarding Calendar events and installed apps on most Android devices. FIREFOX OS PHONES DECODING ADDED This new decoder will work with all Firefox OS devices that XRY now supports; Geeksphone GP-002, Intex Cloud Fx, LG D300f Fireweb and Spice Fire One Mi-Fx 1 to recover Calls, SMS, Calendar and Contact details. COMBINED EXTRACTION & DECODING SECURITY CODE EXTRACTIONS NOW LOGGED IN XRY The ‘finish’ flag used in XRY v6 has been removed to allow for more streamlined extractions, where Along with the concept of single XRY extractions for Case File decoding occurs automatically after extraction. management, we have also implemented XRY log files for security code This is now possible because all XRY files in v7 only extractions. This ensures users automatically have a full audit trail for will be single extractions only from devices. If evidential purposes in the Case File as well. examiners want a logical and physical extraction of a device, these will now be presented as two separate XRY files held within in the Case File. NEW APPS IN XRY V7.0 By popular demand, we have added support for the encrypted chat THE BENEFIT OF TAGS app Threema (iOS) as well as Waze (Android), the world’s largest community-based traffic and navigation app. Other new apps in The MSAB Ecosystem of products now use Tagging this release include: as the primary means of marking data for review. This replaces the old Important/Not important ANDROID IPHONE slider bars used in XRY v6 and provides more » Amaq – Communication app, » PhotoVault – App for hiding photos robust functionality. claimed to be created by ISIS and videos » BlackSMS – Encrypted SMS app » Siri – Built in intelligent personal Tagging has the benefit of providing users with » MeetMe – Dating app assistant unlimited terms for defining the importance of » Waze – Traffic and navigation app » TextMe – Chat app different items of data discovered during the review » Threema – Encrypted chat app stage.