RELEASE NOTES UFED PHYSICAL ANALYZER, Version 5.1 | June 2016 UFED LOGICAL ANALYZER
Total Page:16
File Type:pdf, Size:1020Kb
NOW SUPPORTING 19,776 DEVICE PROFILES +1,729 APP VERSIONS UFED TOUCH, UFED 4PC, RELEASE NOTES UFED PHYSICAL ANALYZER, Version 5.1 | June 2016 UFED LOGICAL ANALYZER HIGHLIGHTS Known for its breakthroughs in mobile data technology, Cellebrite is the industry’s leader – delivering comprehensive and innovative solutions for mobile forensics. Staying true to our DEVICE SUPPORT vision, UFED 5.1 introduces unique and exclusive capabilities, ◼ Cellebrite introduces physical extraction while bypassing providing unmatched access to case-critical evidence. user lock for 22 Samsung Galaxy devices including Galaxy S6, S6 Edge and Note 5 – with forensic recovery partition. Cellebrite introduces physical extraction ◼ A unique lock-bypassing method that allows physical while bypassing user lock for Samsung extraction of more than 140 LG models, including 22 Galaxy S6, S6 Edge and Note 5. previously-unsupported models, such as the MS330 and VS880. This method additionally allows the removal and restoration of the user screen lock. EXCLUSIVE - ONLY AT CELLEBRITE: ◼ A unique user screen lock removal method supporting A unique lock-bypassing method that 137 Samsung device (for some devices, there is more allows physical extraction of more than than 1 method).* 140 LG models, including 22 previously- ◼ First in Industry – Physical extraction while bypassing unsupported models, such as the MS330 lock and decoding support for 19 Huawei devices. and VS880. ◼ A unique user screen lock removal method supporting 17 selected LG devices, including the G5. A user screen lock removal method ◼ Cellebrite introduces physical extraction while bypassing supporting 137 Samsung devices. user lock as well as decoding support for 3 Nokia 105 devices: RM-1133, RM-1134 and RM-1135. You are Physical extraction while bypassing required to use cable 153 in order to perform this type user lock and decoding support for 19 of extraction. Huawei devices. ◼ An enhanced lock-bypassing physical extraction method supporting 28 Samsung devices (MSM8916), overcoming A user screen lock removal method previous firmware limitations. supporting 17 selected LG devices, * This method is expected to unlock all Samsung devices last updated before including the G5. October 2015. This roughly correlates to Android 5.1.1 releases, however there may be exceptions. Physical extraction while bypassing user lock and decoding support for 3 Nokia APPS SUPPORT 105 devices, including RM-1133, RM-1134 ◼ New applications for iOS and Android devices: and RM-1135. Don’t Touch This (iOS), HereMaps (Android), HideSMS (Android), Hot or Not, Kakao Story, Mappy (Android), Meet24, MeetMe, Nike+ Running, Scruff (Android), FORENSIC DEVICE PROFILES v.5.1 Total SpringPad FlipNote (iOS) and TextMe. Logical extraction 146 8,539 ◼ 183 updated application versions. Physical extraction* 190 4,444 FUNCTIONALITY File system extraction 137 4,462 ◼ Improved performance for image thumbnails. Extract/disable user lock 100 2,331 ◼ Improved performance for unallocated carving. ◼ Enhanced Application Usage. Total 573 19,776 ◼ Cell Towers information. The number of unique mobile devices WhatsApp decryption support for older BlackBerry devices. ◼ with passcode capabilities is 3,558 *Including GPS devices CELLEBRITE INTRODUCES PHYSICAL EXTRACTION WHILE BYPASSING USER LOCK FOR SAMSUNG GALAXY S6, S6 EDGE AND NOTE 5 Cellebrite introduces physical extraction while bypassing user lock for 22 Samsung Galaxy devices including Galaxy S6, S6 Edge and Note 5 – with forensic recovery partition. The latest version replaces the device’s original recovery partition with Cellebrite’s custom forensic recovery – based on TWRP (Team Win Recovery Project). Cellebrite’s recovery image prevents any modifications to user data, maintaining a forensically sound extraction. It is recommended to use the Forensic Recovery Partition method when other physical extraction methods (e.g., Bootloader) are not successful, or unavailable (i.e. if the Android’s firmware version is not supported). Note: This capability does not currently support Android 6 and requires the device’s bootloader to be unlocked (usually associated with FRP) in order to flash the recovery partition. Devices with a locked bootloader or other such scenarios that are not compatible with Cellebrite’s recovery partition may be unlocked through CAIS. For more information click here or contact support at [email protected]. If the device does not have a screen lock, or if the lock can be disabled via a Cellebrite method, you should unlock the bootloader (usually associated with FRP): Under Settings > Developer options > Enable OEM unlock > Turn on OEM unlock. This setting may not be available on all specific versions of the operating system. Cellebrite is proud of its unmatched, industry-leading research efforts, resulting in a constant stream of innovative methods and world-unique capabilities provided exclusively to Cellebrite customers. These methods enable physical extractions and lock bypasses on the most recent flagship smartphones, as well as many popular feature phones. For early access to cutting-edge, unpublished lab capabilities contact CAIS. a short procedure and it can be loaded into UFED Physical UFED PHYSICAL ANALYZER AND UFED LOGICAL Analyzer to complete the decoding process. ANALYZER FUNCTIONALITY ◼ New offline map packages New– offline map packages are now available for Argentina, Brazil and Chile. ◼ Improved performance for image thumbnails – Creation and presentation of images and video thumbnails has been SOLVED ISSUES drastically improved. Version 5.1 now provides you with a faster and more efficient examination of media files. ◼ A decoding issue with Samsung Gt-E1200i device has ◼ Improved performance for unallocated carving – The been resolved. unallocated carving time has significantly decreased, providing ◼ An issue with media files decoding of Moto xt1080 JTAG you with the fastest decoding time – than ever before. extraction has been resolved. Note: the number of items recovered might be reduced ◼ When opening a UFDX file created using UFED Physical compared to previous version due to reduction if the number Analyzer, absolute paths were presented. This issue is of false positive items. now resolved, presenting relative paths. ◼ A decoding issue of notes items for an iPhone 6S device ◼ Gain access to wireless network locations – Additional running OS 9.3 specific has been resolved. location events can now be recovered from Android devices. ◼ A decoding issue of Nokia C2-01 (RM-721) has These location events include timestamps, network names been resolved. The decoding process can now (SSID) and basic service set identifier (BSSID) information. successfully complete. SSID is the name of the WLAN network Name and the BSSID ◼ A decoding issue of SMS messages and call logs for represents the wireless network MAC address (can be Samsung GT-B3210 device has been resolved. converted to a physical location). ◼ A decoding issue of BlackBerry dump (.bbb) file has ◼ Enhanced Application Usage – To help you analyze the usage been resolved. of applications, version 5.1 has now added identifier and action ◼ A decoding issue with Nokia Asha 206.1 (RM873) has identifier information. In addition, start time and end time of been resolved. usage were added, indicating the total usage time of any app. ◼ A decoding of TextNow application, version 4.4.37, for iOS ◼ Cell Towers information – Cell Towers information, including devices has been resolved. cell ID is now presented under a new node/model – located in ◼ A decoding issue of Whisper application, version 5.9.0, for the project tree. Android devices has been resolved. ◼ WhatsApp decryption support for older BlackBerry devices- ◼ An issue with call logs for pay phone appears as In many instances, we were unable to decrypt WhatsApp originating in number ‘-3’. This issue is now resolved, databases with older versions of BlackBerry devices. This was presenting the accurate participant information. because one of the keys, which is essential to the decryption process, was missing. The key can now be recovered using Cellebrite Release Notes | v5.1 | June 2016 | 2 APP SUPPORT Apps provide a rich source of data to investigations. Cellebrite keeps you ahead by providing support for the highest number of 3rd party applications in the industry running on iOS, Android, Windows Phone and BlackBerry devices. iOS Application Type Decoding Feature Don't Touch This Media tools Photos, videos, notes, contacts, visited Pages and password Hot or Not Game User account and contacts Kakao Story Social Passwords Meet24 Social User account and password MeetMe Social User account, contacts and chats Nike+ Running Health & Fitness Locations, notes and user account SpringPad Tools Calendar entries FlipNote TextMe Communication User account, contacts and calls ANDROID Application Type Decoding Feature HereMaps Navigation Locations HideSMS Media tools Chats, user account and password Hot or Not Game Contacts and chats Kakao Story Social Contacts and user account Mappy Navigation Locations and searched items Meet24 Social User account and password MeetMe Social Contacts Nike+ Running Health & Fitness Locations, notes and user account Scruff Social User account, contacts, chats and location TextMe Communication User account UFED CLOUD ANALYZER SIGN UP NOW 3 MONTH FREE TRIAL Sign up today and solve more cases with UFED Cloud Analyzer. This limited time offer is available between March 15 - June 15, 2016. In UFED Physical Analyzer version 5.0, you can now