RELEASE NOTES UFED PHYSICAL ANALYZER, Version 5.4 | November 2016 UFED LOGICAL ANALYZER, UFED READER
Total Page:16
File Type:pdf, Size:1020Kb
NOW SUPPORTING 20,854 DEVICE PROFILES +2,851 APP VERSIONS UFED TOUCH2, UFED TOUCH, UFED 4PC, RELEASE NOTES UFED PHYSICAL ANALYZER, Version 5.4 | November 2016 UFED LOGICAL ANALYZER, UFED READER HIGHLIGHTS WE’VE ADDED SUPPORT TO MORE MOTOROLA ANDROID DEVICES! DEVICE SUPPORT Physical extraction and decoding from 26 popular Motorola Android devices ◼ Bootloader-based physical extraction for 17 MTK Android (up to and including OS 5.0.1). devices running the following MediaTek chipsets: MT6735 and MT6753. ◼ Physical extraction and decoding from 26 popular A BRAND NEW USER INTERFACE Motorola Android devices. Due to popular demand, we ◼ Following the previous announcement in version 5.1, are excited to introduce the we have added physical extraction while bypassing new interface for UFED Physical user lock for 18 additional Huawei devices, running Analyzer, UFED Logical Analyzer and UFED Reader 5.4. HiSilicon chipsets. We have redesigned the user interface to deliver a more ◼ Logical extraction and decoding is enabled for the new intuitive user experience. Google Pixel Android devices (Apps data not included). APPS SUPPORT ◼ 26 new Applications supported for iOS and PINPOINT YOUR SUBJECTS’ Android devices. LOCATIONS WITH MORE ACCURACY! ◼ Facebook Messenger: Decoding supported for multiple users of a single device. ◼ 569 updated application versions. FUNCTIONALITY ◼ Pinpoint your subjects’ locations with more accuracy. ◼ Organize and review case evidence with enhanced To fully utilize the large volume of locations data available in a searching, filtering and grouping capabilities. mobile device, UFED Physical Analyzer 5.4 allows you to convert ◼ Analyze more data in Timeline view quicker. the BSSID values (wireless networks) and cell towers into location ◼ Identify critical case information up to 50% faster. positions/specific addresses, in order for you to reveal and track ◼ Improved direction visuals for clearer chat conversations. connections to wireless networks and cell tower stations, within a ◼ Identify recorded audio files for iOS devices. specific timeframe. ◼ Decoding shortcuts for common external extractions. ◼ View platform indication for chat messages. ◼ View description of powering events. FORENSIC DEVICE PROFILES v 5.4 Total ◼ Enhanced decoding of more data from iOS devices. Logical extraction 121 8,906 Physical extraction* 93 4,677 File system extraction 101 4,800 EXPAND YOUR EVIDENCE Extract/disable user lock 50 2,471 REACH WITH ACCESS Total 365 20,854 TO EVEN MORE CHINESE ANDROID DEVICES! Physical extraction while bypassing lock from 3,928 devices Bootloader-based physical extraction from 17 MTK *Including GPS devices Android devices. INTRODUCING A NEW USER INTERFACE We have launched a new and user friendly interface for UFED Physical Analyzer, UFED Logical Analyzer and UFED Reader 5.4. Following customer feedback, we have redesigned the user interface by exposing all the functions in a clearer and intuitive way, with a more modern look and feel for a greater user experience. The new interface has given UFED Physical Analyzer, UFED Logical Analyzer and UFED Reader a much more appealing and sleeker look, making each function easily accessible and intuitive. We have also refreshed the brand with new iconography that we’re excited to share with you! Cellebrite Release Notes | v 5.4 |November 2016 | 2 UFED PHYSICAL ANALYZER AND UFED LOGICAL ANALYZER FUNCTIONALITY ◼ Pinpoint your subjects’ locations with more accuracy ◼ Tag items of interest UFED Physical Analyzer 5.4 enables you to extract more You can now tag items for future reference using one or locations data from mobile devices by converting BSSID more labels via HotKeys. The new tags function can be (wireless network) and cell tower values into physical configured at the application level – add, delete and edit locations (longitude and latitude GPS coordinates). tags according to your needs. The BSSID represents the wireless network MAC address. Note: The tagging functionality has replaced the This solution is free of charge and available offline for a bookmarks functionality. limited time. To start using the BSSID feature: Download the BSSID database. Login to MyCellebrite, and download the BSSID database from the Download page (~60 GB). The database holds millions of BSSID records of wireless networks worldwide. To install the BSSID database: In UFED Physical Analyzer, go to Tools, select the BSSID (wirelesses networks) and cell towers database, then select Install. In the installation window, load the Offline BSSID database. (The loading process takes some time to complete). You can enrich the BSSID and cell tower values by generating an XML report with BSSID and cell tower values (via the Export function), and sending the report via email to [email protected]. The enriched report will be sent ◼ Organize and review case evidence with enhanced back to you and you can import the new values into your searching, filtering and grouping capabilities UFED Physical Analyzer (via the Import function) and continue With version 5.4 you can now group and list information such your investigation. as image and video data files under predefined categories, in Note1: You can place the BSSID database in a shared network order to handle and review case evidence more efficiently. and allow any UFED Physical Analyzer station to connect to The new searching and filtering tools replace the previous this database. Advanced Search functionality - offering cutting-edge Note2: The BSSID database will require an update. From time capabilities that help narrow the search criteria with robust to time it is recommended to install an updated database. filters, giving you the data you need for your investigation in the palm of your hand. Under any table view, click on the table header, and the available sorting and filtering information will be presented, providing intuitive usability, and a look and feel that is similar to common spreadsheet software, such as Microsoft Excel. Cellebrite Release Notes | v 5.4 |November 2016 | 3 ◼ Analyze more data in Timeline view quicker ◼ View description of powering events The Timeline view allows you to analyze data in a chronological When the device is switched on or off, these events are order, for a quicker data analysis. Version 5.4 includes stored on the device. The powering events model includes contact and data file events such as images, videos and audio. the description of the event as well. For example, the device In addition, records with different timestamps are now is turned off due to battery state. presented in the Timeline, event per timestamp. ◼ Enhanced decoding of more data from iOS devices For example, a picture taken is one event, and when We have enhanced decoding capabilities for even more data deleted, is a separate event. You can control which data types including location data, wireless networks, cell towers, file items are included in the Timeline view. web history and search history for iOS devices. ◼ Identify critical case information up to 50% faster ◼ Backup Android PIN number (can be used to unlock the The watch list process has been drastically improved (by up to device when the pattern lock or face lock is unknown) and 50%), providing faster and more efficient capacities to run a list iCloud account info can now be decoded and shown under of keywords on your extracted data. This will make it easier to Device Info. identify and highlight critical information. ◼ Improved direction visuals for clearer chat conversations When the device owner is known, the direction of incoming SOLVED ISSUES and outgoing chat messages is shown. (Similar to conversation views within SMS or WhatsApp.) ◼ UFED: Improved physical mass storage extraction (USB Drive and other mass storage devices) ◼ Identify recorded audio files for iOS devices ◼ Email body information is now presented within the Recorded audio files are now shown in theRecording node right pane in UFED Reader. under Analyzed data. You can view recorded files, meta data ◼ A decoding issue with Samsung SGH- T199 JTAG has been and the recording time. resolved - now parsing call logs and phonebook data. ◼ A decoding issue with the physical extraction of iPhone 4 ◼ Decoding shortcuts for common external extractions has been resolved - now properly parsing video content. Easily decode frequently used external extractions. This is now ◼ A decoding issue with calls from Samsung available directly from the main menu: iTunes backup, iCloud CDMA_SCH-U485 Intensity 3 device has been resolved. Apple production, BlackBerry 10 backup and ADB backup. ◼ The correct status of SMS messages is now presented in the Timeline with DF report. ◼ A decoding of SMS messages from Nokia Lumia RM-1134 device has been resolved. ◼ A decoding of contacts from iPhone 6 plus devices has been resolved. ◼ An issue with generating large PDF reports has been resolved. ◼ A decoding failure when opening Nokia Lumia RM-974 JTAG dump has been resolved. ◼ Advanced Logical extraction of iPad 1 (A1219) now successfully completes. ◼ An issue with the hash value verification function has been resolved. ◼ An issue when running Malware Scanner has been resolved. ◼ An issue with updating the Malware definitions offline is now resolved. ◼ An issue with Meta data decoding for video files has ◼ View platform indication for chat messages been resolved. Today, applications such as WhatsApp, Skype and Facebook ◼ A decoding issue with SMS messages for Nokia 105 RM-1133 Messenger can be used from both mobile and PC platforms. has been resolved. ◼ A decoding issue with SD Card 64GB has been resolved. For each IM message, you can now view the platform type and ◼ Decoding of data files from the physical extraction of the know if it was sent/read from a mobile app or a computer. Samsung GT-E1205Y device has been resolved. ◼ A crashing issue when opening Tomtom decryption has been resolved. ◼ A crashing issue when opening Nokia Lumia 640 (RM-1072) chip-off dump, has been resolved. ◼ The out of memory when trying to decrypt Twitter app issue has been resolved.