Physical Analyzer 2.0 Release Notes
Total Page:16
File Type:pdf, Size:1020Kb
RELEASE NOTES – MARCH, 2011 POWER The most complete mobile forensics solution available today THE BEST GOT BETTER PRECISION An extensive array of highly advanced, flexible tools at your disposal SPEED Faster than ever before SUPPORTING 5,933 DEVICE PROFILES UNMATCHED SUPPORT FOR MOBILE DEVICES UFED strengthens its position as the leading mobile forensics tool with the widest portfolio of supported mobile devices. Every device listed below is fully tested by Cellebrite. Forensic Method New Total INDUSTRY BREAKTHROUGH! Logical Extraction 198 3,080 • Exclusive physical support for Samsung and LG devices Physical Extraction* 388 1,133 • Physical Support for Sony Ericsson, including file system reconstruction File System Dump 34 1,038 • NEW UFED Physical Analyzer 2.0 Password Extraction 8 682 • NEW UFED Phone Detective 628 5,933 • UNMATCHED support for mobile devices • 200+ new CDMA devices added for physical dump support * including GPS Devices The numbers speak for themselves: Cellebrite UFED 2.0 supports a record number of mobile devices for physical and logical extraction. Cellebrite UFED 2.0 introduces a new era in mobile forensics with a unique set of features that address the growing needs and requirements of the mobile forensics market. COMING VERY SOON! • The highly anticipated, comprehensive iPhone Physical solution. • Android Physical Support - allowing bypassing of user-lock code • Windows Phone 7 Physical Support • And more… © 2011 Cellebrite Mobile Synchronization LTD, All rights Reserved | tel: 201-848-8552 | www.ufedsystem.com | [email protected] RELEASE NOTES – MARCH, 2011 IMPROVED PERFORMANCE The result of extensive research and development at Cellebrite, UFED Cellebrite’s UFED Physical Analyzer performance has been Physical Analyzer 2.0 brings a unique set of powerful features, addressing improved in several fronts in effort to boost overall user experience the demanding requirements of the mobile forensics market, while providing and minimize wait time. the user with an enhanced interface to ease the day-to-day work involved • Application load time has been cut down by 75%-80% with mobile forensics. • Parsing engine improvements have been implemented • System performance has been optimized HIGHLIGHTS (Click for more info) • Improved performance • Enhanced Image viewer and thumbnails processing • Redesigned welcome screen • New Hex Bookmark controller • New extraction summary screen • Deleted data recovered from Garmin navigation systems • New hash calculation and verification function • Mio Support • New Instant Search • Advanced report generator • Open Advanced • Python plugin API • Chain Manager • Python shell • Enhanced decoding • Hardware key (dongle) support • iPhone decoding enhancements • Symbian chip-off decoding • Enhanced BlackBerry support • Sony Ericsson chip-off decoding • Support for UFED Logical output (beta) • MTK NOR chip-off & Flash decoding • Improved highlights engine • Supporting Windows 32 and 64 Bit REDESIGNED WELCOME SCREEN The redesigned welcome screen is the user’s initial interface with the application, and as such, provides intuitive access to recently opened projects, new projects or to the application settings. Welcome Screen © 2011 Cellebrite Mobile Synchronization LTD, All rights Reserved | tel: 201-848-8552 | www.ufedsystem.com | [email protected] - 2 - RELEASE NOTES – MARCH, 2011 NEW EXTRACTION SUMMARY SCREEN A new extraction summary screen has been designed to provide detailed information about the extraction. This includes a hash calculation and verification function, and a summary of the content extracted from the device. Extraction Summary Screen HASH CALCULATION AND VERIFICATION A hash calculation function enables users to trigger a verification process which returns the relevant hashes (MD5, SHA256) and compares them against the original hashes provided along with the phone extraction. This valuable feature helps users ensure that no changes have been made to the extraction contents. Hash information is also displayed in generated reports. Image Hash Details © 2011 Cellebrite Mobile Synchronization LTD, All rights Reserved | tel: 201-848-8552 | www.ufedsystem.com | [email protected] - 3 - RELEASE NOTES – MARCH, 2011 INSTANT SEARCH With the powerful new Instant Search Bar, users can now locate keywords and numbers within all data types, device information and file names, anywhere within the Physical Analyzer. Instant Search Bar Search results are displayed instantaneously and grouped by relevancy for convenience. SEARCH RESULTS A dedicated tab provides access to the search results, while search terms are highlighted within each result. The Quick Filter bar may be used to find specific strings within the results tab. Check boxes are utilized to mark results that should be included the extraction report. Double-clicking a result opens a relevant table and highlights the associated data. © 2011 Cellebrite Mobile Synchronization LTD, All rights Reserved | tel: 201-848-8552 | www.ufedsystem.com | [email protected] - 4 - RELEASE NOTES – MARCH, 2011 OPEN ADVANCED The Open Advanced feature allows users to control the way extractions are handled within UFED Physical Analyzer 2.0. This unique feature extends the options made available with the conventional “open” feature. Below are sample scenarios made available with the Open Advanced feature: • Configure the decoding process for UFED extractions • View and customize parsing “rules” applied to extractions • Open extractions and files created by other tools Open Advanced The Open Advanced initial screen allows the following options: 1. Select a UFED extraction – This option is utilized to open an extraction performed by UFED. These extractions are associated with .UFD files. As soon as this option is selected, the user can modify how the extraction is performed. Open Advanced – Customizing the decoding process 2. Start without a .UFD file – This option is utilized to open extractions performed by tools other than UFED. For example, a chip-off dump, a backup of a smartphone such as a BlackBerry .IPD file, or an Apple iTunes backup folder. The user may select a blank project or a device that corresponds to the relevant extraction. * In both options described above, the user has the freedom to customize the decoding process. Open Advanced - Device Selection © 2011 Cellebrite Mobile Synchronization LTD, All rights Reserved | tel: 201-848-8552 | www.ufedsystem.com | [email protected] - 5 - RELEASE NOTES – MARCH, 2011 CHAIN MANAGER The Chain Manager enables the creation of custom chains that allow mixing and matching of plug-ins provided by either Cellebrite, the user, or a third party. Custom Chains may be saved for repeated use and associated with relevant mobile devices. Chain Manager Custom Chains Devices Associated with Chain © 2011 Cellebrite Mobile Synchronization LTD, All rights Reserved | tel: 201-848-8552 | www.ufedsystem.com | [email protected] - 6 - RELEASE NOTES – MARCH, 2011 ENHANCED DECODING Cellebrite’s UFED Physical Analyzer 2.0 introduces enhanced decoding, enabling support for multiple data types such as: text messages, chat, email, web history, SIM data, cookies, MMS, instant messages, locations, contacts and more. The enhanced decoding allows much more data to be analyzed and displayed per mobile device. Cellebrite is constantly working on adding additional data types, and future releases of UFED will feature additional data decoding for various mobile devices. * (Red) indicates deleted data. iPHONE DECODING ENHANCEMENTS iPhone decoding includes calendar, call logs, contacts, text messages, email, locations (Wi-Fi and Cell Tower), MMS, notes, web history, web bookmarks (favorites), Skype (contacts, calls and chat), Facebook contacts, navigation applications, Bluetooth and more. Cellebrite UFED Physical Analyzer 2.0 is also capable of parsing an iPhone backup as well as an iPhone encrypted backup with a known password. iPhone 4 in UFED Physical Analyzer 2.0 Cellebrite UFED Physical Analyzer 2.0 is supplied with various chains that allow processing of iPhone physical dumps, file systems dumps and iTunes backup folders. The physical dump ranges supported by UFED Physical Analyzer are: • Apple Disk Image (DMG) • Apple Partition Map (APM) • GUID Partition Table (GPT) • Master Boot Record (MBR) associated with stacked Hierarchical File System (HFS) partitions • A single HFS • An uncompressed TAR file with a mounted file system. © 2011 Cellebrite Mobile Synchronization LTD, All rights Reserved | tel: 201-848-8552 | www.ufedsystem.com | [email protected] - 7 - RELEASE NOTES – MARCH, 2011 ENHANCED BLACKBERRY SUPPORT Bluetooth device pairings, web bookmarks (favorites), notes and MMS messages decoding have been added. Blackberry 8900 Curve in UFED Physical Analyzer SUPPORT FOR UFED LOGICAL OUTPUT (beta) In an effort to streamline the workflow by UFED users, Cellebrite’s UFED Physical Analyzer 2.0 introduces support for UFED logical extractions (beta). The XML file generated by the UFED system may be viewed with UFED Physical Analyzer 2.0. This exciting new feature allows UFED Physical Pro users to use a single program to manage both UFED logical and UFED physical extraction outputs. Users may select the data relevant for their case and generate reports with the information that is required. Logical extraction analyzed by UFED Physical Analyzer IMPROVED HIGHLIGHTS ENGINE The improved highlights engine in Cellebrite UFED Physical Analyzer 2.0 is a robust mechanism designed to shed light on the challenge