±Forensic Focus Partners

Become an advertising partner

±Your Account


Forgotten password/username?

Site Members:

New Today: 0 Overall: 34069
New Yesterday: 0 Visitors: 125

±Follow Forensic Focus

Forensic Focus Facebook PageForensic Focus on TwitterForensic Focus LinkedIn GroupForensic Focus YouTube Channel

RSS feeds: News Forums Articles

±Latest Articles

RSS Feed Widget

±Latest Webinars

Besides Cellebrite is there an alternative

Discussion of forensic workstations, write blockers, bridges, adapters, disk duplicators, storage etc. Strictly no advertising of commercial products, please.
Reply to topicReply to topic Printer Friendly Page
Forum FAQSearchView unanswered posts
Go to page Previous  1, 2 

Re: Besides Cellebrite is there an alternative

Post Posted: Thu Nov 15, 2012 7:44 am

I have been trying to get a hold of someone from XRY but I am getting no response???


I sent you a message yesterday but perhaps you did not receive it?

Please email me mike.dickinson @ msab.com and I will ensure you get the information and quote you need.

Kind Regards

Micro Systemation


Re: Besides Cellebrite is there an alternative

Post Posted: Thu Nov 15, 2012 3:14 pm

I got it Mike thank you and I spoke with Johnathan this morning, which was a great conversation. I can see his passion for the company, which tells me a lot.  

Senior Member

Re: Besides Cellebrite is there an alternative

Post Posted: Thu Nov 15, 2012 8:02 pm

Just got my XRY quote for the Office Version-Complete at $ 7,990.00 which includes the first year renewal price.

I'm not a cellular technology expert, but I did stay at a Holiday Inn Express last night. 

Senior Member

Re: Besides Cellebrite is there an alternative

Post Posted: Mon Dec 24, 2012 9:39 am

- mrpumba
Besides Cellebrite is there an alternative to capturing data from a cell phone on the physical side (ie deleted items)? In addition to bypassing the swipe or passcode on these devices?

As usual some of my colleagues give just general answers to the question having many "if's".
The answer depends on what devices you're speaking about and on what you're assuming under "physical".
For iOS devices:
1. For some reason it's generally accepted that just file system dump currently assumed under "physical". There is currently no known solution to find deleted files (except 8Mb HFS journal) for iOS 4.x and above.

2. There is a chance to find thumbnails for deleted photos in iOS thumbnails database, and there is no need to go "physical" for that. This database is available with logical extraction too.

3. SQLite database format is the standard to store data in iOS (as well as in Android, by the way). And the only way to extract deleted items of any kind (contacts, messages, calls and so on including 3ed party apps data) - is examining so called "free pages" in SQLite file.

4. The main databases (calls, messages, contacts etc) are extracted even logically, using iTunes backup procedure. So in 99% of cases you don't need "physical" solution to extract the requred deleted items.

5. When do you need "physical", i.e. complete file systems? Only in cases where the interesting databases or files are not included into iTunes backup. Known examples are facebook and foursquare apps.

6. What you cannot do without "physical" solution is to bypass the passcode. I agree - it's very important thing and in my opinion - the main reason to use "physical" tools.

7. Does "physical" approach helps with all iOS devices? My colleagues from CB and XRY usually avoids this question :-), because the answer is "no". Currently there is no known way to bypass the passcode for iPhone 4S, iPhone 5m iPad 2,3,4 and iPad mini.

8. There is an absolutely free and open source solution, which code is actually used in all more or less expensive mobile forensic tools claiming "physical" extraction and passcode bypassing - code.google.com/p/ipho...rotection/ .

9. The main disadvantage of "iphone-dataprotection" project is it opens partitions in read-write mode. You must be warned about that since it's not a completely forensic way.

10. To sum it up, logical extraction is usually enough to find deleted items. And there is no tool that can help you with the recent iOS devices if they're passcode-locked. But in all other cases, in my opinion the optimal set is UFED (great for mobility and extracting data from a lot of devices) plus Oxygen Forensic Suite (has good visual data representation and a lot of analytical tools, and can open images of iOS devices extracted by UFED).

P.S. You can check how "Deleted items" from iOS or Android devices look in Oxygen SQLite Viewer: www.oxygen-forensic.co...iteviewer/

WBR, Oleg.
Oxygen Forensic Suite - Smart Forensics for Smart Phones.

Senior Member

Page 2 of 2
Go to page Previous  1, 2