UFED AND OXYGEN WHA...
 
Notifications
Clear all

UFED AND OXYGEN WHATSAPP DECRYPTION

LRush
(@lrush)
New Member

Hi Folks,

Need help for the subjected topic.

1. How ufed decrypt the whatsapp data for iphones?

2. How oxygen decrypt the whatsapp data from iphone?

Please help...

Quote
Topic starter Posted : 05/07/2020 11:31 am
AmNe5iA
(@amne5ia)
Active Member

Not sure about Oxygen but i don't think UFED decrypts WhatsApp.  UFED just accesses the un-encrypted database files and interprets that for the user.

ReplyQuote
Posted : 06/07/2020 8:36 am
jadams951
(@jadams951)
New Member

Cellebrite's latest release of Physical Analyzer touts being able to parse out Whats App.  Haven't tried it yet so I can't say what it parses out.  

ReplyQuote
Posted : 06/07/2020 10:50 pm
passcodeunlock
(@passcodeunlock)
Senior Member

Both products have a nice list with supported devices and supported app versions.

Please be a bit more specific, tell us your device specs, operating system, app version, etc.

ReplyQuote
Posted : 10/07/2020 11:21 pm
Satyendra
(@satyendra)
New Member

In Case of iPhone, If you acquire the data from unlocked iPhone you will get all the WhatsApp chat there is no need to manually decrypt the database.

In the second scenario if you want to download WhatsApp chat backup from the iCloud, then via Credentials and then OTP is sufficient to decrypt the DB by Oxygen Forensic Cloud.

ReplyQuote
Posted : 06/08/2020 5:46 pm
OxygenForensics
(@oxygenforensics)
Active Member
Posted by: @lrush

Hi Folks,

Need help for the subjected topic.

1. How ufed decrypt the whatsapp data for iphones?

2. How oxygen decrypt the whatsapp data from iphone?

Please help...

Oxygen Forensic Detective can fully extract WhatsApp data from iPhones. You can read more  about all our WhatsApp extraction methods in this brochure https://oxygen-forensic.com/uploads/doc_guide/Whatsapp_forensics.pdf

ReplyQuote
Posted : 12/08/2020 12:52 pm
cs1337
(@cs1337)
Member

you have to do APK downgrade to collect WhatsAPP  from Android via Cellebrite.

ReplyQuote
Posted : 12/08/2020 5:11 pm
AmNe5iA
(@amne5ia)
Active Member

@cs1337 How exactly do you do an APK downgrade on an iPhone which is the type of phone this question is about.    Also, if you get a full physical (FDE) or a full filesystem (FBE) on an android phone you don't need to do an APK downgrade to get Whatsapp data.

ReplyQuote
Posted : 13/08/2020 1:09 pm
cs1337
(@cs1337)
Member
Posted by: @amne5ia

@cs1337 How exactly do you do an APK downgrade on an iPhone which is the type of phone this question is about.    Also, if you get a full physical (FDE) or a full filesystem (FBE) on an android phone you don't need to do an APK downgrade to get Whatsapp data.

my mistake. that's what i get for skimming the message. You shouldn't need to do anything for iPhone as WhatsAPP will be included in an advanced logical.

 

Most androids I come across you cannot perform a full physical image on without rooting the device which is not something we do as the phone needs to be returned in the same state it was received.

ReplyQuote
Posted : 13/08/2020 9:44 pm
jaclaz
(@jaclaz)
Community Legend
Posted by: @cs1337

 

Most androids I come across you cannot perform a full physical image on without rooting the device which is not something we do as the phone needs to be returned in the same state it was received.

A side-side question, if I may.

When is the phone returned, on average, in your experience?

I mean, a phone is seized, then imaged/investigated, then (possibly after some explicit decision by a judge or high rank investigator)  returned.

How long does the process take?

jaclaz

 

ReplyQuote
Posted : 14/08/2020 8:35 am
cs1337
(@cs1337)
Member
Posted by: @jaclaz
Posted by: @cs1337

 

Most androids I come across you cannot perform a full physical image on without rooting the device which is not something we do as the phone needs to be returned in the same state it was received.

A side-side question, if I may.

When is the phone returned, on average, in your experience?

I mean, a phone is seized, then imaged/investigated, then (possibly after some explicit decision by a judge or high rank investigator)  returned.

How long does the process take?

jaclaz

 

I mostly deal in eDiscovery matters where generally Contacts/ Call Logs/ SMS/MMS and Voicemails are of relevance for litigation. Custodian agrees to let us capture the content and then the device is returned immediately after. 

ReplyQuote
Posted : 14/08/2020 11:25 pm
jaclaz
(@jaclaz)
Community Legend
Posted by: @cs1337 

I mostly deal in eDiscovery matters where generally Contacts/ Call Logs/ SMS/MMS and Voicemails are of relevance for litigation. Custodian agrees to let us capture the content and then the device is returned immediately after. 

I see, thanks, I was more curious on criminal cases, where I expect (presume) that the process will take weeks or months.

jaclaz

ReplyQuote
Posted : 15/08/2020 8:52 am
masekul
(@masekul)
New Member

@cs1337 I tried this does not work on android 8.1 and above, Cellebrite will simply acquire the whatsapp stores in encrypted format and you may need to decrypt it manually.

ReplyQuote
Posted : 18/08/2020 8:10 am
OxygenForensics
(@oxygenforensics)
Active Member

@masekul In the latest Oxygen Forensic Detective, we have introduced the ability to extract WhatsApp and WhatsApp Business contacts and chats using OxyAgent utility installed in Android devices. Using this method you can quickly get all WhatsApp data and there will be no need to decrypt. It will be much faster than doing complete physical extraction that we also offer. 

One more method that might be of help for you is scanning a WhatsApp QR code in Oxygen Forensic Cloud Extractor and getting all the evidence very quickly and in a readable format. 

 

ReplyQuote
Posted : 18/08/2020 9:21 am
Share: