UFED AND OXYGEN WHA...
 
Notifications
Clear all

UFED AND OXYGEN WHATSAPP DECRYPTION

14 Posts
9 Users
0 Likes
3,081 Views
LRush
(@lrush)
Posts: 1
New Member
Topic starter
 

Hi Folks,

Need help for the subjected topic.

1. How ufed decrypt the whatsapp data for iphones?

2. How oxygen decrypt the whatsapp data from iphone?

Please help...

 
Posted : 05/07/2020 11:31 am
AmNe5iA
(@amne5ia)
Posts: 168
Estimable Member
 

Not sure about Oxygen but i don't think UFED decrypts WhatsApp.  UFED just accesses the un-encrypted database files and interprets that for the user.

 
Posted : 06/07/2020 8:36 am
jadams951
(@jadams951)
Posts: 27
Eminent Member
 

Cellebrite's latest release of Physical Analyzer touts being able to parse out Whats App.  Haven't tried it yet so I can't say what it parses out.  

 
Posted : 06/07/2020 10:50 pm
passcodeunlock
(@passcodeunlock)
Posts: 792
Prominent Member
 

Both products have a nice list with supported devices and supported app versions.

Please be a bit more specific, tell us your device specs, operating system, app version, etc.

 
Posted : 10/07/2020 11:21 pm
Satyendra
(@satyendra)
Posts: 17
Active Member
 

In Case of iPhone, If you acquire the data from unlocked iPhone you will get all the WhatsApp chat there is no need to manually decrypt the database.

In the second scenario if you want to download WhatsApp chat backup from the iCloud, then via Credentials and then OTP is sufficient to decrypt the DB by Oxygen Forensic Cloud.

 
Posted : 06/08/2020 5:46 pm
OxygenForensics
(@oxygenforensics)
Posts: 137
Estimable Member
 
Posted by: @lrush

Hi Folks,

Need help for the subjected topic.

1. How ufed decrypt the whatsapp data for iphones?

2. How oxygen decrypt the whatsapp data from iphone?

Please help...

Oxygen Forensic Detective can fully extract WhatsApp data from iPhones. You can read more  about all our WhatsApp extraction methods in this brochure https://oxygen-forensic.com/uploads/doc_guide/Whatsapp_forensics.pdf

 
Posted : 12/08/2020 12:52 pm
cs1337
(@cs1337)
Posts: 83
Trusted Member
 

you have to do APK downgrade to collect WhatsAPP  from Android via Cellebrite.

 
Posted : 12/08/2020 5:11 pm
AmNe5iA
(@amne5ia)
Posts: 168
Estimable Member
 

@cs1337 How exactly do you do an APK downgrade on an iPhone which is the type of phone this question is about.    Also, if you get a full physical (FDE) or a full filesystem (FBE) on an android phone you don't need to do an APK downgrade to get Whatsapp data.

 
Posted : 13/08/2020 1:09 pm
cs1337
(@cs1337)
Posts: 83
Trusted Member
 
Posted by: @amne5ia

@cs1337 How exactly do you do an APK downgrade on an iPhone which is the type of phone this question is about.    Also, if you get a full physical (FDE) or a full filesystem (FBE) on an android phone you don't need to do an APK downgrade to get Whatsapp data.

my mistake. that's what i get for skimming the message. You shouldn't need to do anything for iPhone as WhatsAPP will be included in an advanced logical.

 

Most androids I come across you cannot perform a full physical image on without rooting the device which is not something we do as the phone needs to be returned in the same state it was received.

 
Posted : 13/08/2020 9:44 pm
jaclaz
(@jaclaz)
Posts: 5135
Illustrious Member
 
Posted by: @cs1337

 

Most androids I come across you cannot perform a full physical image on without rooting the device which is not something we do as the phone needs to be returned in the same state it was received.

A side-side question, if I may.

When is the phone returned, on average, in your experience?

I mean, a phone is seized, then imaged/investigated, then (possibly after some explicit decision by a judge or high rank investigator)  returned.

How long does the process take?

jaclaz

 

 
Posted : 14/08/2020 8:35 am
cs1337
(@cs1337)
Posts: 83
Trusted Member
 
Posted by: @jaclaz
Posted by: @cs1337

 

Most androids I come across you cannot perform a full physical image on without rooting the device which is not something we do as the phone needs to be returned in the same state it was received.

A side-side question, if I may.

When is the phone returned, on average, in your experience?

I mean, a phone is seized, then imaged/investigated, then (possibly after some explicit decision by a judge or high rank investigator)  returned.

How long does the process take?

jaclaz

 

I mostly deal in eDiscovery matters where generally Contacts/ Call Logs/ SMS/MMS and Voicemails are of relevance for litigation. Custodian agrees to let us capture the content and then the device is returned immediately after. 

 
Posted : 14/08/2020 11:25 pm
jaclaz
(@jaclaz)
Posts: 5135
Illustrious Member
 
Posted by: @cs1337 

I mostly deal in eDiscovery matters where generally Contacts/ Call Logs/ SMS/MMS and Voicemails are of relevance for litigation. Custodian agrees to let us capture the content and then the device is returned immediately after. 

I see, thanks, I was more curious on criminal cases, where I expect (presume) that the process will take weeks or months.

jaclaz

 
Posted : 15/08/2020 8:52 am
masekul
(@masekul)
Posts: 1
New Member
 

@cs1337 I tried this does not work on android 8.1 and above, Cellebrite will simply acquire the whatsapp stores in encrypted format and you may need to decrypt it manually.

 
Posted : 18/08/2020 8:10 am
OxygenForensics
(@oxygenforensics)
Posts: 137
Estimable Member
 

@masekul In the latest Oxygen Forensic Detective, we have introduced the ability to extract WhatsApp and WhatsApp Business contacts and chats using OxyAgent utility installed in Android devices. Using this method you can quickly get all WhatsApp data and there will be no need to decrypt. It will be much faster than doing complete physical extraction that we also offer. 

One more method that might be of help for you is scanning a WhatsApp QR code in Oxygen Forensic Cloud Extractor and getting all the evidence very quickly and in a readable format. 

 

 
Posted : 18/08/2020 9:21 am
Share:
Share to...