Digital Forensics
9.73K subscribers
334 photos
41 videos
164 files
589 links
To get the products, contact @D3HKORDI or @UnBin4A:
UFED 4PC
Physical Analyzer (PA)
PA Ultra
PA Inseyets
Magnet
Oxygen
FinalMobile
Cellebrite Inspector
SPFPro
MDVideo
MDNext
MDLive
MDRED
MDCloud
MDDrone
Amped Five & Authenticate
Arsenal
FTK
CyberTriage
Download Telegram
Digital Forensics
Qualcomm Generic and Qualcomm Decrypting - How to Detect Supported Device Modes DFU/FTM/EDL/ADB Question To use the Qualcomm Generic or Qualcomm Decrypting methods, your device must be able to enter 1 of 3 modes: DFU, FTM, or EDL. Next 4 posts explains how…
FTM
Some devices support a mode called FTM (Field/Factory Test Mode).
Among these are ZTE, Alcatel, and maybe others.
A device in FTM mode will sometimes display the letters "FTM" on the screen, but not always.
A device in FTM mode should use either Generic Qualcomm EDL or Generic Decrypting Qualcomm EDL methods (not the Recommended).
Certain button combinations may put a device in FTM mode.
A device in FTM mode will appear as the following picture in Device Manager:
Digital Forensics
Qualcomm Generic and Qualcomm Decrypting - How to Detect Supported Device Modes DFU/FTM/EDL/ADB Question To use the Qualcomm Generic or Qualcomm Decrypting methods, your device must be able to enter 1 of 3 modes: DFU, FTM, or EDL. Next 4 posts explains how…
DFU
Some devices support a mode called DFU, not to be confused with iPhone DFU.
ZTE devices support this mode, and perhaps others do too.
A device in DFU mode will usually display a black screen.
A device in DFU mode should use either Generic Qualcomm EDL (Recommended) or Generic Decrypting Qualcomm EDL (Recommended).
Certain button combinations may put a device in DFU mode.
A device in DFU mode will appear as the following picture in Device Manager:
DFU
Digital Forensics
Qualcomm Generic and Qualcomm Decrypting - How to Detect Supported Device Modes DFU/FTM/EDL/ADB Question To use the Qualcomm Generic or Qualcomm Decrypting methods, your device must be able to enter 1 of 3 modes: DFU, FTM, or EDL. Next 4 posts explains how…
EDL
Some devices support a mode called EDL: Emergency Download Mode.
A device in EDL mode will usually display a black screen.
A device in EDL mode should use either Generic Qualcomm EDL (Recommended) or Generic Decrypting Qualcomm EDL (Recommended).
Certain button combinations may put a device in EDL mode.
Some devices will enter EDL with the use of Cellebrite's Cable 523.
A device in EDL mode will appear the following picture in Device Manager:
Digital Forensics
Qualcomm Generic and Qualcomm Decrypting - How to Detect Supported Device Modes DFU/FTM/EDL/ADB Question To use the Qualcomm Generic or Qualcomm Decrypting methods, your device must be able to enter 1 of 3 modes: DFU, FTM, or EDL. Next 4 posts explains how…
ADB
To use ADB to perform a Qualcomm extraction, your device must have USB Debugging enabled.
This usually means it needs to be unlocked.
The Generic Qualcomm EDL (ADB) and Generic Decrypting Qualcomm EDL (ADB) methods are applicable.
Power on the device and connect to USB port via Cable 100 or 170.
If the drivers have installed correctly, you should see the device under Portable Devices as the following picture:
Acquire and decrypt a WhatsApp backup using a recovered decryption key

After you acquire an Android image, you can attempt to recover the user's WhatsApp decryption key and use the key to decrypt their WhatsApp cloud backups. In some cases, the decryption key might not be available if you acquired a quick image of the Android device. If the WhatsApp data is missing from the quick image, attempt to acquire a full image.

Note: To acquire and decrypt a user's WhatsApp backups from the cloud, you'll require the following information:

- Google credentials (user name and password) and multi-factor authentication details if required
- Phone number associated with the account
- Decryption key

To acquire and decrypt a WhatsApp backup:
1- In AXIOM Examine, in the Artifacts explorer, browse to Mobile > Android WhatsApp User Information.
2- Find the Private Key and Phone Number.
3- On the Process menu, click Add new evidence to case.
4- In AXIOM Process, click Evidence sources > Cloud > Acquire evidence.
5- Confirm that you have the proper search authorization.
6- Click WhatsApp.
7- Provide the user's Google email address, and then click Next.
8- Provide the user's Google password, and then click Next.
9- If applicable, provide 2-step verification details.
10- When prompted to trust International, Inc., click Allow.
11- Provide the target's phone number, including country code, and then click Next.
12- Select the backups you want to acquire, and then click Next.
13- Browse to Artifact details > Cloud artifacts > Cloud WhatsApp Backups artifact, and click Options.
14- In the Options for decrypting WhatsApp dialog, provide the Private Key listed in the Android WhatsApp User Information artifact in AXIOM Examine and click OK.
15- Click Go to Analyze evidence and click Analyze evidence.

ref: magnetforensics.com
#Magnet
👍1
A minor version for Cellebrite Reader is released!
1 Overview.pdf
7.8 MB
Overview (UFED 4PC, UFED Touch2, UFED Responder)
2 Logical extraction.pdf
1.1 MB
Logical Extraction (UFED 4PC, UFED Touch2, UFED Responder)
3 Password extraction.pdf
913.2 KB
Password Extraction (UFED 4PC, UFED Touch2, UFED Responder)
4 File system extraction.pdf
1.6 MB
File system Extraction (UFED 4PC, UFED Touch2, UFED Responder)
5-6 Physical extraction.pdf
2.2 MB
Physical Extraction (UFED 4PC, UFED Touch2, UFED Responder)
7 Capture images and screenshots.pdf
1.6 MB
Capture images and screenshots (UFED 4PC, UFED Touch2, UFED Responder)
8 Chat capture.pdf
2.2 MB
Chat capture (UFED 4PC, UFED Touch2, UFED Responder)
9 SIM card functionality.pdf
869.7 KB
SIM card functionality (UFED 4PC, UFED Touch2, UFED Responder)
10 Drone extractions.pdf
761.3 KB
Drone Extractions (UFED 4PC, UFED Touch2, UFED Responder)
11 Device tools.pdf
770.9 KB
Device Tools (UFED 4PC, UFED Touch2, UFED Responder)