Digital Forensics
Qualcomm Generic and Qualcomm Decrypting - How to Detect Supported Device Modes DFU/FTM/EDL/ADB Question To use the Qualcomm Generic or Qualcomm Decrypting methods, your device must be able to enter 1 of 3 modes: DFU, FTM, or EDL. Next 4 posts explains how…
EDL
Some devices support a mode called EDL: Emergency Download Mode.
A device in EDL mode will usually display a black screen.
A device in EDL mode should use either Generic Qualcomm EDL (Recommended) or Generic Decrypting Qualcomm EDL (Recommended).
Certain button combinations may put a device in EDL mode.
Some devices will enter EDL with the use of Cellebrite's Cable 523.
A device in EDL mode will appear the following picture in Device Manager:
Some devices support a mode called EDL: Emergency Download Mode.
A device in EDL mode will usually display a black screen.
A device in EDL mode should use either Generic Qualcomm EDL (Recommended) or Generic Decrypting Qualcomm EDL (Recommended).
Certain button combinations may put a device in EDL mode.
Some devices will enter EDL with the use of Cellebrite's Cable 523.
A device in EDL mode will appear the following picture in Device Manager:
Digital Forensics
Qualcomm Generic and Qualcomm Decrypting - How to Detect Supported Device Modes DFU/FTM/EDL/ADB Question To use the Qualcomm Generic or Qualcomm Decrypting methods, your device must be able to enter 1 of 3 modes: DFU, FTM, or EDL. Next 4 posts explains how…
ADB
To use ADB to perform a Qualcomm extraction, your device must have USB Debugging enabled.
This usually means it needs to be unlocked.
The Generic Qualcomm EDL (ADB) and Generic Decrypting Qualcomm EDL (ADB) methods are applicable.
Power on the device and connect to USB port via Cable 100 or 170.
If the drivers have installed correctly, you should see the device under Portable Devices as the following picture:
To use ADB to perform a Qualcomm extraction, your device must have USB Debugging enabled.
This usually means it needs to be unlocked.
The Generic Qualcomm EDL (ADB) and Generic Decrypting Qualcomm EDL (ADB) methods are applicable.
Power on the device and connect to USB port via Cable 100 or 170.
If the drivers have installed correctly, you should see the device under Portable Devices as the following picture:
Acquire and decrypt a WhatsApp backup using a recovered decryption key
After you acquire an Android image, you can attempt to recover the user's WhatsApp decryption key and use the key to decrypt their WhatsApp cloud backups. In some cases, the decryption key might not be available if you acquired a quick image of the Android device. If the WhatsApp data is missing from the quick image, attempt to acquire a full image.
Note: To acquire and decrypt a user's WhatsApp backups from the cloud, you'll require the following information:
- Google credentials (user name and password) and multi-factor authentication details if required
- Phone number associated with the account
- Decryption key
To acquire and decrypt a WhatsApp backup:
1- In AXIOM Examine, in the Artifacts explorer, browse to Mobile > Android WhatsApp User Information.
2- Find the Private Key and Phone Number.
3- On the Process menu, click Add new evidence to case.
4- In AXIOM Process, click Evidence sources > Cloud > Acquire evidence.
5- Confirm that you have the proper search authorization.
6- Click WhatsApp.
7- Provide the user's Google email address, and then click Next.
8- Provide the user's Google password, and then click Next.
9- If applicable, provide 2-step verification details.
10- When prompted to trust International, Inc., click Allow.
11- Provide the target's phone number, including country code, and then click Next.
12- Select the backups you want to acquire, and then click Next.
13- Browse to Artifact details > Cloud artifacts > Cloud WhatsApp Backups artifact, and click Options.
14- In the Options for decrypting WhatsApp dialog, provide the Private Key listed in the Android WhatsApp User Information artifact in AXIOM Examine and click OK.
15- Click Go to Analyze evidence and click Analyze evidence.
ref: magnetforensics.com
#Magnet
After you acquire an Android image, you can attempt to recover the user's WhatsApp decryption key and use the key to decrypt their WhatsApp cloud backups. In some cases, the decryption key might not be available if you acquired a quick image of the Android device. If the WhatsApp data is missing from the quick image, attempt to acquire a full image.
Note: To acquire and decrypt a user's WhatsApp backups from the cloud, you'll require the following information:
- Google credentials (user name and password) and multi-factor authentication details if required
- Phone number associated with the account
- Decryption key
To acquire and decrypt a WhatsApp backup:
1- In AXIOM Examine, in the Artifacts explorer, browse to Mobile > Android WhatsApp User Information.
2- Find the Private Key and Phone Number.
3- On the Process menu, click Add new evidence to case.
4- In AXIOM Process, click Evidence sources > Cloud > Acquire evidence.
5- Confirm that you have the proper search authorization.
6- Click WhatsApp.
7- Provide the user's Google email address, and then click Next.
8- Provide the user's Google password, and then click Next.
9- If applicable, provide 2-step verification details.
10- When prompted to trust International, Inc., click Allow.
11- Provide the target's phone number, including country code, and then click Next.
12- Select the backups you want to acquire, and then click Next.
13- Browse to Artifact details > Cloud artifacts > Cloud WhatsApp Backups artifact, and click Options.
14- In the Options for decrypting WhatsApp dialog, provide the Private Key listed in the Android WhatsApp User Information artifact in AXIOM Examine and click OK.
15- Click Go to Analyze evidence and click Analyze evidence.
ref: magnetforensics.com
#Magnet
👍1
Guidelines for Evidence Collection and Archiving
RFC-3227
https://datatracker.ietf.org/doc/html/rfc3227
RFC-3227
https://datatracker.ietf.org/doc/html/rfc3227
IETF Datatracker
RFC 3227: Guidelines for Evidence Collection and Archiving
A "security incident" as defined in the "Internet Security Glossary", RFC 2828, is a security-relevant system event in which the system's security policy is disobeyed or otherwise breached. The purpose of this document is to provide System Administrators…
1 Overview.pdf
7.8 MB
Overview (UFED 4PC, UFED Touch2, UFED Responder)
2 Logical extraction.pdf
1.1 MB
Logical Extraction (UFED 4PC, UFED Touch2, UFED Responder)
3 Password extraction.pdf
913.2 KB
Password Extraction (UFED 4PC, UFED Touch2, UFED Responder)
4 File system extraction.pdf
1.6 MB
File system Extraction (UFED 4PC, UFED Touch2, UFED Responder)
5-6 Physical extraction.pdf
2.2 MB
Physical Extraction (UFED 4PC, UFED Touch2, UFED Responder)
7 Capture images and screenshots.pdf
1.6 MB
Capture images and screenshots (UFED 4PC, UFED Touch2, UFED Responder)
8 Chat capture.pdf
2.2 MB
Chat capture (UFED 4PC, UFED Touch2, UFED Responder)
9 SIM card functionality.pdf
869.7 KB
SIM card functionality (UFED 4PC, UFED Touch2, UFED Responder)
10 Drone extractions.pdf
761.3 KB
Drone Extractions (UFED 4PC, UFED Touch2, UFED Responder)
11 Device tools.pdf
770.9 KB
Device Tools (UFED 4PC, UFED Touch2, UFED Responder)
Analyzing MTK Backup Files.pdf
833.4 KB
Analyzing MTK Backup Files using Cellebrite Physical Analyzer
New version of FinalMobile version 2021.06.07 is released.
You can download setup from here:
https://drive.google.com/u/0/uc?id=1ggqmZuhkoZKovN60CkoOpoIr2Bf9eI43&export=download
Soon, the update crack will be sent to the old customers privately.
New customers can contact @UnBin4A to get the crack.
You can download setup from here:
https://drive.google.com/u/0/uc?id=1ggqmZuhkoZKovN60CkoOpoIr2Bf9eI43&export=download
Soon, the update crack will be sent to the old customers privately.
New customers can contact @UnBin4A to get the crack.
UFED_Supported_Phone_List_7.45.zip
1.4 MB
UFED 4PC 7.45 Supported Phone List