Showing posts with label Cellebrite. Show all posts
Showing posts with label Cellebrite. Show all posts

Thursday, January 7, 2021

Cellebrite Reader: You Don’t Know What You’re Missing!

January 7, 2021

Cellebrite Reader:  You Don’t Know What You’re Missing!

As a digital forensic practitioner who logs approximately 70% of cases in the mobile device forensics arena, it has become the norm for us to receive discovery in any number of forms from opposing counsel, law enforcement agencies, etc.  Being one of the most commonly used mobile forensic tools on the market (particularly by law enforcement), Cellebrite has wisely developed a way for people who wish to view the data on a particular device to do so, also with the capability of generating their own report.  This pared-down or lightweight version of the Cellebrite Physical Analyzer program, called the Cellebrite Reader, is a great free way to browse the 30,000-foot view of the data, particularly for laypersons who may just want to get text messages, pictures, videos, etc.  These are traditionally the “high points” of the data on the phone or tablet and can sometimes include deleted items, but a serious warning should accompany the Cellebrite Reader file:  You don’t know what you’re missing!



Who Should Use The Cellebrite Reader?

The Cellebrite (or UFED) Reader is a lightweight version of the paid version of the analysis tool that accompanies a full Cellebrite product license called Physical Analyzer.  To say it’s a “lightweight version” of Physical Analyzer is a bit of an understatement.  At first glance in the user interface, the two applications look very similar, but as with most things in digital forensic analysis, the devil is in the details.  So then who should use the Cellebrite/UFED Reader?  If your case involves any of the “basic” data areas, such as undeleted text messages, photographs and some location data, then the UFED Reader tool is probably fine.  The tool is best for on-staff investigators, paralegals, private investigators and other mostly non-technical support staff.  If you have absolutely no need to dig into the data at all, the UFED Reader program should serve your purposes just fine.  The issues emerge when we dive into how the data is generated and what is included, or rather not included, by the person who generated the Reader file.


The “Analyzed Data” portion provides a great overview of the simple data areas decoded automatically by Cellebrite, including *some* deleted data (red parentheses)


How Is a Cellebrite Reader File Generated And What Is Included?

A Cellebrite/UFED Reader File is generated within the larger licensed tool called Cellebrite UFED Physical Analyzer.  Many times, because of case backlog or by specific request, the person doing the data extraction from the device(s) will create a “data dump” report, viewable in the UFED Reader.  This creates a .UFDR file, which is only able to be opened and read in the UFED Reader program, which accompanies the UFDR file at no cost to the user.  In the case of a data dump report, ostensibly all of the readily viewable and automatically decoded data on the device is included in the UFDR file. 

However, one strong warning about UFDR files is that they can easily be generated by the analyst cherry-picking or selectively choosing the data to include in the UFDR file, which is NOT a data dump.  For example, the person responsible for generating the Cellebrite Reader file can choose only certain picture file types or certain text messages or message strings to include in the Reader file. This could *look* the same as a data dump within Cellebrite Reader, but would have far less data than the 100% dump of everything available from the device.  There is no clear indication that a data dump file has been generated versus one that is selectively created by the analyst and exported into a UFDR and Cellebrite UFED Reader file.  It is not unlikely that the person generating the Cellebrite Reader file for your review has not included things like the databases from the device (pictured below).  We’ll discuss the importance of this shortly…


The other strong warning about Cellebrite Reader (UFDR) files is that they MAY NOT include all of the data.  While companies like Cellebrite, Oxygen, MSAB and Magnet Forensic try very hard to keep up with the trends in mobile technology, they are always playing a game of catch-up with their support of hardware and software because mobile technology moves so fast.  Add into the support equation that only a fraction of third-party applications are supported for decoding by these tools and the point becomes clear that if you are relying solely on UFED Reader files, you are likely missing data!  There is currently no exception to this rule.

The analogy we often use is that the Cellebrite Reader file is like a “prepared meal”.  A competent digital forensic analyst wants to inspect the ingredients that went into preparing that “meal” to make sure there’s nothing missing.


What Data Is Missing From Cellebrite Reader Files?

At a basic level, all application data (i.e., apps) on mobile devices is stored in roughly the same way.  This common storage approach is in a series of databases that are created, updated and stored as part of the application itself.  The databases work in the background of the user interface to store and present the data to the user on the device in the native user experience.  The problem is that, as stated earlier, a mere fraction (probably 10% or less) of the applications available on the Apple App Store (iPhone) or Google Play Store (Android) are supported for automatic decoding in Cellebrite or any other mobile forensic analysis tool.  This means that manual analysis of these databases will frequently become a necessity in your cases.  And these databases may not included as part of a UFED Reader file, and you may only be provided with automatically decoded data from supported applications.  The illustration below shows a snapshot of how many applications are decoded by Cellebrite on an iPhone 8 Plus running iOS 14.  Among the applications not decoded are common applications like Snapchat, Twitter, Instagram and others:



Even if an application like WhatsApp is supported for automated decoding in your tool, when the developers of WhatsApp make even minor changes to the application in development and roll the new version of the application out to their users, this could cause the mobile forensic tool to no longer be able to decode and display the data automatically.   This is another circumstance where manual analysis of the database(s) for the application will be required and as stated previously, the databases may very well not be included in your Cellebrite Reader file.

This is why you should always consult with a digital forensic professional in any case where you are provided data from an opposing party, particularly if there is a possibility that any of this data could be presented as evidence.


Wrapping It Up

While Cellebrite and their UFED Reader program are used as an example in this article, many other mobile forensic tools also have similar lightweight versions for simple review of the data.  These are often called “portable case files”, or something similar.  Regardless of the tool and what they call their lightweight application, the same limitations and warnings apply.  And when faced with the possibility that your client could go to prison for a significant period of time or lose custody of their children or perhaps even lose a large sum of money, due diligence dictates consultation with an expert who knows how this data is stored, how to appropriately analyze it and what steps should be taken to ensure nothing is missed.  Lives depend on it!


Author: 

Patrick J. Siewert

Principal Consultant

Professional Digital Forensic Consulting, LLC 

Virginia DCJS #11-14869

Based in Richmond, Virginia

Available Wherever You Need Us!


We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation

About the Author:

Patrick Siewert is the Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia (USA).  In 15 years of law enforcement, he investigated hundreds of high-tech crimes to precedent-setting results and continues to support litigation cases and corporations in his digital forensic practice.  Patrick is a graduate of SCERS & BCERT and holds several vendor-neutral and specific certifications in the field of digital forensics and high-tech investigation and is a court-certified expert witness.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.

Email:  Inquiries@ProDigital4n6.com

Web: https://ProDigital4n6.com

Pro Digital Forensic Consulting on LinkedIn: https://www.linkedin.com/company/professional-digital-forensic-consulting-llc

Patrick Siewert on LinkedIn:  https://www.linkedin.com/in/patrick-siewert-92513445/


Sunday, May 20, 2018

Apple iPhone “Significant Locations”



May 20, 2018

Apple iPhone “Significant Locations”

I recently attended a conference of civil litigators in Virginia.  During the cocktail hour and after a very interactive CLE presentation on “Leveraging Data in Insurance Fraud Investigations”, I was talking with a few attendees about the different types of data available to them in their investigation and litigation of insurance fraud claims.  Admittedly, I was taken aback when one of the attorneys mentioned to me the “Significant Locations” that are logged on iPhones and showed me the locations on his.  This is probably because I have most (or all) location services turned off on my personal device, so I’d never given it much thought.  However, the conversation brought up the question, are these artifacts available through forensic data extraction and analysis?  And if so or if not, how do we access them?  What value might they serve in both criminal and civil investigations?

For the extraction, testing and exhibits illustrated here, we used an iPhone 5s running iOS v. 11.2.6.  Cellebrite Physical Analyzer v. 7.5 was used for the extraction and analysis. As mentioned later, location services must be turned ON with the device in order for this information to be logged, as detailed in the UFED Device Extraction Info below:




Where & What Are “Significant Locations”

The first step is to identify where and what “Significant Locations” are.  The artifact is available to view on the device at Settings>Privacy>Location Services>System Services>Significant Locations (see below).







If location services are turned OFF, the significant locations data will not be logged and therefore unavailable.  Interestingly, to access Significant Locations on the device, the passcode or Touch ID must be entered, as shown below:




As we should all know by now, we need to obtain the passcode in some way (consent, court order, Gray Key, etc.) in order to facilitate data extraction in iOS 11 regardless, so while this may seem like an obstacle, it’s just another reason to obtain the passcode.

Upon accessing Significant Locations, a disclaimer is present, which reads the following:




The final sentence that the Significant Locations are encrypted already gives us a clue about whether or not UFED will be able to parse this data, but more on that a little later.

What’s Inside Significant Locations?


Once accessed, the Significant Locations are presented as a list, shown here:





Some interesting things of note about these particular locations:  This device doesn’t travel much.  The 13 locations logged in Henrico (Richmond/Midlothian), VA are related to the home location(s) of the device, which is already good information to have in the course of an investigation.  The device visits Williamsburg, which is the reason for the listings for that location.  All of the remaining locations are related to a trip from April, 2018 to and from Richmond, VA to Cincinnati, OH.  The device stopped in Beaver, WV and Beckley, WV.  Covington, KY is across the Ohio River from Cincinnati, where a dinner stop was made.  A stop in Fishersville, VA was made to get gas on the way back from Cincinnati.  Essentially, we have a road map of the trip to and from Cincinnati.

Further inspection of the locations where there are multiple listings reveals even more detail about where the device has been, as shown here in the Richmond, VA area:


And even more as shown here in the Cincinnati, OH area:


What’s most interesting about these artifacts is that no time was the device connected to any wireless networks in either location, save one in the Mt. Adams section of Cincinnati.  Yet in some instances, the business name and/or street address is listed in the log.



UFED Extraction & Access to “Significant Locations”

An Advanced Logical (option 1) encrypted extraction was conducted in Cellebrite UFED Physical Analyzer v. 7.5 to see if this data would be available through mobile forensic data extraction.  When the names of the locations were searched globally in the case, no results were presented.  When the term “Significant” was searched globally in the case, the following artifacts were located at var/root/library/caches/locationd:




The highlighted .plist files were exported and opened in XCode on a Mac system.  Each of these artifacts did not present any data that was readily identifiable as useful.  Is it possible that these artifacts are encoded within the extraction data and could therefore be located?  Sure, but for the purposes of this article, those measures were not undertaken.  As these artifacts are behind a double security wall (main passcode, then re-entry of the passcode to access Significant Locations on the device), it is logical to conclude that they are not accessible through mobile forensic data extraction (i.e., encrypted).

How Does This Help Your Case?

To recap, we located the Significant Locations on the device and performed a data extraction and it appears that these locations are not part of any readable portion of that data.  So how can we best incorporate this data into our investigations to add value?  Unfortunately, the best answer is the “old fashioned way”.  Access the device, navigate to “Significant Locations” and document each entry through photographs (NOT screen shots).  Depending on the level of usage of the device, this can be tedious and time-consuming, but the value of the data cannot be overlooked.

In criminal cases, this data can help put the device in locations where the suspect may have been (or not have been) during the time of the incident.  It can also help identify home locations and frequently visited locations, which can increase investigative leads, present additional accomplices, serve to impeach statements already made and more.  Naturally, accessing the device is key.  It bears noting that the “Significant Locations” data, combined with cellular provider call detail records could help paint a more thorough picture of the device location and/or movements than either one or the other alone.

In civil litigation, this data can be used in much the same way, but more likely to prove or disprove frequent locations, known associates (paramours, accomplices, etc.), and to help confirm or refute deposition or trial testimony.  If your case involves insurance fraud and the claimant says that he cannot travel, this data helps refute that statement without the need to obtain cellular carrier records.  But again, ideally we would couple this data with cellular location data to paint a more complete picture of the device usage patterns. 

A couple of final notes about the existence of this data.  First, it can be deleted.  Note in the image above the option to “Clear History” is present and if the user selects this, the logging will be reset.  It also appears (from checking a separate device with this logging turned on) that the data is stored for approximately 6 months.  It is unknown whether or not the data would transfer from an older device to an upgraded device as further testing would need to be conducted.  Finally, it is also unknown whether or not this data would be more readily accessible through mobile forensic data extraction on a jail-broken device.

Conclusions

This data is a proverbial gold mine, but it’s one we need to access in ways we generally don’t like to – by manipulating the device and accessing the UI.  However, this is still a valid form of analysis and documentation, especially when the access limitations on iOS devices forces us to use tools and techniques other than those that are automated.  As with most things in forensics, simply knowing where to look, how the data got there and how to best utilize the data to confirm or refute the other aspects of your case is (about) half the battle.  We all know Google, Apple and the cellular carriers are tracking us.  Let’s start using that data to help serve justice, no matter what we’re investigating!

Author:
Patrick J. Siewert
Principal Consultant
Professional Digital Forensic Consulting, LLC
Virginia DCJS #11-14869
Based in Richmond, Virginia
Available Wherever You Need Us!


We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation
About the Author:
Patrick Siewert is the Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia.  In 15 years of law enforcement, he investigated hundreds of high-tech crimes, incorporating digital forensics into the investigations, and was responsible for investigating some of the highest jury and plea bargain child exploitation investigations in Virginia court history.  Patrick is a graduate of SCERS, BCERT, the Reid School of Interview & Interrogation and multiple online investigation schools (among others).  He is a Cellebrite Certified Operator and Physical Analyst.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.
Twitter: @ProDigital4n6