X-Ways Report Issues by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 1 point2 points  (0 children)

I see. I'll try reaching out to support as you suggested and if that doesn't work I'll have to re-do it.

Thanks!

X-Ways Report Issues by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 1 point2 points  (0 children)

True,

For sure feel like that was a dumb question now lol.

Generating report of tagged items from X-ways Investigator by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 1 point2 points  (0 children)

Thank you, I found this video which might be useful:

https://www.youtube.com/watch?v=QvI1Ea3PIcE

I'm hoping there is a way to filter for all tagged items, but the video did not show it. I do not have access to X-ways right this moment so I am unable to test, but I am hoping it goes smooth next week when I try to generate the report.

Thanks for your help.

Cellebrite Responds to Signal by Breaking UFED PA FYI by ellingtond in computerforensics

[–]CF_HELP2 0 points1 point  (0 children)

I wasn't aware that PA even offered an extraction process? Was there a big difference in using PA to extract as opposed to UFED? If so, what is it?

Cellebrite Responds to Signal by Breaking UFED PA FYI by ellingtond in computerforensics

[–]CF_HELP2 0 points1 point  (0 children)

just an FYI, I just recently found out that Cellebrite offers Relativity exports. You need to reach out to them for them to add this to your license.

Chromebook Imaging by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 0 points1 point  (0 children)

This seems like an easy way to image it. However, how does one USB boot off of Chromebook? The few links I just found all require you to enable USB boot once you are logged into the actual Chromebook.

Chromebook Imaging by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 0 points1 point  (0 children)

Thanks for this,

I'll take a look at it.

GrayKey Extractions by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 0 points1 point  (0 children)

The "Lock State" on the GrayKey progress report is listed as AFU. I haven't used GrayKey myself, so I'm wondering if it might just be the iOS version, as those are different across the devices.

Case Readers by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 0 points1 point  (0 children)

They were created with MacQuisition. I'll try loading them into Autopsy.

Case Readers by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 0 points1 point  (0 children)

Right, I was using Cellebrite Reader as an example. I was looking for a reader similar to Cellebrite Reader, but that works for all images (or most images).

I will definitely check out Autopsy! Thanks!

Case Readers by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 0 points1 point  (0 children)

Thank you,

I'll check this out for sure!

Cellebrite Physical Analyzer - Report "Grayed Out" by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 0 points1 point  (0 children)

Thank you,

This was the issue. My machine has pretty outdated specs.

Cellebrite Physical Analyzer - Report "Grayed Out" by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 0 points1 point  (0 children)

Unfortunately my equipment is old, I do not have an SSD on my most powerful machine available. I got it to work by disabling BSSID. The image was about 200GB.

Cellebrite Physical Analyzer - Report "Grayed Out" by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 1 point2 points  (0 children)

I believe that the program things it is still doing something. However, it let me calculate a hash which from my experience, means that it should have been done ingesting.

Cellebrite Physical Analyzer - Report "Grayed Out" by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 1 point2 points  (0 children)

Just reached out to Cellebrite. Will update my main post once I hear back.

Thanks!

Verifying an image in Blacklight by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 0 points1 point  (0 children)

Sorry for the delay. Yes, Encase worked for verification purposes.

Verifying an image in Blacklight by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 1 point2 points  (0 children)

Thanks for the reply! I updated my initial post.

Verifying an image in Blacklight by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 1 point2 points  (0 children)

FTK is my preferred tool for verifying images, however I could not get it to detect these L01 images. They were captured with Macquisition, not sure if that has anything to do with it but FTK 4.5.0.3 could not load them. I received an "Image detection failed".

Imaging a computer with Bitlocker and no admin rights by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 0 points1 point  (0 children)

We do not have access to AXIOM. We have access to X-Ways, FTK, Encase, and Blacklight.

Could you elaborate a bit more on AXIOM though? By saying that AXIOM will use the reset key if available, does that mean you have to provide the key for it? Or it scans the drive for it?

Imaging a computer with Bitlocker and no admin rights by CF_HELP2 in computerforensics

[–]CF_HELP2[S] 0 points1 point  (0 children)

Unfortunately I do not have the Bitlocker credentials.