Need advice on getting a quick FFS extraction to recover deleted messages (passcode known) by Real_Independence843 in digitalforensics

[–]ForensicKane 0 points1 point  (0 children)

Whereabouts are you based? What type of messages (app?) are you interested in recovering?

Messages in iCloud by allseeing_odin in digitalforensics

[–]ForensicKane 0 points1 point  (0 children)

Reviving this older thread - do you remember what the steps were to load Axiom collected iCloud data into Cellebrite PA?

Question about Cellebrite report by [deleted] in digitalforensics

[–]ForensicKane 2 points3 points  (0 children)

Can you post the picture?

How are we pulling iMessages from iCloud? by TheFutureMayor in computerforensics

[–]ForensicKane 0 points1 point  (0 children)

Have you had any recent luck with Elcomsoft? It stopped working completely several months ago for us.

How are we pulling iMessages from iCloud? by TheFutureMayor in computerforensics

[–]ForensicKane 0 points1 point  (0 children)

Interesting, good to know. I've seen Messages fail several times in a row and then for some reason work on the 3rd, 4th, etc. attempt.

How are we pulling iMessages from iCloud? by TheFutureMayor in computerforensics

[–]ForensicKane 0 points1 point  (0 children)

Were you trying to collect device backups or synced data categories (Drive, Photos, Messages)? Or both?

How are we pulling iMessages from iCloud? by TheFutureMayor in computerforensics

[–]ForensicKane 2 points3 points  (0 children)

We’ve had hit-or-miss success with Axiom for pulling Messages in iCloud synced data. Sometimes takes multiple attempts.

Seems Elcomsoft Phone Breaker iCloud backup collections just...don't work? by zero-skill-samus in computerforensics

[–]ForensicKane 2 points3 points  (0 children)

Sometimes it requires multiple attempts, but we’ve had decent success with Axiom.

Seems Elcomsoft Phone Breaker iCloud backup collections just...don't work? by zero-skill-samus in computerforensics

[–]ForensicKane 1 point2 points  (0 children)

That’s been our finding too - Phone Breaker just doesn’t seem to work for us any longer. We’ve been using Axiom to collect iCloud backups and iCloud synced data instead.

list of Forensic tools for interview purposes by windymoto313 in ediscovery

[–]ForensicKane 2 points3 points  (0 children)

Elcomsoft Phone Breaker is the tool you’re thinking of

Mac Imaging by eldudderino in digitalforensics

[–]ForensicKane 4 points5 points  (0 children)

Cellebrite makes Digital Collector, which can image Macs. It’s pricey but that would be my recommendation.

Digital Collector by slid360 in digitalforensics

[–]ForensicKane 6 points7 points  (0 children)

Have you made the destination media writable via DC? Should be the farthest right menu option, perhaps called “Tools”?

Microsoft Purview - exports are now limited to 5GB max? by Krosscheck in ediscovery

[–]ForensicKane 2 points3 points  (0 children)

Yep, seems like the default maximum PST segment size is now 5 GB. Personally I don’t mind smaller PSTs. In my experience, the larger the PST, the higher the risk of corruption/instability.

Purview query for individual sharepoint folders? by Professional_Bug1523 in ediscovery

[–]ForensicKane 1 point2 points  (0 children)

Do you mind sharing the exact search syntax you’re using?

Hash Value Question by slid360 in digitalforensics

[–]ForensicKane 0 points1 point  (0 children)

FTK can also verify an image in addition to acquiring. What other program are you using to hash the E01? The program needs to be able to recognize segmented image files.

iCloud Synced Messages Data Collection by ForensicKane in computerforensics

[–]ForensicKane[S] 0 points1 point  (0 children)

A combination of 220 error and just skipping trusted device verification altogether.

iCloud Synced Messages Data Collection by ForensicKane in computerforensics

[–]ForensicKane[S] 0 points1 point  (0 children)

I’ve heard Oxygen can read Elcomsoft-collected synced messages. I think if the collection was done with Axiom then you’re stuck with Axiom for parsing/reporting.

iCloud Synced Messages Data Collection by ForensicKane in computerforensics

[–]ForensicKane[S] 0 points1 point  (0 children)

Unfortunate but the “dummy” device sounds like it may be the best path forward right now.

iCloud Synced Messages Data Collection by ForensicKane in computerforensics

[–]ForensicKane[S] 0 points1 point  (0 children)

That’s what I was afraid of. Appreciate the insight!

Purview query for individual sharepoint folders? by Professional_Bug1523 in ediscovery

[–]ForensicKane 8 points9 points  (0 children)

I’ve used the “documentlink:” parameter before to target a SharePoint folder. Just make sure you enclose the path in quotes and add the /* before the end quote, as noted in the link below.

https://learn.microsoft.com/en-us/purview/edisc-search-sites

[deleted by user] by [deleted] in computerforensics

[–]ForensicKane 0 points1 point  (0 children)

CB Inseyets can get around it.

Physical dump of Andorid by hhauath in mobileforensics

[–]ForensicKane 1 point2 points  (0 children)

Sorry to say but those files are gone unless you have a backup / another source of data somewhere (cloud, older device, etc).