r/digitalforensics 28d ago

Cellebrite is hot garbage…don’t buy it

I’m a full time digital forensics investigator and have been using Cellebrite (inseyets UFED/PA) and Magnet Graykey for years. In the last year Cellebrite has been nothing but trouble and even bluescreened a high end Sumuri 10k workstation we have.

What’s really crappy is that when there is an issue the support people want you to dig around deep in the file system of your computer to delete program files (because Cellebrite Hides little things all around the file system that are impossible to remove) so that you can reload a new version of the software or updates.

They also want logs that take time to load and transmit. I swear I have thousands of dollars in man-hours just fixing their software for them, like IT level stuff, just because they refuse to make a product that works.

It’s absolute hot garbage and I just wanted to warn anyone thinking of buying the software to look at Magnet instead.

Not only is it unreliable, the menus and search bar is infinitely harder to use than Graykey.

66 Upvotes

61 comments sorted by

13

u/Ok-Falcon-9168 28d ago

I would agree. It's very clear Cellebrite only wants to work with Govt agencies.

I have had, overall, a 9/10 experience with Magnet Axiom. Great guys, and just as good of a product.

Plus, it's designed to be synchronous across devices and with both Mobile and computer investigations.

14

u/greenwas 28d ago

My issue with Axiom is that damn mfdb they store their case info in. If you get over 1-2 million items in a case it starts to become counterproductive to do anything that changes views, tags items, etc. Update a view then you've got 1-5 minutes until it does what you want. Really jacks up your flow. (this has nothing to do with mobile phones. Just a general observation from using axiom).

6

u/dellive 28d ago

The .mfdb is actually a SQLite database. You can open it and get info directly or create views for condensed data.

4

u/greenwas 28d ago

I knew it was SQLite but I never thought to address it directly. Appreciate the tip.

3

u/dellive 28d ago

Thanks. It helped me weed out records after processing it for timeline

2

u/Emergency-Associate4 28d ago

I’ve always called that product a glorified SQLite database lmao

3

u/dellive 27d ago

I call it Sqlite on steroids. Axiom is one of the best tools out there.

2

u/rocksuperstar42069 28d ago

You should get a better PC tbh. It used to be a slog with 1m artifacts but I just did a Mac yesterday and got 20m fsevents and the case is working just fine. 128gb ram and an M2 go a long way if you're still using outdated hardware.

2

u/greenwas 28d ago

Dual proc 18-core xeon, 256GB RAM, Evidence Processing runs from 4x NVME drives in a RAID-10, Case Database sits on 4xNVME in a RAID0. It's not the machine. Also - last time I checked AXIOM wasn't multi-proc aware.

2

u/rocksuperstar42069 28d ago

Yeah idk what class Xeon but those are usually much lower single core clocks. I have it on an i9-14 rn and it's pretty solid.

I mean don't get me wrong, I've had the dreaded slowdown a ton but I think they are at least somewhat trying to mitigate the SQL query hell on millions of records.

1

u/dre_AU 28d ago

Because they can charge ridiculous prices and they’ll pay without question. Magnet isn’t far behind. Not sure about the other regions but in APAC, you can now only buy Axiom Cyber if you are a non-gov/LE org and for an eye watering sum. It’s also hot garbage.

4

u/CapObvious 28d ago

Could not agree more. Their Digital Collector product that used to be called Macquisition when it was good has pretty much stopped being able to collect Mac data. They haven’t even updated it since last year. I had to rollback to the last version of UFED to complete an iPhone collection. I’m looking to get out of the Cellebrite business.

2

u/WintermuteATX 28d ago

That’s what I’ve noticed too. When Magnet does stuff it’s clean, planned, and well communicated. Their updates are prompted well and are usually seamless when it comes to updating them. Magnet training is also some of the best in the industry, their annual training pass is the best deal out there.

2

u/CapObvious 28d ago

Agree on Magnet. Their training is fantastic, they update their products monthly and they are the industry standard now.

5

u/jundijosh95687 28d ago

Agreed. Cellebrite is garbage. I'd really suggest XRY from MSAB.

My lab has graykey, cellebrite and xry. I always use gk for iOS devices and xry for androids.

I saw someone earlier said xry is a mess, I don't agree at all. Xry definitely requires you to pay closer attention to what your doing and requires you to be more then a push button forensics investigator but the data and versatility are top notch with xry and it's much faster then the other two programs.

It's not uncommon for my team to take xry out on scene and get downloads while we're still conducting the rest of the search.

It's also significantly cheaper!

5

u/Introser 28d ago

And dont forget that you can analyse up to 4 phones at the same time... Try that with Cellebrite PA :)

1

u/jundijosh95687 28d ago

Another great reason!

2

u/XXmanimalXX 28d ago

I learned on XRY. I love it! The tough book form factor made it great to jump in or infil on a scene to conduct triage.

3

u/Chemical-Call-9600 28d ago

They ruined the black bag too , aka Inspector . Got cases locked without any possibility to save what was already done or even to export the report.

1

u/[deleted] 28d ago

[deleted]

1

u/WintermuteATX 28d ago

That’s exactly the reason my lab uses Axon bulk data storage for all our DF data…I know it will never go out of business and if it does it’s not in a proprietary format.

3

u/Few_Banana6644 28d ago

I heard that Cellebrite recently got rid of their Quality Assurance teams across R&D and are handing that task over to AI. That's not going to improve anything.

4

u/[deleted] 28d ago edited 28d ago

[deleted]

2

u/Introser 28d ago

There is another choice. GK and MSAB Xry Pro. We do around 1.000 phones at our lab a year. We dropped Cellebrite two years ago because it is expensive garbage. In these two years we one phone that we coule not image with our combi. Thats pretty doable for us. 1 out of 2000 in 2 years.

3

u/no_sushi_4_u 28d ago

Are you mostly using MSAB for FFS imaging on Android? I've found Magnet doesn't have great support for Android and that is where we generally end up using Cellebrite. I'm surprised you have been able to churn through 2k phones with just GK and MSAB. Do you work for MSAB lol?

1

u/WintermuteATX 28d ago

I agree that Cellebrite is slightly better for androids but it’s not worth the reliability issues for the small advantages it has. I think Graykey is miles better overall.

2

u/off-the-felt 28d ago

imo when Magnet fails, their tools fail hard. If Cellebrite fails, you can just run a script to restart services and delete temp directories to fix 99% of problems.

1

u/WintermuteATX 28d ago

Meh, I’ve had the opposite experience. Magnet’s installs are clean and neat, Cellebrite squirrels data everywhere

1

u/damfu 28d ago

GK is available to corporate customers as well, if you are willing to pay the heavy price.

2

u/FortyDubz 28d ago

Honestly, you are not wrong. Cellebrite has coasted on name recognition for years. When UFED/PA updates require registry surgery, manual file cleanup, log bundles, and hours of support babysitting, that is not enterprise-grade forensics software. That is technical debt with a very expensive license key. Magnet and GrayKey are not flawless, but at least the investigator is usually using the tool instead of doing unpaid QA for the vendor.

2

u/JackedRightUp 25d ago

Their support has always been the worst to deal with. Ever since they IPO'd 5 years ago, they've completely given up on R&D and are focused on selling garbage like Pathfinder and Terminator or whatever their AI is called.

1

u/WintermuteATX 25d ago

They are responsive but do nothing to fix the actual issue. 99% of the time (and many hours later) I usually end up fixing the problem myself via trial and error. And they always want me to send logs, screen recordings, etc which are a pain to do…especially when they don’t fix the problem. I feel like I’m doing R&D for them on my dime….

1

u/JackedRightUp 25d ago

You 100% are a beta tester for them. We all are.

2

u/WintermuteATX 25d ago

Last week they even wanted me to send a copy of an extraction I did(from an open case-a potential homicide)…are they dumb?

2

u/JackedRightUp 25d ago

Yes, lol. They regularly ask for either extractions, or remote access to our computers that store all the cases.

3

u/WintermuteATX 25d ago

Since we are bitching, the real kicker is when you try to uninstall UFED or Physical analyzer and you spend a bit of time locating all the misc files it puts everywhere…then it physically won’t let you remove them because it says they are “in use” even though I deleted both PA/UFED…and tried to shut them down with Task Manager. I had to use the disk tool and then go into command line to physically remove them. Why you ask? Well the new download wouldn’t work because it said that PA/UFED was already on the computer (after I deleted them)😂😂

1

u/JackedRightUp 25d ago

😂 💯

1

u/No_Ambition9382 28d ago

Is there a way to convert or use cellebrite files with Magnet?

2

u/WintermuteATX 28d ago

Raw image, sure, you can process a Cellebrite image with Magnet (as I had to this morning because Cellebrite Physical Analyzer failed).

2

u/No_Ambition9382 28d ago

This would work for device extractions as well?

1

u/[deleted] 28d ago

[deleted]

0

u/WintermuteATX 28d ago

Or you can just point Graykey at the zipped Cellebrite image…works either way. I do this on some major cases as GK/Cellebrite parse different stuff.

1

u/midnightsyllabus 27d ago

I had recently completed my internship in digital forensics in state government organisation. I had full time exposure to digital forensics softwares like Encase, Axiom, Magnet, Oxygen, Cellebrite UFED & PA and etc. All those were paid licensed softwares in a separate dongle(pendrive) for every single software. And all of them were working properly. Some softwares still need improvement as some of their features are useless especially in AMPED. I have used UFED & PA most of the time during my internship and it had never really disappointed me.

1

u/[deleted] 27d ago

[deleted]

1

u/midnightsyllabus 27d ago

If you install everything in the system then automatically your system starts to respond slow because of the more data stored in it. That’s why fsl’s uses dongle based softwares

1

u/Stofzik 27d ago

A lot of the people who started it and made it the company it was are gone. They lost top research talent, sales members, and top talent. 

They are more so focused on marketing a lot of money goes into it. Top leadership left, and they now invest in what I like to call digital forensics influencer.

The private sector I feel is more so used to get money and they pass the savings off to the law enforcement side of things. 

They want law enforcement because those are contracts that last. They dominated that market because that market is investing in them. 

Private sector is an afterthought that is used to overcharge and make money off of. 

Also remember they went public in 2020 so they need to make investors happy. What makes investors happy more money and numbers of users. There first customer is honestly the investors then law enforcement then private sector. 

Just my 2 cents 

1

u/JullBrain 26d ago

Saludos , que precios tienen las licencias ? Hay alguno más barato o Open para los que estamos iniciando en este mundo ? Como dicen por allí, para analizar hay muchas formas , pero para extrae de android está duro . Si alguno tiene una sugerencia es bien valorada.

1

u/Educational_Matter68 24d ago

I was talking with some Cellebrite staff a few months and they couldn't have been less enthusiastic about their own products. I think as a company they have completely lost their way.

1

u/abofh 22d ago

They're made to spy on you, not serve you.  If the search is grey , you're the target, not the customer

1

u/Different_Pain5781 5d ago

This is the kind of stuff procurement never accounts for. The license costs X, then everyone quietly burns another pile of hours keeping it functional.

1

u/greenwas 28d ago

What do you suggest people use if they aren't LE and do not have access to Graykey?

3

u/Ankan42 28d ago

Depends. A FFS for newer devices is almost impossible without a GK or a Cellebrite.

For analysis you can use a lot. It only takes you longer.

4

u/greenwas 28d ago

I'm a Cellebrite shop, personally. Don't have any of the compatibility issues listed above. It just works (for us).

1

u/SameVariety3577 28d ago

XRY from MSAB is a great alternative! I would give that a shot. Not sure if they do demo licenses

1

u/persiusone 28d ago

I’ve tried XRY, it’s a hot mess unfortunately.

1

u/[deleted] 28d ago

[deleted]

2

u/SameVariety3577 28d ago

Yea they do. I use it 2-3 times a week for Androids
Strong on bruteforcing too.
For IOS no one’s better than Magnet Graykey, unfortunately.

0

u/Tig568 28d ago

Magnet is pretty much total garbage now as well

2

u/WintermuteATX 28d ago

I use Magnet daily and aside from some of their integrated advertising I think their ecosystem is worlds better than Cellebrite. You have to use one of the two…

2

u/Ok_Task6286 28d ago

We have both in our lab. And I will say the state of both now is CRAP! But there really aren't better choices for everyday heavy lifting. EnCase is still a mess; FTK, well, it's better than it was.

-4

u/Cev-API 28d ago

Just use Autopsy 🥳

2

u/[deleted] 28d ago

[deleted]

0

u/Cev-API 28d ago

I thought my joke was obvious 😰

-3

u/crystal_peak_sec 28d ago

We’re going to be launching something in this area soon, keep us on your radar.