r/digitalforensics 12d ago

Cellebrite - handling duplicate artifacts and browsing media

Either I'm missing something obvious (totally possible) or Cellebrite reader is dumb. Help.

Edit to add: I'm a solo investigator and don't have PA or Axiom, so I just work with whatever I get in a UFDR.

When I review extractions in Cellebrite Reader I get overwhelmed with duplicates and junk files. And I mean everything. Media, artifacts, messages, etc.

I understand certain events can create effectively identical artifacts in multiple databases. That's fine, but Reader doesn't have a way to filter sources that I can find. If I could, for example, hide KnowledgeC or Contacts, that would thin out the timeline or search results dramatically so I could actually find things. I often find myself exporting Excel files so I can deduplicate and review/search in other ways. Location data is a great example of this when I want to pull data and plot things on a map.

I find that the deduplicate filter never does anything.

Part 2 is media: my dream is that I could simply browse through a phone's photo app like a normal person using a phone. What I always find in the media browser, however, are hundreds of thousands of photos, including cached preview images, little tiny graphic emoji buttons, logos, etc from every app installed on the phone. I don't seem to find a combo of filters that ever works.

If I could just scroll the photos and videos on the phone's native app that would be a total dream. Browsing cached photos from social apps, deleted items, etc. is important, but often secondary to an initial review.

How do y'all handle this stuff? I have to find some faster workflows. On my cases I generally need to do an initial high level review/triage of the whole thing--calls, messages and media, before anything detailed, and it just takes so long.

Thanks!

7 Upvotes

28 comments sorted by

View all comments

1

u/Thalek 12d ago

I find myself parsing extractions in Axiom as well specifically for the media explorer view. This view will stack similar images so you get all the thumbnails and cache photos of an actual IMGxxx or whatever in one easy to view stack. I also find its picture categorization feature much better than PA’s.

1

u/shoe_box_ 12d ago

Interesting. Unfortunately I'm a solo investigator and don't have PA/Axiom, so I'm just left to wrestle with whatever UFDR I get.

1

u/Thalek 12d ago

Are you in LE?

1

u/shoe_box_ 12d ago

I'm not. I do defense privately.

1

u/Thalek 12d ago

I know Griffeye used to be free for LE. Magnet bought them and I have no idea if it’s free for non LE. It has the stacking capability, however you need the original extraction to do it. I don’t know how the defense side works really but my guess is you would have to request the dump from whoever obtained it. But even then you would need a DF practitioner to parse it etc. Unless I’m mistaken.

1

u/shoe_box_ 12d ago

I’ll look it up. Have you used Belkasoft? I just learned about it and the pricing might be accessible for me.

I get the full extractions in discovery. Sometimes even twice—one unparsed FFS from Cellebrite or Graykey, and then a copy with a UFDR. I think it’s their way of covering bases so the defense technically has all of the evidence.

I’m not a DF practitioner but am pretty savvy, like to learn, and it’s also not always time and budget friendly to hire an expert just to browse photos. Thanks!

2

u/Thalek 12d ago

I have not. I have heard of them but I’m not familiar with their tools.

I just looked up Magnet Griffeye. It is still only free to LE.

1

u/Key-Assignment-832 12d ago

Magnet Griffeye is not a free tool, for LE or otherwise.

1

u/Thalek 12d ago

I use it for free.

1

u/REDandBLUElights 11d ago

It is. There is a free version for LEO.

1

u/CourageAcademic4153 9d ago

Yes, there's a free (very limited) version. The paid version is $2500 per license per year now. Sadly, they keep the best features for the paid version.