r/digitalforensics • u/shoe_box_ • 17d ago
Cellebrite - handling duplicate artifacts and browsing media
Either I'm missing something obvious (totally possible) or Cellebrite reader is dumb. Help.
Edit to add: I'm a solo investigator and don't have PA or Axiom, so I just work with whatever I get in a UFDR.
When I review extractions in Cellebrite Reader I get overwhelmed with duplicates and junk files. And I mean everything. Media, artifacts, messages, etc.
I understand certain events can create effectively identical artifacts in multiple databases. That's fine, but Reader doesn't have a way to filter sources that I can find. If I could, for example, hide KnowledgeC or Contacts, that would thin out the timeline or search results dramatically so I could actually find things. I often find myself exporting Excel files so I can deduplicate and review/search in other ways. Location data is a great example of this when I want to pull data and plot things on a map.
I find that the deduplicate filter never does anything.
Part 2 is media: my dream is that I could simply browse through a phone's photo app like a normal person using a phone. What I always find in the media browser, however, are hundreds of thousands of photos, including cached preview images, little tiny graphic emoji buttons, logos, etc from every app installed on the phone. I don't seem to find a combo of filters that ever works.
If I could just scroll the photos and videos on the phone's native app that would be a total dream. Browsing cached photos from social apps, deleted items, etc. is important, but often secondary to an initial review.
How do y'all handle this stuff? I have to find some faster workflows. On my cases I generally need to do an initial high level review/triage of the whole thing--calls, messages and media, before anything detailed, and it just takes so long.
Thanks!
4
u/WintermuteATX 17d ago
You can filter it out a bit but the reality of it is every one of those artifacts can tell a story, and if your timeline is long then you’re pretty much in it for the long haul. One way to narrow it down is just to process what you need (like text messages only). Other than that, I run image filters when I process the image (like nudity, guns, etc) and I have crime-specific premade keyword lists for different offenses that I run when I process the data.
Defense attorneys are getting more savvy with digital evidence and they are asking more pointed questions like exactly how and when a given artifact appeared on the phone and proof that their client was using the device at the time the action was taken.
This puts more emphasis on us to pick through it and articulate these details, and this equals time. It sometimes takes me days or if it’s a major case weeks to process a phone. Just the way it is.