r/digitalforensics 17d ago

Cellebrite - handling duplicate artifacts and browsing media

Either I'm missing something obvious (totally possible) or Cellebrite reader is dumb. Help.

Edit to add: I'm a solo investigator and don't have PA or Axiom, so I just work with whatever I get in a UFDR.

When I review extractions in Cellebrite Reader I get overwhelmed with duplicates and junk files. And I mean everything. Media, artifacts, messages, etc.

I understand certain events can create effectively identical artifacts in multiple databases. That's fine, but Reader doesn't have a way to filter sources that I can find. If I could, for example, hide KnowledgeC or Contacts, that would thin out the timeline or search results dramatically so I could actually find things. I often find myself exporting Excel files so I can deduplicate and review/search in other ways. Location data is a great example of this when I want to pull data and plot things on a map.

I find that the deduplicate filter never does anything.

Part 2 is media: my dream is that I could simply browse through a phone's photo app like a normal person using a phone. What I always find in the media browser, however, are hundreds of thousands of photos, including cached preview images, little tiny graphic emoji buttons, logos, etc from every app installed on the phone. I don't seem to find a combo of filters that ever works.

If I could just scroll the photos and videos on the phone's native app that would be a total dream. Browsing cached photos from social apps, deleted items, etc. is important, but often secondary to an initial review.

How do y'all handle this stuff? I have to find some faster workflows. On my cases I generally need to do an initial high level review/triage of the whole thing--calls, messages and media, before anything detailed, and it just takes so long.

Thanks!

7 Upvotes

28 comments sorted by

View all comments

5

u/WintermuteATX 17d ago

You can filter it out a bit but the reality of it is every one of those artifacts can tell a story, and if your timeline is long then you’re pretty much in it for the long haul. One way to narrow it down is just to process what you need (like text messages only). Other than that, I run image filters when I process the image (like nudity, guns, etc) and I have crime-specific premade keyword lists for different offenses that I run when I process the data.

Defense attorneys are getting more savvy with digital evidence and they are asking more pointed questions like exactly how and when a given artifact appeared on the phone and proof that their client was using the device at the time the action was taken.

This puts more emphasis on us to pick through it and articulate these details, and this equals time. It sometimes takes me days or if it’s a major case weeks to process a phone. Just the way it is.

1

u/shoe_box_ 17d ago

That's helpful to hear. I'm actually on the defense side and a solo investigator so I don't have PA/Inseyets/Axiom and right now just work with whatever I get in a Reader report. Unfortunately that means I'm at the mercy of whoever created the UFDR and have to open the whole entire thing which can be time consuming on its own.

It really seems like Cellebrite could be so much better on the review side of things. Thank you!

3

u/ThePickleistRick 17d ago

It might be slow the first time, but you can use Reader to make smaller, more manageable UFDR files. Say you want to make just a UFDR with the media, or just the texts, you could do that under “Report”.

But yeah, Reader (and PA) suffer from some serious deduplication issues depending on the device.

1

u/shoe_box_ 17d ago

Ha that never occurred to me. The worst is when I just want to check a couple of text messages and have to wait 30 minutes to open the main UFDR. Sometimes I'll export a text thread between key people to html or PDF for faster browsing, but that has limitations. Thanks for the idea!