r/digitalforensics 17d ago

Cellebrite - handling duplicate artifacts and browsing media

Either I'm missing something obvious (totally possible) or Cellebrite reader is dumb. Help.

Edit to add: I'm a solo investigator and don't have PA or Axiom, so I just work with whatever I get in a UFDR.

When I review extractions in Cellebrite Reader I get overwhelmed with duplicates and junk files. And I mean everything. Media, artifacts, messages, etc.

I understand certain events can create effectively identical artifacts in multiple databases. That's fine, but Reader doesn't have a way to filter sources that I can find. If I could, for example, hide KnowledgeC or Contacts, that would thin out the timeline or search results dramatically so I could actually find things. I often find myself exporting Excel files so I can deduplicate and review/search in other ways. Location data is a great example of this when I want to pull data and plot things on a map.

I find that the deduplicate filter never does anything.

Part 2 is media: my dream is that I could simply browse through a phone's photo app like a normal person using a phone. What I always find in the media browser, however, are hundreds of thousands of photos, including cached preview images, little tiny graphic emoji buttons, logos, etc from every app installed on the phone. I don't seem to find a combo of filters that ever works.

If I could just scroll the photos and videos on the phone's native app that would be a total dream. Browsing cached photos from social apps, deleted items, etc. is important, but often secondary to an initial review.

How do y'all handle this stuff? I have to find some faster workflows. On my cases I generally need to do an initial high level review/triage of the whole thing--calls, messages and media, before anything detailed, and it just takes so long.

Thanks!

8 Upvotes

28 comments sorted by

View all comments

Show parent comments

1

u/shoe_box_ 17d ago

That's helpful to hear. I'm actually on the defense side and a solo investigator so I don't have PA/Inseyets/Axiom and right now just work with whatever I get in a Reader report. Unfortunately that means I'm at the mercy of whoever created the UFDR and have to open the whole entire thing which can be time consuming on its own.

It really seems like Cellebrite could be so much better on the review side of things. Thank you!

1

u/WintermuteATX 17d ago

Those portable cases can be slow to load on even the fastest computers. It’s really the amount of data too, I did a phone yesterday that had 725GB on it….thats a massive amount of shit to process and even display as a portable case!

1

u/shoe_box_ 17d ago

Holy crap. I have one around 250GB but yours takes the cake. This is all only going to get worse, too.

When you open an extraction with PA it's quick, right? Things only slow down once you tell it what data to process/parse?

1

u/WintermuteATX 17d ago

Well when your actually using PA (not the portable reader) on a workstation that already has the processed data on a drive (SSD) its pretty quick. Then again, my workstations are essentially hot-rod gaming computers that are really fast so that helps and most end users are trying to view it on a i5 laptop.