Compelson MOBILedit Forensic Express

Descripción

MOBILedit Forensic is a phone extractor, data analyzer, and report generator, all in a single solution. A powerful 64-bit application that uses physical and logical data acquisition methods, MOBILedit Forensic excels at advanced application analysis, deleted data recovery, live updates, a wide range of supported phones—including most feature phones—tailored reports, concurrent phone processing, and a user-friendly interface. With the password and PIN breaker, you can gain access to locked ADB or iTunes backups with GPU acceleration and multi-threaded operations for maximum speed.

MOBILedit Forensic delivers maximum functionality at a fraction of the price of other tools. It can be used as the only tool in a lab or as an enhancement to other tools through its data compatibility. When integrated with Camera Ballistics, it scientifically analyzes the origins of camera photos.

All-in-one tool used to collect evidence from phones.

With MOBILedit Forensic Express, you can extract all data from a phone with just a few clicks. This includes deleted data, call history, contacts, text messages, multimedia messages, photos, videos, recordings, calendar items, reminders, notes, data files, passwords, and app data such as Skype, Dropbox, Evernote, Facebook, WhatsApp, Viber, Signal, WeChat, and many others. MOBILedit Forensic Express automatically uses multiple communication protocols and advanced techniques to get the most data from each phone and operating system. It then combines all found data, removes any duplicates, and presents everything in a comprehensive and easy-to-read report.

Cell phone unlocking

Forensic Express has a built-in feature to unlock many cell phone models and obtain their physical images, even if the phone is turned off or locked. The lock of a wide variety of Android phones can be bypassed. It is prepared to use refreshed images to perform physical acquisition with a few clicks. Lock screen patterns, gestures, PINs, and passwords are not an obstacle to obtaining data from various Android devices.

Physical data acquisition and analysis. Beyond extraction, the technology has become a data source. Physical analysis allows opening the data file through this process, chip-off, or other tools to recover deleted files.

Advanced application analysis

The use of applications for communication and sharing has grown considerably. Many applications are published or updated every day. It is obvious that application analysis is necessary to obtain all possible evidence. It is the most powerful aspect of MOBILedit Forensic Express, and we dedicate a large part of our technical team specifically to this matter. We use adaptive and deep methods to obtain the possible data from each application, especially the recovery of deleted data. The data is analyzed to determine its meaning, as well as what can be seen on the timeline as a note, photo, video, or message regardless of the application used. Check our database of supported applications.

Live Updates

The use of applications for communication and sharing has grown considerably. Many applications are published or updated every day. It is obvious that application analysis is necessary to obtain all possible evidence. It is the most powerful aspect of MOBILedit Forensic Express, which receives application analysis updates as often as needed. The data is analyzed to determine its meaning, so it can be viewed on the timeline as a note, photo, video, or message regardless of the application used.

Deleted data recovery

Deleted data is the most valuable information on a cell phone. It is frequently found in applications; and since this is our strongest aspect, we produce wonderful results in this matter. Our special algorithms thoroughly examine databases, their invalidated pages, and caches to find data that is still on a phone. MOBILedit Forensic Express downloads deleted data and presents it clearly in the special section of the report.

Tailored reports

A great deal of effort has been dedicated to refining reports so they are customizable, easy to read, concise, and professional. Extensive report configuration allows you to define precisely which data will be extracted from the phone and how the report will look. Each report is divided into sections labeled with icons, images, and relevant data so evidence can be found quickly. A complete, configurable list of all events with a timestamp is shown on a timeline, and messages can be filtered by conversation or contact name. Reports are available in PDF, XLS, or HTML formats and can generate data exports compatible with other analysis tools used in the lab, such as UFED.

Password breaker with GPU acceleration

Gain access to a phone's locked backups using our password and PIN breaker. Passwords can be decrypted through a dictionary attack using our built-in dictionary, or you can use your own dictionary for other languages. The password breaker uses GPU acceleration and multi-threaded operations for maximum speed. Although iOS has well-protected data due to its hardware encryption, MOBILedit Forensic Express can penetrate this protection and recover data using the lock method.

Concurrent extractions and new 64-bit engine

The new 64-bit engine provides stability and the ability to analyze enormous amounts of data—applications with hundreds of thousands of messages, photos, and other items, and several phones at once. Accelerate your investigative process by extracting multiple phones simultaneously and generating multiple outputs for each. All you need is a USB hub, cables, and a sufficiently powerful computer to perform parallel work. Finish a week's worth of work overnight!

Easy-to-use user interface

Having the right tool is not enough; having the right personnel is also important. The shorter the learning time, the better. Since we designed the software for millions of users, it was a challenge for us to make MOBILedit Forensic Express a more pleasant forensic tool for users. With its friendlier interface, every step will be easy and the instructions clear. It is optimized for touch screens to facilitate use in the field.

Camera Ballistics – scientific analysis of images

By combining with Camera Ballistics, it is possible to identify which phone images were taken by a camera with a fingerprint sensor. This process is a new perspective on images as they are: brand, model, GPS, camera settings, mean square error, fingerprint presence result, probability, and correlation will be organized into a comprehensive PDF report suitable for presentation as evidence.

iCloud Analyzer

You can now analyze your iOS tools backups placed in iCloud. Don't have the phone? Don't worry, you don't need it. The iCloud Analyzer finds all iOS backups in the cloud and lets you choose which ones you want to extract, analyze, or create. It can find key evidence hidden even in deleted data, app data, and more directly from your cloud. We support all versions of iOS, including two-factor authentication.

Reports in any language

Reports now control users. Messages adapt to your own style or are translated into another language so they can meet the criteria determined by law.

Photo recognition

This module automatically searches for and recognizes suspicious content in photos such as: weapons, drugs, nudity, currency, and documents. Photo Recognizer uses artificial intelligence and deep learning for the rapid analysis of an unlimited number of photos and is designed to eliminate many hours of searching for key evidence in enormous photo databases. Each photo is placed in its own specific category, so the investigator can keep the case well organized and easily present the suspicious content in the report.

Face Matcher

This important feature easily finds photos of wanted persons. Based on new deep learning methods, Face Matcher tests against the enormous number of photos on users' phones. It eliminates many hours of manual work. It easily delivers photos of faces that need to be found and lets Face Matcher locate the correct photos on the phone or computer.

MOBILedit Forensic Express version 7.4. This new version focuses mainly on perfecting the acquisition of iPhone and iPad devices.

MOBILedit users can now use three different routes when communicating with an iOS device:

The first is low-level communication through the Apple device driver (downloadable from our website). This feature eliminates the need to download iTunes on your forensic workstation, as other forensic solutions usually require. iTunes can write data to a target phone, affecting its forensic integrity. That is why the MOBILedit team has developed this communication method and now tuned it to be perfectly reliable.

If you already have iTunes installed on your forensic workstation (for example, UFED, which requires it), MOBILedit can now communicate with an iOS device through the Apple Mobile Service, giving the user a simple solution. (In previous versions, MOBILedit required stopping this service.)

We have added a protocol for full file system reading of jailbroken iPhones, so if you use the checkra1n / checkm8 jailbreak available in our latest connection kit, you will get the complete content of an iPhone, including application test environments, keychains, system databases, iMessages, and all other hidden data.