最新版 MOBILedit Forensic v9 更新於 2024/8/14
MOBILedit Forensic 是一款用於從手機、智慧手錶和雲端擷取資料的一體化解決方案。它利用實體和邏輯資料收集,具有出色的應用程式分析、刪除的資料復原、廣泛的支援設備、微調的報告、並發處理和易於使用的介面。 MOBILedit Forensic 採用全新的方法,在安全繞過方面比以往任何時候都強大得多。
MOBILedit Forensic 以其他工具的一小部分價格提供了最大的功能。它可以用作實驗室中的唯一工具,也可以用作其他工具及其資料相容性的增強。當與相機彈道學整合時,它可以科學地分析相機照片的來源。
Security bypassing
MOBILedit Forensic has built-in security bypassing for many phone models, allowing you to acquire a physical image even when the phone is protected by a password or pattern. Bypass the lock screen on a wide range of Android phones, so you can keep the investigation moving forward. We are introducing a new approach to security bypassing with Live updates technology - new phone models can be added even without a MOBILedit reinstallation, just like updating antivirus software!
Physical data acquisition and analysis
In addition to advanced logical extraction we also provide Android physical data acquisition, allowing you to extract physical images of investigated phones and have exact binary clones. Physical analysis allows you to open image files created by this process, or those obtained through JTAG, chip-off or other tools to recover deleted files plus all other deleted data where our product is known to be excellent.
Advanced application analysis
The use of apps to communicate and share has grown rapidly. Many apps are released or updated everyday. It is obvious that the analysis of apps is vital to retrieving as much evidence as possible. This is the strongest point of MOBILedit Forensic, we dedicate a large part of our team specifically for application analysis. We employ adaptive and in-depth methods to ensure you retrieve the most data available for each app- especially recovering deleted data. Data is analyzed for its meaning so you see it on a timeline as a note, a photo, a video or a flow of messages no matter what app was used to send them.
Smart Screenshots
The Smart Screenshots feature provides a solution for obtaining evidence from applications that cannot be accessed through logical extraction. This advanced feature enables the extraction of conversations and other information from popular messaging apps like Instagram, Signal, Skype, Telegram, Viber, and WhatsApp. The screenshotting is automatic without requiring any user interaction on the device.
Live updates
Thanks to Live updates, we are able to add additional models (or chipsets) of devices or new supported applications in the form of packages without the need to reinstall the software. Live updates is a unique feature and a strong point of MOBILedit Forensic, providing immediate updates of application analysis, security bypassing and other features live and as often as needed.
Cloud forensics
Besides phone content acquisition, cloud extraction is a necessity to get all possible data. MOBILedit Cloud Forensic supports the most popular cloud-based services such as Booking, Microsoft Teams, Dropbox, Box, Microsoft OneDrive, Google Drive, Facebook, Instagram, LinkedIn, Twitter, Facebook Messenger, Slack and many others. This powerful feature is available as a standalone product or can be integrated within MOBILedit Forensic Pro.
Smartwatch forensics
With the rise in popularity of wearable devices, smartwatch forensics plays an essential role and is vital if a smartwatch is the only digital evidence available. MOBILedit Forensic supports smartwatches made by manufacturers such as Apple, Garmin, Samsung, TCL and others, via special readers which are available in our Smartwatch Kit.
Deleted data recovery
Deleted data is almost always the most valuable information in a device. It often hides in applications; and because this is our strongest expertise, we deliver great results in finding deleted data. Our special algorithms look deeply through databases, their invalidated pages and within caches to find any data that still resides in a phone. MOBILedit Forensic retrieves the deleted data and presents it clearly in a special section of the report.
Fine-tuned reports
A tremendous amount of effort has been dedicated to refining reports so they are customizable, easy to read, concise and professional. An enhanced report configurator allows you to define exactly which data will be extracted from the phone and how the report will look. Each report is divided into sections, labeled with icons, pictures, and highlighted relevant data so you can find evidence quickly. A complete, configurable and comprehensive list of all events with a time-stamp is shown on a timeline and messages can be filtered by conversation or by contact names.
Reports are available in PDF, XLS, or HTML formats, and you can generate data exports compatible with the other data analysis tools you use in your lab, such as UFED.
Concurrent extractions and new 64-bit engine
The new 64-bit engine provides stability and the ability to analyze huge amounts of data, apps with hundreds of thousands of messages, photos and other items, plus several phones at once. Speed up your investigation process by extracting multiple phones at the same time, and generating multiple outputs for each one. All you need is a USB hub, cables and a computer powerful enough to perform concurrent jobs. You can finish a week's worth of work overnight!
Malware detection
The new Malware detection is based on the Yara project. Yara works on the basis of rules that describe any pattern of data, in our case patterns that may indicate malware. MOBILedit Forensic applies these rules and searches the file to see if it accomplish any of these rules, and returns a list of results. This means that it contains the data patterns described.
Easy to use UI
Having the right tool is not enough, you need the right staff to work with it. The shorter the learning curve the better. Because we have designed software for millions of consumers, it was a welcome challenge for us to make MOBILedit Forensic the most user-friendly forensic tool available. With a straightforward interface, each step is simple and guided with clear instruction. It is also optimized for touch screens allowing for easy use in the field.
Camera Ballistics - scientific image analysis
When combined with Camera Ballistics you are able to identify which images present on the analyzed phone were actually taken by the phone's camera using a sensor fingerprint. This process delivers new insight into the images such as make, model, GPS, camera settings, mean square error, fingerprint presence result, probability, and correlation will be organized into a well designed and comprehensive PDF report suitable for submission as evidence.
Reports in any language
Reports are now under the user’s control. You can customize reports to your own style or translate them to your language, so you can meet the criteria defined by the law.
Photo Recognizer
This module automatically locates and recognizes suspicious content in both photos and videos, such as weapons, drugs, nudity, currency, and documents. Photo Recognizer utilizes artificial intelligence and deep machine learning to quickly analyze an unlimited number of photos and videos, and is designed to eliminate countless hours that would be spent manually searching for key evidence in huge databases of visual media. Each piece of media is placed in its own specific category so that investigators can keep their cases well-organized and easily present the suspicious content in a fine-tuned report.
Face Matcher
This important feature easily finds photos and videos of people you are looking for. Based on the newest deep learning techniques, Face Matcher rapidly analyzes even large quantities of visual media that users often have in their phones or PCs. Eliminate countless hours spent manually looking through photo and video albums. Simply supply photos of faces you want to find, and let Face Matcher find the right photos and videos.
Single Phone Edition |
Standard Edition | PRO Edition | ULTRA Edition |
Single Phone edition allows for activation per phone with functionality described in the table below. You pay exactly for as many phones as needed. | Standard edition is packed with the essentials - ideal for users who need a complete forensic tool, but might not need advanced add-ons. | PRO edition is designed for users seeking advanced functionality - perfect for all law enforcement, industry experts and forensic professionals. | ULTRA edition is designed for users seeking advanced functionality - perfect for all law enforcement, industry experts and forensic professionals. |
► Phone forensic at logical level ► App analysis ► Pay per phone ► 6 month of updates ► 1 computer
|
► Phone forensic at logical level ► App analysis ► Unlimited phones and imports ► One-time license fee ► 12 months of updates ► 1 computer
|
► All features of Standard and additionally: ► Permission bypassing ► Physical analysis ► App downgrade ► Advanced app analysis (WhatsApp, Messenger, Snapchat, Instagram, Viber, LINE and many more) ► Deleted data ► Smartwatch forensics ► Malware and spyware detection ► Photo object recognition ► Face matcher ► UFED support ► Cloud forensic (optional) ► Camera Ballistics (optional) |
► All features of PRO and additionally: ► Screenlock unlocking ► Authentication bypassing ► Password type detection ► Brute force attacks ► GPU utilization ► Full Disc Decryption (FDE) ► Files Based Decryption (FBE) ► Online and Offline decrypt ► Chipset attacks ► Exploits utilization ► Latest Android versions supported ► Large variety of brands supported ► Smartwatch security bypassing |
System Requirements
To enjoy the best possible user experience, please ensure your computer meets the minimum system requirements as shown below. We have also included additional specifications for a more powerful system:
- CPU: Intel Core i3 or Ryzen 3 as a minimum, i7 or Ryzen 7 is recommended for concurrent extractions, and a CPU with AVX is required for Face Matcher and Photo Recognizer.
- RAM: 16 GB as minimal configuration, 32 GB is recommended.
- Please note that meeting the minimum RAM requirements may impact concurrent extractions and performance on phones with a larger amount of data.
- HDD: free space of 30 GB on the system drive, plus suitable storage space for the reports. Ideally, separate disks should be used for storing the data, and using SSDs will mean read/write speeds are quicker.
- OS: Windows 64-bit OS is required, Windows 10 as minimal configuration.
- Minimum screen resolution: 1250x800, recommended 1920x1080.
- High-quality cables for connecting phones are essential.
- GPU: The only feature that benefits from a GPU is the Password toolkit for brute force attacks on backup Pins and passwords. The GPU can be of any type and either integrated, a dedicated graphics card or fully external.
To install MOBILedit Forensic successfully, please disable your antivirus program. If enabled, our security bypassing features (i.e. Dirty Cow) may trigger the antivirus warning system. If it is not possible to disable it completely, disable at least the automatic scan of the folders.
By disabling your antivirus program you will also prevent any possible errors that may occur during installation and extraction.
For Windows 10 and above, you may also need to add MOBILedit Forensic to the safe/allowed list of apps in the controlled folder access settings.
It is not necessary to use write-blocking hardware when using MOBILedit Forensic.
MOBILedit Cloud Forensic
People interact within today’s digital universe through their phones and applications, leaving digital footprints everywhere. For a full and successful digital investigation, it is necessary to analyze all traces. Phone forensics is extremely important, but what is stored in a mobile device is only a snapshot of the overall data. The evidence found in clouds, message platforms, and social networks brings a complete insight into a person's life. Understand their lifestyle, activities, personality, likes/dislikes, preferences, and social activities through services such as Facebook, Instagram, LinkedIn, Twitter, Slack, or Google apps.
Camera Ballistics
Camera Ballistics is a unique software product that uses advanced algorithms and cutting-edge technology to determine if a photo was truly taken by a suspected camera or not.
Photos contain more information than what you can see in the image. Camera Ballistics' unique scientific algorithm goes deeper than just EXIF. It will identify if a photo was taken by a suspected camera device or not, giving you maximum data from photos and making Camera Ballistics an essential tool for every forensic investigator.
MOBILedit Phone Manager
Whether its the latest and greatest or your tried and true classic phone, MOBILedit is the central toolbox that can manage them all. Control your phones content the way that you have always wanted. With so much important content in your phone the convenience of MOBILedit on your PC makes all the difference when adding new contacts to your phone book, managing files, making back ups or sending text messages.