±Forensic Focus Partners

Become an advertising partner

±Your Account


Username
Password

Forgotten password/username?

Site Members:

New Today: 1 Overall: 32925
New Yesterday: 2 Visitors: 142

±Follow Forensic Focus

Forensic Focus Facebook PageForensic Focus on TwitterForensic Focus LinkedIn GroupForensic Focus YouTube Channel

RSS feeds: News Forums Articles

±Latest Articles

RSS Feed Widget

±Latest Webinars

Bits And More

Wednesday, March 22, 2017 (19:30:54)

MOBILedit Forensic Express 4.0 Features Physical Analysis, 64-Bits And More

MOBILedit Forensic Express enters a new era by adding physical extraction and analysis, and it is now a native 64-bit application providing more power and stability for processing huge data. Version 4.0 brings in total 359 improvements making MOBILedit Forensic Express a must-have comprehensive forensic tool for any lab.

MOBILedit Forensic is back and stronger than ever before. We can briefly say that it is a phone extractor, data analyzer and report generator in one solution. It is excellent for its deleted data recovery, advanced application analyzer, wide range of supported phones including most feature phones, fine-tuned reports, concurrent phone processing, physical acquisition and easy-to-use user interface.

MOBILedit Forensic Express supports the newest iOS 10.2.1 and Android 7.0.x, extracts maximum possible data, such as passwords, messages, media, web history, web searches, bookmarks, geolocations, contacts, call logs, calendars, notes, keyboard cache and dictionaries, emails, Bluetooth pairing history, cookies, log files and a lot of data from applications. The built-in password breaker uses GPU to maximize computing power and concurrency.

Forensic Express offers maximum functionality at a fraction of the price of other tools. It can be used as the only tool in a lab or as an enhancement to other tools through its data compatibility. When integrated with Camera Ballistics it scientifically analyzes camera photo origins.

Read more about all product features here.

New features in version 4.0
Android physical data extraction, yes now you can extract physical images from investigated phones!
Physical analysis allows you to open image files, ours or 3rd party and recover deleted files plus all other deleted data where our product is known to be excellent
• The entire application is now native 64-bit for processing huge amounts of data, such as hundreds of thousands of messages with photos which greatly improves its speed and stability
• New File Manager to copy, move, and work with complete export folders, it solves problems with long filenames – which Windows File Explorer or Total Commander usually cannot handle
• Import of Cellebrite UFD files from UFED for both logical and physical analysis
• Built from scratch, a rich MS Excel report allows you to do your own data analysis using Excel features

Improvements
• Improved Android 7.0 support
• Wi-Fi connection now also supports app analysis and physical extraction for rooted Android phones
• New report sections for Notes, Tasks, and deleted iOS applications
• ADB and iTunes backup password can be included in reports and exports
• More information from iOS, including itunesmetadata. plist analysis, better keychain decryption, more iCloud information
• Additional phone information presented, such as cell info, device name, serial number and unique id
• Option to also pack binary files linked to PDF and HTML reports to create more compact reporting
• Memory usage optimizations
• More reliable cancelling of operations
There are 359 new features and improvements in total...

Application analyzers
One of the strongest features of Forensic Express is the application data decryption, undelete and analysis. Hundreds of applications are supported, such as:
Signal Private Messenger, Silent Phone, Threema, WhatsApp, WeChat, QQ, Blackberry Messenger, Private Photo Vault and many others. Find list of application analyzers for iOS and for Android.

App analyzers added or updated in version 4.0
myMail, Verizon messaging app, ASUS Browser, ASUS Email, Play Store, Chrome Canary, BBM, eBay, Mi Fit, Opera Free VPN, WowApp, BlackBerry Hub+ Services, 360 Browser, Blendr, Hide My Text, ZOOM Cloud Meetings, Wikipedia, Textie, TextMe Up Free Calling & Texts, Google Quicksearch Box, Android Blockednumber, WhatsApp, Telegram, Viber, Hangouts



Classical MOBILedit Forensic 9.0 also released
MOBILedit Forensic 9.0 brings improved support of iOS, updated support of Android 7.0, advanced filtering and many other improvements. Click this link for MOBILedit Forensic 9.0 release details

For more information about Compelson and MOBILedit please visit our website.

4 comments

Log in to post a comment. The comments are owned by the poster. Forensic Focus is not responsible for their content.
Threshold
Sloman

1. Absolutely Fantastic!

I have been using this product for a year now and have found it to be one of the easiest mobile forensic software programs to operate especially in a triage situation. I have tested it against competitor's software and am very pleased with the results. Very glad to see this update.


UnallocatedClusters

2. Re: Excellent deleted data recovery capabilities

We use MOBILedit Forensic Express in our practice to have a tool to validate Cellebrite extraction results.

Oftentimes there will be a delta in terms of what deleted messages MOBILedit Forensic Express can carve versus what Cellebrite can carve.

Comparing the two tools' results has been very helpful in enabling us to give our clients a more thorough picture of what is actually in the evidence itself.

In instances in which the subject phone could or would not connect to our forensic workstations, MOBILedit Forensic Express saved the day by allowing for an extraction to be performed over WiFi for both Android and iPhones(https://play.google.com/store/apps/details?id=com.compelson.mefconnector&hl=en).


indexplorer

3. Re: An essential instrument in the mobile forensic toolkit

MOBILedit Forensic was our first tool in house back in 2006 and with many competitors on the market we added several mobile forensic products to our portfolio. In all honesty we moved away from MOBILedit Forensic for quite a while since the product did not meet our needs for a while, but since two years Compelson built the product almost from scratch and hit the market in a novel way: filling the gaps where the "big boys" missed out. We use MOBILedit Forensic Express now to either validate results from tools like Oxygen, MSAB and Cellebrite as well as utilising it for what it does so excellent: partial (target oriented) extractions.

The very good plug & play functionality is very useful for non-forensic operators, the support for older devices and operating systems is a big benefit and thus it is good to just have MOBILedit Forensic Express as one of your essential tools, especially considering the extremely modest pricing of it.

The generated reports are very easy to read for the non-technical/forensic persons involved in cases and the capability to read the competitor's proprietary file formats is a big pro.

Last but not least the effort taken into physical extraction capabilities makes the solution as a whole more and more interesting in the field and seriously worth considering when deciding what mobile forensic tool to deploy.


MOBILedit

4. News Update

MOBILedit Forensic Express 4.0 supports iOS 10.3 including encrypted backups, Android 7.1.1, extracting Signal app encrypted messages.