Difference between pages "Training Courses and Providers" and "Cellebrite UFED"

From Forensics Wiki
(Difference between pages)
Jump to: navigation, search
 
 
Line 1: Line 1:
{| border="0" cellpadding="2" cellspacing="2" align="top"
+
The Cellebrite 'Universal Forensic Extraction Device' , or UFED, is a unique and very cost effective mobile phone, smartphone, and PDA forensic device that is completely stand alone.
|- style="background:#bfbfbf; font-weight: bold"
+
! Title
+
 
! Date/Location
+
As of February 2009, the UFED is compatible with 1,874 mobile phones (including GSM, TDMS, CDMA, iDEN), with the standard package containing 71 different phone cables. The UFED has an intergrated SIM reader, with Wireless connection options also being integrated, such as IR and Bluetooth.
! Website
+
 
! Limitation
+
 
|-
+
The UFED also supports native iPHONE extraction on both 2G and 3G versions. This is clientless, and via a physical cable, and works on jailbroken and non-jailbroken devices.  
|Computer Forensics Training and CCE™ Testing for Litigation Support Professionals
+
 
|Oct 05-08, Denver, CO
+
 
|http://www.md5group.com
+
Using the MD5 Hash Algorithm, and SHA-256, subject data can be retrieved via logical extraction or via physical extraction (ie: hex dump). Moreover, all cable connectors from subject (source) side act as a write-blocker, being read only via the onboard hardware chipset. Extracted data includes:
|-
+
 
|Paraben Handheld Forensic Course
+
 
|Oct 08-11, Potomac Falls, VA
+
- Handset data (IMEI, ESN, Manufacturer, Model No., ect.)
|http://www.paraben-training.com/
+
 
|-
+
Phonebook
|SMART Windows Data Forensics
+
|Oct 08-10, Austin, TX
+
SMS and MMS messages
|http://asrdata.com/training/training2.html
+
 
|-
+
- SIM data
|EnCase® v6 Computer Forensics II-Private Sector
+
 
|Oct 09-12, Chicago, IL
+
- SIM cloning
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
 
|-
+
- Multimedia (images, videos, audio, ect.)
|EnCase® v6 NTFS
+
 
|Oct 09-12, Houston, TX
+
- Date and Time stamps (with GMT and daylight savings options)
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
 
|-
+
- Deleted data
|EnCase® v6 Network Intrusion Investigations - Phase I
+
 
|Oct 09-12, Los Angeles, CA, The Netherlands
+
- Fragmented or Partial data
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
 
|-
+
- HEX Dump
|EnCase® v6 Advanced Computer Forensics
+
 
|Oct 09-12, Washington DC
+
- and much more.  
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
 
|-
+
 
|EnCase® v6 Computer Forensics II
+
The UFED is flexible enough to be used in many environments, such as:
|Oct 09-12, Melbourne, Australia
+
 
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
 
|-
+
- Fixed to a desk in a crime lab connect to a PC
|Computer Forensics Training and CCE™ Testing for Litigation Support Professionals
+
 
|Oct 12-15, Dallas, TX
+
- Fixed to a desk in a crime lab (stand alone with no PC)
|http://www.md5group.com
+
 
|-
+
- Mobile in a car or at a VCP (connected to car 12V power)
|Digital Evidence Acquisition Specialist Training Program (DEASTP)
+
 
|Oct 15-26, FLETC, Glynco, GA
+
- Mobile in the field (using integrated battery kit)
|http://www.fletc.gov/training/programs/computer-financial-investigations/technology-investigation/
+
 
|Limited to Law Enforcement
+
 
|-
+
While the UFED is completely stand alone, additional software is included to create specialised reports on the retrieved raw data. Customised reports give the additional option of containing your own logo, case file number, address, etc.
|BlackBag Introductory MacIntosh Forensics
+
 
|Oct 15-19, Tacoma, WA
+
Standard hardware options include a portable mobile phone battery charger set (with 42 plug heads), Faraday bag, and 9-in-1 media card reader.
|http://www.blackbagtech.com/products/training.htm
+
|-
+
|Macintosh Forensic Survival Course
+
|Oct 15-19, Philadelphia, PA
+
|http://www.phoenixdatagroup.com/cart/index.php
+
|-
+
|EnCase® v6 Network Intrusion Investigations - Phase II
+
|Oct 15-18, Los Angeles, CA
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase® v6 Advanced Computer Forensics
+
|Oct 16-19, Chicago, IL
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase® v6 Computer Forensics II
+
|Oct 16-19, Houston, TX and Washington DC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase® v6 Network Intrusion Investigations - Phase II
+
|Oct 16-19, The Netherlands
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|X-Ways Forensics
+
|Oct 22-24, Hong Kong
+
|http://www.x-ways.net/training/hong_kong.html
+
|-
+
|EnCase® v6 Computer Forensics II-Private Sector
+
|Oct 23-26, Washington DC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase® v6 Computer Forensics I - Private Sector
+
|Oct 23-26, Houston, TX
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase® v6 Computer Forensics II
+
|Oct 23-26, Toronto, Canada
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase® v6 Computer Forensics I
+
|Oct 23-26, Los Angeles, CA and Singapore
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase® v6 Advanced Internet Examinations
+
|Oct 23-26, Canberra, Australia
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|Neutrino-Mobile Phone Forensics
+
|Oct 23-24, Los Angeles, CA
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|File Systems Revealed
+
|Oct 25-26, Hong Kong
+
|http://www.x-ways.net/training/hong_kong.html
+
|-
+
|SARC Steganography Examiner Training
+
|Oct 26 - 27, Gaithersburg, MD (Techno Forensics Conference 2007)
+
|http://www.sarc-wv.com/training.aspx
+
|-
+
|Seized Computer Evidence Recovery Specialist (SCERS)
+
|Oct 29-Nov 9, FLETC, Glynco, GA
+
|http://www.fletc.gov/training/programs/computer-financial-investigations/technology-investigation/
+
|Limited to Law Enforcement
+
|-
+
|Search and Seizure of Computers and Electronic Evidence
+
|Oct 29-30, Oxford, MS
+
|http://www.security.cse.msstate.edu/ftc/schedule.php
+
|Limited to Law Enforcement
+
|-
+
|EnCase v6 Computer Forensics II
+
|Oct 30-Nov 02, Los Angeles, CA and The Netherlands
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Advanced Computer Forensics
+
|Oct 30-Nov 02, Washington DC and Toronto, Ontario, Canada
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Computer Forensics I - Private Sector
+
|Oct 30-Nov 02, United Kingdom
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Network Intrusion Investigations - Phase I
+
|Oct 30-Nov 02, Chicago, IL
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase Enterprise v6 - Phase I
+
|Oct 30-Nov 02, Washington DC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Computer Forensics II Private Sector
+
|Oct 30-Nov 02, Houston, TX
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|Paraben Handheld Forensic Course
+
|Nov 05-08, Mississauga, Ontario, Canada
+
|http://www.paraben-training.com/
+
|-
+
|Advanced Cell Phone/SIM Card Forensics
+
|Nov 05-08, San Diego, CA
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|SMART for Linux
+
|Nov 05-08, Austin, TX
+
|http://asrdata.com/training/training2.html
+
|-
+
|EnCase v6 Network Intrusion Investigations - Phase II
+
|Nov 05-08, Chicago, IL
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase Enterprise v6 - Phase II
+
|Nov 05-08, Washington DC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|Introduction to Cyber Crime
+
|Nov 05-07, Jackson, MS
+
|http://www.security.cse.msstate.edu/ftc/schedule.php
+
|Limited to Law Enforcement
+
|-
+
|EnCase v6 Computer Forensics II Private Sector
+
|Nov 06-09, United Kingdom
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Advanced Computer Forensics
+
|Nov 06-09, Los Angeles, CA
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 NTFS
+
|Nov 06-09, Washington DC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Computer Forensics II
+
|Nov 06-09, Houston, TX
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|AccessData BootCamp
+
|Nov 06-08, Austin, TX
+
|http://www.accessdata.com/training
+
|-
+
|AccessData Windows Forensics
+
|Nov 06-08, Solna, Sweden
+
|http://www.accessdata.com/training
+
|-
+
|Forensics Tools and Techniques
+
|Nov 07-09, Jackson, MS
+
|http://www.security.cse.msstate.edu/ftc/schedule.php
+
|Limited to Law Enforcement
+
|-
+
|SMART Linux Data Forensics
+
|Nov 12-14, Austin, TX
+
|http://asrdata.com/training/training2.html
+
|-
+
|Handheld Forensic Course
+
|Nov 12-15, Potomac Falls, VA
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|EnCase v6 Computer Forensics I - Private Sector
+
|Nov 13-16, Houston, TX
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Advanced Computer Forensics
+
|Nov 13-16, The Netherlands and United Kingdom
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Computer Forensics I
+
|Nov 13-16, Sydney, Australia and Singapore
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Advanced Internet Examinations
+
|Nov 13-16, Chicago, IL and Los Angeles, CA
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Computer Forensics II
+
|Nov 13-16, Washington DC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|AccessData BootCamp
+
|Nov 13-15, Mississippi State University
+
|http://www.security.cse.msstate.edu/ftc/schedule.php
+
|Limited to Law Enforcement
+
|-
+
|EnCase v6 Computer Forensics II
+
|Nov 20-23, Toronto, Canada
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 FIM/Mobile Use of EE Live Forensics
+
|Nov 20-23, Vancouver, BC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 NTFS
+
|Nov 27-30, Vancouver, BC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Network Intrusion Investigations - Phase I
+
|Nov 27-30, Sydney, Australia
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Computer Forensics II – Private Sector
+
|Nov 27-30, Houston, TX
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Computer Forensics I
+
|Nov 27-30, Washington DC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase eDiscovery with v6
+
|Nov 27-30, Los Angeles, CA
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|Computer Network Investigation Training Program (CNITP)
+
|Dec 03-14, Glynco, GA
+
|http://www.fletc.gov/training/programs/computer-financial-investigations/technology-investigation
+
|Limited to Law Enforcement
+
|-
+
|Internet Investigations Training Program (IITP)
+
|Dec 03-07, Glynco, GA
+
|http://www.fletc.gov/training/programs/computer-financial-investigations/technology-investigation
+
|Limited to Law Enforcement
+
|-
+
|SMART for Linux
+
|Dec 03-06, Austin, TX
+
|http://asrdata.com/training/training2.html
+
|-
+
|Handheld Forensic Course
+
|Dec 03-06, San Diego, CA
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|Introduction to Cyber Crime
+
|Dec 03-05, Mississippi State University
+
|http://www.security.cse.msstate.edu/ftc/schedule.php
+
|Limited to Law Enforcement
+
|-
+
|EnCase v6 Computer Forensics I
+
|Dec 04-07, Chicago, IL; Los Angeles, CA; Houston, TX; and United Kingdom
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Network Intrusion Investigations - Phase I
+
|Dec 04-07, Washington DC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Computer Forensics II
+
|Dec 04-07, Washington DC, Leipzig, Germany and Toronto, Ontario, Canada
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Advanced Internet Examinations
+
|Dec 04-07, Vancouver, BC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|AccessData Internet Forensics
+
|Dec 04-06 , Solna, Sweden
+
|http://www.accessdata.com/training
+
|-
+
|Forensics Tools and Techniques
+
|Dec 05-07, Mississippi State University
+
|http://www.security.cse.msstate.edu/ftc/schedule.php
+
|Limited to Law Enforcement
+
|-
+
|EnCase v6 Network Intrusion Investigations - Phase II
+
|Dec 10-13, Washington DC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|Network Incident Response
+
|Dec 10-13, Potomac Falls, VA
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|Enterprise Data Forensics
+
|Dec 10-12, Austin, TX
+
|http://asrdata.com/training/training2.html
+
|-
+
|EnCase v6 Computer Forensics II
+
|Dec 11-14, Chicago, IL; Houston, TX; Los Angeles, CA; United Kingdom; and Melbourne, Australia
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Advanced Computer Forensics
+
|Dec 11-14, Washington DC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|X-Ways Forensics
+
|Dec 17-19, Singapore
+
|http://www.x-ways.net/training/SGP.html
+
|-
+
|EnCase v6 Advanced Computer Forensics
+
|Dec 17-20, Chicago, IL and Los Angeles, CA
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 FIM/Mobile Use of EE Live Forensics
+
|Dec 17-20, Washington DC
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 Advanced Internet Examinations
+
|Dec 17-20, Washington, DC and United Kingdom
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|EnCase v6 NTFS
+
|Dec 17-20, Los Angeles, CA
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|Advanced Cell Phone/SIM Card Forensics
+
|Dec 17-20, Mississauga, Ontario, Canada
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|DEK: Data Exploitation
+
|Dec 17-20, Potomac Falls, VA
+
|http://www.paraben-training.com/schedule.html
+
|Restricted Enrollment
+
|-
+
|EnCase v6 Computer Forensics II – Private Sector
+
|Dec 18-21, Houston, TX
+
|http://www.guidancesoftware.com/training/course_schedule.aspx
+
|-
+
|BlackBag Introductory MacIntosh Forensics
+
|Jan 07-11, Santa Clara, CA
+
|http://www.blackbagtech.com/products/training.htm
+
|-
+
|Advanced Cell Phone/SIM Card Forensics
+
|Jan 07-10, Potomac Falls, VA
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|Cellular/GPS Signal Analysis
+
|Jan 24-25, San Diego, CA
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|E-Discovery: E-mail & Mobile E-mail Devices
+
|Feb 04-07, Potomac Falls, VA
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|Wireless Forensics
+
|Feb 11-12, Potomac Falls, VA
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|Network Incident Response
+
|Feb 25-28, Potomac Falls, VA
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|Handheld Forensic Course
+
|Mar 03-06, Potomac Falls, VA
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|BlackBag Introductory MacIntosh Forensics
+
|Mar 10-14, Santa Clara, CA
+
|http://www.blackbagtech.com/products/training.htm
+
|-
+
|E-Discovery: E-mail & Mobile E-mail Devices
+
|Mar 10-13, Potomac Falls, VA
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|Cellular/GPS Signal Analysis
+
|Mar 10-11, San Diego, CA
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|Wireless Forensics
+
|Mar 13-14, San Diego, CA
+
|http://www.paraben-training.com/schedule.html
+
|-
+
|BlackBag Introductory MacIntosh Forensics
+
|May 19-23, Santa Clara, CA
+
|http://www.blackbagtech.com/products/training.htm
+
|-
+
|BlackBag Introductory MacIntosh Forensics
+
|Aug 18-22, Santa Clara, CA
+
|http://www.blackbagtech.com/products/training.htm
+
|-
+
|BlackBag Introductory MacIntosh Forensics
+
|Oct 06-10, Santa Clara, CA
+
|http://www.blackbagtech.com/products/training.htm
+
|-
+
|}
+

Revision as of 06:35, 6 February 2009

The Cellebrite 'Universal Forensic Extraction Device' , or UFED, is a unique and very cost effective mobile phone, smartphone, and PDA forensic device that is completely stand alone.


As of February 2009, the UFED is compatible with 1,874 mobile phones (including GSM, TDMS, CDMA, iDEN), with the standard package containing 71 different phone cables. The UFED has an intergrated SIM reader, with Wireless connection options also being integrated, such as IR and Bluetooth.


The UFED also supports native iPHONE extraction on both 2G and 3G versions. This is clientless, and via a physical cable, and works on jailbroken and non-jailbroken devices.


Using the MD5 Hash Algorithm, and SHA-256, subject data can be retrieved via logical extraction or via physical extraction (ie: hex dump). Moreover, all cable connectors from subject (source) side act as a write-blocker, being read only via the onboard hardware chipset. Extracted data includes:


- Handset data (IMEI, ESN, Manufacturer, Model No., ect.)

– Phonebook

– SMS and MMS messages

- SIM data

- SIM cloning

- Multimedia (images, videos, audio, ect.)

- Date and Time stamps (with GMT and daylight savings options)

- Deleted data

- Fragmented or Partial data

- HEX Dump

- and much more.


The UFED is flexible enough to be used in many environments, such as:


- Fixed to a desk in a crime lab connect to a PC

- Fixed to a desk in a crime lab (stand alone with no PC)

- Mobile in a car or at a VCP (connected to car 12V power)

- Mobile in the field (using integrated battery kit)


While the UFED is completely stand alone, additional software is included to create specialised reports on the retrieved raw data. Customised reports give the additional option of containing your own logo, case file number, address, etc.

Standard hardware options include a portable mobile phone battery charger set (with 42 plug heads), Faraday bag, and 9-in-1 media card reader.