|Quotation Request||Mobile Phone Forensic Tools|
|Statement of Requirements||Cellebrite UFED Touch2 Ultimate Standard
Cellebrite UFED4PC Ultimate
Please supply one-off prices valid for the next 90 days and Licence Terms and Conditions
Quotations will be assessed on the basis of Price and Quality Mix (Most Economically Advantageous Tender), Quality to include Availability of Upgrades as part of annual licencing
100 marks are available in total:
25 marks price
The total MEAT Score is arrived at by adding the Price score to the Quality score
|Closing Date/Time||22nd May 2017 at 12:00 (Midday)
Quotations received after the deadline will not be considered
|Contact Details||Simon Lang
Phone Number: 01782 286300
|The purchase of the Forensic Tools is subject to securing funding from the European Regional Development Fund.|
|Supplier Response||Please submit completed quotations to:
SYTECH DIGITAL FORENSICS TO OPEN NEW DIGITAL FORENSIC LABORATORY IN WARWICKSHIRE
SYTECH are delighted to announce that they are to open a new Digital Forensic laboratory in Alcester, south-west Warwickshire.
Following the successful winning of two major digital forensic contracts for Law Enforcement, SYTECH are opening their fourth laboratory to help service their client’s needs, and Law Enforcement generally across the UK. The laboratory will be a “full-service” facility with mobile device, computer and cell-site forensics on site.
The site is due to open in early summer 2016 and SYTECH is therefore looking to receive applications for the following positions:
- Computer Digital Forensic Analysts
- Trainee Computer Forensic Analysts (relevant graduates)
- Mobile Device Forensic Analysts
- Trainee Mobile Device analysts (relevant graduates)
- Cell Site Expert
- Cell Site Analyst
- Administrative Support and Exhibit Officer
All positions offer competitive salaries and benefits.
Please respond by submitting your CV and a covering letter.
For the Trainee roles please supply the above with a short critique of approximately 250 words detailing your expression of interest in this position and in the field of Digital Forensics.
Please state the job you wish to apply for. Full details of the roles are available on the website www.sytech-consultants.com
Responses should be made to: firstname.lastname@example.org
SYTECH brings together leading-edge specialists in all areas of Digital Forensics to provide a comprehensive one-stop analysis service. We work with all sectors and have over the years been involved in thousands of cases, including many high profile cases. The HQ is in Stoke with offices in Swansea and Newport.
Windows ‘Storage Spaces’ introduced in consumer builds of Windows 8 and Windows Server 2012 allows a user to ‘span’ several (sometimes various) devices into a unified ‘span’ or ‘pool’ of storage space.
Devices used for ‘Storage Space’ volumes can be easily identified in forensic software as a drive with a ‘Windows Reserved’ partition, often 128MB in size and a ‘Storage Pool Partition’ (which will vary in size depending on the user configuration) with the header ‘SPACEDB’.
Although displayed as unallocated this device has a plethora of investigative data which can be configured in a very similar way to RAID storage ‘Simple (no resiliency), a ‘Two-way mirror’, a ‘three-way mirror’ and drives which can also use ‘parity’ volumes for redundancy.
Due to the way these volumes work (depending on the device configuration) a user can add disks at a later date. It should also be noted that users can start a span on a single device with the plan of adding disks later.
All of the above taken into consideration and scenarios (as shown below) where a user may lose, corrupt or destroy a device causing the computer to no longer detect the configuration of a Windows ‘Storage Volume’ can seriously hinder an investigation.
Please call (01782 286 300) or email (email@example.com) SYTECH in cases where the potential reconstruction of ‘Windows Storage’ file systems is needed, in cases where the ‘STORAGEDB’ header is found and evidential material has been found in what normal forensic tools are calling ‘Unallocated’ SYTECH can help.
All submissions in relation to Windows ‘Storage Spaces’ should include all drives with ‘STORAGEDB’ headers for the greatest chance of success.
Missing drives, broken configurations or just in need of technical assistance please make use of our free consultancy service.
If a rebuild of the ‘Storage Space’ is possible SYTECH can offer both reconstruction and production of just volume data in an evidential format or full forensic analysis of the ‘Storage Space’.
The Evolution of Vehicle Forensics
by Matthew J Parkinson BSc (Hons), Digital Forensic Analyst, SYTECH
Matthew G McKay MComp (Hons), Digital Forensic Analyst, SYTECH
In this day and age, technology surrounds our everyday lives, whether it be at home watching the Smart TV, at the gym using a Smart Watch or in the car using a Sat-Nav, society thrives on it. At the center of this ever-growing, fast paced industry, is the Mobile Phone.
Mobile Phones are leading the way in technological advancements with many new technologies exploiting the phone’s connectivity and capabilities, since a mobile phone is generally with the user, it is the perfect hub for all of our digital needs. This has led to a growing interest in the “Internet of Things” and the idea of a “Smart Home” which allows different aspects of your home to be autonomous or controlled via a Mobile Phone. This growth of the idea of everything being connected has now extended into vehicles, altering the way vehicle technology is implemented.
Since 1930, when the first stereo was implemented within a car, until not so long ago, car technology has been stagnating with not many changes away from the original idea. Recently, car technology has started catching up to the 21st Century with the buyer’s expectation increasing, and expecting; Bluetooth, Touch Screens and DAB radio as standard. With the implementation of the aforementioned features comes concerns over what data the car will store.
Currently, Vehicle Forensics involves the investigation of a bespoke system with limited research available and manufacturers restricting information to assist. We believe the future of Vehicle Forensics will revolve around a Mobile Phone, eliminating past issues and forensic limitations.
Predicting the direction in which technology will flow towards is important for any digital forensics company and here at SYTECH Digital Forensics it’s no different. At SYTECH, we endeavour to maintain a strong arm in research and development in order to stay up-to-date with “bleeding edge” technology, this innovative characteristic of the company is vital in order to maintain a well-established advantage in the digital forensic age.
This article explores the marriage of two industries, mobile devices and vehicle technology, and how they will change Vehicle Forensics for the better.
The Evolution of Vehicle Technology
In the past, Vehicle Technology was confined to the car radio, with the only improvements relating to different ways of storing and accessing music, this originally came in the form of a tape (cassette) which was then followed by CD’s. The first stage of device connectivity to a car was an Auxiliary Port (AUX) which was implemented by vehicle manufacturers. This enabled a user to play music from a personal device.
After this, Car manufacturers started developing Vehicle Infotainment Systems, which generally used a touch-screen with bespoke hardware and software. These systems displayed a visual interface of what was once analogue and included features such as programmable radio stations and basic manufacturer-supplied satellite navigation. This system was quickly outdated as the process of updating the system’s software was inconvenient and not undertaken by the majority of the users. This process involved getting the software from the manufacturer, commonly in the form of a CD / DVD. This led the car manufacturers to look for other means of keeping the system up-to-date.
Society’s heavy reliance on Mobile Phones and their idea of being connected at all times has led to vehicles needing to implement a strong link to take advantage of these devices. This started out as the connection to a phone being possible via Bluetooth or Physical connection. This allowed the user to play music stored on their mobile phone, download their phonebook onto the in-car system and make and receive phone calls hands-free. This was achieved by the phone sharing its data with the in-car system that displayed the music, phonebook and call information in its native format.
At this stage, the connectivity of the phone and vehicle infotainment system was useful but still restrictive with the users still having to rely on limited functionality and basic software provided by the vehicle manufacturer. This often included a native satellite navigation system that was both expensive and difficult to update leading to maps becoming erroneous. Due to the issues of the in-car system, many technology companies started looking for a solution. Overlooking these issues, there is a strong foundation for an efficient, connected and up-to-date eco-system to build upon, with the already present Bluetooth and USB connections, Touch Screen display and microphones placed for hands-free control.
The in-car technology market is at a very pivotal point right now with two well-established companies introducing the following standards:
Apple CarPlay is a development from Apple which was released in 2014 as “iOS in the Car” but rebranded to CarPlay, it allows the user to connect their iPhone to the in-car display through a USB or Bluetooth connection. The display will then show a refined version of the iPhone’s display with all the applications and notifications the user will need whilst in the car. As standard these applications are; Apple Maps, Phone, Messages and Music. The user will then have the option to include additional third-party apps that are compatible with CarPlay and accepted by Apple, these include music streaming, navigation, radio, communication and many other genres of apps. Currently, application development is in its infancy but will grow as the technology is standardised across the vehicle manufacturing range.
The user can control CarPlay using their voice, touch or in-car controls. The voice control will use the already established voice recognition software built into most Apple products called Siri, this can be activated from the steering wheel or saying the words “Hey Siri”. After activating this voice control the user is able to control all the supported applications, as well as perform internet searches. Siri can also answer many different queries from the user for example “How long will it take to get home?” and “Play a song by Bon Jovi”, both useful if stuck in traffic. The touch controls will be utilised on the in-car screen where the current activity will be displayed. CarPlay will integrate and operate with the vehicle’s in-car controls such as steering wheel buttons and dashboard dials. Apple CarPlay requires a compatible Infotainment System and an iPhone 5 or later running Apple’s mobile device operating system, iOS 7.1 or above.
Android Auto was developed and released by Google in 2015, it allows the Android operating system to be displayed on an in-car infotainment system. Android Auto requires a Physical and Bluetooth connection which enables the device to display notifications, sync contact information and make and receive calls. Android Auto is built around Google Maps, Google Now and the ability to talk to Google and also has a growing audio and messaging app eco-system. Android Auto requires an application to be installed on the Mobile Phone to allow the connection to the in-car system, this is downloaded from the Google Play store.
Android Auto displays five option panels to the user: Navigation, Phone function, Information, Music & Media and Car diagnostics information. The Navigation pane will present the user with a polished version of Google Maps, this will include a voice controlled search function, live traffic information and turn-by-turn directions. The Phone function pane will allow the user to receive and make calls as well as dictating SMS messages. The Information pane will allow the user to conduct internet searches, using Google, with their voice. The Music & Media pane will contain all the entertainment apps which include Spotify, Pocket Casts and Google Play Music. The Car diagnostics pane will show the car’s various statistics.
In a similar fashion to Apple, Google will monitor and control the applications that will be compatible with Android Auto to keep driver-safety measures at the forefront of their vision. Android Auto requires a compatible vehicle infotainment system and can be used with mobile devices running Android operating system, version 5.0, also known as “Lollipop”, or higher.
Technologies similar to both Apple CarPlay and Android Auto include, MirrorLink, a research project by Nokia, created to integrate a smart phone and a car’s infotainment system. Some vehicle manufacturers have native systems for syncing the car with smartphones but Android Auto and Apple CarPlay will have many benefits over the competition, this is due to the link to the user’s mobile phone. This link provides the user with the already present functionality, applications and personal data that the phone possesses to use with the in-car system.
Another technology that has features that compliment both Apple CarPlay and Android Auto is “OnStar”. This is being introduced to many new vehicles across the UK, with Vauxhall being the first to include this service across the range. “OnStar” provides direct communication to an advisor who can assist with tasks such as Navigation, security and various other features. Along with this, “OnStar” also brings other useful technologies to the vehicle system which include WiFi, sensor access, automated emergency response and limited app control such as unlocking your car using an app on your mobile phone.
An analogy for these technologies is a set top box and a TV:
- The set top box is the Mobile Phone
- The TV is the Car Display
The TV alone has limited functionality but the connection of a set top box allows further capabilities to be added and displayed on the TV.
The implementation of all this new technology brings a new perspective on the way we use our cars, resulting in different data being collected about its user. In the past, vehicles have been a gold mine of data but forensic barriers including bespoke systems and unsupported hardware meant that vehicles were being overlooked, although potentially imperative to an investigation. The introduction of new in-car systems means the Mobile Phone will become the hub of all the data thus allowing a clear cut method in obtaining the data without the previous complications, meaning Vehicle Forensics will become Mobile Forensics.
Vehicle & Mobile Forensics
The merging together of Mobile & Vehicle Forensics will result in the main extraction method of vehicle data becoming the analysis of Mobile Phones that have been connected to the vehicle in question. This will bring simplicity and speed to these investigations, as Mobile Forensics has a strong foundation with industry-recognised tools, a Mobile Phone is easier to store and work with and the fact that two avenues of data can be analysed as one.
Along with data that is already recovered from a Mobile Phone examination, data from the connection to the in-car system through Apple CarPlay or Android Auto will also be included, this will show the user’s activity whilst in the car. Applications running through Android Auto and Apple CarPlay from the connected phone will create the majority of the data. The types of applications currently available and future considerations are as follows:
- Location-based applications are predominately satellite navigation apps such as Apple Maps and Google Maps. Siri and Google Now both use the user’s location to narrow down the scope of a user’s requests such as nearby petrol stations and restaurants. These applications will create location data which is very useful in pin-pointing the user’s movements and location, potentially providing important evidence for a case.
- Phone applications will include the native Phone app and various other third-party apps, these allow contacts to be saved and the making and receiving of calls over GSM or an internet-based network e.g. Skype and FaceTime Audio. These applications will create call logs which will provide the user’s communication activity, which is useful evidence in a case.
- Messaging applications will include the native Messaging application, Email and various third-party apps, these allow for messages to be sent over GSM or an internet-based network, e.g. iMessage, WhatsApp and Kik. These applications will create chat logs which could be used for evidence of communication between two or more parties.
Music & Audio Applications
- Music & Audio applications will include the native Audio application as well as many music streaming options such as Spotify and Deezer. Other types of Music & Audio applications will include Audiobooks, Podcasts and News apps. These applications can show user activity and they have potential to compliment evidence in a case.
- Voice Control applications will utilise the user’s voice to control various aspects of the in-car system, this will be achieved through the native voice recognition software from the Mobile Phone, e.g. Siri and Google Now. This software brings functionality that is easy to control whilst maintaining driver safety, this functionality includes:
- Internet Searches
- Voice Dialling, e.g. “Call George”
- SMS dictation, e.g. “Message Stuart”
- Updating social media feeds, e.g. Facebook and Twitter
- Location queries, e.g. Where’s the nearest petrol station?
- Various other requests, e.g. Music, Time, Weather, Sport
- These activities will amass valuable data that can be used in many types of investigations.
Car Diagnostics Applications
- This area of Apple CarPlay and Android Auto has limited support but we believe it will become useful and increasingly popular as car manufacturers implement this. Car Diagnostic applications will show the user many statistics about the vehicle, for example, fuel level, service reminders, crash information and speed warnings, all of which could be of beneficial use within a case.
All of these different types of applications and the various data that they store will need extracting to be used in a forensic investigation.
Since the data is stored upon the Mobile Phone, the extraction will be performed in exactly the same manner in which a normal Mobile Phone examination will be completed. This involves various stages that takes it from the extraction of raw data, the analysis and finally production of an expert witness statement.
The three common extraction types are:
- Physical – this will recover both live and deleted data
- File System – this will recover both live and deleted data depending on the phone
- Logical – this will recover live data.
There are also five advanced forensic techniques that assist in completing the extraction of the Mobile Phone which are as follows:
- JTAG / Flasher Box examinations
- Advanced iOS PIN Decryption (iOS 7, iOS 8 and working towards an iOS 9 exploit)
- Advanced Chip-Off Examination
- In-System Programming (ISP)
- Custom Recoveries
All of which SYTECH Digital Forensics can provide.
After the data has been successfully extracted using one or many of the aforementioned techniques it will then be analysed.
Analysis involves parsing the raw data to present it in an understandable format including different data types such as SMS messages, Search History and other valuable evidence recovered from the Mobile Phone.
Prior to a full investigation and further in-depth testing of both Apple CarPlay and Android Auto we are unable to say how the data, that is created from both, is stored on the Mobile Phone. We do however believe the following:
- Apple CarPlay – The data created whilst using Apple CarPlay will not contain any indication that the data was created via this, resulting in Mobile Phone and in-car data being analysed as one.
- Android Auto – Taking into consideration that Android Auto requires an application to be installed on the Mobile Phone for a connection to the vehicle, we believe that the data will be sent through this application thus making it identifiable as in-car data. However, as all of the data is stored on the Mobile Phone, it will still be analysed as one.
The analysis carried out will depend on the type of case we are dealing with, as previously mentioned it may not be easy to differentiate in-car and mobile data, causing issues with cases that only involve in-car data. However, if we need to find out if the suspect has contacted a certain person, we will be able to analyse the communication data whether or not it has been created whilst connected to Apple CarPlay / Android Auto.
Below are examples of cases that data from cars and mobiles can be used as one:
- Robbery – We may use the data from the Sat Nav application to see the details of a journey, as well as calls to accomplices and internet searches, all of which could be created whilst the phone was connected to the car.
- Grooming – Messages of a grooming nature may have been sent whilst the phone was connected to the car through voice dictation.
- IIOC offenses – The user could use voice dictation whilst their phone is connected to the vehicle to search for, and/or view Indecent Images of Children.
- Drug Offenses – Activity of intent to supply or the purchase of illegal drugs could be created whilst the user’s device is connected to the car, for example SMS messages or call history.
- Person of interest – The device’s Music & Audio may be used to assist in a case where very limited evidence is available, for example the user’s music or audiobook preference may help identify the device’s user.
- Murder – Activity that could be used as evidence in a murder case may be created upon the Mobile Phone whilst connected to the in-car system. This includes location, communication and many other types of data.
Many vehicle manufacturers will be implementing Apple CarPlay and Android Auto compatibility into their new build models, for example Ford, who have said they will be adding support for both platforms to all 2017 models.
The availability and support of both platforms will increase significantly over the coming years, this will lead to more applications being developed, adding more functionality to the in-car system, this will in turn create more data that can be forensically extracted, analysed and used for a digital forensic investigation.
SYTECH Digital Forensics
In conclusion, Mobile Phone forensics is going to take over Vehicle Forensics and being one of the leading companies in the UK dealing with Mobile Forensics, SYTECH will in turn become leading experts in Vehicle Forensics.
Our already successful advanced forensic techniques will play a key role in the future of Vehicle Forensics.
SYTECH Digital Forensics can conduct In-House Advanced Chip-off examinations
SYTECH also offers Advanced iOS PIN Decryption.
SYTECH & University of South Wales – Get the career you want
“To achieve this position is a dream come true”
Iain Macleod is an MComp (Hons) Computer Forensics graduate who now works for Stoke-on-Trent, Newport & Swansea – based Digital Forensic company, SYTECH. He reveals how he ‘worked backwards’ to achieve his new role as a Digital Forensic Analyst.
“I was in my late thirties when I decided that I needed a changed of career. Due to new family commitments I also needed to be able to study alongside being a house husband. At the time, I worked as a bank care support worker, so my first plan was to pursue nursing.
“However, my wife suggested I explore something to do with computers or forensics, as I was very interested in computers and had an obsession for forensics on TV and in books. I researched both potential careers and came across the role of Digital Forensic Analyst. I then worked backwards to get the qualifications that would allow me to get that career.
“I phoned the University of South Wales and spoke to the Associate Head of Computing and Mathematics, who sounded so excited and passionate about the computer forensic course, that by the time he had finished telling me what it entailed, I really wanted to give it a go.
“The best thing about becoming a student was that after years of thinking I couldn’t do any better with my education and career, the realisation that with a little bit of direction, training, and belief from my peers and lecturers, I could achieve anything.
“My current role at Sytech (Systems Technology Consultants) is to analyse and investigate forensically extracted data, using a range of digital forensic software and techniques. My role also involves reading through case paperwork provided by the police force, in order to gain a full understanding of the alleged and potential criminal offences involved in the investigation I’m working on.
“I find the whole job interesting, and at times it can be extremely exciting and rewarding. My career choice came before the degree choice, so to achieve the position of Digital Forensic Analyst straight out of university is a dream come true. This is especially the case with a company such as Sytech, who have an advanced digital forensic laboratory and specifically employ graduates with relevant degrees.
“I’m looking forward to gaining further training in report writing and courtroom training, as well as potentially completing my EnCase Certification (EnCE) with an external trainer and becoming an expert witness within this field of digital forensics.
“My advice to anyone considering the MComp (Hons) Computer Forensics course is study hard, listen and research, and you will succeed on this course and get the career you want.”