Cellebrite Advanced Smartphone Extraction (CASE)
Level - Expert
Course Length: 5-Days
Cellebrite’s Advanced Smartphone Extraction (CASE) training is an advanced-level five-day course lead by Cellebrite Certified Instructors (CCIs). During this course, participants will learn about the chip-off process using a milling process, IR Heat and polishing through the board, flash memory in mobile devices (NAND/NOR, eMMC/eMCP, UFS), methodologies, and purpose as well as understand the equipment and accessories necessary for performing successful chip-off extractions. Instructors will help attendees to not only develop, but also to hone fundamental soldering skills, various methods to clean and “reball” a chip, and gain practical knowledge with hands-on practice as well as share best practices and legal considerations for processing chip-off extractions. Students hone their skills with a minimum of five chip offs, using the techniques learned, including UFS style chips. Additionally, participants will learn how to fully leverage the Physical Analyzer in order to properly decode the extractions. Students will become familiar with conducting eMMC/ eMCP extractions directly from a damaged memory chip using the Z3X Pro box, should it be necessary. A written test and practical is conducted at the end of the course, and students may use any of the three techniques learned to conduct the practical. Successful completion of the written test AND practical awards the participant the CASE Certification.
Overview of the CASE Training Course
Chip Off Methodology
- Describe the basic chip-off process, and why the advanced technique exists.
- Identify appropriate scenarios for the use of the chip-off technique.
- Discuss advantages and disadvantages of chip-off.
- Summarize critical need-to-know elements of chip-off
- Demonstrate Android device operating system version identification.
- Explore software installation procedures needed to complete the chip-off course and lab usage.
- Summarize the basic operations of NAND/NOR flash memory
- Describe the flash memory function of Wear-Leveling and FTL
- Use Cellebrite Physical Analyzer program to view Wear-Leveling artifacts captured in a mobile device extraction.
- Learn about eMMC/eMCP and UFS memory types.
- Discuss different types of mobile device memory.
Tools and Equipment
- Describe the various tools needed for chip off/subtraction techniques.
- Summarize the purpose of chip off/subtraction techniques.
Research and Disassembly
- Differentiate between the appropriate and inappropriate methodologies used to extract data from mobile devices.
- Explain how to locate the memory size and OS version for a mobile device
- Demonstrate how to safely disassemble a device for the chip subtraction process.
- Demonstrate how to research a device to implement a chip subtraction.
Milling Chip Off
- Explain when to use the milling subtraction chip-off process
- Compare and contrast the benefits and risks of milling chip-off procedures.
- Describe the equipment and setup required to safely conduct milling
- Demonstrate the steps required to successfully complete the milling process on a chip. (Practical)
- Describe how to identify and utilize the appropriate adapter to image a memory chip.
- Explain how to properly place a memory chip into an adapter.
- Demonstrate how to use various tools to create a raw physical memory image of the chip.
- Produce an image from a memory chip using Cellebrite forensic tools.
- Discuss how to use MacOS and Linux to image a chip.
- Recount basic troubleshooting steps in the chip imaging process
Z3X Pro ISP and EMates Pro
- Describe how to install the Z3X Pro software.
- Discuss the features and uses of the E-Mate Pro Kit.
- Demonstrate how to Image an exhibit using the Z3X Pro and E-Mate Pro kit. (Practical)
- Summarize the Ultrapol setup and operation processes.
- Recount how to safely prepare an evidence device for polishing.
- Demonstrate the necessary steps to polish the board away from the flash memory chip. (Practical)
- Explain the process of using a stencil to apply solder.
Dediprog NuProg-E Reader
- Install and configure the Dediprog NuProg-E programmer.
- Describe which exhibits may be read using the NuProg-E
- Recount the hardware and software utilized to read the data from a UFS memory chip.
IR Heat Removal
- Describe when heat may be an option
- Discuss precautions to consider
- Review equipment to use
- Demonstrate proper techniques for using IR heat to remove a chip (Practical)
Introduction to Physical Analyzer
- Complete the configuration of Cellebrite Physical Analyzer program advanced setting.
- Explore data extractions from mobile devices using the Cellebrite Physical Analyzer software.
- Demonstrate viewing data in the Cellebrite UFED Physical Analyzer interface.
- Describe the dynamics of the Plug-in Chain Manager.
- Relate and explore the capabilities Plug-in Chain Manager, including customization.
- Demonstrate the fully-automated and modified application of the Plug-in Chain Manager to enhance capabilities for content decoding.
At the conclusion of the instruction portion of this course, students will be presented with a device which must have the chip removed to extract the data. Students may use either method learned in the course to remove the chip and successfully extract the data. A report of results will be prepared at the conclusion of the course. Successful completion of this practical is required to earn the CASE certification.