MPE+ Mobile Forensics Software Supports 7000+ Devices, Including iOS®, Android™ and Blackberry® Devices, as well as Devices with Chinese Chipsets
Mobile Forensic Examiner PLUS (R) is AccessData’s market leading stand-alone mobile forensics software solution that delivers an intuitive interface, data visualization and smart device support in a single forensic interface. MPE+ supports even the most challenging mobile device profiles and features advanced carving, deleted data recovery, SQLite database browsing and filtering options. Furthermore, MPE+® images integrate seamlessly with Forensic Toolkit ® (FTK ®) computer forensics software, allowing you to correlate evidence from multiple mobile devices with evidence from multiple computers within a single interface.
Broad Mobile Device Support and Functionality in a Single, Easy-to-Use Solution
With support for more than 7000 cell phones and mobile devices, including iOS , Android , Blackberry, Windows Mobile™ and Chinese devices, MPE+ enables examiners to perform advanced mobile device investigations without having to purchase an overpriced suite of modules or cumbersome hardware. Advanced carving and filtering options, as well as broad support for even the most challenging mobile device profiles, facilitate thorough analysis and reporting. Plus its integration with FTK and the touch tablet option make it the intelligent choice for mobile forensics examiners looking to upgrade their capabilities.
Adding MPE+® Velocitor Enables Your MPE+ Solution to Support More Chinese Devices than Any Other Solution on the Market Today.
MPE+ Velocitor is an optional hardware add-on that integrates seamlessly with MPE+ version 5.3 and above. MPE+ Velocitor solves the problem investigators now face when processing cheap generic phones, tablets and Chinese phones as key evidence in critical investigations. MPE+ Velocitor provides physical and logical extraction from 95% of Chinese chipsets, including full flash data extraction. Supported devices include MediaTek, Spreadtrum, MStar, TI, Phillips, Coolsand and more.
MPE+® for E-Discovery
In addition, MPE+® is the only mobile forensics solution designed to facilitate mobile device discovery for litigation support personnel addressing e-discovery requirements. The interface is the most intuitive on the market and includes visualization tools that allow you to easily see communication relationships among contacts and automatically construct graphical data timelines.. An intuitive interface, advanced analysis, easy export and robust reporting make MPE+® the tool of choice for e-discovery practitioners.
NOTE: MPE can be purchased with a SIM reader and phone cables. Cable updates are shipped to those who maintain SMS.
Supports 7000 Mobile Devices
MPE+ supports 7000+ devices, including more than 1300 unique profiles that often present challenges to investigators. (Cable kit available separately.)
- Motorola including Atrix HD, Photon Q, Razr M,and Razr I and others
- Android ™ devices, including full user data extraction from rooted devices
- Any iOS compatible devices up to iOS 7
- Physical extraction limited to devices up to and including iPhone® 4 and iPad® 1
- iLogical Enhanced Support allows the acquisition of many sources of data beyond most products in the market can deliver.
- Windows Mobile® devices
- Blackberry ® devices, including the import of Blackberry BBB (Blackberry Backup) files and select general devices
- Legacy phones including LG, Nokia Series 30/40, Samsung, Motorola, ZTE, Sony Ericsson and others
SUPPORTS 95% OF MOBILE DEVICES CONTAINING CHINESE CHIPSETS
Adding MPE+ Velocitor* to your MPE+ solution allows the extraction of the file system, call history, messages (SMS/MMS), flash images and device information from mobile devices containing Chinese embedded chipsets including:
- Chinese MediaTek (MTK)
- Coolsand and more.
*MPE+® Velocitor is sold separately and requires a license plus the MPE+® v.5.3 software upgrade or above Software upgrade
AUTOMATED SMART APPLICATION RECOVERY
MPE+ allows for the one-click recovery of application data, including but not limited to:
- QQ and more
ANDROID™ DEVICE ANALYSIS
- MPE+® enables the physical imaging of Android devices including both Samsung Galaxy S®II and III devices even if USB debugging is not enabled. This allows MPE+® to bypass any passcodes even if the device is protected with USB debugging in the OFF position.
- MPE+® provides an extraction wizard when extracting both Samsung Galaxy SII and SIII Android devices.
- INDUSTRY-FIRST Logical Support for Samsung S4. Users do not need to select the specific Samsung Galaxy S4 name, simply select Android and Generic.
- MPE+ provides an automated Android parser which allows auto parsing of call history logs from Samsung Galaxy Devices when call logs are not stored in standard files
- Physical Image Support for Android RFS file system and more
IOS ® DEVICE ANALYSIS
- Physical and logical acquisition of iOS devices up to iOS 7 (both CDMA and GSM). Physical extraction is limited to devices up to and including iPhone® 4 and iPad® 1
- No jail breaking required.
- Acquire physical and logical data simultaneously, without the need for iTunes ®.
- On-the-Fly decryption of operating system and logical data
- Logical acquisition of any iOS devices from v.1.0 to up to v.7 utilizing MPE+ iLogical™ Enhanced iDevice Support. MPE+ iLogical Support allows investigators to acquire many sources of data beyond what most logical products on the market are able to deliver. It will facilitate the acquisition of any compatible iOS devices, ranging from iOS v1.0 to the most recent iOS devices. Learn more about MPE+ iLogical Support
- iTunes® Backup Browser
- Import folders and files containing an iTunes Backup.
- Using a mounted image, point to the iTunes folder.
- Support for both encrypted and non-encrypted backups.
- iTunes backup parsing over the network.
- Parse any drive anywhere you can access a network.
- Users can navigate to a local folder, mapped drive, mount a forensic AD1 or E01 file, and even navigate across a computer’s network to parse user’s data stored in an iTunes backup folder
GRAPHICAL INTERFACE FOR MORE INTUITIVE ACQUISITION AND ANALYSIS
- Home “Launch Area”:
- User Guide
- RSS Feeds for MPE+ Support Videos
- Recent Collections and Quick Links
- Training, Forum and Product web interface
- Timeline Viewer illustrates SMS, EMAIL, MMS and Call Logs for any selected timeframe.
- Social Analyzer illustrates SMS, EMAIL, MMS and Call Logs for selected contacts – comparing each with all selected.
Advanced Analysis Tools
File systems are immediately viewable and can be parsed in MPE+ to locate lock code, EXIF and any data contained in the mobile phone’s file system.
- Filter any column by Data or Values, such as Contains/Is equal to, and more.
- New Data View Tabs
- Enhanced Gallery View
- File system will display all images in selected folders.
- Carving Window displays all images.
- Media View shows all images extracted.
- PLIST Viewer Built into Natural View and embedded SQLite Database Browser
- Now you can view data in both binary and standard PLIST files in CHTML.
- View tables within SQLite databases in CHTML.
- Ability to export the viewed data in several formats including Microsoft Excel
- Carve Data for Embedded Phone-Specific Data.
- Built-in iOS and Android Parsers
- Carve ALL SQLite Database Files from iOS ® to Android ™ for Deleted Data.
- Right click on any SQLite database and select to parse the free file area.
- All parsed SQLite databases are then displayed for review.
- Hex Interpreter
- Highlight bytes to display common date/time formats.
- SIM and USIM support, with Forensic SIM cloner for Phone Processing without Altering Data
- Import Many File Types, Including AD1 Forensic Containers, Back into MPE+ to View Data as if the Device is Connected.
SMS messages from any device can now be displayed in “Conversation Mode”. This mode displays data in the familiar threaded conversation view used in the Android and iOS environments. With MPE+’s Conversation Mode, it is easy to follow an SMS conversation by viewing the SMS data from any device.
ADVANCED ALERT MANAGER
The Alerts feature allows you to create keywords that MPE+ will use to flag and label extracted data that matches those keywords. Users can create alerts from within MPE+, import folders containing alerts, create a single alert file and import into the alerts and even export all the alerts into a folder to share with other MPE+ users.
- Information that is located when running alerts is given a tag. This tag is found in the Alerts column for each data type. The number of alerts for each row along with the alert that triggered the tag is given for each alert. (16256)
- Have multiple alerts selected to run on each data set and more.
- Alerts can be run manually as well as be set to automatically run for every device extraction, import, and parse conducted in MPE+. This feature will allow the user to immediately be notified of alerts when parsing images, collecting from a device or running our built-in parsers.
Ideal System Setup
Our experienced team can provide in depth product or service explanations as well as, schedule a demo, and/or price quotes. You can expect a reply within 24-48 hours.
For an immediate response please contact us at: Domestic US: 800.574.5199 | Int’l: +44(0)20 7010 7800.
Mobile E-Discovery Collection Demonstration with AD MPE+
Learn what MPE+ can do: Using Python with MPE+
I really like how easy it was to get the logical and physical acquisition. It’s like “one stop shopping.” No need for a passcode either. Other tools require a passcode or jailbreak to get the logical.
Law Enforcement Officer
Chances are mobile devices containing Chinese-manufactured chipsets are already part of your forensic investigation. Chances are…
… you haven’t being able to process them. Now you can.
MPE+ Velocitor is an add-on hardware tool that integrates seamlessly with MPE+ to unleash the power of physical and logical extraction from 95% of Chinese mobile devices. The MPE+ Velocitor appliance enables MPE+ to support more Chinese devices than any other mobile forensics tool
The manufacture, export and purchase of cheap, generic, phones and tablets are becoming more and more common these days. In 2011 alone, over 800 million mobile devices and close to 40,000 models were manufactured in China. In 2012, more than half of those were exported to world markets, comprising more than 30% of the global cell phone market. As result, these devices are becoming one of the most prominent sources of forensic evidence.
MPE+ Velocitor assists mobile forensics labs with critical examinations involving these devices. In many cases a mobile device may look like a mainstream smart device, but it is actually a cloned or counterfeit phone containing Chinese components. In those instances, most mobile forensics solutions fall short, making it impossible to process critical data. MPE+ Velocitor enables full flash data extraction from these devices, exposing critical evidence quickly and effectively, without the need for a third-party tool or software.MPE+ Velocitor Highlights
Physical and logical extraction from 95% of Chinese chipsets, including but not limited to:
- Infineon, TI, Phillips and Coolsand and more
Parse user data to include:
- SMS, MMS, Media, Contacts and Call Logs. Deleted data is also accessible.
- Passwords, Chip ID, IMEI numbers and device information
The MPE+ Velocitor solution includes…
- MPE+ Velocitor License
- MPE+ Velocitor Hardware Device
- MPE+ Velocitor Cable Kit
- MPE+ Carrying Case
MPE+ Velocitor User Guide