MD-RED

Mobile forensic software for recovery, decoding, decryption, visualization and reporting evidence data from a mobile and digital device

  • MD-RED is a forensic software for recovery, decryption, visualization, analytic data mining, and reporting of evidence data extracted via MD-NEXT or other tools. All the results of the analysis can be exported as the forensic reports for the investigation of crimes and accidents. Also, the analysis module of the latest mobile apps is quickly updated by continuous research.

View PDF

Category:

Description

FEATURES :
SELECTIVE EXTRACTION AND ANALYSIS OF EVIDENCE DATA

  • Prioritizes on-site proceeding and acquiring, so image and case files can be analyzed afterwards
  • Only data related to the case can be selected and analyzed
  • Selective acquisition of data for the protection of personal information
  • Scans important applications based on time and frequency of use

ANALYSIS DATA VIEW JUST LIKE LOOKING AT A REAL SMARTPHONE SCREEN

  • Quick evidence data identification by providing data view themes similar to that of a smartphone app

INTEGRATED DATA VIEWERS

  • Includes the viewers to display files such as photo, video, audio, document, map and website browsing history

MIRRORING AND REMOTE CONTROL OF SMARTPHONE DISPLAY

  • Smartphone screen mirroring and remote control can be used when smartphone display is broken or the prevention of unwanted operation on the phone
  • The mirrored screen can be captured and recorded as evidence

SCREEN RECORDING

  • PC screen recording of MD-LIVE to reproduce and verify its forensic process

EASY AND CONCISE PROCESS

  • Intuitive user interface
  • Auto-detection of smartphone model
  • Automated analysis after data acquisition

REPORTING FEATURES

  • Exports reports into PDF and Excel formats
  • Supports ‘Witness Document’ generation
  • Supports a various HASH algorithms MD5, SHA1/224/256/384/512, RIPEMD128/160/256/320

EXTERNAL STANDING CAMERA (OPTION)

  • For taking a photo of the evidence and its display or recording the investigation procedure
  • Hardware-based auto-focusing
  • Anti-reflection pad

SPECIFICATION

PARSING AND RECOVERY OF VARIOUS IMAGES AND FILESYSTEMS

  • Images: SD Card, phone data partition, MDF, E01, GrayKey, UFED image format
  • Filesystems: FAT12, FAT16, FAT32, NTFS, exFAT, HFS+, EXT2, EXT3, EXT4, F2FS, VDFS, APFS, TAT16, TAT32, NxFS, IKVISION, DHFS4.1, WFS0.4, TANGO, RSFS, WOW, VDFS, XFS, YAFFS, EFS2, TFS4
  • Data carving for unused area

ANALYSIS OF MOBILE DATA AND APPS

  • Multimedia files taken by phone camera
  • Call log, Address book, SMS/MMS, Email, Memo, Internet history
  • SNS, Map, Navigation, Health, Banking and Lifestyle apps
  • Detects Steganography, Anti–forensic apps
  • Deserialization, Decryption and Recovery of data

ADVANCED ANALYSIS OF POPULAR MESSENGERS

  • Description of encrypted messenger data
  • Multiple backup files of WhatsApp decryption and analysis
  • Multiple account analysis

DATA VISUALIZATION AND SOCIAL RELATIONSHIP ANALYSIS

  • Map view for GPS data and cell tower location
  • Timeline view of analyzed data
  • Chat viewer for communication visualization
  • Web browser for internet history review
  • Social relationship analysis
  • Community analysis by centrality

MULTIPLE SPACE ANALYSIS

  • Samsung secure folder(KNOX space) analysis
  • Huawei PrivateSpace analysis
  • Android Multi-Space analysis

DATA DECRYPTION AND RECOVERY

  • Identifies encrypted document
  • Decrypts encrypted chat message, email, file and app data
  • Recovery of deleted file and multimedia data

DYNAMIC DATA FILTER AND SEARCH

  • Filter by file system, signature, time and more fields
  • Dynamic filtering operators, sorting, grouping
  • Search by regular expression
  • Keyword registration
  • Bookmarking of selected data
  • Multimedia filter by app, status, size, type, property, path

REPORTING

  • Export of original or converted files with hash value of files
  • Supports PDF, Excel, ODS, HTML, XML and SQLite DB format
  • Supports 3rd party report formats such as NUIX, Relativity and ForensIQ one
  • Electronically stored information can be included in a report
  • Analyzed result can be reviewed with a stand-alone data viewer MD-Explorer