Cellebrite Inseyets Physical Analyzer Release Notes 10.3
Cellebrite Inseyets Physical Analyzer Release Notes 10.3
Cellebrite Inseyets Physical Analyzer Release Notes 10.3
1. Introduction 4
5. Solved Issues 17
7. Installation Guidelines 28
15. General 49
These Release Notes are regularly updated. You should check for any patches or changes in the
documentation that may have been released after the initial product launch on MyCellebrite
Community.
Physical Analyzer Ultra 8.x is now labeled Cellebrite Inseyets Physical Analyzer in MyCellebrite
Community.
Inseyets Physical Analyzer Version 10.3 introduces a range of new and exciting examination features
and capabilities, designed to enhance your analytical experience and efficiency.
We now provide the Python Shell and Decoding Scope script capabilities for Inseyets Pro license users.
You can create plugins to enable these scripts to run either as part of their generic/custom chains, or as
part of processing devices. To develop a new Python script and run this as part of a case creation
workflow, see Python Integration, Inseyets.PA User Manual 10.3.
This is an early release. We will continue to enhance this feature for a future
release.
We are thrilled to announce the launch of our latest innovation, the Cellebrite Assistant, designed to
revolutionize your interaction with our Physical Analyzer user guide.
Say goodbye to endless scrolling and searching for information. Our chatbot provides instant answers
drawn directly from our comprehensive user guides.
Effortless Interaction: Simply type your question, and our chatbot will deliver the information you
need.
Smart and Intuitive: Powered by AI, our chatbot understands the context of your queries, ensuring
you receive relevant responses.
Always Available: Our chatbot is available 24/7, providing uninterrupted access to the information
you need, whenever you need it.
Disclaimer: Please note that at this stage, the Cellebrite Assistant's knowledge is solely based on the
information contained within our user guide.
Gallery Performance: Faster loading of images, improved 'mark for report’ speed, quicker filter
application and smoother scrolling and searching. Tagging and redacting numerous images is now
more efficient without delays or UI issues.
Chat Functionality: Chat views and message sorting are now faster making it easier to manage long
chat sequences.
Language Support: Upgraded to the latest engine for better language processing.
We are excited to launch the Warrant Return Automation Tool (WRAT). This is a standalone
application, which simplifies the downloading and processing of Warrant Returns, initially targeting
Apple Warrant Return data. No installation or license is required, simply launch the
CellebriteWarrantReturnAutomationTool.exe.
The Warrant Return Automation Tool is available from the Community Portal under Technical Data
Sheet.
Information about getting started can be found under the Help Menu.
Simply provide the tool with the GPG file and Password from Apple and let WRAT download, decrypt
and organize the data, creating the UFD and UFDX files to make processing the data easier.
You can now take free online Reader training in the new Learning Hub. This is aimed at Investigators,
Analysts, District Attorneys, and Private Investigators. Your agency can easily keep your teams updated
for better collaboration and faster case closure.
Dive into our Learning Hub, tailored for seamless navigation and enriched with over 40 new training
videos. Enhance your skills with interactive learning - download practical samples phone extractions
from MyCellebrite and apply them during video sessions.
Open Videos in a new window, allowing you to watch tutorials and navigate PA
simultaneously
Search function
Video duration
Training
You can now view the status of a message that was sent from an owner’s device, such as Read,
Received, and Open. The status is updated with the date and time.
Recipients tab: Open and view the status of a message by selecting Recipients on the Device
owner’s Conversation chat.
Status: No message sent: No messages were sent from this participant in this chat group.
You can now tag highlighted bytes in Hex View for any file. Hex tags can be color-coded and reported
on like normal tags and they are viewable in Cellebrite Reader.
We are excited to announce that Inseyets.PA 10.3 introduces support for incremental Decoding Engine
updates. This installation will only update the decoding engine and not the PA version which will
expand the support of decoded applications.
We recognize that applications are forever evolving; whether that’s an entire overhaul of the
application’s back-end or simply renaming a field in a database, these changes often affect the data
that can be decoded, sometimes completely preventing anything from parsing at all.
We at Cellebrite are constantly updating the support for these applications in an effort to expedite
your investigations.
Coming soon these incremental updates will be a small easy-to-install package requiring minimal
waiting time.
Each Decoding Engine release is tied to a specific version of Physical Analyzer to ensure compatibility
and is available for download from the Community Portal. For users who are connected to the internet,
you may receive notifications when an update is available.
The current version of the Decoding Engine in use on your Physical Analyzer installation can be found
in the About Screen available via the Help menu.
If for any reason you need to Roll Back to an earlier version of the Decoding Engine, simply run the
installer for the required version. Note that the currently installed version of Physical Analyzer must be
compatible with the DE version being installed.
The use of this feature is completely optional, and all Decoding Engine updates are
consolidated into the next release of this product. This feature is exclusive to PA
10 and it provides a more up to date and advanced decoding than PA 7. Please
note that this will create a disparity between PA7 and PA10.
We are happy to introduce new and enhanced capabilities that allow you to enter additional
case/report information directly into the Inseyets UFED system. This information seamlessly transfers
to the Physical Analyzer system and is integrated into the generated reports, ensuring a more
comprehensive and organized case process.
The new parameters that can be entered in UFED and passed to Physical Analyzer are:
Crime Type
Department
Location
Report Path
Report Name
We've upgraded our language engine offering improved translation capabilities and an expanded
vocabulary. You can now enjoy more accurate translations and access a richer pool of words for
enhanced communication.
You can't run PA 7.68, which uses the old SDL engine, and Inseyets.PA 10.3, which
uses the new SDL 8.6.3 engine together on the same machine. The engine will
sync in the PA 7.69 release, which also uses the new SDL 8.6.3 engine. To use both
versions simultaneously, upgrade to PA 7.69 and Inseyets 10.3.
The Offline Maps available for download have been updated and are available from the Cellebrite
Portal.
Decoding Engine 11.1 adds support for Location and Search data from
AlpineQuest Off-Road Explorer
AlpineQuest Off-road Explorer.
Support for Maps.Me support User Account, Search Queries and Location
Maps.Me
information.
DE11.2 brings support for Blue Kik; a mod designed to enhance the user
Blue Kik
experience of the Kik Messaging application.
DE11.3 introduces support for the ChatGPT AI Assistant app for Android. This
app allows users to have a Chat style conversation with ChatGPT who will
ChatGPT
respond to questions, provided internet search capabilities and create
images etc.
iOS
Support for Maps.Me support User Account, Search Queries and Location
Maps.Me
information.
DE11.3 introduces support for the ChatGPT AI Assistant app for iOS. This app
allows users to have a Chat style conversation with ChatGPT who will
ChatGPT
respond to questions, provide internet search capabilities and create images
etc.
New support introduced for the Audio Route stream from knowledge &
Biome files. This new artifact indicates both the input audio route (e.g.
microphone, Bluetooth) and audio output route (e.g. Speaker, Earpiece,
iOS Native Improvements Bluetooth, Headset) and includes external device identifier information
where available.
Cloud
Our cloud capabilities enhance the Facebook parser run time and add new
Facebook Data Source
important Facebook artifacts: Blocked contacts, comments, sub-comments,
Enhancements
and attachments of comments
OnOff - 5.6.1
Support for multiple devices in a single case will be supported in the future.
Some emojis may not be displayed correctly in PDF reports generated by PA and Reader.
00626711
This is because there is not a single font that supports all emojis. This issue is not
specific to PA/Reader, but rather it is an industry-wide challenge. Cellebrite will continue
to work towards finding a general solution.
When selecting a location in the Locations model that includes >200 aggregated sub-
locations, PA will only highlight/select the first 200 in the table view. J_PAOD- 31303
This results in any sub-locations in excess of the first 200 not being highlighted/selected.
Filtering the Locations model table by source file may return less results than
J_PAOD- 31679
anticipated.
In extractions that contain an excessively large Telegram database, PA will fail during
J_31169
decoding.
When utilizing translation packages (SDL), users cannot run PA 7.68 and Inseyets.PA 10.3
together on the same machine due to conflicting translation engine versions.
N/A
The engine versions will sync in the PA 7.69 release. To use both versions at once ,
upgrade to PA 7.69 and Inseyets 10.3.
Commander cannot distribute Inseyets.PA version to the end points (targeted to PA 10.4).
N/A
It can only distribute the license.
UFDX files with long files path can cause issues. UFDX files which point to a UFD location
with a long file path can cause issues as they are not automatically converted to long file N/A
paths.
In some cases having multiple cryptocurrencies in one wallet may cause the dashboard
to go blank. When examining a cryptocurrency wallet with multiple different coins, N/A
selection of anything other than the primary currency return a blank page.
Not all app sources are displayed when searching by attached media. Not all Applications
N/A
may show in the Media Viewer’s Attachment Source Filter.
When loading 2 UFDRs generated from the same source, duplicates are not recalculated
N/A
but rather taken from each UFDR separately, which may result in unidentified duplicates.
Users may occasionally encounter login issues when accessing the Learning Hub via N/A
Reader. Usually, retrying the log in process several times will resolve this issue.
Learning Hub favorites are not saved between sessions. Note that these favorite
N/A
selections are not currently saved when PA is closed.
Learning Hub videos selected on the Training tab duplicates the selected video on
N/A
Favorites tab.
Learning Hub All tab : There is a navigation issue between the "All Category" tab and the
N/A
rest of the categories.
00783798 |
00789894 |
Cloud tab unavailable when we open multiple 00796415 |
Private Cloud
evidence. 00803112 |
00812241 |
00823790
71155 | 00805415 |
Timezone settings PA / Reader
PA / Reader Ignores the Timezone settings. 00813594 |
Ignores
00814929
00813823 |
Cases Screen sorting Incorrect sorting by dates in the new cases screen. 00814299 |
00815461
00811359 |
Thumbnail view Latency Latency when scrolling down on multiple images. 00816190 |
00819213
SDL Translate SDL doesn't work when 2 dongles are attached. 00797274
00773420 |
00785816 |
Media classification is run only on the first extraction
Image Classification 00785707 |
when multiple extractions belong to the same UFDX.
00807890 |
00810399
00802898 |
00831219 |
An issue was resolved which prevented Silk files from
Silk Files (Multiple) 00795120 |
playing.
00697708 |
00807914
00757488 |
00773412 |
Large Telegram databases (~10GB) would take a long 00775640 |
time to process, causing the appearance of a crash. 00777319 |
Telegram
Improvements have been made to the handling of 00735392 |
these large databases. 00802119 |
00819069 |
00816352
PDF report name Report can’t be generated when file name is too long. 00783766
00773420 |
00785816 |
Reader Dashboard Not showing the Report Filter used. 00785707 |
00807890 |
00810399
00803345 |
00803745 00806791
Updated Facebook Warrant Return parser to account
Facebook Warrant Returns | 00807262
for changes made to the formatting of the return.
00807253 |
00823211
00782305 |
Changes were made to our parsers to handle the 00808883 00810392
Instagram Warrant Return updated changed Meta made to their Warrant | 00777715
Returns. 00811031 |
00810949 00805176
You can find downloads and guides for Inseyets at MyCellebrite Community.
The guides that are provided with the product or included in the product download are current when
the product is released. If there are any guide updates after the product is released, you can download
these updates from the MyCellebrite website. It’s important to regularly check the Release Notes as
they are frequently updated.
Inseyets is our digital forensics suite that enables forensic teams to increase their case closure rates
and scale to meet growing data demands. The technology is built to make your teams more efficient
and deliver insights so your teams can surface key digital evidence during an investigation. It’s all
available in a single solution so your department can start solving cases faster.
For your convenience, this bundle is delivered as individual installers on Cellebrite MyCellebrite.
The following table lists all components of Inseyets. Cellebrite recommends using MyCellebrite support
center to download software.
MyCellebrite Community
Cloud
10.3 MyCellebrite Community
(formerly known as UFED Cloud)
For additional information about Inseyets or for supplemental information about related products,
refer to the following documents, which are available on MyCellebrite Community.
Drone support
Warrant returns
Storage devices
Drones
Vehicle
Case Import/Export
Dashboard
Search
Tags
Timeline
Carving
Hash Sets
Enrichment
Cryptocurrency 'Chainalysis'
Enrichment
Cryptocurrency Scanner
Media Classification
Commander Integration
Hex View
Malware Scanner
Selecting Decoding
Watchlist
Advanced
Tools AppGenie
Media Origin
Run Plug-in
Language Add-ons
Smart Translations (SDL) Premium
available in Pro ONLY
SQLite Wizard
Reader
Reports
Reports
Inseyets 10.3 can run simultaneously with 7.x versions of Physical Analyzer.
The current version of Inseyets 10.3 supports upgrades without the need to uninstall prior to
upgrading.
When upgrading the Inseyets 10.3 version, the case data remains the same.
If you have version 8.8.x or higher installed, you can upgrade it to the current version without doing
an uninstall. For versions prior to 8.8, an uninstallation process is required.
Uninstalling Inseyets.PA 10.3 will remove all cases and case data, including
Global settings such as Watchlist and Hashset definitions. Existing cases will no
longer be accessible, unless exported prior to deletion.
During installation you will be prompted that certain services need to be stopped before the
install/upgrade can continue. Allow the installer to close all services.
In certain instances, the installation may encounter an issue re-starting one of the services it needs
to complete the installation.
Example: "Service 'SERVICE_NAME' failed to start. Verify that you have sufficient
privileges to start system services."
Where 'SERVICE NAME' is the name of the specified service that failed to start.
Due to Physical Analyzer now utilizing a database infrastructure, there is an increased number of disk
I/O operations, and it is highly recommended to use multiple, fast NVMe/SSD drives for PA’s setup.
HDD (Platter) drives are not recommended for either the PA Database or Temp Files locations, due to
their limited performance.
Best performance will be achieved if the extraction being processed is also stored on a high-
performance drive, but it is also supported from any media type including HDD, USB or Network
Storage.
Windows OS
Temp Files
Windows OS
Three Drives Database (Data Folder)
PA Installation
NOTE: If the OS Drive has limited free storage, configure the Temp files on the same drive where the
evidence files are located.
The Database (Data Folder) should be allocated to the fastest drive, which should
not be the same as the OS Drive.
Inseyets PA and the Windows OS both utilize Temp files to manage tasks and
supplement missing RAM. You must have enough available disk space in the
designated Temp folders to process large extractions. If the disk space is too low,
these extractions may not open.
RAM Size 64 GB
1 Drive for OS
*AMD Equivalent Processors are supported although CPU based Media Classification performance may
be slightly slower due to differences in architecture.
Memory (RAM) 16 GB
The Reader.exe is approximately 1 GB. It will require an additional 800 MB when running.
Space
Additional space is required for temporary files that are needed when opening the UFDR.
Requirements
The total volume required is approximately 40% of the size of the UFDR.
Machines with more RAM will enjoy a better user experience. We encourage
users to upgrade their system memory to fully benefit from these improvements.
Systems with limited memory may experience reduced performance. For an
optimal experience, ensure your computer has sufficient memory capacity.
Larger extractions may require more RAM and disk space than the minimum
specification.
Inseyets.PA is compatible with the server versions of the operating systems specified in its release
notes. These versions can be installed on either physical or virtual hosts, including cloud platforms like
Google Cloud, Amazon Web Services, and Microsoft Azure. Customers opting for a virtual environment
are advised to choose a virtualization platform that is designed for production systems and is fully
endorsed by the server operating system provider.
Although virtualization products are not officially tested environments for Inseyets.PA, Cellebrite will
strive to provide support if any issues occur. In some cases, it may be necessary to replicate a problem
in a non-virtualized environment to accurately diagnose and resolve the issue.
Inseyets.PA is a resource intensive application and will need at least the same
amount of resources in a virtual environment as it does in a physical one. As a
result, virtual hosts may need additional resources beyond your standard VM
configuration to achieve desired performance. For scenarios where performance
is critical, static or committed resources within a virtual environment are typically
required. Virtual machines require software licenses.
For the best performance and stability, Intel suggests using CPUs from their recommended list:
ARM and ARM64 CPUs; including Apple M1, M2, and Raspberry Pi models
The list provided above is applicable to the most recent version of the ImAn server, which is version
7.5.11. If you require details for previous versions, please refer to the resources mentioned below:
The present list is derived from the official OpenVINO website, which can be accessed at the
following URL: https://docs.openvino.ai/2023.3/system_requirements.html.
For system requirements pertaining to older versions of ImAn, which utilize previous releases of
OpenVINO, please see: https://docs.openvino.ai/archive/2020.1/_docs_install_guides_installing_
openvino_windows.html#system_requirements%20.
See the Intel Blog for a complete overview of the GPU. This overview will help you decide which GPU to
purchase.
The graphics processing unit, (GPU), has become one of the most important types of computing
technology, both for personal and business computing. Designed for parallel processing, the GPU is
used in a wide range of applications, including graphics and video rendering. Although they are best
known for their capabilities in gaming, GPUs are becoming more popular for their use in creative
production and Artificial Intelligence (AI).
GPUs were originally designed to accelerate the rendering of 3D graphics. Over time, they became
more flexible and programmable, enhancing their capabilities. This allowed graphics programmers to
create more interesting visual effects and realistic scenes with advanced lighting and shadowing
techniques. Other developers also began to tap the power of GPUs to dramatically accelerate
additional workloads in high performance computing (HPC), deep learning, and more.
Cellebrite makes use of the GPU for the Image Analytics Service when categorizing media files. Moving
forward, we plan to leverage GPUs for more capabilities outlined in our roadmap, including thumbnail
generation and hash set matches, along with other operations that demand significant computing
resources.
We support all Ampere and Turing Architecture GPUs, specifically, we have tested the following GPUs:
NVIDIA A10
NVIDIA V100
* We consider this the best GPU option. (The results are not guaranteed and can vary.)
Arabic AR Yes
Croation HR Yes
Czech CS Yes
Danish DA Yes
Dutch NL Yes
English EN Yes
Estonian ET Yes
French FR Yes
German DE Yes
Greek EL Yes
Hebrew HE Yes
Hindi HI Yes
Hungarian HU Yes
Italian IT Yes
Japanese JA Yes
Korean KO Yes
Latvian LV Yes
Lithuanian LT Yes
Norwegian NN Yes
Polish PL Yes
Slovak SK Yes
Swedish SV Yes
Thai TH Yes
Vietnamese VI Yes
The default UI language for the components is English; other languages are available as language packs
or language module versions on MyCellebrite Community
Mobile (Cellebrite,
Graykey) Mobile (Cellebrite,
Graykey)
Computer (Windows)
Warrant returns
Warrant returns
Cloud
Evidence Source Cloud
Drones
Drones
Vehicle
Vehicle
Storage device
Storage device
Backup
Backup
Cases
Dashboard
Cryptocurrency ‘Chainalysis’
Enrichment
Media Origin
UFED to PA Streamline
Extraction Info
Reports
Timeline
Tags
Search
UI Translation
Malware Scanner
Watch List
Hash Sets
Selective Decoding
Reader
Insights
Carving
Media Classification
Cryptocurrency Scanner
AppGenie
SQLite Wizard
Basic Translations
Run Plug-in
Screenshot Tool
Public Cloud
Tom Tom
*Smart Translations (SDL) requires a license upgrade at an extra cost. Please contact your sales
representative for more information in the interim.
** These features are being reviewed for possible removal, inclusion into another feature, and/or
replacement.
We understand that by launching Inseyets.PA, you may have some unanswered questions. This FAQ
section was created to provide you with further clarity on how to use Inseyets.PA, including its features
and functionality, as well as insights into upcoming releases.
The FAQs will be updated with every release with the relevant information.
No. The same PA license can be used for PA 7.x, PA Ultra, and Inseyets PA at no additional cost.
No. Inseyets PA 10.x can be installed alongside PA 7.x and will even run at the same time. However,
you need to close PA 7.x while you install Inseyets 10.x.
No. Inseyets.PA includes an upgrade feature which will replace older versions without the need to
uninstall.
Uninstalling Inseyets.PA will cause the loss of any case data, unless you already exported the case
data and stored it. The original extraction will remain secure where you saved it. In addition
uninstalling will erase any Hash sets, Watch lists or any other non-default global settings.
Inseyets.PA will work alongside most other forensic tools. However, Inseyets.PA and PathFinder
(Single User) cannot be installed on the same computer.
Application path
We recommend configuring the default database path on a separate, high-performance drive as this
can have a significant impact on the parsing speed.
Q: Can I install Inseyets.PA and utilize a network drive/NAS to store the case data?
Installing the Postgres databases on a machine other than the Postgres Service is not supported.
Network instability can cause issues when creating or accessing the data from a network drive. This
option is not available.
As of version PA 8.5, all versions of PA Ultra through 8.8 and Inseyets.PA include GPU support.
Inseyets.PA is built on top of a database, any updates made by the user are immediately saved in
the database, so there is no longer a need to use .pas files before generating a UFDR file. If you are
using Inseyets.PA Reader to review a UFDR then you can use session files in a similar fashion as in
PA 7.x
The database that Inseyets.PA creates only stores the results of the parsers but not the data itself.
While this necessitates continued access to the original extraction, it means that the database that
it creates is compact.
Example: A 60GB extraction results in a 7GB database and A 16GB extraction results
in a GB database.
Currently, it is possible to add multiple extractions to a device, but not to add multiple devices to a
case. We are working on adding support for multiple devices in a future release.
Q: Can I place my extractions and other evidence files on a network drive and open them from my
machine?
Each case is separated into its own database and saved in either the default case data location or in
the location specified at the time of case creation.
No. Although Inseyets.PA is designed to eventually allow multiple devices to exist in a single case, it
is still a tool for examining a single device at a time and not for cross-device analysis.
Editing a case includes altering the Case information, Device information or adding extractions to a
case. In the future, this will also include adding additional devices to a case.
The user must first ensure that the case is not open, then, from the Case Management screen, use
the inline case action menu (three vertical dots) where you can Close, Edit, Delete, Export, or
Upgrade a case.
With each release of Inseyets.PA, there might be slight changes to the database schema with the
addition of new functionality. This necessitates each case being “upgraded” to work in the current
release. It does not make any changes to the data other than making it compatible with the latest
database schema.
During the Inseyets.PA upgrade process, your existing cases will be backed up and restored
automatically.
Q: Are existing cases reprocessed with the new parsers when upgrading to new versions?
No. Minor adjustments may be made to the database schema to ensure compatibility, but no data
will be altered. This means that you can open an old case at any point in the future and be
confident the data is the same as when it was first parsed.
To take advantage of new parsing capabilities in the new version of Inseyets.PA, a new case must
be recreated and reprocessed. There is no requirement to delete the existing case if you wish to
retain both.
PA Ultra and Inseyets.PA use the same decoding engine as PA7.x and are fully aligned with PA7.x
releases as shown in the table below.
It is important to also note that differences in the deduplication logic may result in some differences in
the record counts.
Like PA7.x, Inseyets.PA is designed as a single user tool. It is not designed for multi-user
collaboration.
Yes – Inseyets.PA supports running multiple instances of the same version and future releases will
support the installation of different Inseyets.PA versions.
Q: When would I use Inseyets.PA instead of Cellebrite Inspector? And vice versa.
The breadth (number of source types) and depth (number of artifact types) differs between
Inseyets.PA and Inspector and deciding which product to use will depend on your case needs. In
some cases, you may start your examination in one and complete it in the other. Generally,
Inseyets.PA is your go-to solution allowing a single examiner advanced mobile insight, and vital
Windows® computer data, with Mac OS support on the horizon. If your case requires advanced, in-
depth analysis of Windows and Mac OS machines, Inspector is the right tool for you.
If you would like to parse the backup data, you must extract the backup files and process it as a
separate device.
The current version of Inseyets.PA only supports Windows data from e01, .l01, .vmdk and .bin files.
The computer data roadmap for Inseyets.PA includes supporting a complete, case driven
intelligence picture of different digital data sources. If you want to parse macOS, please use
Inspector.