Password Recovery – Evidence Intake – Faraday Bags

Powerful

End-to-End

Efficient

Digital Investigator Tools and Add Ons

Password Breaking – Mobile – Computer 

Working with Experts

Paraben and Passware

Paraben and Passware, both leading developers in the digital forensics industry, have a collaborative relationship that leverages each companies strengths to provide a more comprehensive solution for investigators. This relationship combines Passware’s renowned decryption capabilities with Paraben’s powerful forensic analysis platform-E3.

Passware Kit Mobile

Passware Kit Mobile (PKM) is a dedicated forensic tool for bypassing or recovering passcodes and extracting data from locked or encrypted mobile devices. It is a highly specialized solution, and as such, it is not available to individuals and is sold only to qualified organizations.

 

  • Primary Function: PKM is used to recover or bypass pattern, password, PIN, and alphanumeric passcode locks on mobile devices.
  • Data Extraction: It performs a forensically sound, full file-system extraction from devices. This includes decrypting data and extracting information from various sources, such as iOS Keychain, password managers like 1Password and Dashlane, and encrypted app data from messengers like Signal.
  • Supported Devices: PKM supports a wide range of devices from manufacturers like Apple, Samsung, Huawei, LG, Xiaomi, and more. It is regularly updated to support new models and security schemes, including those with advanced processors like Apple A-series, Huawei Kirin, and various MediaTek and Qualcomm chipsets.
  • Acceleration: The software can accelerate the recovery process using NVIDIA and AMD GPUs and distributed computing, which significantly reduces the time it takes to crack passcodes.
  • Licensing: The software is licensed on an annual basis, with a set number of “successful extractions” allowed per license.
  • Support of images in E3.

Passware Kit Ultimate

Passware Kit Ultimate is Passware’s most comprehensive and powerful solution, often referred to as their “ultimate password breaking kit.” It is an all-in-one forensic decryption solution that combines the capabilities of several of their products into a single license.

  • Comprehensive Decryption: PKU is designed to tackle a vast array of password-protected items. It recovers passwords for over 380 file types, including Microsoft Office documents, PDFs, Zip and RAR archives, password managers, and cryptocurrency wallets.

  • Full Disk Encryption (FDE): A key feature of the Ultimate kit is its ability to decrypt or recover passwords for full disk encryption containers and volumes. It supports all the major encryption schemes, including BitLocker, APFS, FileVault2, LUKS, and VeraCrypt.

  • Live Memory Analysis: The kit can acquire and analyze live memory images to extract encryption keys for hard drives and passwords for Windows and Mac accounts.

  • Mobile and Device Forensics: PKU includes all the functionality of Passware Kit Mobile, allowing users to perform passcode recovery and data extraction from locked mobile devices. It also includes the “Device Decryption Add-on,” which is an exclusive solution for unlocking, decrypting, and recovering passwords from specific hardware like Western Digital My Passport hard drives and Macs with Apple T2 Security Chips.
  • Distributed Computing: For brute-force and dictionary attacks on complex passwords, PKU leverages distributed computing. It comes with 10 Passware Kit Agents, which can be installed on other computers to create a powerful network for a parallel password recovery effort.

  • Passware Kit Ultimate is intended for professional use and is only sold to law enforcement agencies, government organizations, and forensic firms. 

Review – Search – Report

Tiered Case Review Tool

In today’s complex digital investigations, collaboration is key. But sharing sensitive evidence with non-technical team members—such as attorneys, management, and other stakeholders—can be a challenge.

How do you provide them with access to the case file without risking its integrity? 

The answer is E3:View, the read-only evidence analysis tool.

E3:View is designed to empower anyone on your team to securely review, analyze, and report on digital evidence. It’s built on the powerful E3 Forensic Platform, so you get all of the advanced analysis features without the need for data acquisition capabilities. This makes it a cost-effective, secure, and intuitive solution for a more streamlined workflow.

With E3:View, you can bridge the gap between your forensic lab and the rest of your investigative team. It eliminates the need for manual data preparation, ensures the integrity of your evidence, and allows for efficient, secure collaboration. Empower your entire team to find the answers they need with E3:View.

E3:View is priced at a monthly price of $39.00/month making it easy and affordable for case review.

Key Features That Simplify Your Workflow:

  • Forensically Sound Review: E3:View is a read-only platform, which means you can share a case file with complete confidence. The original evidence can never be accidentally altered or compromised, maintaining a perfect chain of custody.
  • Universal Data Compatibility: Don’t let different forensic tools slow you down. E3:View can import and analyze data from a wide range of sources, including Paraben’s tools as well as data from other leading tools like Cellebrite and GrayKey.
  • Powerful Analysis in a Simple Interface: Your team doesn’t need to be a forensics expert to find the truth. E3:View provides a user-friendly interface with sophisticated features like:
    • Intelligent Searching: Use full-text indexing, Boolean logic, regular expressions, and even emoji searches to quickly locate critical information.
    • Broad File Type Support: Access over 100 built-in file viewers for documents, images, chat logs, email data, and more, all within a single application.
    • Advanced Data Filtering: Narrow down vast datasets with ease using filters for file systems, hash sets, and more.
  • Flexible Reporting and Exporting: Once key evidence is identified, E3:View makes it easy to share. Export individual files, produce detailed reports in multiple formats (PDF, HTML, CSV), and present findings clearly for court or for internal review.

 

Blocked – Secure – Patented

StrongHold Faraday Bags

Paraben’s Patented StrongHold Faraday Bags

Faraday technology, used in digital forensics, plays a crucial role in preserving the integrity of wireless devices deemed as evidence. By effectively blocking wireless signals, Faraday technology safeguards these devices from any potential tampering or data corruption. Paraben Corporation understands the need for such advanced technology to secure valuable evidence and ensure the accuracy and reliability of digital investigations. Paraben Corporation’s StrongHold bags, featuring a patented (U.S. Patent No. 7,601,921) design, are your ultimate defense against wireless signals from cell towers, wireless networks, and other signal sources that pose a threat to your digital evidence. The Wireless StrongHold Bag employs a special multi-weave material, composed of multiple metals, to deliver optimal blocking protection. Upholding the same principles, Paraben’s other StrongHold products offer multi-layered protection.

Paraben’s Patented StrongHold Faraday Bags

Faraday technology, used in digital forensics, plays a crucial role in preserving the integrity of wireless devices deemed as evidence. By effectively blocking wireless signals, Faraday technology safeguards these devices from any potential tampering or data corruption. Paraben Corporation understands the need for such advanced technology to secure valuable evidence and ensure the accuracy and reliability of digital investigations. Paraben Corporation’s StrongHold bags, featuring a patented (U.S. Patent No. 7,601,921) design, are your ultimate defense against wireless signals from cell towers, wireless networks, and other signal sources that pose a threat to your digital evidence. The Wireless StrongHold Bag employs a special multi-weave material, composed of multiple metals, to deliver optimal blocking protection. Upholding the same principles, Paraben’s other StrongHold products offer multi-layered protection.

What devices can you block signals on?

Any device that can receive a signal can technically be blocked. The StrongHold designs are typically able to block signals in almost any situation, but there are times and circumstances when they may be less effective. Signal blocking can fail if there is a direct connection to a cell tower, such as when a building has a cell tower on top of it. Another factor that can affect the effectiveness of signal blocking is poor shielding closure. To ensure the best protection, it is important to make sure all seals on the Faraday device are closed properly. Additionally, power going to the device from outside the Faraday device can cause it to have an antenna, resulting in the failure of protection. It is also crucial that the device used for shielding is not damaged, with holes in the seams or anywhere else, as this will prevent it from effectively blocking the signal. Moreover, for successful signal blocking, the device must fit 100% within the StrongHold Faraday protection and should not be too close to a tower or the origination of the signal. With our double layers, the blockage can be 97% accurate.

Pricing

Paraben’s StrongHold can be ordered off the shelf based on inventory. Custom orders are available with custom branding, numbering, and more for bulk customers. 

Cyber – DFIR – OSINT

Forensic Grade Imaging

Brand: WiebeTech Forensic UltraDock

Model FUDv6 – WiebeTech Forensic UltraDock write blocker.

Included Items

  • AC adapter & power cord

  • USB Type-C cable

  • USB Type-A to Type-C cable

  • SATA drive attachment cable

  • IDE drive cable

  • Molex MiniFit to legacy power cable

  • Quick Start Guide

Professional Grade Write Blocking

The WiebeTech® Forensic UltraDock™ FUDv6 allows digital forensics investigators, technicians, and lawyers to view and image a data drive without altering its contents. It’s an easy-to-use drive dock that is compatible with forensic acquisition and analysis software and connects via USB-C.

Detect and Remove Hidden Areas

You can detect, remove, or modify Host Protected Areas (HPAs), Device Configuration Overlays (DCOs), and Accessible Max Address Configurations (AMAs) that may be hiding additional data on the suspect drive. The LCD menu makes such actions easy—there are no complicated DIP switches to set.

Effortless Drive Connections

The Forensic UltraDock FUDv6’s drive connector enables automatic alignment and easy insertion. Then attach it to your computer via its orientation-free USB-C connector.

Wide Drive Support Available

The Forensic UltraDock FUDv6 works natively with the most common types of hard drives and SSDs like IDE/PATA and SATA. But if you need to work with a non-standard drive there are a variety of adapters available for additional flexibility.

Additional features:

  • Compatible with forensic acquisition and analysis software

  • Aluminum case for rugged durability

  • 3-year warranty

  • Free US-based customer support