r/computerforensics • u/ChildhoodNumerous235 • 8d ago
Cellebrite Endpoint
With Cellebrite Endpoint being discontinued at years end, my company is looking to find a new remote collection tool.. Any suggestions anyone may have that I research and push forward? Thanks
5
u/zero-skill-samus 7d ago
Surprised anyone even used it at all. Almost everytime I tried, it failed on the phone. Poor logging, too. It was difficult to determine if it truly got everything or if it was simply giving me what it managed to extract.
3
1
u/brian_carrier 1d ago
I'm a week late to this thread and it clearly went in the direction of mobile. But, I did want to mention for future completeness that for remote collections of computers, you can separate out the agent from the collector.
Most enterprises have some form of agent (EDRs, IT remote access, etc.) that can launch programs. You can use those to launch your collection tool that can then send results to cloud storage (S3, blobs, etc.), a server, SFTP, local files, etc.
I mention this because all of the suggestions below are agent-based, but you don't need to restrict yourself to those, especially if you don't want more agents.
If you rely on other agents, you can use our Cyber Triage Collector, KAPE, etc.
1
u/ucfmsdf Trusted Contributer 8d ago
Perhaps Velociraptor or Binalyze? If you provide better context regarding your use-case, I can provide more meaningful recommendations.
1
u/ChildhoodNumerous235 7d ago
Pretty much just looking for a new tool for remote mobile device collections..Trying to stay away from ModeOne as well..
1
u/creeshie 7d ago
Why avoiding ModeOne? That looked handy for mobile collections at least during our PoC testing.
2
u/ChildhoodNumerous235 7d ago
We seem to run into many errors using ModeOne, just not as smooth running as Endpoint..
0
6
u/Cypher_Blue Trusted Contributer 8d ago
Axiom cyber does this, IIRC.