MSAB XAMN Pro – Discover Evidence: Time, Place and Persons

Not everyone who commits a crime plans it carefully. Suspects in most crimes usually have a couple of devices, such as a mobile phone and a tablet, and communicate under an alias using common apps.  

This can make the task of tying a suspect to a crime scene difficult, but it becomes easier when using XAMN Pro, which quickly and efficiently filters suspects’ conversations, images, and videos. And since this type of data has a built-in timestamp, by analyzing it you can better understand when the crime was committed even if the data volumes are large. 

Establishing the provenance of timestamped digital evidence

Given the critical role of timestamps in digital investigations, this blog post seeks to highlight how analyzing these key pieces of information can yield potentially game-changing insights for your case. 

Here are three vital areas for investigators to keep an eye on: 


1. Timestamps must be found


Most artifacts (i.e. pieces of digital evidence) extracted from a mobile device are timestamped with information indicating when the artifact was created, updated, and sometimes, deleted. This includes everything from calls, messages, pictures, and web history to generic files and when a particular app was installed. 

Which timestamps are presented in XAMN Pro for a given artifact depends on multiple factors such as what was originally recorded by the source device, what was possible to retrieve during extraction and the category of the artifact in question. 

Being able to link a piece of digital evidence to a specific point in time can be of great importance to any investigation. 

Here is an example of how to effectively narrow down a search in XAMN Pro based on Time:

Case: You’re working on a grooming case and want to narrow your search to only see messages and calls from the last year.

Solution: An easy way to do this is to use the Timeline view. Simply select the year that is of interest. The “Timeline” filter will now allow you to search the data more effectively. You can filter by year, month, day, hour, minute or even second to identify the periods of greatest activity on a device and build a picture of event sequences.

In this episode of #MSABMonday, take a closer look at the Timeline filter in XAMN Pro, which allows you to swiftly narrow down your artifact search based on specific timeframes. This streamlined approach simplifies sifting through huge amounts data, streamlining data analysis and enhancing investigations. 


3 tips you need to know about “Time” in XAMN Pro:

  • A time-based search will match all time-related properties of artifacts in the case. This means that a single file appearing on a device can show activity in multiple places on the timeline – both when it was created and subsequently (potentially) updated and deleted.
  • Time searches can be saved in Quick Views. If, for instance, your standard procedure is to limit your search to the last 24 months, you can save it into a custom Quick View called ‘Last 2 years”. This allows you to immediately start with this filter without having to do a manual selection.
  • The Time filter is automatically linked to all other filters in XAMN. If you add a time filter selection, you will see how e.g., the artifact Categories section is instantly updated. If a category, say Calls, is grayed out after applying your filter, this means there are no calls from that period.
    Bonus Tip:
    Using the Timeline can be a quick and convenient way to exclude a device from further investigation. If, for instance, multiple devices have been seized, it’s possible that some of them are old and no longer used by the suspect. If, after quickly looking at the timeline, the device shows no activity after 2016, you can likely disregard it (assuming you are investigating a recent crime).

Additionally, make sure to always validate your data. XAMN Pro makes this process easy for you. In this #MASBMonday tutorial, learn how to validate important data, such as times and dates associated with calls or messages, to ensure the reliability of your findings in court. 


2. Cross-referencing data to find the exact location

Determining where the crime has been committed also involves processing large amounts of data. Some digital artifacts extracted from a mobile device have associated Location information. This may include pictures or information extracted from health and fitness apps for example. Of course, being able to link an individual to a physical location based on digital trails in an extracted device can be of great interest and importance to any investigation.

Previously, you were forced to spend hours and sometimes days sorting out vital data to determine the time, place and person. With XAMN Pro, it takes seconds. Once you master the tools, the program will quickly determine the geographic location by cross-referencing data from cell towers, web history, images and, for example, fitness apps.

This is an example of how you can effectively narrow down a search in XAMN based on Location:

Case: You are investigating an individual suspected of preparation to commit armed robbery. You are interested in the general whereabouts of the individual.

Solution: Use “Maps” view. This allows you to analyze location artifacts more easily and effectively. This view presents all artifacts with associated Location data. Artifacts are clustered as groups and break up into individual artifacts as you zoom in. This provides you with both a convenient overview and the ability to zoom in and pinpoint an individual artifact.

3 tips you need to know about “Location” in XAMN Pro:

  • You can combine the new filter views, Maps and the improved Timeline, with any view in XAMN Pro.
  • If you are using offline maps, you can also use the search box to find places by street name, city or name of an area.
  • To get an even more complete view of Locations linked to a particular device and person, XAMN Pro allows you to import call data records from mobile network operators. These often include the location of cell towers to which a device has been connected. If you have access to CDRs (Call Detailed Record) as a part of your investigation it is recommended to import these before you start digging into the data.

Bonus Tip: 

The Areas of Interest filter in XAMN Pro is a powerful feature which allows you to define a specific area that you’re interested in for a more refined analysis. In this episode of #MSABMonday, learn how to leverage this functionality in order to swiftly see the artefacts within your chosen area, streamlining your investigations and saving you valuable time. 

3. Roles of all involved specified

Depending on its scope, there may be many individuals involved in the planning and execution of a crime. Being able to determine who has been in contact with whom and the ability to link digital artifacts to an individual person is of great importance to most investigations. Given the vast amounts of information to process and the added complexity when individuals communicate using either more than one device or using multiple apps, this can be both challenging and time consuming. XAMN Pro has a unique capability to simplify this process; we call it Persons. 

XAMN Pro not only enables you to immediately filter the relevant persons in your case and view the relationships between them, but you can also select specific identities and view their communication. This includes identifiers like names, phone numbers, messenger nicknames, and email addresses and will, for example, show a phone number identified both in a device-native phone call and a WhatsApp voice call. 

You can manually join relevant identities into common Persons. However, this should only be done if you have corroborating evidence e.g. two specific email addresses belong to the same Person. 

3 tips you need to know about “Persons” in XAMN:

  • Persons are always created from identities identified in extracted data.
  • Persons never alter the source extraction data. The Persons directory is maintained in your Case file and can be rebuilt and managed without impacting the source data.
  • A picture is automatically assigned to a Person if supported in source data. You can also assign a picture manually.

Watch this episode of #MSABMonday for a quick walkthrough of the powerful ‘Persons’ feature.  

Final Thoughts 

XAMN Pro unlocks a whole new level of analytics in mobile forensics. It combines efficiency with ease of use and powerful search capabilities making it an excellent choice for digital investigators who need to discover, analyze, package, and share digital evidence and artifacts from a crime scene quickly and securely. 

To get the most out of the tool, sign up for our comprehensive training courses. With the expansive list of analytical capabilities included with XAMN Pro, getting certified ensures you are aware of all the time-saving capabilities within the platform and can make the best use of your valuable time. Our courses will empower you to work with speed and precision in the most powerful digital forensic analytical tool. It will ensure you’re well-prepared to solve cases in a smarter way, organize results and complete powerful reports and visuals to convey the information.   

Learn more about available training opportunities. 

Read more

If you’re not already using XAMN Pro, now is the time to start. If you want to learn more or have any questions, don’t hesitate to get in touch with us.  

Contact us