E-Detective Decoding Centre (EDDC)Offline Decoding & Reconstruction Solution
Decision Groupwww.edecision4u.com
2
EDDC Application Diagram (1)
EDDC Application Diagram (2)
Offline Raw Data Decoding and Reconstruction system.Comes with User and Case Management functions.
Investigator 1Case 1
Investigator 2Case 2
Case 1 Results
Case 2 Results
Collect,Import
Raw Data For Case 1 Case 1
Case 2Collect,Import
Raw Data For Case 2
Reconstruct various Internet Protocols
EDDC Home Page Dashboard Reports
Top-Down View Report
IM/Chat(Yahoo,
MSN, ICQ,QQ, IRC,
Google TalkEtc.)
EmailWebmail
HTTP(Link, Content,Reconstruct,
UploadDownload)
File TransferFTP, P2POthers
Online GamesTelnet etc.
Internet Protocols Supported
Support more than 140 protocols
Sample Reconstruction: Email (POP3)
Sample Reconstruction: Email (SMTP)
Company Logo
Sample Reconstruction: Webmail (Read)
Supports various Webmail Type such as Yahoo Mail, Gmail,
Hotmail etc.
Sample Reconstruction: Webmail (Sent)
Sample Reconstruction: IM – MSN
Sample Reconstruction: IM - YAHOO
Sample Reconstruction: IM - QQ
QQ messages are encrypted. QQ cracking tool is provided.
Sample Reconstruction: File Transfer (FTP)
Sample : File Transfer (P2P File Sharing Log)
Bittorent, eMule/eDonkey, FastTrack, Gnutella
Sample : HTTP Web Link Content Reconstruct
Company Logo
Sample : HTTP (Download/Upload)
Sample: HTTP Video Streaming (FLV)
Youtube, Google Video, Metacafe etc.
Sample: Telnet (with play back)
Sample: VoIP Reconstruction (Playback)
Codecs:G.711a-lawG.711µ-law
G.729ILBC
Sample: HTTPS/SSL Decryption
SSL Private Key must be known
EDDC User Management
Admin create multiple users that can have
access to authority to use this system.
EDDC Case Management
User can create own case based on their
authority assigned by Administrator.
Import Analysis (Manual Import Raw Data)
User import raw data files to be parsed and analyzed (reconstructed)
Reconstructed Data Export/Backup
Sniffer Mode (Raw Data Retention)
System can be connected to the network. Raw data can be captured and reserved through mirror mode. Only when administrator require to see the content of traffic at specific period (date-time), these raw data files can be
imported, parsed and analyzed.
References – Implementation Sites and Customers
Criminal Investigation Bureau The Bureau of Investigation Ministry of Justice National Security Agency (Bureau) in various countries Intelligence Agency in various countries Ministry of Defense in various countries Counter/Anti Terrorism Department National Police, Royal Police in various countries Government Ministries in various countries Federal Investigation Bureau in various countries Telco/Internet Service Provider in various countries Banking and Finance organizations in various countries Others
Notes: Due to confidentiality of this information, the exact name and countries of the various organizations cannot be revealed.
Decision Groupwww.edecision4u.com