Ameba Ownd

アプリで簡単、無料ホームページ作成

fullmatafo1971's Ownd

Ufed cellebrite manual

2022.01.16 00:55




















Cellebrite's complete collection solution examines more types of devices and data to produce meaningful insights quickly. Delve deep to thoroughly review logical file systems and physically extracted data to discover critical evidence. Combine the collection power of CellebriteUFED with the advanced decoding software of Cellebrite Physical Analyzer to get all the digital data you need. Speed up the time to collection and bypass technical hurdles to access data from the widest range of devices.


Perform logical, filesystem and physical extractions, and use exclusive bootloaders, Advanced ADB, EDL and other methods to get the most data out of the devices.


Reassemble device and application data into readable formats with advanced decoding capabilities: SQLite Wizard, Virtual Analyzer, Python scripting and Hex highlighting.


Carve unallocated space to recover hidden or deleted data. Consolidate device data from a variety of sources and formats; get a unified timeline view to determine connections between people, places, and events using search, filter, tag, and maps. For the complete list of phone data types, see the Analyzed Data item in Project tree page See Data files page Chapter 4: Orientation to the workspace 77 4.


Data tabs Data tabs show files of a specific type such as call log, contacts, SMS messages, and so on. See Viewing image files page Working in data tabs Selecting items Select items in the data display area to include them in any report you generate.


By default, all items are selected. Sorting columns Sort each column alphabetically or by time. Re-ordering the columns For your convenience, you can change the order of the columns. Your preference is retained for the duration of the session. Viewing more information For data tabs containing textual information, by default the right pane is open, displaying the selected item's information.


The Export Dialog Window appears. The report is generated, and a message appears asking if you would like to open it in third party software. The file is opened in the default third party software. Text view For text-based data files, view the data as text. Table view for data files For data files, the table shows the following information: Indicates whether to include checked or exclude unchecked the item in the report generated.


Row number. Indicates if the item is bookmarked. Indicates whether the data file was deleted , or has an unknown status gray dot.


Image A thumbnail of the image or an icon of the file type. Image data files only. Name The file name. Path The root path of the data file. Size The size of file. Chapter 4: Orientation to the workspace 83 Metadata Additional metadata of the data file. Created The creation time stamp of the data file. Modified The modification time stamp of the data file. Accessed The last access time stamp of the data file.


Bookmark Note Details of the bookmark. In addition, indicators are displayed to show attachments, indicate video calls, and to show even direction. Table view for analyzed data For analyzed data, table view tabs display a list of all the events of a specific type Call Log, Contacts, SMS messages, and so on that were found during the data analysis process.


Chapter 4: Orientation to the workspace 85 4. Folder view Folder view shows how the items were organized in the device. Selected items are included in generated reports. When you select an item, it is selected in all tabs in the data display area. To locate a folder: 1 In the Search box, enter any string to locate a folder name that matches the entered string.


The icons of matching folders are colored in blue. Chapter 4: Orientation to the workspace 87 4. Database view displays the contents of database files that were found in the extraction.


Database view consists of the following sections: 1 List of the database tables. Select a table in the left column to display its records in the right column. Chapter 4: Orientation to the workspace 89 4. Hex view A Hex view tab appears for each binary item you open from the project tree. When opening, for example, an Image memory disk, a Hex view tab opens alone. When opening a binary item, for example, an image file, the Hex view tab may be accompanied by other tabs.


The information frame displays links pointers to analyzed data items, such as files and folders in the project tree, and search results associated with the pointed data. Hex view toolbar Chapter 4: Orientation to the workspace 91 Save Click to save the entire memory extraction to a local folder.


Copy Selection Copy the currently selected content of the Hex View tab to the clipboard. Find Displays the Find dialog to search for all occurrences of specified information in the displayed Hex display pane. Find Next Displays the Find dialog box with the search parameters used in the latest search.


Add Bookmark Bookmark the currently selected content of the Hex display pane. Go To Redirect the offset to specific address in the content of the Hex display pane. See Working in the Values tab page See Working with bookmarks page The number of highlight results is shown in brackets next to the tab name.


See Working in the Highlights tab page A new search results tab opens for each search query performed. The number of results for each search is shown in brackets next to the tab name. Double click the floating panel header strip to dock it back to the default location at the bottom of the Hex View tab. Double click the floating panel header strip to dock it back to the original location. Chapter 4: Orientation to the workspace 93 4. Working in the Values tab Decode the raw data to a variety of encoding types in real time, and expand them in the Values list.


Some encoding options, such as 16 Bit, have sub-encoding types. Working in the Highlights tab The Highlights tab contains a list of content segments that are highlighted in the displayed Hex data. Each segment represents locations of analyzed data within the Hex.


The Highlights tab enables you to locate particular types of analyzed data in the Hex. Chapter 4: Orientation to the workspace 95 2 In the project tree, click an Analyzed Data folder for example, Contacts. The location of the selected folder is highlighted in the Hex view tab, and the list of chunks that the folder is comprised of is listed in the Highlights tab.


Viewing image files 1 Double-click an image in a data display tab. Chapter 4: Orientation to the workspace 97 A new tab opens containing the image. The tab is divided into two sub-tabs; Image view and File Info. Rotate image clockwise and anti-clockwise. Zoom in and out. You can also adjust the zoom using the slider. Zoom to fit the tab. Hide image controls. For example, the File metadata section includes information such as the Capture Time, which is the date and time a photo was taken.


Playing video or audio files To play the audio or video within UFED Physical Analyzer: 1 In the data table, double-click the media file that you want to play. A new tab opens for the media file. Chapter 5: Locating and analyzing information This section describes how to browse, search, filter, bookmark, and manage the information in your project. Searching for information in a data tab In Table View tabs, search for a particular item within the data table.


The search is performed on all the data entries within the table. The table updates to display only items containing the string you entered. Capture filter time Filter image and video files by capture time. The maximum range is displayed by default, and you can select a specific date and time range. NOTE: The toolbar items are context-sensitive, and only appear when relevant data is displayed. Using the advanced filter Use the advanced filter to filter the list based on a combination of several parameters.


The fields list comprises the columns in the current data tab. The tab displays only items that match the filter. When you place additional filters in the Advanced search, the returned results match all specified criteria. Chapter 5: Locating and analyzing information 8 To close the advanced filter, click Advanced. Searching for information in all open projects Use the All projects search box in the toolbar to search for information in all open projects.


A list of matching results appear under the All Projects search field. The results are sorted by open project. Within each open project, the results are sorted by categories according to type SMS, messages, contacts, files, and so on. The number of matching results found in each type category is also displayed.


The matching string in each item is colored in red. As in the quick results list, the results tab lists the results by type. Browsing the file system UFED Physical Analyzer has the ability to reconstruct and display the device file system in a tree structure. Chapter 5: Locating and analyzing information The number information tabs displayed for the file changes according to the file type.


For example, an unknown file may display only the Hex View and File info tabs, while a jpeg image may display additional Image view and Meta data tabs. The default view is Hex view. For more information on working with Hex view, see Hex view page 89 and Working with Hex data page 4 While the Hex extraction of an image is displayed in the data display area, click a file under the File Systems tree item to highlight the data portion of this file in the Hex data in the data display area.


Timeline view Timeline view is a powerful tool that enables you to analyze data in chronological order, to identify the order of events and make connections between them.


Timeline view has two views; table and graphic. In graphic view, the events are displayed in a graph, enabling you to quickly identify activity spikes that may be of interest.


Events that occur within close proximity are flagged in groups. Accessing conversation view Communication-based data, such as call logs, email, SMS and MMS messages, and so on, can be displayed in a conversation view layout for easier and better tracking over the communication between two or more parties. Chapter 5: Locating and analyzing information A conversation tab opens, displaying related items as a conversation between the sending and receiving parties of the selected item.


Working with watch lists Run a watch list of keywords against your extracted data to identify and highlight important and relevant information. The watch list search can either be activated automatically or run manually on selected decoded data.


Chapter 5: Locating and analyzing information When you run the watch list, only selected data types are checked for matches. A new keyword row appears in the Keywords list. Editing a watch list 1 In the Watch List Editor, select the watch list that you want to edit.


Chapter 5: Locating and analyzing information 5 To edit a keyword, click the relevant keyword in the list, and make the desired changes. Importing a watch list The export and import functions enable you to share watch lists and receive watch lists from your colleagues.


The Watch List Editor appears. The watch list appears in the Watch List Editor. Chapter 5: Locating and analyzing information 3 Browse to the location where you want to save your watch list, and click Select Folder.


The watch list is exported. Deleting a watch list 1 In the Watch List Editor, select the watch list that you want to delete. The watch list is deleted. Running a watch list You can run watch lists on open projects. Chapter 5: Locating and analyzing information 5. Running a watch list on particular projects When you run a watch list from the Watch List Editor, you can select which watch lists to run, and on which projects you want to run them.


A list of open projects appears. NOTE: A tick mark shows that the selected watch list is currently active for the project. When complete, the watch list results appear in the Watch Lists tree item. If the watch list is assigned to only particular information types see Creating a watch list page , only matches to those types appear in the watch list results. Running a watch list on your current project When you run a watch list from the project tree, you can select which watch lists to run on the project that you are currently working in.


If you have more than one project open, the selected watch lists run on the project that you last clicked in in the project tree. A list of watch lists appears. NOTE: A tick mark shows that the watch list is currently active for the project. NOTE: When you click from the toolbar, you can only run the watch list s on the project that you last clicked in in the project tree. See the Analyzed Data item in Project tree page See the Data files item in Project tree page The entity bookmarks you create are managed in the Entity Bookmarks tree item.


Selected entity bookmarks are included in reports that you generate. Creating a new entity bookmark Entity bookmarks can be added to items in Table view.


A new entity bookmark pointing to the selected item is added to the entity bookmarks list of the project. The bookmarked item record is marked with a. The bookmark is deleted. Device Locations 5. These locations are called "harvested" information. The location calculated in this way is considered accurate. When the device Wi-Fi is turned on, the device periodically sends the harvested locations to Apple iPhone devices or Google Android devices.


The harvested information is then deleted from the device. When the device Wi-Fi is turned off, or there is no Wi-Fi connection available, the device harvests and stores the locations of the cell towers and Wi-Fi networks, and then sends the information when the Wi-Fi is turned on, or connection is available. This information is saved on the device and is called "non-harvested" information. How confident the service provider is that the phone indeed lies in the calculated location.


The categories displayed in this item are divided by application. The categories displayed in this item are divided by application and source. After activation the following screen is presented: If activation is not done at startup, Bing maps can be activated later via the help menu. Users can browse and search topographically-shaded street maps for many cities worldwide.


Two primary types of street map views are available to users: Road View, Aerial View Road View Road view is the default map view and displays vector imagery of roads, buildings, and geography. Aerial View Aerial view overlays satellite imagery onto the map and highlights roads and major landmarks for easy identification amongst the satellite images.


Markers and information windows Markers signify the location where a person's device registered. The color of the marker signifies which person was registered at a particular location. At a low zoom level, markers show the approximate location, and may include the data of more than one person. The following markers are examples of the types of markers that are displayed in the map: At low zoom level, this marker displays a number of recorded locations in a particular area.


The marker may include the data of more than one person, as shown by more than one color in the marker. Zoom in to split the marker. Markers that do not split at high zoom indicate one location. Chapter 5: Locating and analyzing information At low zoom level, this marker displays a number of recorded locations in a particular area. Indicates the location of the cell tower that registered the person's device. Indicates the location of the WiFi network receptor that registered the person's device.


Indicates the recorded location or a media object. Indicates the location of an unidentified entity that registered the person's device.


Retrieving addresses You can view street address for longitude and latitude positions extracted from a device. This can then be used to filter the locations. You can select single or multiple locations up to a maximum of You can retrieve street addresses in the following views: Project search, Timeline views and Watch List results.


To retrieve an address: 1 In the Locations or Device locations table view, select a row and right-click and select Retrieve address, or click. The address is displayed in red in a column called Map Address. Chapter 6: Working with project analytics Project Analytics enables you to view the extraction data in terms of the number of communication events between the device and other parties, identified by phone number, or other user identity such as email address, Skype handle, and so on.


The analysis enables you to easily and efficiently identify communication patterns between the device and other parties. Communication events are listed by volume per type. Project analytics runs automatically when you open an extraction file. To view project analytics: 1 Click next to the Project Analytics tree item to view the analytics results displayed in the Project Analytics tree item.


Chapter 6: Working with project analytics The view is sorted in descending order, based on the total number of events. NOTE: Project analysis information can be included in a report. For more information, see Generating a report. If this is the first time you are using the malware scanner, or if you want to update the database before you scan, follow the steps in Updating the signature database online page If you are working on a computer without an internet connection, follow the steps in Updating the signature database from file offline page The results are displayed under the Malware Scanner tree item.


Image curving 4 The data shown includes the malware type and malware information, such as the name. Updating the signature database online Update the signature database before the first time you use the malware scanner in order to populate the database, and thereafter in order to keep the signature database up to date.


NOTE: Once the signature database is populated, you can run the malware scanner using the existing database. It is strongly recommended that you update the signature database on a regular basis in order to keep it current.


Chapter 7: Scanning for malware 2 Click Update from server. The database is populated. You can now scan the project for malware.


Updating the signature database from file offline Update the signature database from file when you are working on a computer that does not have an internet connection. NOTE: To streamline your workflow and save time, it is recommended that you always use the same computer to download the definitions.


When you download the definitions. Make sure that you do not delete the definitions. Chapter 7: Scanning for malware 10 Click Update from file. Chapter 7: Scanning for malware The database is populated. This folder can be used for all reporting as each report will occupy a separate sub-folder.


The default is the current date and time. Chapter 8: Generating a report - report wizard 5 In the Project select the project or projects you want to include in this report.


More than one format can be chosen and a report for each format will be generated. See Setting the case information page See Additional report fields page and Report defaults page for other defaults. Additionally, the last 10 values entered in these fields are also available in the drop down. This selection is for the whole report and applies to all projects within the report.


TIP: To shorten the report generation process of large projects do not select these options. Select the relevant Analytics item s to include them in the report. By default, a categorized report in which each category in the data items group is generated as a separate section in the report is generated. For example, when generating a report with SMS, select the check box to generate the SMS messages as a single list, or clear the check box to break it to a separate list for each category of SMS messages Inbox, Outbox, Drafts, etc.


When not selected, logs only the state of deleted items as Yes, and is left empty for other states. Ensure that each section of the report starts on a new page. NOTE: Finish is unavailable until all the required fields are filled. A yellow warning icon is displayed next to all required fields that are not yet complete.


When the report is successfully generated, you are prompted to open the generated report file. The file opens using the associated application to the file format installed in the workstation. Once a report has been generated for the project, it can be accessed from the Reports section in the project tree. Double click on any of the generated reports to open it in the associated application installed in the workstation.


Right click any of the generated reports to open the report file, or select Open containing folder to browse the files and folders of the report. In addition, an internet connection is required the first time you run iOS Device Extraction in order to download the necessary support package.


Alternatively, the support package can be downloaded using a different computer and copied manually to the computer running iOS Device Extraction. Performing physical extraction Perform physical and file system extractions from the following devices running iOS version 3. The support package contains the latest utilities that enable iOS Device Extraction to work with a variety of devices and iOS versions.


Depending on your internet connection, the download may take some time. Chapter 9: Performing extractions 4 Follow the displayed instructions to activate the iOS device in Recovery Mode. After a device in Recovery Mode is detected, iOS Device Extraction displays some device information, such as serial number, hardware version, iOS version and more.


NOTE: When a range of versions are displayed, the version of the device may be any version within the displayed range. For example, if the version shows 4. NOTE: This step requires precise timing. If the device accidentally turns on, disconnect it from the cable, turn it off, then go back to step 4. Chapter 9: Performing extractions When the device is in DFU mode, a forensics program required for the extraction automatically uploads to the device.


The device is now ready for extraction. Chapter 9: Performing extractions Choose the location to which to save the extracted data. You can save it locally on the computer or to any removable storage device. NOTE: If the device is locked with a passcode, see Performing physical extraction from encrypted devices page The duration varies depending on the extraction method, the device model, the amount of data on the device, the extracting computer, and other parameters.


Performing physical extraction from encrypted devices iOS Device Extraction can extract data from encrypted devices. The amount of data that can be extracted depends on the type of passcode the device is locked with. Most data, such as contacts, messages, photos, some emails, and more, can be decrypted without knowing the passcode.


However, to decrypt some of the saved passwords and emails, you need to know the device passcode. If the device is locked with a simple passcode, iOS Device Extraction automatically recovers the passcode for you.


If the device is locked with a complex passcode, you can manually try as many passcodes as you like, or continue the extraction without being able to decrypt some of the saved passwords and emails. If the device isn't locked with a passcode, all data is extractable even if the device is encrypted.


Extracting data from a device with a simple password 1 Perform steps of Performing physical extraction from non-encrypted iOS devices page When the device is ready for extraction step 8 , an additional Passcode Recovery option is added to the two extraction options Physical Extraction and File System Extraction.


The Passcode recovery option provides the device passcode so you can unlock and use the device. Chapter 9: Performing extractions 6 If you know the passcode, enter it in the text box field below.


A check mark verifies if the correct passcode was entered. The extraction process starts. Extracting data from a device with a complex password 1 Perform steps of Performing physical extraction from non-encrypted iOS devices page Use the Test Passcodes option to test and verify as many passcodes as you like in real time.


Most data is decrypted in UFED Physical Analyzer, but some of the saved passwords and email files are not decrypted unless the complex passcode is known. The following steps demonstrate a physical extraction starting at step 8 of Performing the Data Extraction , but they are the same for a file system extraction. A check mark appears when you enter the correct passcode.


The extraction process begins. If the iOS device is locked the Locked Device screen is displayed. If the. If the device is locked and no.


Call logs are not extracted. Extended extraction time. This decoding process may require entering the iTunes backup password. In addition the application indicates a specific recommended method per iTunes backup configuration and jailbroken status.


Ensure that there is enough disk space on your chosen location. You can save it locally on the computer or to any removable storage device or to a network location. Wait for the extraction process to complete. Chapter 9: Performing extractions NOTE: The duration varies depending on the extraction method, the device model, the amount of data on the device, the extracting computer, and other parameters.


TAR file. Open the advanced logical extraction in UFED Physical Analyzer to access all extracted information, including any deleted information.


Chapter 9: Performing extractions 3 Select the device. Chapter 9: Performing extractions The extraction begins. When finished, the following message appears: 7 Click Yes to open the extraction.


Chapter Advanced features Working with TomTom TomTom generate trip log files that are encrypted by the device only if TomTom users select to share their location information with TomTom. TomTom registers the device location in the trip log files. For more information on extracting data from a TomTom device, see Reading data from a GPS or mass storage device page NOTE: The processing service can take up to a few days, depending on the volume of data and requests.


The service is currently free of charge, but this may be subject to change. NOTE: The file does not contain personal user information such as locations.


Your request enters a queue at Cellebrite support. Processing of the TomTom extraction file may take a few days. The Locations tree item is populated. The tab shows the device's location at every three seconds with a time and date stamp and geographical coordinates. Carving images Perform image carving to retrieve jpeg image files or fragments that are incomplete or corrupt, signifying that they have been deleted by the user.


Image carving retrieves the images and rebuilds them as much as possible. NOTE: Image carving is only available for physical extractions. Image carving is can take some time to process. NOTE: When you click in the toolbar, the scan applies to the active project, that is, the project that you last clicked in.


A full scan takes longer than a quick scan, and potentially finds more images. The scan begins. Working with carved images Open data display tabs for all the carved images, for individual carved images, and extract the images to your computer. For more information on working with images, see Viewing image files page Verifying hash values A hash value is a unique and compact representation of a piece of data, which can be used for integrity protection due to the fact that it is computationally improbable to find two distinct inputs that hash to the same value.


Comparing a reference hash value that was generated during the extraction process for each binary extraction against their calculated hash values enables you to verify the integrity of the binary extractions you received. The hash information is calculated or verified. If no reference data is available, a Hashes have been calculated for this project, but no reference data is available message is displayed in the Image Hash Information section of the Extracted Summary tab.


Chapter Advanced features The Image Hash Details dialog displays the comparison result of the reference and calculated hash values of each image. For more information on the Image tab, see Hex view page The find options can be enhanced and extended by adding new search plug-ins.


Searching strings Search for strings to locate different types of data in the Hex data, e. The colors you set here are retained for the duration of this session. To change the default colors, set the colors in the Setting window. For more information, see Hex viewer settings page Tip: To easily distinguish between the given results of each search performed, set different text and background colors for each search you run.


This can help you locate specific results, or even limit the results to specific entities of the searched value. For Show before, the Length cannot be longer than the Offset. The additional data is logged to the Additional before and Additional after fields of search results.


If you did not select Find All Instances in the Options area, the next found instance is highlighted in the Hex View tab. Chapter Working with hex data Searching bytes Search for bytes to look for specific occurrences in the Hex data.


This is especially useful when you know the identifying header of a file type or information you are looking for. Therefore, the result of searching for FF D8 FF provides the locations of all possible jpeg image headers in the Hex data. The Search parameters area appears. If you selected Find All Instances in the Options area, the results appear in the Search results tab in the analysis information tab in the Hex view tab.


Searching dates Search for dates to find date ranges in the Hex data. Chapter Working with hex data NOTE: What plug-ins are suitable depend on how the data is encoded, what type of device you are analyzing, and so on. If you select a plug-in that is not suitable, your search results may contain false results. For example, you can select BlackBerry if you are analyzing a BlackBerry device.


If you are not analyzing a BlackBerry device, selecting BlackBerry may return results that are inaccurate. Tip: Set a short date range in order to reduce the number of given results. Tip: When searching for a particular date, set the Min Date and Max Date fields to a range of not less than 24 hours. Chapter Working with hex data f Select Show after to show the data immediately after what you are searching for, and repeat steps NOTE: Use this option when the data has been encoded to include reversed nibbles.


Chapter Working with hex data The colors you set here are retained for the duration of this session. Searching for regular expressions GREP Search for regular expressions to RegEx in order to look for a specific string structure within the data.


Chapter Working with hex data 5 Click to clear the regular expression field. Chapter Working with hex data 3 In the Text Options area, set the following search parameters: a Set the search type: Letters only, Numbers only, or Both.


Chapter Working with hex data Tip: To easily distinguish between the given results of each search performed, set different text and background colors for each search you run. Searching for patterns When navigating within a large memory structure, the search for patterns to locate any content that is textual in nature.


Chapter Working with hex data d To show low match results, select Show low match results. This option enables you to filter the results according to the searched patterns. To minimize the number of false positive results set the Minimal Length value to a higher number. Searching for codes and passwords Search large memory structures for user codes and passwords.


Chapter Working with hex data a Select Show before to show the data immediately before what you are searching for. Using an offset to jump to a different location in the file Scan the Hex data by setting an offset value by which to jump through the data. To move from a set position: 1 Click.


The cursor moves to the offset location. To move from the current location: 1 Click on a specific location in the Hex data. Working with bookmarks A bookmark is a quick reference pointer you can create on Hex data. The bookmarks you create are managed in the Bookmarks tree item.


The number of bookmarks in the project is shown in brackets next to the Bookmarks tree item. Chapter Working with hex data The Add Bookmark dialog box is displayed. The new bookmark is saved and displayed in the Hex view Bookmarks tab. The marked segment is highlighted in the chosen colors. Details about the bookmark appear in the results window. Editing a bookmark 1 In the Hex view Bookmarks tab, click. The Add Bookmark dialog box is displayed. Decoding raw data Select segments of the Hex data and decode them to a variety of encoding types on the fly.


To decode segments of Hex data: 1 In the Hex View tab, select the segment of data that you want to decode.


The results in the Values tab change to reflect the selected segment. Viewing the hex data information Display the information of bookmarked segments and search results when you point to them in the Hex View tab.


Chapter Working with hex data 1 In the Hex View tab toolbar, click. The floating information frame appears. The data is copied to the clipboard. The information frame remains open and displays the information for the last segment that you point to. The information displayed in the frame is automatically updated when you point to a different bookmarked segment or search result.


Locating specific data types in the Hex The Highlights tab presents analyzed data locations within the Hex data, enabling you find the exact location s of a particular type of analyzed data in the Hex data.


The selected folder is highlighted in the Hex View tab; the Highlights tab lists the chunks in the selected folder. Chapter Advanced decoding Managing chains A chain is a set of plug-ins grouped together, which is used to process the extracted data of a device. Each device in the supported devices list of the application has a predefined parsing chain assigned to it. As part of its building blocks, a chain can also include other predefined chains. The Chains list on the left enables you to filter the displayed chains list.


Chapter Advanced decoding 3 Click All Chains to display a list of all the predefined chains. The chains window of the device displays at least one chain that was assigned to it. The new chain is added to your My Chains list. Editing an existing chain 1 Edit chains that you have created. Chapter Advanced decoding 6 To edit the parameters of a plug-in or chain, select it from the chain components list on the left and set the options displayed.


NOTE: Changes made to factory predefined locked chains can only be saved as a new chain Managing device chains Attaching devices to a chain You can attach devices to chains you have created, or modify device chains and save them as a copy. Chapter Advanced decoding 5 Click Select. Setting the default device chain 1 In the Chain Manager window, use the Devices list to locate the device you wish to modify.


Detaching devices from a chain 1 Double click on the chain from which you wish to detach a device. Removing a chain You can remove chains from the My Chains list only.