SIM card acquisition and analysis with TULP2G
TULP2G is a free tool developed by Netherlands Forensic Institute for forensic examination of SIM cards and cellular phones. Unfortunately, this program has not been updated for a long time. However, it can be used for very old cellular phones and SIM cards data acquisition and analysis.
Getting ready
On the TULP2G download page (https://sourceforge.net/projects/tulp2g/files/), select the TULP2G-installer-1.4.0.4.msi
file and download it. At the time of writing this, the most up-to-date version is 1.4.0.4. When the download is finished, double-click on this file. The installation process of the program will be started.
Note
If the installation of the TULP2G program is performed in the Windows XP operating system, you need to install Microsoft Net Framework 2.0 and Windows Installer 3.1 before the installation of the TULP2G. The programs mentioned previously can be downloaded from the Microsoft Corporation website.
How to do it...
- When the program is launched, click on the
Open Profile...
button:
The main window of the TULP2G program
- In the opened window, you will find profiles, one of which has to be loaded in the program. Select the
TULP2G.Profile.SIM-Investigation
profile, and then click onOpen
.
Data extraction profiles of TULP2G
- In the
Case/Investigation Settings
window, fill in the fields:Case Name
,Investigator Name
, andInvestigation Name
. This information will be used later in the preparation of the report by TULP2G.
The Case/Investigation Settings window
- In the next window,
TULP2G - SIM card;
for theCommunication Plug-in
field, set the value asPC/SC chip card communication [1.4.0.3]
. For theProtocol Plug-in
field, set the value asSIM/USIM chip card data extraction [1.4.0.7]
. If the examined SIM card has PIN or PUK code, enter it by clicking on theConfigure
button, which is located next to theProtocol Plug-in
field.
Window TULP2G - SIM card.
Note
Reading data from the examined SIM card will not be possible if the PIN or PUK code are not entered.
- Click on the
Run
button. The process of data extraction from the SIM card will begin. The progress of extraction can be seen in the progress bar.
The progress bar.
- When the data is extracted from the SIM card, you can conduct a new extraction or generate a report about the extraction that has been performed. To generate the report, go to the
Report
tab. In theReport Name
field, enter the name of the report; in theExport Plug-in
andSelected Conversion Plug-in(s)
fields, select plugins that will be used for the report generation. In theSelected Investigation(s)
field, select those extractions for which you want to generate the report, and then click onRun
.
The options window for the report generation
- When the report generation process is finished, there will be two files with formats HTML and XML. The HTML file can be opened with any web browser.
A fragment of the report
These files contain information (a phonebook, text messages, calls, and so on) that was extracted from the examined SIM card. It can be viewed and analyzed.
How it works...
TULP2G extracts data from the SIM card that is installed in the card reader, which is connected to the expert's computer, and generates a report. During the verification process, MD5 and SHA1 hashes of the image and the source are being compared.
See also
- The TULP2G project website: http://tulp2g.sourceforge.net
- The TULP2G download page: https://sourceforge.net/projects/tulp2g/files/