SIMIS will extract data from a SIM card in a forensically sound manor and provide that data in a convienient HTML report and exportable text file.
SIMIS is part of the SIM Tools suite. SIMIS2 handles the interrogation of Phase 1, 2 and 2+ GSM SIM Cards, now commonly referred to as 2G.SIMIS 3G provides similar funtionality for USIM (3G cards)
Overview
Information taken from the SIM Card, coupled with information collected from the associated mobile equipment, can provide valuable evidence to validate a line of enquiry, prove an association or provide vital intelligence. In today’s fast moving high-tech society, it is rare to find any activity that does not involve some aspect relating to mobile telephony. If GSM telephony is involved, a trail of information is waiting to be retrieved from the SIM Card.
SIMIS automates the process of forensic SIM data recovery. By interrogating the SIM card, SIMIS provides a detailed report in easily viewable HTML format and user-definable printed format for every SIM interrogated.
Unicode support for SMS & phonebook files with alphanumeric elements allows foreign characters and scripts from any international language to be decoded and displayed.
Forensically Sound
In accordance with ACPO guidelines SIMIS ensures that no data on the SIM is modified during the read process. The resulting reports are digitally signed with both MD5 and SHA hashes to ensure integrity. A full audit trail data is included in the analysis detailing important aspects from the acquisition process such as:
Operator identity
Start / End time and date stamp for each process carried out during the SIM interrogation
MD5 and SHA checksum of acquired data
SIMIS Pedigree
SIMIS (SIM card Interrogation System) was originally commissioned by Metropolitan Police (London) in 1998. The system facilitates the recovery of information from SIM cards and plugs, used in mobile subscriber equipment (mobile telephones).
SIMIS is a development of Crownhill's popular EdSIM SIM card editor application, that has proved to be popular with both Network Operators and major mobile phone resellers. SIMIS draws on the expertise gained by Crownhill in in the development of SIM and USIM by Silcom Technologies and SIMIS is continually evolving and improving to meet the requirements of many of the UK, US and European Police Technical support units.
Features
Forensically safe - no facility for the modification of system or user data held on the SIM card.
Correctly handles PIN and PUK entry under controlled conditions.
Builds a database with unique file references for each SIM Card.
Searchable database with appropriate index categories.
Reads data directly from SIMIS Mobile card reader
Presents data in a printable format for reports.
Provides commented RAW data in a standard format for use in third party applications.
SEARCH Engine
The SIMIS database search engine, allows comprehensive searches to be made across all SIM cards data that have been interrogated. All recovered data is stored in a locally held database. Searches can be carried out across the entire database, or can be narrowed down to things like a specific case reference, or a specific mobile number.
A typical search would allow you to enter a mobile phone number and identify if that number was held in the ADN of any card previously interrogated - potentially opening up new lines of enquiry in investigations, or linking suspected criminals and networks together.
Ten most wanted list, will allow the investigator to identify up to 10 mobile numbers that are of special interest. Regardless of the case reference, each time a crd is interrogated, the 10 most wanted list is referred to alerting the investigator via audible and visual aalrm if a match is found.
Standards Compliant
SIMIS adheres to the technical specifications laid down in the ETSI document GSM11.11 and other related ETSI documents. The present document defines the interface between the Subscriber Identity Module (SIM) and the Mobile Equipment (ME) for use during the network operation phase of GSM as well as those aspects of the internal organization of the SIM which are related to the network operation phase.
In the creation of our SIM Interrogation System, we utilised the information from GSM11.11 and related documents to identify:
Security features
Interface functions
Commands
Contents of the files used in GSM applications
The application protocol
We used this knowledge to identify what data may be present in the SIM card, how raw data should be retrieved from the SIM, and how to correctly interpret and display the raw data.
The Package
The SIMIS package is flexible, with a range of options available to suit your needs. Typically a SIMIS package consists of:
PC based software application
PC/SC Smart Card Reader (USB or Serial)
Mini-Sim Adapter
USB License Key
There is also the option to use a PC Card (PCMCIA) Reader for laptops and notebooks.