Uploading UFDR Files
TRULEO accepts Cellebrite UFDR forensic exports through standard file upload in Analyst. Upload the .ufdr file as-is — TRULEO extracts it, adds the supported files to the case, and converts SMS data into a searchable spreadsheet. This is the path for iPhone data extraction and for any extraction your digital forensics unit already ran in Cellebrite. It is separate from TRULEO's Android phone extraction tool.
What a UFDR is
A UFDR (Universal Forensic Extraction Device Report) is Cellebrite's packaged phone data extraction. It is a ZIP archive with a .ufdr extension. TRULEO treats it like a ZIP: it unpacks the archive, then processes the supported files inside.
You do not need Cellebrite Reader open to upload. If cyber crime handed you a flash drive with a .ufdr and a copy of Reader, upload the .ufdr file itself.
Upload a UFDR to a case
- Open Analyst and either click Analyze New Case or open an existing case.
- In the upload dialog, stay on the File Upload tab — do not use Phone Extraction. Phone Extraction is TRULEO's Android desktop tool; UFDRs go through File Upload.
- Drag the
.ufdrfile onto the dropzone, or click Choose files. - For a new case, enter the case or DR number, then click Start Case Evaluation. For an existing case, click Upload Files.
- Wait for the confirmation that extraction is in progress. A UFDR can take several minutes (sometimes longer for multi-gigabyte data extraction).
[SCREENSHOT: Analyst upload dialog on the File Upload tab with a .ufdr file queued]
The original .ufdr is unpacked in the background and then removed from the case. What you see in Files & Evidence are the extracted files, not the archive.
What TRULEO pulls out
After extraction, TRULEO adds supported files from the data extraction to the case — documents, spreadsheets, images, audio, and video in accepted formats.
For a standard Cellebrite layout, TRULEO also looks for the device SMS database (sms.db on iPhone, mmssms.db on Android) and converts it to a messages.csv file you can search, chat over, and include in reports.
Files inside the archive that are larger than 2 GB are skipped. Convert or split those files and upload them on their own if you need them in the case.
See Supported Upload Types for the full list of formats TRULEO keeps after extraction.
Analyze the data extraction
Extraction finishing is not the same as a report. Once the extracted files show as processed in Files & Evidence:
- Select the files you want in the report.
- Choose the Cell Phone Extraction template (under Cell Phone Analysis).
- Click Generate Report.
- Review the draft in TRULEO Reports.
Use TruAssist on the same case to ask follow-up questions — for example, messages with a specific number, or images from a date range.
A Cell Phone Extraction Report generates automatically only when you used TRULEO's Android Phone Extraction tool. A UFDR upload does not auto-generate that report; generate it from the template as above.
[SCREENSHOT: Files & Evidence with extracted UFDR files selected and the Cell Phone Extraction template chosen]
Size and storage limits
- Individual uploads, including a UFDR, can be up to 15 GB.
- Each user has a 50 GB Analyst storage quota. A UFDR that is larger than the storage you have left will fail.
- Files inside the UFDR that exceed 2 GB are skipped during extraction.
- Very large data extraction take longer to upload and extract. Leave the case open or check back later rather than uploading the same file again.
If a data extraction is larger than 15 GB, export a smaller subset from Cellebrite (for example messages and images only) or split the export, then upload those files. Contact support@truleo.co if you are blocked on a case-critical data extraction.
iPhone vs Android
| Source | How to get it into TRULEO |
|---|---|
| Android phone in hand | Use the Phone Extraction tab — see Cell phone extraction |
| iPhone, or any Cellebrite UFDR you already have | Upload the .ufdr on the File Upload tab (this article) |
| ZIP of exported files from another tool | Upload the .zip the same way as a UFDR, if the files inside are supported types |
Magnet .mfdb files are not a supported upload type. If your lab uses Magnet or GrayKey, export or copy the individual supported files (or a ZIP of those files), not the proprietary database.
If upload or extraction fails
- Confirm the file ends in
.ufdror.zipand is not password-protected. - Check that the file is under 15 GB and within your remaining 50 GB storage quota.
- Do not unzip the UFDR on your computer first unless you are uploading specific files from it. Prefer the original
.ufdr. - After a successful upload, give extraction time. Refresh Files & Evidence rather than re-uploading.
- If the file is still pending after an hour, or the upload fails immediately, contact support@truleo.co with the case name, file name, and approximate size.
See Troubleshooting file uploads and processing for general upload failures.
Best practices
- Upload the
.ufdryour forensics unit produced — do not re-extract the phone in TRULEO if you already have a Cellebrite data extraction. - Keep related data extraction in the same case so TruAssist and reports can cross-reference devices.
- Wait until extracted files show as processed before generating a report.
- For iPhone work, this File Upload path is the supported workflow — TRULEO's Phone Extraction tool does not detect iPhones.