Skip to content

Mobile forensics

Mobile forensics extracts and analyzes evidence from smartphones and tablets: messages, calls, location, apps, photos, and system artifacts. It’s complex due to default encryption, closed systems, and the fast pace of iOS/Android change.

- default encryption (FBE/FDE): without the passcode/key, data is inaccessible
- closed systems: full physical access often requires device exploits
- device states: BFU (Before First Unlock) vs AFU (After First Unlock) -> how much can be extracted
- cloud: part of the data is in iCloud/Google (with legal authorization)
Manual browse the phone and photograph the screen (last resort)
Logical OS backup/API: contacts, SMS, calls, some apps
Filesystem FS access (more apps and artifacts), usually needs unlock/exploit
Physical bit-for-bit image (the maximum); increasingly hard due to hardware/encryption
Cellebrite UFED / Physical Analyzer the commercial forensic standard
Magnet AXIOM cross-platform acquisition and analysis
MSAB XRY forensic extraction
iLEAPP / ALEAPP (open-source) parse iOS/Android artifacts
libimobiledevice / adb logical/backup access (iOS/Android)
iOS SQLite (sms.db, CallHistory, Photos.sqlite), KnowledgeC/biome (usage and location),
iTunes/Finder backups, keychain (with access)
Android /data/data per app (SQLite, SharedPrefs), logs, partitions, Google activity
Common messaging (WhatsApp/Signal/Telegram DBs), location, history, media with EXIF
1. isolate the device's network (airplane mode / Faraday bag) -> prevent remote wipe
2. document state (on/off, locked) and chain of custody (dfir-cadena)
3. choose the extraction method by device/state/legal authorization
4. parse artifacts (iLEAPP/ALEAPP/AXIOM) and build a timeline (dfir-timeline)
- authorization/warrant essential; data is highly personal (GDPR)
- "remote wipe" is a real risk -> isolate from minute one
- document methods (some use exploits) to defend evidence integrity
  • Isolate from the network immediately (Faraday/airplane) to prevent remote wipe or alteration.
  • Choose the least intrusive method that achieves the goal; document state and custody.
  • Correlate with other sources (cloud, network) and respect the strict legal framework for personal data.
  • Pegasus (NSO): zero-click mobile spyware detected by forensics (Amnesty’s MVT analyzes iOS/Android backups).
  • Extraction exploits (iOS chains) used by forensic suites evolve with each version.
  • Criminal and corporate DFIR investigations where WhatsApp/location were central evidence.
  • Legal authorization and chain of custody (Chain of custody)
  • Isolate from the network (Faraday/airplane) against remote wipe
  • Document device state (BFU/AFU, locked)
  • Choose extraction (manual/logical/FS/physical) per case
  • Parse artifacts (iLEAPP/ALEAPP/AXIOM)
  • Analyze messaging, location, media (EXIF), and usage
  • Build a timeline (Timeline analysis) and correlate with cloud/network