Mobile forensics
Mobile forensics extracts and analyzes evidence from smartphones and tablets: messages, calls, location, apps, photos, and system artifacts. It’s complex due to default encryption, closed systems, and the fast pace of iOS/Android change.
Specific challenges
Section titled “Specific challenges”- default encryption (FBE/FDE): without the passcode/key, data is inaccessible- closed systems: full physical access often requires device exploits- device states: BFU (Before First Unlock) vs AFU (After First Unlock) -> how much can be extracted- cloud: part of the data is in iCloud/Google (with legal authorization)Extraction types (least to most complete)
Section titled “Extraction types (least to most complete)”Manual browse the phone and photograph the screen (last resort)Logical OS backup/API: contacts, SMS, calls, some appsFilesystem FS access (more apps and artifacts), usually needs unlock/exploitPhysical bit-for-bit image (the maximum); increasingly hard due to hardware/encryptionCellebrite UFED / Physical Analyzer the commercial forensic standardMagnet AXIOM cross-platform acquisition and analysisMSAB XRY forensic extractioniLEAPP / ALEAPP (open-source) parse iOS/Android artifactslibimobiledevice / adb logical/backup access (iOS/Android)Key artifacts
Section titled “Key artifacts”iOS SQLite (sms.db, CallHistory, Photos.sqlite), KnowledgeC/biome (usage and location), iTunes/Finder backups, keychain (with access)Android /data/data per app (SQLite, SharedPrefs), logs, partitions, Google activityCommon messaging (WhatsApp/Signal/Telegram DBs), location, history, media with EXIFForensic process
Section titled “Forensic process”1. isolate the device's network (airplane mode / Faraday bag) -> prevent remote wipe2. document state (on/off, locked) and chain of custody (dfir-cadena)3. choose the extraction method by device/state/legal authorization4. parse artifacts (iLEAPP/ALEAPP/AXIOM) and build a timeline (dfir-timeline)Legal aspects
Section titled “Legal aspects”- authorization/warrant essential; data is highly personal (GDPR)- "remote wipe" is a real risk -> isolate from minute one- document methods (some use exploits) to defend evidence integrityBlue Team / DFIR
Section titled “Blue Team / DFIR”- Isolate from the network immediately (Faraday/airplane) to prevent remote wipe or alteration.
- Choose the least intrusive method that achieves the goal; document state and custody.
- Correlate with other sources (cloud, network) and respect the strict legal framework for personal data.
Real-world cases
Section titled “Real-world cases”- Pegasus (NSO): zero-click mobile spyware detected by forensics (Amnesty’s MVT analyzes iOS/Android backups).
- Extraction exploits (iOS chains) used by forensic suites evolve with each version.
- Criminal and corporate DFIR investigations where WhatsApp/location were central evidence.
Testing checklist
Section titled “Testing checklist”- Legal authorization and chain of custody (Chain of custody)
- Isolate from the network (Faraday/airplane) against remote wipe
- Document device state (BFU/AFU, locked)
- Choose extraction (manual/logical/FS/physical) per case
- Parse artifacts (iLEAPP/ALEAPP/AXIOM)
- Analyze messaging, location, media (EXIF), and usage
- Build a timeline (Timeline analysis) and correlate with cloud/network