0% found this document useful (0 votes)
26 views20 pages

Essential Android Forensic Tools Guide

The document presents various Android tools useful for mobile device forensics, including All-In-One, Android Tools, Autopsy, BitPim, and Cellebrite. Each tool has unique functionalities, such as ADB command execution, mobile image analysis, and data recovery capabilities. Additionally, Dr. Fone is highlighted for its data transfer and recovery features, making it valuable for forensic investigations.

Uploaded by

whittykrish19
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
26 views20 pages

Essential Android Forensic Tools Guide

The document presents various Android tools useful for mobile device forensics, including All-In-One, Android Tools, Autopsy, BitPim, and Cellebrite. Each tool has unique functionalities, such as ADB command execution, mobile image analysis, and data recovery capabilities. Additionally, Dr. Fone is highlighted for its data transfer and recovery features, making it valuable for forensic investigations.

Uploaded by

whittykrish19
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Android ONLY TOOLS

Presented by
[Link]
Assistant Professor
Department of Computer Science & Engineering
SETHU INSTITUTE OF TECHNOLOGY
Reference Book: Chuck Easttom, “An In-depth Guide to Mobile Device Forensics”, First
Edition, CRC Press, 2022.

Department of CSE, SIT 3/8/2020


TOOL ALL-IN-ONE
This tool will prompt you for a donation, but you can
use it for free.
It can be downloaded from [Link]
a=show&w=files&flid=38683.
This is essentially a nice GUI for ADB. It does all the
things ADB does, but without requiring you to
remember all the ADB commands.
If it cannot recognize your phone, you can simply
choose “generic device.”

Department of CSE, SIT


Department of CSE, SIT
TOOL ALL-IN-ONE
This is not designed just for forensics. In fact, there are items you
probably would never use in a forensic exam such as “Install
Drivers,” “APK Installer,” or “Erase All Data.”
If you choose the Bootloader unlock, the tool will tell you that
this is a fastboot command and ask if you wish to reboot the
phone in fastboot mode.
The process of unlocking the bootloader is just as difficult and
may not work, but this does give you an easy to-follow GUI to
perform the task in.
This tool is primarily helpful if you are trying to reboot into some
specific mode such as fastboot.

Department of CSE, SIT


ANDROID TOOLS
This is far more versatile than All-In-One and is a free
download from https
://[Link]/projects/android-tools/.
ADB commands simply at the touch of the button. You
can also launch a shell console to perform your own Linux
commands if you need to.
So, you have all the benefits of a GUI, and still can use the
Linux shell. There is a tab for fastboot commands that can
allow you to attempt to unlock or root the phone.
The advanced tab is very interesting. Among other things it
allows you to work with various ADB backup files. This can
be quite useful.

Department of CSE, SIT


Department of CSE, SIT
AUTOPSY
The most well-known open-source forensics software is
Autopsy. This tool is designed for PC forensics but can
analyze mobile phone images.
You can download Autopsy for free from
[Link] Android won’t extract from your
phone, but if you have an image from an Android phone you
can examine it with Autopsy.
Autopsy can extract quite a bit of information. As you can
see the call logs, contacts, messages, GPS track points and
more is retrieved.

Department of CSE, SIT


Department of CSE, SIT
Department of CSE, SIT
BITPIM
This is an open-source tool you can freely download from
[Link]
However, it is limited in the phones it can recognize. This tool
does come with a very useful help file that is easy to navigate.
Most of the functionality is obtained by using the diagnostics
mode available in Qualcomm Mobile Station Modem (MSM)
used by virtually every manufacturer of CDMA phones.
The diagnostics mode provides direct access to the embedded
filesystem in the phone.
The remainder of the functionality is via protocols provided by
the handset manufacturers, but these usually only cover updating
the phonebook.

Department of CSE, SIT


Department of CSE, SIT
Department of CSE, SIT
Forensic Procedures
• Supporting materials, such as printouts of particular
items of evidence, digital copies of evidence, and chain of
custody documentation.
Details of findings:
• Specific files related to the request.
• Other files, including deleted files, that support the
findings.
• String searches, keyword searches, and text string
searches.
• Internet-related evidence, such as website traffic
analysis, chat logs, cache files, email, and news group
activity.
Department of CSE, SIT
DUAL USE TOOLS - CELLEBRITE
Cellebrite is a digital intelligence company that offers tools for
collecting, analyzing, and managing digital data. Their tools
are used by law enforcement, businesses, and service providers
Cellebrite tools
Cellebrite Physical Analyzer: Helps uncover digital evidence,
trace events, and examine data
Cellebrite UFED: A flagship product series that helps collect
digital data
Cellebrite Responder: Helps streamline device and system
management
Cellebrite Commander: Helps remotely distribute and install
software updates and configuration modifications

Department of CSE, SIT


DUAL USE TOOLS - CELLEBRITE

How Cellebrite works

Cellebrite can collect content that phones collect without


user action, such as GPS locations, web history, and email
headers

Deleted data may be recoverable, depending on the level


of extraction and the encryption type on the devic

Department of CSE, SIT


Department of CSE, SIT
DUAL USE TOOLS - DR. FONE
Dr. Fone is a widely used tool for mobile device recovery and
transferring of data. This makes it particularly interesting for
forensics. This tool is very inexpensive and works with both
iPhone and Android.
The tool can be found at [Link]
The full version is $139.95.
The information tab will allow you to view SMS messages and
phone numbers.
These are often critical to a digital forensic investigation.
Most important will be the ability to copy data from the phone to
your forensics workstation.
There is the backup option and the transfer option

Department of CSE, SIT


Department of CSE, SIT
Department of CSE, SIT 6/8/2020
3/8/2020
Department of CSE, SIT 6/8/2020
3/8/2020

You might also like