Professional Documents
Culture Documents
Mobile Forensics
Acquisition Tools
Fapna Co.
Mesbah
Fapna Forensics
Site: www.fapna-co.ir E-mail: info@fapna-co.ir 1
Mobile devices forensics challenge:
Does the mobile forensics tool make any changes to the device phone?
Logical methods
This method collects all important files and evidence such as video,
audio, image, contacts, messages, calls, browser history, and etc.
This method can be used on different mobile phones brands and
manufactures such as apple, Samsung, Xiaomi, Huawei, and etc.
Image Chat Video Android Partial internal Downgrade Full Internal Full File Exynos Decrypt
Capture Capture Capture ADB Rooted
Backup storage apk Storage System Bootloader
Mesbah has offered several methods to collect data and evidence from
mobile phones (base on their brand, version of operating system and
security features).
Site: www.fapna-co.ir E-mail: info@fapna-co.ir 7
Receive screenshots automatically from all messages and chats of
WhatsApp messengers. It provides an html file that includes text
chats, profile photos, contacts, and etc. It has the ability of detecting
unread messages, channels, groups, and some other features.
Site: www.fapna-co.ir E-mail: info@fapna-co.ir 8
This method collects all important files and evidence such as video,
audio, image, contacts, messages, calls, browser history, and etc.
from mobile device phones of different brands and manufactures
such as apple, Samsung, Xiaomi, Huawei, and etc.
File system
This method is used to collect evidence and data from all apple
phones or iPads. It make use of iTunes backup and AFC method.