Mobile Forensics - The File Format Handbook: Common File Formats and File Systems Used in Mobile Devices
Christian Hummert, Dirk Pawlaszczyk (editors) · Springer · First edition · 2022
Identifier: ISBN 978-3-030-98466-3
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
An open-access reference to the structures underneath mobile evidence, in two parts: mobile file systems (APFS, Ext4, F2FS, QNX6) and the serialisation formats that carry app data (SQLite, property lists, Java serialization, Realm, protocol buffers), each chapter written by a specialist and each noting the forensic value of the structure.
Who it is for, and when
This is the citable source when you have to explain, at structure level, why a record recovered from an SQLite write-ahead log or a freelist page says what you claim it says. The SQLite chapter in particular is the closest thing to an authoritative published treatment. Published open access by Springer under a Creative Commons licence, so the full PDF is free.
What it does not cover
A format and structure reference, not casework: no acquisition, no device-by-device methodology, no tool workflow, and nothing on Windows. The named decoding tools are 2022-vintage even though the structures are not.
Go to the source
Open at link.springer.com (opens in a new tab)https://link.springer.com/book/10.1007/978-3-030-98467-0
Details
- Type
- Book
- Written for
- AdvancedAdvanced
- Author
- Christian Hummert, Dirk Pawlaszczyk (editors)
- Publisher
- Springer
- Version verified
- First edition
- Year
- 2022
- Identifier
- ISBN 978-3-030-98466-3
- Topics
- sqlite, file-systems, mobile, android, ios
- Checked at source
Related entries
A family of open-source Python parsers for mobile and returns data: iLEAPP for iOS logs, events and plists, ALEAPP for Android, and RLEAPP for returns and records from cloud and carrier providers. All three are released very frequently and are among the most actively maintained tools in mobile forensics.
Alexis Brignoni's blog on mobile forensics and open-source tooling, closely tied to the xLEAPP family of parsers — iLEAPP, ALEAPP, RLEAPP and VLEAPP — which he maintains with others.
The Binary Hick
FreeA research blog by Joshua Hickman covering mobile and Apple-platform artifacts, timestamp semantics and the test images he builds and publishes for the community.
A device-by-device walkthrough of mobile acquisition and analysis: iOS and Android internals and file systems, logical and physical extraction, app and SQLite artifacts, cloud extraction, mobile malware and reporting.
Cellebrite's mobile forensics flagship, now branded Inseyets and positioned within the company's broader Case-to-Closure platform. The familiar component names persist inside it rather than having been retired: UFED, Physical Analyzer, Kiosk, CFID, Reader, and C-TEK are all listed as parts of the Inseyets suite.