Evidence review
Which Mobile Forensic Vendors Publish Testable Specifications?
Seven vendors' public pages, read on one day against nine questions an examiner would need answered before a capability claim could be checked. Some answer eight of them. Some answer one.
Cellebrite · Magnet Forensics · Oxygen Forensics · Belkasoft · and 3 more
Evidence review
What CFTT Testing Shows About Mobile Extraction Tools
Fourteen government test reports, read for what they measured — where extraction tools omitted data, where they reported it wrongly, and why the extraction method matters as much as the tool.
Cellebrite · Magnet Forensics · Grayshift · MSAB · and 4 more
Evidence review
The Legal Questions Around Mobile Device Extraction Are Not One Question
Searching the device, defining the search, compelling a passcode, compelling a biometric and reaching cloud data are five different legal questions. Two have Supreme Court answers. Two are split. This is a source review, not legal advice.
Evidence review
Extraction Depth and Device State Are Not the Same Thing
Two independent questions hide inside most extraction capability claims — how much data a method returns, and what condition the device has to be in. Read separately, vendor documentation becomes much easier to interpret.
Oxygen Forensics · Belkasoft · ElcomSoft · Cellebrite · and 1 more
Evidence review
Access, Disclosure and Testimony Around Restricted Mobile Forensic Tools
Buying the tool, reading its documentation, and questioning how it works are three different problems with three different answers. One vendor agreement, two product pages and two appellate opinions, read on one day.
Cellebrite · Magnet Forensics · Belkasoft
Artifact finding
An iPhone Photo Can Tell You More Than Its File Path
A practical iOS finding — the Photos database can preserve application-import context for an image that sits in an ordinary DCIM path.
iOS · Photos · Cellebrite
No finding matches .
Try a shorter fragment, or a broader term — part of a table name, a folder, an application, or a tool. The categories above show what has been written up so far. This library grows one finding at a time, so a term with no result usually means nobody has documented it here yet, not that there is nothing to find.
Independent and educational. DEVI Digital Forensics is an independent educational project created by digital forensic practitioners outside of their official employment. It is not sponsored, reviewed, approved, or endorsed by any contributor's employing agency.
Forensic behavior changes between operating system versions, application versions, extraction methods, and tool versions. Validate every finding against your own data, and do not interpret an artifact in isolation. Read the full statement and methodology.