Digital Forensics

Practical findings from the field.

A searchable notebook of mobile and computer forensic findings — unusual artifacts, native database records, tool behavior, and the workflows that got to the answer. Search a table name, a path, a bundle identifier, or a problem.

No finding matches .

Try a shorter fragment, or a broader term — part of a table name, a folder, an application, or a tool. The categories above show what has been written up so far. This library grows one finding at a time, so a term with no result usually means nobody has documented it here yet, not that there is nothing to find.

Independent and educational. DEVI Digital Forensics is an independent educational project created by digital forensic practitioners outside of their official employment. It is not sponsored, reviewed, approved, or endorsed by any contributor's employing agency.

Forensic behavior changes between operating system versions, application versions, extraction methods, and tool versions. Validate every finding against your own data, and do not interpret an artifact in isolation. Read the full statement and methodology.