Our website may use cookies to improve and personalize your experience and to display advertisements (if any). Our website may also include cookies from third parties like Google Adsense or Google Analytics. By using the website, you consent to the use of cookies. We’ve updated our Privacy Policy. Please click on the button to check our Privacy Policy.

AboutDFIR.com – The Definitive Compendium Project
Digital Forensics & Incident Response

Android

Android Artifacts

Artifact or ProcessResource
7bit PDU7bit PDU (GSM-7)
AndroidAndroid version without the build.props file
AndroidIdentifying the Android Operating System Version thru UsageStats
AndroidCorroboration. That Is All.
Android - BluetoothHow Android Bluetooth Connections Can Determine If The Hands of a Driver Were On The Wheel During An Accident
Android - BluetoothTurbo Strikes Again - Tracking Bluetooth Device Battery
Android - BluetoothAndroid Bluetooth Connection Configuration
Android - cast.db An Android Casting (Device) Story: "cast.db"
Android - Deleted Samsung AppsAndroid - Samsung Traces of Deleted Apps
Android - Device Health Services Turbo Pt. 3 - Device Health Services Application Usage
Android - Device MigrationAndroid - Tracking Device Migration
Android - Device Personalization ServicesWalking the Android (time)line Part 2 – Using Android’s Device Personalization Services to timeline user activity
Android - Digital WellbeingHow to Find User Activity Using the Digital Wellbeing Native App
Android - Digital WellbeingWalking the Android (time)line. Using Android’s Digital Wellbeing to timeline Android activity.
Android - external.dbAndroid’s external.db – Everything Old Is New Again
Android - Factory ResetsWipeout! Detecting Android Factory Resets
Android - Gallery ImgcacheA Timestamp Seeking Monkey Dives Into Android Gallery Imgcache
Android - Mobile TelephonyGeodata & Mobile Telephony Artifacts in 3rd-Party Android Apps: Recreating User Travel Patterns
Android - Nearby ShareNearby Share – AirDrop for Android (Return of the Unsolicited Richard Photograph)
Android - Now Playing HistoryGoogle Pixel Now Playing History
Android - PermissionsAndroid - Roles and Permissions (Android 10/11)
Android - PermissionsAndroid’s “Dangerous” Permissions
Android - Recent TasksAndroid Recent Tasks XML Parser
Android - Samsung Predictive TextAndroid - Predictive text exclusions in Samsung devices
Android - Turbo.db Charging Battery with Turbo DB
Android - Unsupported ArtifactsMobile Forensics: Discovering the Undiscovered
Android - Usagestats XMLAndroid Usagestats XML Parser
Android - Video ThumbnailsVideo Thumbnails ".lvl" Found on Android Devices
Android 10 - UsagestatsUsagestats on Android 10 (Q)
ARTEMISARTEMIS - Android support for APOLLO
BadooFinding Badoo chats in Android using SQL queries and the MAGNET App Simulator
Calculator Photo VaultApp Review of Calculator Photo Vault
CamScannerDeep Dive into CamScanner — Android
CCleanerQuick DFIR review - CCleaner for Android
DiscordDiscord Android App Review - DFIR
DiscordDiscord Forensics
DJI Fly Android - DJI Fly & The Pesky Problem of Preferences
Files By Google Files By Google: More Mobile Explorer Artifacts
Firefox FocusLocal Storage - Firefox Focus Privacy Browser Artifacts in Android
Flud Torrent DownloaderTorrent Applications in Android - Flud Torrent Downloader
GarminThe State of Android Health Data (Part 1) – Garmin
Google AssistantGoogle Assistant Butt Dials (aka Accidental & Canceled Invocations)
Google AssistantGoogle Search & Personal Assistant data on Android
Google Call Screen May I Ask Who's Calling - Google Call Screen
Google Docs Google Docs - Cello & DocList DBs
Google Duo Google Duo - Android & iOS Forensic Analysis
Google KeepGoogle Keep - Notes and Lists: Mobile Artifacts
Google Photos Dumpster Diving in Google Photos Android App: "local_trash.db"
Google Tasks Google Tasks - Android Forensics analysis
HealthMate App HealthMate on Android Part 1 - Users, Messages, Devices
HealthMate App HealthMate on Android Part 2 - Activities
HealthMate App HealthMate on Android Part 3 - Heart Rate, GPS, Steps
Huawei - ExtractionPractical Guide to Huawei Device Extraction in UFED
LA FitnessQuick DFIR review - LA Fitness Android app
Launcher.dbRecreate Android apps, folders, and widget screen positions from a forensic extraction
LG - MPTMPT – LG’s incognito version of KnowledgeC
Microsoft RDPAndroid Remote Desktop Apps - Microsoft RDP
Microsoft TranslatorMicrosoft Translator - Android DFIR App Review
Nanbox MessengerApp Nandbox Messenger on Android
Nike RunAndroid Nike Run app - Geolocation, SQLite views & self joins
PrivateSpaceNot so private: extracting data from PrivateSpace
ProtobufsParsing unknown protobufs with python
ProtonMailProtonMail
Qualcomm - EDL ModeMastering EDL Mode
Qualcomm - EDL ModeIt’s as easy as EDL
Qualcomm - EDL Test PointsMastering EDL Test Points
QuickPicQuickPic for Android - Don't forget external/emulated storage!
Samsung My FilesAndroid - Samsung My Files App
Samsung Power Off Reset LogsSamsung Power Off Reset Logs
Samsung Smart Switch Android - Samsung Smart Switch // iOS Transfer Artifacts
SignalObtain a logical dump of Signal data on Android with signal-back
SignalDecrypting Signal DB for Android
SignalInvestigating Signal with ArtiFast Signal
SKOUTApp SKOUT on Android
SkypeSkype on Android - Images in Web Cache
SlackFinding Slack app messages in Android and using json_extract to do it.
SnapChatSnapchat Analysis to Discover Digital Forensic Artifacts on Android Smartphone
SnapChatGone in 10 Seconds Snapchat Forensics
SnapChatTwo Snaps and a Twist – An In-Depth (and Updated) Look at Snapchat on Android
SystemPanel2Android SystemPanel2 - App usage tracking
TeamViewer Remote ControlAndroid Remote Desktop Apps - TeamViewer Remote Control
TikTokFinding TikTok messages in Android
TileAndroid - Locating Location Data: The Tile App
ToxAnalysis of Antox - Android Tox App
VenmoVenmo. The App for Virtual Ballers.
Video Player Apps (VLC, MX Player, Archos, Plex, LocalCast)Was the video played? - Android video player apps
Wear OSClockin’ In with Google’s Wear OS
WhatsAppWhatsApp - Images and Messages - An overview
WhatsAppWhatsApp messages in Non-Rooted Android Devices
WickrWickr. Alright. We’ll Call It A Draw.

Android Tools

Coming soon….