
Android-Forensics-References
Curated reference for Android forensic artifacts and log paths, with links to CTF writeups, research papers, and mobile device analysis tooling.

Curated reference for Android forensic artifacts and log paths, with links to CTF writeups, research papers, and mobile device analysis tooling.

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact…

Android Connections Forensics

Utility for recovering ES File Explorer encrypted files (.eslock)


Linux Distro for Mobile Security, Malware Analysis, and Forensics

This is the development tree. Production downloads are at:


Cellebrite Physical Analyzer python scripts to aid analysts with extended functionality

Scan for evidence of CVE-2021-30860 (FORCEDENTRY) exploit

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices

Portable forensic acquisition tool for Android devices that collects relevant data via USB debugging to identify potential spyware or compromise…