
Android-Forensics-References
Curated reference for Android forensic artifacts and log paths, with links to CTF writeups, research papers, and mobile device analysis tooling.

Curated reference for Android forensic artifacts and log paths, with links to CTF writeups, research papers, and mobile device analysis tooling.

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.

Android Connections Forensics

Manage WhatsApp .crypt12, .crypt14 and .crypt15 files.

Utility for recovering ES File Explorer encrypted files (.eslock)


Linux Distro for Mobile Security, Malware Analysis, and Forensics

This is the development tree. Production downloads are at:


Cellebrite Physical Analyzer python scripts to aid analysts with extended functionality

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

A robust digital forensics tool for extracting and analyzing Google Chrome artifacts from Android devices

Scan for evidence of CVE-2021-30860 (FORCEDENTRY) exploit

A free, open-source, and cross-platform iDevice management tool

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.