
MESH
Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

Free hands-on digital forensics labs for students and faculty

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Manage WhatsApp .crypt12, .crypt14 and .crypt15 files.

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact…

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

Filesystem monitor tool for Linux/Android iOS/macOS

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which…

Utility for recovering ES File Explorer encrypted files (.eslock)

Portable forensic acquisition tool for Android devices that collects relevant data via USB debugging to identify potential spyware or compromise…

A robust digital forensics tool for extracting and analyzing Google Chrome artifacts from Android devices

Curated reference for Android forensic artifacts and log paths, with links to CTF writeups, research papers, and mobile device analysis tooling.

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252