Digital Forensics Across Multiple Android Versions Using the MOBILEdit Forensic Tool
Kohal Deep Maheshwari, Pardeep Kumar, Najma Imtiaz Ali, Imtiaz Ali Brohi, Dua Agha · 2024
Open-source Android smartphones present both opportunities and difficulties for forensic investigators as they become more widely used. Advancements in Android security, encryption, and storage features necessitate newer forensic methods. The performance of MOBILedit Forensic across several Android versions will be covered in this article, with a concentrate on those running the Android 4.x version series. Data extraction, file recovery from deletion, and examination of call logs, messages, multimedia, and social media activity were among the main forensic activities carried out using this program. The tool's performance was evaluated on data from locked or corrupted devices, including its ability to decrypt information. The findings indicate that while MOBILedit Forensic is compatible with many Android versions, the speed and effectiveness of data extraction depend on the particular security measures used on each version. Newer Android models with advanced encryption and secure boot processes require more complex recovery techniques compared to older models, which recover data more quickly due to fewer security mechanisms. MOBILedit Forensic is still helpful in mobile forensics despite its flaws, but only partially understanding of encrypted data. This study also provides a more thorough understanding of the tool's functionality across different Android versions, which can help forensic investigators make better decisions about the best evidence extraction methods. Regular updates to forensic tools are crucial to adapt to evolving Android security measures.