Diese Übersicht bündelt alle Fragen und Antworten rund um die mobile Forensik bei LanCologne – von der Datensicherung am Gerät über Messenger-, iOS- und Android-Artefakte bis hin zu Schadsoftware, Gutachten und Kosten. Klicken Sie auf eine Kategorie, um die passenden Fragen zu sehen.
Grundlagen, Datensicherung und Extraktion
- Physical removal of a smartphone
- Logical extraction of a smartphone
- Advanced logical extraction from a smartphone
- Full File System (FFS) in mobile IT forensics
- Cellebrite in mobile forensics – Professional data recovery and analysis of digital evidence
- Cellebrite in mobile forensics
- Why different tools in mobile IT forensics produce different results
- Preservation of evidence from smartphones
- Chain of Custody for Smartphones
- SQLite Forensics – When digital traces are stored in databases
- WAL and SHM Analysis – Unassuming files of great significance to IT forensics
- WAL and SHM analysis in IT forensics
Messaging and communication
- Messenger forensics – Analysis of digital communications on smartphones and tablets
- WhatsApp Forensics – Analysis of chat histories and digital evidence
- Signal forensics – Analysis of encrypted communications on smartphones
- Telegram Forensics – Forensic Analysis of Telegram Communications
- iMessage forensics
- Forensic analysis of WhatsApp on Android
- Conducting a forensic analysis of Signal Messenger on Android
- Forensic analysis of Telegram on Android
- Forensic analysis of Threema on Android
- Forensic analysis of Facebook Messenger on Android
- Detecting chat manipulation – Objective IT forensic analysis of digital communications
- Proving chat manipulation
- Checking Messenger messages for tampering
- FaceTime artefacts
- AirDrop artefacts
iPhone und iOS
- iPhone Forensics – Admissible analysis of digital evidence on Apple devices
- The iOS file system explained in simple terms
- APFS – Apple’s file system
- Apple Data Protection and data protection mechanisms
- Secure Enclave – Security in the iPhone
- iCloud forensics and Apple cloud data
- Forensic analysis of iTunes and Finder backups
- iOS logs and system logs
- iPhone Backups – Options and Limitations
- Conduct a forensic analysis of installed apps
- Apple ID, synchronisation and device pairing
- Jailbreaking in iPhone forensics
- Apple Health (HealthKit) – IT forensic investigation
- Apple Maps artefacts
- Safari artefacts
Android – System, Zugriff und Sicherheit
- Android Forensics – Professional analysis of digital evidence on Android devices
- The Android file system explained in simple terms
- Android Verified Boot (AVB)
- File-Based Encryption (FBE) and Full Disk Encryption (FDE)
- Android Keystore and Security Architecture
- Fastboot and bootloader
- ADB (Android Debug Bridge) in IT forensics
- Android Backups – Options and Limitations
- Forensic analysis of installed apps (Android)
- Google Account and Google Cloud artefacts
- Timestamps and metadata on Android
- Android system logs and Logcat
- Recovering deleted data on Android
- Root in Android forensics
- Rooting from the perspective of Android forensics
- Custom Recovery (TWRP & Co.) from an Android forensics perspective
- Custom ROMs from the perspective of Android forensics
- Detecting anti-forensics on Android
Android – Artefakte im Detail
- Forensic analysis of Android location data
- Forensic analysis of Android notifications
- Forensic analysis of Android timestamps and time zones
- Forensic analysis of Android call logs
- Forensic analysis of the Android calendar
- Forensic analysis of Android contacts
- Forensic analysis of Android SMS and MMS messages
- Forensic analysis of Android file managers and downloads
- Android email forensics
- Forensic analysis of Android file system artefacts
- Forensic analysis of Android app permissions
- Forensic analysis of Android-WLAN artefacts
- Forensic analysis of Android system settings
- Forensic analysis of Android Bluetooth artefacts
- Forensic analysis of Android NFC artefacts
- Forensic analysis of Android SIM card artefacts
- Forensic analysis of Android USB and OTG artefacts
- Android eSIM Forensics
- Forensic analysis of Android crash dumps and tombstones
- Forensic analysis of Android device logs (events and system logs)
- Forensic analysis of Android cloud synchronisation
- Forensic analysis of Android backup artefacts
- Android Timeline and Event Reconstruction
- Forensic analysis of Google Photos on Android
- Forensic analysis of Google Chrome on Android
- Forensic analysis of Google Maps on Android
- Forensic analysis of Samsung Gallery on Android
- Forensic analysis of EXIF metadata in images
Mobile Artefakte geräteübergreifend
- Mobile artefacts – call logs in IT forensics
- Mobile Artefacts – Contacts in IT Forensics
- Mobile artefacts – text messages in IT forensics
- Mobile Artefacts – MMS in IT Forensics
- Mobile artefacts – photographs in IT forensics
- Mobile artefacts – videos in IT forensics
- Mobile Artefacts – EXIF Metadata in IT Forensics
- Mobile artefacts – location data in IT forensics
- Mobile devices – Bluetooth devices in IT forensics
- Mobile artefacts – WLAN artefacts in IT forensics
- Mobile artefacts – browser artefacts in IT forensics
- Mobile artefacts – calendars in IT forensics
- Mobile artefacts – files in IT forensics
- Mobile Artefacts – Notes on IT Forensics
- Mobile devices – Downloads in IT forensics
- Mobile artefacts – Notifications in IT forensics
- Mobile artefacts – The clipboard in IT forensics
- Mobile artefacts – App usage in IT forensics
- Mobile Devices – Screen Time in IT Forensics
- Metadata in mobile forensics – what digital traces can reveal
- Metadata in mobile forensics
- Have digital metadata professionally analysed
Schadsoftware, Spyware und Stalkerware
- Mobile malware analysis – scanning smartphones for malware and digital anomalies
- IT forensic malware reports for smartphones
- Stalkerware on smartphones
- Detecting spyware on smartphones
- Malware Indicators (IoCs), MVT and YARA
- Android Trojans, banking malware and RATs
- Government-sponsored malware (e.g. Pegasus) – the scope and limitations of investigations
Gutachten, Beweiskraft und Kosten
- Expert reports for courts and public prosecutors’ offices
- Expert reports for solicitors
- Expert reports in accordance with recognised forensic standards
- Counter-assessment / Plausibility check
- Verification of the authenticity of digital evidence
- The evidential value of digital artefacts
- Technical documentation and reproducibility
- Limitations and uncertainties in IT forensic reports
- Evidence of deleted data
- Timeline analysis
- Mobile phone expert reports admissible in court
- Private report on smartphones
- Mobile phone expert reports admissible in court
- Private report on smartphones
- Costs of an IT forensic report
- Costs of an IT forensic investigation
- Fees in accordance with the JVEG and individual fee agreements
- Package deals for private individuals, businesses and solicitors
- Frequently asked questions about costs, remuneration and invoicing
- Forensic Services – An overview of all services