MOBILE FORENSICS

Detecting anti-forensics on Android

The term ‘anti-forensics’ refers to technical measures designed to hinder subsequent analysis, conceal artefacts or remove traces. In the context of an Android forensic investigation, identifying such measures is one of the key tasks, as they can influence the interpretation of the investigation’s findings.

Safe fire-extinguishing procedures
Root-Hiding and Magisk DenyList
Tampering with log files
Changes to timestamps
Hiding apps or processes
Changes to system partitions
Custom ROMs and kernel modifications
Changes to the bootloader or recovery

TECHNICAL BACKGROUND

Technical Fundamentals

Anti-forensic measures can occur at various levels of the Android system.

Forensic aspects:

  • Safe fire-extinguishing procedures
  • Root-Hiding and Magisk DenyList
  • Tampering with log files
  • Changes to timestamps
  • Hiding apps or processes
  • Changes to system partitions
  • Custom ROMs and kernel modifications
  • Changes to the bootloader or recovery

Not every anomaly automatically constitutes an attempt at manipulation. The technical assessment is always carried out within the overall context.

OUR APPROACH

This is how your examination will be carried out

A transparent process – from the initial enquiry to the handover of the report.

1
We analyse the Android system for evidence of modifications, root artefacts, boot configurations, logs and other technical characteristics. This involves combining recognised IT forensic tools with manual analysis. All findings are documented in a reproducible manner and assessed solely on the basis of objectively verifiable technical evidence.
2
LanCologne produces expert reports for private individuals, as well as for companies and solicitors. Our reports have already been used in court proceedings. In some cases, we have been directly commissioned to produce IT forensic reports. Upon request, we can provide anonymised or redacted sample reports or extracts.

TYPICAL QUESTIONS

When is this analysis required?

  • Is there any evidence of anti-forensics?
  • Have any log files or timestamps been altered?
  • Are there any root-hiding techniques?
  • What impact does this have on the validity of the study?
  • What technical conclusions can objectively be drawn?

LIMITATIONS & CONCLUSION

What you should know

Not every change to the system is the result of an anti-forensics measure. Similarly, the absence of relevant artefacts cannot prove that no tampering has taken place. The assessment is always based on the totality of all available technical evidence.

The identification of potential anti-forensics measures is a key component of modern Android forensics. However, a robust assessment requires a comprehensive analysis of all relevant artefacts.

CUSTOMER REVIEWS

What our customers say

4.8 out of 5 stars on Trustpilot · 54 reviews

★★★★★

“The highest standards of professionalism, prompt service and excellent communication. They made the seemingly impossible a reality. This is what genuine customer service is all about – unrivalled in Germany!”

idalein

Verified review on Trustpilot

★★★★★

“Very helpful advice, excellent responsiveness and communication. My problem was completely resolved and the lost data was recovered. I’m very satisfied and, of course, relieved!”

Layla Pankratz

Verified review on Trustpilot

★★★★★

“My problem was sorted out professionally and quickly; everyone I spoke to was always friendly, and I can still get in touch if I have any questions – I’m very grateful for that!”

a woman from Cologne

Verified review on Trustpilot

Enquire now – free initial consultation

Would you like to have an Android device examined to see if it shows any signs of tampering or anti-forensic measures? LanCologne can assist you with an objective IT forensic investigation and comprehensive expert documentation.

FREQUENTLY ASKED QUESTIONS

Frequently Asked Questions

Click on a question to see the answer.

What does ‘anti-forensics’ mean?
Technical measures designed to hinder or influence a subsequent forensic investigation.
Does root access automatically mean anti-forensics?
No. Root access alone does not prove an intention to tamper.
Is it possible to prove manipulation beyond doubt?
Not always. Often, it is only technical information that can be assessed.
Do altered timestamps constitute evidence?
No. They must always be assessed within the overall technical context.
Could an expert report be drawn up on this matter?
Yes. The technical findings are documented and assessed in a way that is easy to follow.