MOBILE FORENSICS

The Android file system explained in simple terms

The Android file system forms the basis of any forensic examination of an Android device. An understanding of the storage structure makes it easier to categorise user files, app data and system artefacts, and is essential for a professional analysis.

boot
init_boot (on newer devices)
system
vendor
product
odm
userdata
recovery
metadata

TECHNICAL BACKGROUND

Technical Fundamentals

Android consists of several partitions, each with a different function. The structure and names may vary slightly depending on the manufacturer and the version of Android.

The most important partitions include:

  • boot
  • init_boot (on newer devices)
  • system
  • vendor
  • product
  • odm
  • userdata
  • recovery
  • metadata

The file systems used include ext4, F2FS and – on newer devices – EROFS. Within the userdata partition, applications run in separate sandboxes. This ensures that app data is always stored in an isolated manner.

OUR APPROACH

This is how your examination will be carried out

A transparent process – from the initial enquiry to the handover of the report.

1
As part of an Android investigation, the relevant partitions and file systems are analysed in accordance with the available data backup. In addition to recognised IT forensic tools, a manual examination of relevant directory structures, metadata and file system artefacts is carried out. All steps in the process are documented in a reproducible manner.
2
LanCologne produces expert reports for private individuals, as well as for companies and solicitors. Our reports have already been used in court proceedings. In some cases, we have been directly commissioned to produce IT forensic reports. Upon request, we can provide anonymised or redacted sample reports or extracts.

TYPICAL QUESTIONS

When is this analysis required?

  • Where is user data stored?
  • Where is app data stored?
  • Which partitions are relevant to forensic analysis?
  • What role does an app’s sandbox play?
  • Which file systems are used?

LIMITATIONS & CONCLUSION

What you should know

The available data set depends, amongst other things, on the extraction method, the device’s encryption, the bootloader status and the Android version. Not every partition is fully accessible on every device.

The Android file system forms the technical basis for virtually every Android forensic investigation. Only by understanding the partitions and storage locations is it possible to properly assess digital artefacts.

CUSTOMER REVIEWS

What our customers say

4.8 out of 5 stars on Trustpilot · 54 reviews

★★★★★

“The highest standards of professionalism, prompt service and excellent communication. They made the seemingly impossible a reality. This is what genuine customer service is all about – unrivalled in Germany!”

idalein

Verified review on Trustpilot

★★★★★

“Very helpful advice, excellent responsiveness and communication. My problem was completely resolved and the lost data was recovered. I’m very satisfied and, of course, relieved!”

Layla Pankratz

Verified review on Trustpilot

★★★★★

“My problem was sorted out professionally and quickly; everyone I spoke to was always friendly, and I can still get in touch if I have any questions – I’m very grateful for that!”

a woman from Cologne

Verified review on Trustpilot

Enquire now – free initial consultation

Would you like to have the data structure of an Android device professionally analysed? LanCologne can assist you with an objective IT forensic investigation and comprehensive expert documentation.

FREQUENTLY ASKED QUESTIONS

Frequently Asked Questions

Click on a question to see the answer.

Which file systems does Android use?
Often ext4, F2FS and, on some newer devices, EROFS.
Are all manufacturers structured in the same way?
No. Samsung, Google, Xiaomi and other manufacturers sometimes use different partition layouts.
What is the userdata partition?
Among other things, it contains user and app data and is usually the most important part of an investigation.
Why are app sandboxes important?
They separate the data from individual applications and affect the forensic analysis.
Could an expert report be drawn up on this matter?
Yes. The results can be documented in a transparent manner and assessed by experts.