A mobile digital-forensics case study completed in a controlled university environment using Cellebrite Reader. The examination focused on device attribution, messaging artifacts, call history, Safari activity, application-generated artifacts, and iOS filesystem structures within a provided UFDR logical extraction.
Academic Case Disclaimer
This project is based entirely on a fictional digital-forensics scenario created for university coursework. All individuals, communications, evidence, and investigative circumstances are simulated and do not represent a real criminal investigation.
A pre-created UFDR logical extraction of an iPhone 8 Plus was provided for examination as part of a university digital-forensics practical.
Using Cellebrite Reader, I examined artifacts contained within the extraction to associate the device with the fictional subject and reconstruct relevant activity across multiple sources.
The examination included Apple account information, device metadata, SMS and iMessage records, WhatsApp artifacts, call history, media files, Safari history, application-generated artifacts, iOS filesystem structures, and timeline data.
The examination focused on several primary questions:
- What artifacts could be used to associate the device with the fictional subject?
- What messaging and communication activity was present?
- What browser and application activity could be identified?
- What media and filesystem artifacts were present within the extraction?
- Could artifacts from different sources be correlated to provide additional context?
The analysis was limited to the provided UFDR logical extraction and was performed using Cellebrite Reader.
I did not acquire or image the original iPhone.
The investigation began by examining account and device metadata to establish attribution within the fictional scenario.
The analysis then progressed through several artifact categories:
- Apple account and device information
- SMS and iMessage records
- WhatsApp artifacts
- Call-history records
- Media and application-generated artifacts
- Safari browser history
- iOS filesystem structures and databases
- Timeline data
Rather than relying on individual artifacts in isolation, related findings were compared across multiple sources when additional context could be established.
The first stage of the examination focused on identifying artifacts that could associate the iPhone 8 Plus with the fictional subject.
Cellebrite Reader identified an Apple ID account within the device's accounts database. The extraction summary also reported the user-configured device name as: Eddie's iPhone
These artifacts provided independent indicators associating the device with the fictional subject Eddie Johnson.
Additional supporting information was later identified within a system-generated Contacts application snapshot.
Taken together, these artifacts supported attribution within the fictional scenario. They do not independently establish who physically operated the device at a specific time.
Cellebrite Reader displaying the Apple account artifact, associated username, logical extraction type, and source database.
Messaging artifacts stored within the iPhone's sms.db database were examined to reconstruct conversations associated with the device.
Cellebrite Reader displayed message participants, message contents, timestamps, read or delivery information, and source artifacts.
Several recovered conversations contained references to substances, quantities, dollar amounts, and proposed meeting arrangements relevant to the fictional investigative scenario.
The examination focused on documenting what the recovered messages contained rather than treating individual messages as proof that a physical event occurred.
Cellebrite Reader displaying recovered SMS/iMessage records, message participants, timestamps, and message contents originating from the iOS sms.db database.
The examination also identified WhatsApp communication artifacts stored separately from the device's native messaging database.
Recovered WhatsApp data was associated with: ChatStorage.sqlite
Cellebrite Reader displayed communications involving the same device-associated phone number identified elsewhere in the extraction.
This provided an example of correlating communication activity across multiple applications rather than relying solely on native SMS or iMessage records.
The WhatsApp artifacts also demonstrated how third-party application data can remain accessible within a logical mobile extraction through application-specific SQLite databases and storage locations.
Cellebrite Reader displaying recovered WhatsApp communications and associated message metadata from the application's stored artifacts.
Call-history records were examined to identify inbound and outbound communication activity.
Cellebrite Reader recovered call records from: CallHistoryDB/CallHistory.storedata
The recovered artifacts contained information including telephone numbers, timestamps, call duration, and status information indicating whether calls were answered, missed, or unanswered.
The call records provided an additional communication source that could be compared with contacts and messaging artifacts identified elsewhere in the extraction.
Cellebrite Reader displaying recovered outbound call records, including phone numbers, timestamps, call duration, and call status.
One notable artifact was recovered from the iOS SplashBoard snapshot directory associated with the Contacts application.
The recovered .ktx file displayed a Contacts card labeled: Eddie Johnson
Importantly, this artifact was not a screenshot manually captured by the device user.
It was a system-generated application snapshot created by iOS as part of application state and interface handling.
System-generated Contacts application snapshot recovered from the iOS SplashBoard directory and displaying a contact card labeled Eddie Johnson.
Cellebrite Reader identified Safari history artifacts stored within: Library/Safari/History.db
The extraction contained hundreds of browser-history records, including Google search activity and visited webpages.
Among the recovered artifacts were searches related to deleting messages from an iPhone. A corresponding Apple Support page regarding message deletion was also present shortly after one of the searches.
The recorded timestamps allowed these browser artifacts to be examined chronologically.
Cellebrite Reader displaying a recovered Safari history artifact, search query, timestamp, URL, and originating History.db source.
The examination identified an additional filesystem structure labeled: TarArchive
Within the associated backup data, a decrypted Manifest.db SQLite database was identified.
The database contained 6,940 entries and included fields such as:
fileIDdomainrelativePath
These fields provided mappings between file identifiers, their associated applications or domains, and their relative locations within the iOS filesystem.
This finding demonstrated how database structures within mobile backups or extractions can provide context about where artifacts originate even when filenames alone are not descriptive.
Examination of Manifest.db showing file identifiers, application domains, and relative filesystem paths contained within the extracted iOS backup structure.
Cellebrite Reader's timeline functionality was used to examine the distribution of activity across the extracted dataset.
Within the displayed range, the highest concentration of activity occurred between approximately November 2020 and January 2021.
Timeline analysis provided a higher-level view of artifact activity and could be used to identify periods warranting more focused examination.
Cellebrite Reader timeline view showing the distribution of recovered activity across the examined time period.
The examination involved comparing information across multiple mobile artifact sources rather than evaluating each artifact independently.
Examples included:
- Comparing Apple account data, device naming information, and application-generated artifacts when establishing device attribution.
- Relating contact information to SMS, WhatsApp, and call-history records.
- Comparing native messaging artifacts with third-party WhatsApp communications.
- Examining Safari searches together with their timestamps and subsequently visited webpages.
- Using filesystem paths and SQLite database information to identify the origin and context of recovered artifacts.
- Distinguishing user-created media from application-generated snapshots and thumbnail artifacts.
This process demonstrated how mobile forensic findings can gain additional context when artifacts from separate applications and databases are examined together.
This project provided hands-on experience with:
- Cellebrite Reader
- UFDR logical extraction analysis
- iOS mobile-forensics workflows
- Device and account attribution
- Apple account artifacts
- SMS and iMessage analysis
sms.db- WhatsApp artifact analysis
ChatStorage.sqlite- Call-history analysis
- Safari
History.db - Application-generated snapshot analysis
- Media and thumbnail artifact interpretation
- SQLite database examination
Manifest.db- iOS filesystem paths
- Timeline analysis
- Cross-artifact correlation
- Forensic documentation and reporting
This investigation demonstrated that mobile forensic analysis extends beyond reviewing visible messages, photographs, or application content.
Some of the most useful findings came from understanding the underlying sources of the artifacts, including SQLite databases, application storage locations, system-generated snapshots, browser databases, and filesystem metadata.
The investigation also reinforced the importance of distinguishing what an artifact directly demonstrates from what might only be inferred from it. For example, a browser search can establish that a search artifact exists at a particular time, but additional evidence would be required to determine the user's intent or what actions followed.
A complete version of the forensic examination is available below. The full report contains additional artifacts, supporting figures, source paths, and documentation that were condensed in this README.
View the Full Mobile Forensic Examination Report
The original UFDR forensic extraction is not included or distributed through this repository.







