Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 

Repository files navigation

Mobile Digital Forensics Investigation Using Cellebrite

A mobile digital-forensics case study completed in a controlled university environment using Cellebrite Reader. The examination focused on device attribution, messaging artifacts, call history, Safari activity, application-generated artifacts, and iOS filesystem structures within a provided UFDR logical extraction.

Academic Case Disclaimer

This project is based entirely on a fictional digital-forensics scenario created for university coursework. All individuals, communications, evidence, and investigative circumstances are simulated and do not represent a real criminal investigation.


Case Overview

A pre-created UFDR logical extraction of an iPhone 8 Plus was provided for examination as part of a university digital-forensics practical.

Using Cellebrite Reader, I examined artifacts contained within the extraction to associate the device with the fictional subject and reconstruct relevant activity across multiple sources.

The examination included Apple account information, device metadata, SMS and iMessage records, WhatsApp artifacts, call history, media files, Safari history, application-generated artifacts, iOS filesystem structures, and timeline data.


Investigation Objectives & Scope

The examination focused on several primary questions:

  1. What artifacts could be used to associate the device with the fictional subject?
  2. What messaging and communication activity was present?
  3. What browser and application activity could be identified?
  4. What media and filesystem artifacts were present within the extraction?
  5. Could artifacts from different sources be correlated to provide additional context?

The analysis was limited to the provided UFDR logical extraction and was performed using Cellebrite Reader.

I did not acquire or image the original iPhone.


Investigative Approach

The investigation began by examining account and device metadata to establish attribution within the fictional scenario.

The analysis then progressed through several artifact categories:

  • Apple account and device information
  • SMS and iMessage records
  • WhatsApp artifacts
  • Call-history records
  • Media and application-generated artifacts
  • Safari browser history
  • iOS filesystem structures and databases
  • Timeline data

Rather than relying on individual artifacts in isolation, related findings were compared across multiple sources when additional context could be established.


Findings

1. Device & Account Attribution

The first stage of the examination focused on identifying artifacts that could associate the iPhone 8 Plus with the fictional subject.

Cellebrite Reader identified an Apple ID account within the device's accounts database. The extraction summary also reported the user-configured device name as: Eddie's iPhone

These artifacts provided independent indicators associating the device with the fictional subject Eddie Johnson.

Additional supporting information was later identified within a system-generated Contacts application snapshot.

Taken together, these artifacts supported attribution within the fictional scenario. They do not independently establish who physically operated the device at a specific time.

Apple account artifact examined in Cellebrite Reader

Cellebrite Reader displaying the Apple account artifact, associated username, logical extraction type, and source database.



2. SMS & iMessage Analysis

Messaging artifacts stored within the iPhone's sms.db database were examined to reconstruct conversations associated with the device.

Cellebrite Reader displayed message participants, message contents, timestamps, read or delivery information, and source artifacts.

Several recovered conversations contained references to substances, quantities, dollar amounts, and proposed meeting arrangements relevant to the fictional investigative scenario.

The examination focused on documenting what the recovered messages contained rather than treating individual messages as proof that a physical event occurred.

SMS and iMessage artifacts examined in Cellebrite Reader

Cellebrite Reader displaying recovered SMS/iMessage records, message participants, timestamps, and message contents originating from the iOS sms.db database.



3. WhatsApp Artifact Analysis

The examination also identified WhatsApp communication artifacts stored separately from the device's native messaging database.

Recovered WhatsApp data was associated with: ChatStorage.sqlite

Cellebrite Reader displayed communications involving the same device-associated phone number identified elsewhere in the extraction.

This provided an example of correlating communication activity across multiple applications rather than relying solely on native SMS or iMessage records.

The WhatsApp artifacts also demonstrated how third-party application data can remain accessible within a logical mobile extraction through application-specific SQLite databases and storage locations.

WhatsApp artifacts examined in Cellebrite Reader

Cellebrite Reader displaying recovered WhatsApp communications and associated message metadata from the application's stored artifacts.



4. Call-History Analysis

Call-history records were examined to identify inbound and outbound communication activity.

Cellebrite Reader recovered call records from: CallHistoryDB/CallHistory.storedata

The recovered artifacts contained information including telephone numbers, timestamps, call duration, and status information indicating whether calls were answered, missed, or unanswered.

The call records provided an additional communication source that could be compared with contacts and messaging artifacts identified elsewhere in the extraction.

Outbound call history examined in Cellebrite Reader

Cellebrite Reader displaying recovered outbound call records, including phone numbers, timestamps, call duration, and call status.



5. System-Generated Application Artifacts

One notable artifact was recovered from the iOS SplashBoard snapshot directory associated with the Contacts application.

The recovered .ktx file displayed a Contacts card labeled: Eddie Johnson

Importantly, this artifact was not a screenshot manually captured by the device user.

It was a system-generated application snapshot created by iOS as part of application state and interface handling.

System-generated iOS Contacts application snapshot

System-generated Contacts application snapshot recovered from the iOS SplashBoard directory and displaying a contact card labeled Eddie Johnson.



6. Safari History Analysis

Cellebrite Reader identified Safari history artifacts stored within: Library/Safari/History.db

The extraction contained hundreds of browser-history records, including Google search activity and visited webpages.

Among the recovered artifacts were searches related to deleting messages from an iPhone. A corresponding Apple Support page regarding message deletion was also present shortly after one of the searches.

The recorded timestamps allowed these browser artifacts to be examined chronologically.

Safari browser history artifact examined in Cellebrite Reader

Cellebrite Reader displaying a recovered Safari history artifact, search query, timestamp, URL, and originating History.db source.



7. iOS Filesystem & Manifest Database Analysis

The examination identified an additional filesystem structure labeled: TarArchive

Within the associated backup data, a decrypted Manifest.db SQLite database was identified.

The database contained 6,940 entries and included fields such as:

  • fileID
  • domain
  • relativePath

These fields provided mappings between file identifiers, their associated applications or domains, and their relative locations within the iOS filesystem.

This finding demonstrated how database structures within mobile backups or extractions can provide context about where artifacts originate even when filenames alone are not descriptive.

iOS Manifest database examined in Cellebrite Reader

Examination of Manifest.db showing file identifiers, application domains, and relative filesystem paths contained within the extracted iOS backup structure.



8. Timeline Analysis

Cellebrite Reader's timeline functionality was used to examine the distribution of activity across the extracted dataset.

Within the displayed range, the highest concentration of activity occurred between approximately November 2020 and January 2021.

Timeline analysis provided a higher-level view of artifact activity and could be used to identify periods warranting more focused examination.

Cellebrite Reader forensic timeline

Cellebrite Reader timeline view showing the distribution of recovered activity across the examined time period.



Evidence Correlation

The examination involved comparing information across multiple mobile artifact sources rather than evaluating each artifact independently.

Examples included:

  • Comparing Apple account data, device naming information, and application-generated artifacts when establishing device attribution.
  • Relating contact information to SMS, WhatsApp, and call-history records.
  • Comparing native messaging artifacts with third-party WhatsApp communications.
  • Examining Safari searches together with their timestamps and subsequently visited webpages.
  • Using filesystem paths and SQLite database information to identify the origin and context of recovered artifacts.
  • Distinguishing user-created media from application-generated snapshots and thumbnail artifacts.

This process demonstrated how mobile forensic findings can gain additional context when artifacts from separate applications and databases are examined together.


Skills Demonstrated

This project provided hands-on experience with:

  • Cellebrite Reader
  • UFDR logical extraction analysis
  • iOS mobile-forensics workflows
  • Device and account attribution
  • Apple account artifacts
  • SMS and iMessage analysis
  • sms.db
  • WhatsApp artifact analysis
  • ChatStorage.sqlite
  • Call-history analysis
  • Safari History.db
  • Application-generated snapshot analysis
  • Media and thumbnail artifact interpretation
  • SQLite database examination
  • Manifest.db
  • iOS filesystem paths
  • Timeline analysis
  • Cross-artifact correlation
  • Forensic documentation and reporting

Key Takeaways

This investigation demonstrated that mobile forensic analysis extends beyond reviewing visible messages, photographs, or application content.

Some of the most useful findings came from understanding the underlying sources of the artifacts, including SQLite databases, application storage locations, system-generated snapshots, browser databases, and filesystem metadata.

The investigation also reinforced the importance of distinguishing what an artifact directly demonstrates from what might only be inferred from it. For example, a browser search can establish that a search artifact exists at a particular time, but additional evidence would be required to determine the user's intent or what actions followed.


Full Forensic Examination Report

A complete version of the forensic examination is available below. The full report contains additional artifacts, supporting figures, source paths, and documentation that were condensed in this README.

View the Full Mobile Forensic Examination Report

The original UFDR forensic extraction is not included or distributed through this repository.

About

Mobile forensics case study using Cellebrite Reader to analyze a provided iPhone UFDR logical extraction, including device attribution, messaging, Safari, and iOS filesystem artifacts.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors