performing-mobile-device-forensics-with-cellebrite

Featured

Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.

AI & Automation 13,115 stars 1533 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Performing Mobile Device Forensics with Cellebrite ## When to Use - When extracting evidence from smartphones or tablets during an investigation - For recovering deleted messages, call logs, and location data from mobile devices - During investigations involving communications via messaging apps - When analyzing mobile application data for evidence of criminal activity - For corporate investigations involving employee mobile device misuse ## Prerequisites - Cellebrite UFED Touch/4PC or UFED Physical Analyzer (licensed) - Alternative open-source tools: ALEAPP, iLEAPP, MEAT, libimobiledevice - Appropriate cables and adapters for target device - Faraday bag to isolate the device from network signals - Legal authorization (warrant, consent, or corporate policy) - Knowledge of iOS and Android file system structures ## Workflow ### Step 1: Prepare the Device and Isolation ```bash # CRITICAL: Immediately place device in airplane mode or Faraday bag # This prevents remote wipe commands and additional data changes # Document device state before acquisition # Record: make, model, IMEI, serial number, OS version, screen lock status # Photograph the device from all angles # For Android - Enable USB debugging if accessible # Settings > Developer Options > USB Debugging > Enable # For iOS - Trust the forensic workstation # When prompted on device, tap "Trust This Computer" # If device is locked, document lock type (PIN, pattern, biometric) # Cellebrite UFED can bypass certain lo...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

performing-disk-forensics-investigation

Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases. Utilizes tools such as FTK Imager, Autopsy, and The Sleuth Kit for evidence acquisition, deleted file recovery, and artifact examination. Activates for requests involving disk forensics, hard drive analysis, forensic imaging, file recovery, evidence acquisition, or digital forensic investigation.

13,115 Updated today
mukul975
API & Backend Featured

performing-sqlite-database-forensics

Perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode encoded timestamps, and extract evidence from browser history, messaging apps, and mobile device databases.

13,115 Updated today
mukul975
AI & Automation Featured

detecting-mobile-malware-behavior

Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile applications for data exfiltration, command-and-control communication, credential stealing, SMS interception, or other malware indicators. Activates for requests involving mobile malware analysis, app behavior monitoring, trojan detection, or suspicious app investigation.

13,115 Updated today
mukul975
API & Backend Featured

performing-endpoint-forensics-investigation

Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal proceedings, or analyzing endpoint compromise scope. Activates for requests involving endpoint forensics, memory analysis, disk forensics, or incident investigation.

13,115 Updated today
mukul975
AI & Automation Featured

conducting-mobile-app-penetration-test

Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls. The tester performs static analysis of application binaries, dynamic analysis at runtime, and API security testing to evaluate the complete mobile attack surface. Activates for requests involving mobile app pentest, iOS security assessment, Android security testing, or OWASP MASTG assessment.

13,115 Updated today
mukul975