Below you will find a list of add-ons that can be updated in the Updates section from the main menu. All the following add-ons give you advanced options and are essential for extracting as much data as possible. We are continuously working on updates for MOBILedit Forensic, so whenever you receive an update notification, make sure to update all the newly released packages.
Some applications manufacturers made restrictions on what data can be acquired from their apps. This is especially relevant for non-rooted phones.
To bypass this you can use the App downgrade, feature in MOBILedit Forensic, which will downgrade the apps to a version, in which there was no problem in obtaining the data from them directly.
The App downgrade feature must be activated in the specific selection.
The app engine turns on automatically as a source for the application script during the analysis. It is part of the program from the start and does not have to be downloaded separately.
iOS screenshot support
Captured phone photos enable you to make a screenshot of the phone's display, import your own images or take a picture with the webcam. For Android OS devices, this feature is turned on automatically.
To enable this feature on iOS devices, you will need to download the iOS screenshots package from the Updates section.
Data about cell towers that the subject phone was connected to can be obtained. However, this is only possible with rooted Android phones. Obtained cell tower locations can be individually viewed on the map through the provided link.
When installed, it is turned on automatically both for the specific selection and full content.
Face matcher is a neat feature that allows you to find photos with faces and compares them with provided source images. It can be turned on in the specific selection and to activate it, you need to upload at least one source image.
File exclude list
This feature allows the user to filter regular and unnecessary files. The filtering is based on hashes that the software gathers from NIST as a part of NSLR packages for Android and iOS.
The Photo recognizer is powered by an artificial intelligence module utilizing machine learning to automatically recognize suspicious content in photos such as drugs, nudity, weapons, currency, and documents.
Photo recognizer can be turned on the specific selection if the respective package is installed.
Malware detection lets you check the extracted application APK files for malware. It must be installed first and turned on in the Application list section. The new Malware detection is based on the Yara project.
Recovery mode helps you to extract more data from an Android device. It is used by TWRP to flash the recovery.
EDL package consists of programmers that are essential for EDL hack. In future releases, this package will be removed and replaced by one that will be the same for all of these hacks.
Samsung Engineering root
Kernel image (boot), with root access and unauthorized ADB, enabled and signed by Samsung, allowing you to flash it with OEM and FRP lock.
A special boot for devices with Spreadtrum chipset. Provides a possibility to create a physical dump of internal memory.