User Guide - MOBILedit Forensic
Breadcrumbs

Applications

Perform advanced application analysis using adaptive, in-depth methods to maximise the amount of application data recovered from each app, including deleted data and data from encrypted apps. We regularly update MOBILedit Forensic to support the latest applications, application versions, and changes to their data structures.

Application analysis depends on the data available within the selected extraction. Results may vary depending on the device, operating system, application version, acquisition method, encryption, and the data retained by the application.

Android runtime permissions are included for each application within the output report.

For Android apps, you may need to use Rooting methods, Advanced data extraction, or Application downgrade to obtain additional application data. This is due to Android application sandboxing and restrictions on accessing private application data. Some applications also do not export their data using an ADB backup.

For iOS apps, much of the application data can be obtained from an encrypted iTunes backup. An unencrypted backup contains less data because some protected data is only included when backup encryption is enabled.

MOBILedit Forensic ULTRA provides additional advanced acquisition and decryption methods for supported devices. These methods can provide access to otherwise inaccessible or encrypted device and application data. Available methods depend on the device model, chipset, operating system, security patch level, and other device-specific factors. See MOBILedit Forensic ULTRA and ULTRA device compatibility for further information.

Applications commonly store user data in SQLite or LevelDB databases, as well as configuration files, caches, logs, media, attachments, and other application-specific storage. Additional application information and metadata can also be obtained from the application installation package.

The database of supported applications is available at apps.mobiledit.com.