---
language: "en"
---
# MOBILedit Forensic User Guide

MOBILedit Forensic is an all-in-one solution for data extraction from phones, smartwatches and clouds. It utilizes both physical and logical data acquisition, has excellent application analysis, deleted data recovery, a wide range of supported devices, fine-tuned reports, concurrent processing, and easy-to-use interface. With a brand new approach, MOBILedit Forensic is much stronger in security bypassing than ever before.

MOBILedit Forensic offers maximum functionality at a fraction of the price of other tools. It can be used as the only tool in a lab or as an enhancement to other tools with its data compatibility. When integrated with Camera Ballistics it scientifically analyzes camera photo origins.

To access the [MOBILedit Forensic ULTRA user guide](https://portal.mobiledit.com/), please sign in to the [User portal](https://portal.mobiledit.com/) and select the User guide from the menu. Find out more information about the [User portal](https://forensic.manuals.mobiledit.com/MM/mobiledit-user-portal.md).

**Popular articles**

[Description of editions](https://forensic.manuals.mobiledit.com/MM/description-of-editions)

[MOBILedit Forensic ULTRA: Device Compatibility Overview](https://forensic.manuals.mobiledit.com/MM/mobiledit-forensic-ultra-device-compatibility-over.md)

[Getting started](https://forensic.manuals.mobiledit.com/MM/getting-started.md)

[Connecting Android](https://forensic.manuals.mobiledit.com/MM/android.md)

[Connecting iOS](https://forensic.manuals.mobiledit.com/MM/ios.md)

[MOBILedit Smartwatch Forensics](https://forensic.manuals.mobiledit.com/MM/smartwatch-connection.md)

[MOBILedit Cloud Forensic](https://forensic.manuals.mobiledit.com/MM/mobiledit-cloud-forensic.md)

[How to get as much data as possible from WhatsApp](https://forensic.manuals.mobiledit.com/MM/how-to-get-as-much-data-as-possible-from-whatsapp.md)

[System Requirements](https://forensic.manuals.mobiledit.com/MM/system-requirements.md)

[License activation](https://forensic.manuals.mobiledit.com/MM/license-activation.md)

---
language: "en"
---
# About

![Home_about.png](https://forensic.manuals.mobiledit.com/__attachments/a_6149ff83627ad82a29c07f5846d9d5b108cef71a792710ada6a9d11735033727/Home_about.png?cb=e0f6d57b446596974282f3d29dc0b075)

In this view we list details about MOBILedit Forensic; the SW version number, driver manager version number, a link to our website and also a comprehensive list of the programming languages and third-party plugins and sources used to run the SW.  
![image-20221214-140303.png](https://forensic.manuals.mobiledit.com/__attachments/a_c66d2da1ec988552262776aaf5d12cfed3033da8b0e05aaf4cbfe91ddef3c7b9/image-20221214-140303.png?cb=76db97fa9ff1738125a1a57094af3d18)

---
language: "en"
---
# About Camera Ballistics technology

Image sensors suffer from several fundamental and technological imperfections that result in performance limitations and noise. If you take a picture of an absolutely evenly lit scene, the resulting digital image will still exhibit small changes in intensity between individual pixels. This can be due to pattern noise, readout noise or shot noise.

While readout noise or shot noise are random components, the pattern noise is deterministic (its behavior can be mathematically modeled and estimated) and remains approximately the same if multiple pictures of the same scene are taken. As a result, pattern noise might provide the sensor fingerprint we are searching for.

Pattern Noise (PN) has two components: Fixed Pattern Noise (FPN) and photo response nonuniformity (PRNU). FPN is independent of pixel signal; it is additive noise, and some high-end consumer cameras can suppress it. The FPN also depends on exposure and temperature.

PRNU is formed by variation in the dimensions of pixel and inhomogeneities in the silicon which results in variations in pixel output. It is multiplicative noise. Moreover, it does not depend on temperature and seems to be stable over time.

The values of PRNU noise increase with the signal level (it is more visible in pixels showing light scenes). In other words, PRNU noise is suppressed in very dark areas. Moreover, PRNU is not present in areas of an image that are completely saturated. Thus, such images should be ignored when searching for PRNU noise.

Since it can be shown that PRNU has a dominant presence in the pattern noise component, PRNU noise is employed as the fingerprint of camera sensors.

Nonetheless, having a larger set of cameras of the same and different models available, and a large set of ground-truth digital images captured by these devices, one can run an experiment to measure the effectiveness and fragility of existing methods. By performing such an experiment it is fairly easy to notice that state-of-the-art source identification methods suffer from a number of basic imperfections. These have been fixed by Camera Ballistics.

There are some freely available libraries that allow the computation of PRNU. Despite this, users often fail and become disheartened. Below, we reveal three major reasons for their failure. Unfortunately, for reasons of security, we are not at liberty to divulge exactly how we managed to solve the problem of providing accurate results.

**Impact of optical zoom**

Perform a simple experiment. Take a camera with a rich optical zoom option and shoot some test images with varying degrees of optical zoom. Then, carry out camera source identification using the freely available PRNU software.

You'll be disappointed by your results and you'll be asking yourself how this could possibly happen. The reason is a phenomenon called vignetting, which causes a change in the PRNU values at different zoom levels. There are several types of vignetting: mechanical, optical, natural and pixel. Some types of vignetting can be completely covered by lens settings (using special filters), but most digital cameras use built-in image processing to compensate for vignetting when converting raw sensor data to standard image formats such as JPEG or TIFF.

Camera Ballistics managed to solve the problem and provide accurate results.

**Impact of embedded camera software**

Let's assume that we have 100 different iPhone devices. Moreover, we have a digital image captured by one of these iPhones and we want to identify the particular source device. In other words, we need to have a fingerprint of each device that distinguishes it uniquely and eliminates any features it might have in common with the other devices.

On the other hand, digital consumer cameras contain embedded software that performs operations such as color filter array (CFA) interpolation, white balancing, gamma correction, color enhancement, and interpolation (digital zoom). Because this embedded software is usually common to cameras/smartphones of the same model, it introduces similar changes in the digital images produced by these cameras. This is a serious problem that results in a higher rate of false positives when a large number of source imaging devices of same model are under investigation.

**Impact of heavy JPEG compression**

Let's stay with the previous iPhone example and assume that this digital camera produces heavily compressed JPEG images. As we know, highly compressed JPEG images exhibit blocking artifacts. These blocking artifacts are another change brought into the image by the camera's embedded software and they are also common to cameras of the same model. In other words, this is another source of false positive results when linking a photo to a large set of possible source cameras of the same model. Moreover, this is quite a common problem in real-life applications (for example, when inspecting Facebook photos or YouTube videos).

---
language: "en"
---
# Accessibility and Compatibility Features

MOBILedit Forensic includes several accessibility and compatibility features designed to support users operating with Windows accessibility tools and system preferences.

* **Keyboard Access:**

  All primary functions can be performed using the keyboard. Use **Tab** and **Shift + Tab** to move between interface elements, and **Spacebar** to activate buttons.

* **Display and Contrast:**

  The application supports Windows High Contrast themes and colour filters. Interface elements remain visible when system contrast settings are applied.

* **Screen Magnification:**

  The software is compatible with Windows Magnifier and other third-party magnification tools.

* **Assistive Technologies:**

  Basic control information is exposed through Windows UI Automation. Screen readers may provide limited feedback due to the program's closed-functionality design.

* **Reports and Documentation:**

  Generated reports are provided in HTML, PDF, and Excel formats that can be read and enlarged using standard assistive technologies.

* **System Preferences:**

  MOBILedit Forensic inherits operating-system language and regional settings. Text scaling and keyboard preferences follow Windows configuration.

For additional assistance or to report an accessibility issue, contact [**support@mobiledit.com**](mailto:support@mobiledit.com).

---
language: "en"
---
# Android - Acquiring manufacturer backups

Within the security bypassing options you will see options for acquiring backups from connected devices.

The reason this has been included here is that in some circumstances, depending on make, model and OS version, it is possible that you may get additional data over and above what you would get from a logical extraction.

Sometimes a backup will export application data that might not normally be accessible with a logical extraction due to application package permission security. We do not have a specific list of devices yet, have included it in security bypassing as another option.

The following backup types are supported for direct acquisition from a connected device:

* Acquire Huawei backup

* Acquire Xiaomi MIUI backup

* Acquire Smart Switch backup

![image-20260701-144059.png](https://forensic.manuals.mobiledit.com/__attachments/a_0a3da8e47bf4ee03ac877850a2a7250580d2348d458119acfc40b3a78c19eb08/image-20260701-144059.png?cb=0b4a4b9fe9e8acacf020ec621fe82fe7)

If you do not have a connected device and, you have seized a computer containing a phone backup as part of your investigation, you can import the backup for extraction and analysis. More details can be found in the user guide pages under the heading [Import data](https://forensic.manuals.mobiledit.com/MM/sources-of-data).

It is always advisable to use dedicated forensic software to match the type of device, image or files that you wish to examine. So for mobile device-related files, you should use MOBILedit Forensic. For computer-related devices, images and files, you should use forensic software compatible with that platform.

---
language: "en"
---
# ADB backup (Extraction)

ADB backup is an Android backup. It backs up system data and app data but not the apps themselves. Some apps are not able to be backed up using ADB backup and need to be backed up independently. For example, WhatsApp and Viber.

MOBILedit Forensic can interact with the device and confirm the creation of the backup automatically. In this case, you do not have to touch the display.  
[ADB backup.mp4](https://forensic.manuals.mobiledit.com/__attachments/a_6408e2f415a3d0cd1f7dd71f633b505c8a0c985566e2843f06dd2391518cc46c/ADB%2520backup.mp4.md?cb=4be6f213c32498e296f57c40bbbd7a76)

If the MOBILedit Forensic app is not able to confirm the ADB backup on its own, a window is displayed with a notification asking you to confirm it manually on the device.

In some cases rebooting the device will help to avoid any issues with automatically confirming the ADB backup.

With Xiaomi devices and MIUI, if MOBILedit Forensic is unable to confirm the backup it may be due to "USB debugging (security settings)" not being set to "allow" in the developer options. This is different from "USB debugging" which allows the initial communication between MOBILedit Forensic and the device.

Information on how to set up a Xiaomi device and other devices correctly can be found [here](https://forensic.manuals.mobiledit.com/MM/how-to-enable-usb-debugging.md).  
![MOBILedit Forensic 9.1.0_Google Pixel 3a_ADB backup_Screenshots_01-20230126-124925.png](https://forensic.manuals.mobiledit.com/__attachments/a_3dc3a97ddd6efe06e19ec55f6a223259475074cab99fe8a006af59fda343e3f4/MOBILedit%20Forensic%209.1.0_Google%20Pixel%203a_ADB%20backup_Screenshots_01-20230126-124925.png?cb=99e38f2a103f30f6b1daf4d866059750)

![Google Pixel 3a_Full backup_Screenshot_Back up my data_02-20230126-132609.png](https://forensic.manuals.mobiledit.com/__attachments/a_3b1a929b21aba0836fcce6ea15261ab5d880c684e11233b158318ec408ca81c4/Google%20Pixel%203a_Full%20backup_Screenshot_Back%20up%20my%20data_02-20230126-132609.png?cb=6cee3604e2a7fbb3c3566f702de7cf91)

An ADB backup can be [imported](https://forensic.manuals.mobiledit.com/MM/adb-backup-import.md) into MOBILedit Forensic or it can also be saved as an [output format](https://forensic.manuals.mobiledit.com/MM/outputs-reports-exports-and-backups.md).

---
language: "en"
---
# ADB backup (Import)

![Choose_data_to_import_ADB.png](https://forensic.manuals.mobiledit.com/__attachments/a_b90b7316c8641e26b779bd5881d2e6f804826d7378f77d7e6dec5ab0d4d55b1f/Choose_data_to_import_ADB.png?cb=1160a65b9343ff9e1ecfb0eef9bef771)

To import an ADB backup into MOBILedit Forensic, follow these steps:

1. Select the "**Android ADB backup file**", which has an ".ab" file extension.

2. Import the selected file into MOBILedit Forensic. The Android ADB backup file will have an ".ab" file extension.

3. If the backup is protected by a password, enter the same password when prompted by MOBILedit Forensic.

![Choose_data_to_import_ADB_encrypted.png](https://forensic.manuals.mobiledit.com/__attachments/a_f17e3a84cbe3dae738b9f59170b3d189ddcfb5f17471d9f840791aa6061604a2/Choose_data_to_import_ADB_encrypted.png?cb=04a2e545dfe5af0aa80581038b8974d6)

If the ADB backup has been successfully imported it will be shown in the logging window as below:  
![Choose_data_to_import_MEF_backup_xml_decrypted_done.png](https://forensic.manuals.mobiledit.com/__attachments/a_95bc56b77a8b431ded881a1ca192ae80660368a7ad651881798dee7e442c31eb/Choose_data_to_import_MEF_backup_xml_decrypted_done.png?cb=8df631f11ff798506d8026cec3eec538)

Then, a Logical extraction and analysis report can be confirgured.

*** ** * ** ***

## ADB backups - General information

An Android ADB (Android Debug Bridge) backup typically includes various categories of data and artifacts from the device. However, the specific data included can vary depending operating system version in which it was created and various other factors.

Generally the following can be included in an ADB backup:

* System applications and data

* 3rd party applications and data

* Shared storage

An ADB backup can include the following categories:

1. **App Data:**

   * User app data (e.g., settings, databases, shared preferences, files within the app's private storage)

   * App-specific data (e.g., cache, logs)

   * App APK files

2. **System Data:**

   * System settings and configurations

   * System app data (limited by permissions)

3. **User Data:**

   * Contacts

   * Call logs

   * SMS/MMS messages

   * Calendar events

   * Browser data (e.g., bookmarks, history)

4. **Multimedia Files:**

   * Photos and videos (typically stored in the DCIM folder)

   * Music and audio files

5. **Documents and Downloads:**

   * Files in the Downloads folder

   * Documents and other user-created files

6. **Other Data:**

   * Wi-Fi network settings and passwords

   * Bluetooth pairings

   * Certain configuration files

Not all data might be backed up due to various limitations:

* Some applications may restrict or encrypt their data, making it inaccessible for ADB backups.

* Certain system data and settings might be excluded for security reasons.

* Data stored in some apps' private storage might not be included if the app is designed to prevent such backups.

*** ** * ** ***

### ADB backup - Encryption

The amount of data in an encrypted ADB backup is the same as in an unencrypted ADB backup. The difference lies in the security of the data rather than the quantity or type of data included. Encryption ensures that the data is secure and can only be accessed with the correct password, but it does not add additional data to the backup file.

---
language: "en"
---
# Live Update Packages

Below is a list of packages that can be updated in the Updates section from the main "Home" screen menu. All the following packages give you the most up-to-date advanced options and are essential for extracting as much data as possible. We are continuously working on updates for MOBILedit Forensic, so whenever you receive an update notification install all the newly released packages.  
![image (1).png](https://forensic.manuals.mobiledit.com/__attachments/a_77821d038c84116d4c68045667cf86dab017baef56cbd9689d2dad3a83203ea3/image%20(1).png?cb=b4e29323223598f8d09ac4d117b34129)

## Program update

Many features come pre-installed with MOBILedit Forensic and when you first start the program up and it is connected to the internet, it will connect with our server to see if there are any updates

If there is a new version of MOBILedit Forensic you will be notified on startup, either a release version or, a beta version if you are registered as a tester.

## App downgrade

Some application manufacturers restrict what data can be acquired from their apps. This is especially relevant for non-rooted phones.

To bypass this restriction you can use the App downgrade feature in MOBILedit Forensic, which will downgrade the app to a version in which it was possible to obtain the data directly from the app.  
You can read more about App downgrade [here](https://forensic.manuals.mobiledit.com/MM/app-downgrade.md).  
The App downgrade feature must be activated in the specific selection.

## Bluetooth

The Bluetooth package is specifically for connecting to some Smartwatches and uses the Bluetooth LE protocol.

## Cell towers

Data about cell towers the subject phone was connected to can be obtained. However, this is only possible with rooted Android phones and has further limitations. Cell tower locations can be viewed on an interactive map that can be accessed through the provided link in the report.

When the Cell tower package is installed, Cell tower analysis is automatically included as an analysis category in the full content or, can be chosen as a category in specific selection.

## Clouds

Downloading and installing the Cloud package installs new cloud services and updates for existing cloud services.

A subscription for MOBILedit Cloud Forensic must be linked to the license key to see and update this option.

## File exclude list

This feature allows the user to filter regular and unnecessary files. The filtering is based on hashes that the software gathers from NIST as a part of [NSLR packages](https://www.nist.gov/itl/ssd/software-quality-group/national-software-reference-library-nsrl) for Android and iOS.

## Image processing

The image processing package includes all the functionality needed to run analysis modules such "Face matcher" and "Photo recognizer"  
Read more about [Face Matcher](https://forensic.manuals.mobiledit.com/MM/data-face-matcher.md) or [Photo Recognizer](https://forensic.manuals.mobiledit.com/MM/data-photo-recognizer.md)

## iOS screenshot support

This package facilitates communication with iOS devices and captured phone photos enable you to take a screenshot of the iPhone's display.  
Android OS devices do not require an additional driver as they are supported within the main MOBILedit Forensic program for Camera and screen capture.

## Malware Detection

Malware detection lets you scan the extracted application APK files for malware and the process is based on the Yara project.

## Rooting

Within MOBILedit Forensic there is a temporary rooting option and it is essential to have the latest update version installed to get access to more devices.

## Scripts

Scripts provide essential updates for APK analysis and other functionalities within MEF. These updates ensure that the scripts used are up-to-date, enhancing the accuracy and efficiency of data analysis.

## Security bypassing

The security bypassing live update is the foundation on which all other security bypassing methods depend. It must be installed to install other security bypassing live updates.  
**Update package dependencies**

When installing packages, MOBILedit Forensic will alert you if there are required dependencies. One may need to be installed before another.

If you have additional updates selected for installation that do not require dependencies, they will be installed, just not those that require dependencies.

For the packages to be installed, the package, MOBILedit Forensic software version and license key version entitlement must all match; otherwise, the installation will fail.

---
language: "en"
---
# Add other evidence

"Add other evidence" will allow import of images or photos and present them in one of the MOBILedit Forensic report output formats.

Use cases for these features could be, talking images of damaged devices that you have received or, scene photography.

The options for import are:

**Webcam**

There are options to include a type of image and a name for the image. You can select which connected webcam to capture the image with and add as many images as you wish.

**Import images**

There are options to include a type of image and a name for the image. This enables you to import images or photos from your forensic computer. You can add as many images as you want.  
![image-20260701-133553.png](https://forensic.manuals.mobiledit.com/__attachments/a_4aca36f98115fa85e3e6ec259dcbf1c055120f0d936f0a1f02b8245dd1b0f4ac/image-20260701-133553.png?cb=597a44cfdbacc8f248dbc0ff7aefc8fb)

---
language: "en"
---
# Advanced data extraction (Android)

MOBILedit Forensic includes an **Advanced Data Extraction** feature designed to retrieve data from sandboxed Android applications---without the risk of losing user data. This feature utilizes one or both of two known CVEs (Common Vulnerabilities and Exposures) to bypass app sandboxing protections. The effectiveness of each method depends on the **Android version** and the device's **security patch level (SPL)**.

## **Exploit Methods Used**

* **Method 1** -- Supports **Android 9 through 15** with a **security patch level lower than June 2024**.

* **Method 2** -- Supports **Android 12 and 13** with a **security patch level lower than October 2024**.

During the extraction process, both methods are automatically attempted based on the device's specifications to maximize success.  
Advanced data extraction was tested on WhatsApp and WeChat, where the app was installed but the account owner had signed out.

Both Advanced data extraction and App downgrade produced different results; this is the case even when the user is signed in.

Advanced data extraction produces better results than App downgrade.

*** ** * ** ***

### **How to Use Advanced Data Extraction**

There are three ways to activate this feature:

1. **Logical Extraction \> Full Content**

   * Select the checkbox for **Advanced Data Extraction**.

   * This will attempt to extract data from **all supported sandboxed apps** automatically.

![Screenshot 2025-06-17 144813-20250617-124813.png](https://forensic.manuals.mobiledit.com/__attachments/a_65d7ee705bd9f47a59b407fa22079f71caec05f1243192bc72727a66e941f776/Screenshot%202025-06-17%20144813-20250617-124813.png?cb=b2b926a59620383a7aefcf8e7a6bf3e3)

2. **Logical Extraction \> Specific Selection \> Applications**

   * Tick the checkbox for **Advanced Data Extraction**.

   * Choose **"Let me choose"** (radio button) to manually select which apps to target.

   * This provides greater control and is useful when focusing on specific apps only.

![Screenshot 2025-06-17 145631-20250617-125631.png](https://forensic.manuals.mobiledit.com/__attachments/a_86e305eca821da5da524e12d18cac86956858b06311bbe08ec1dcb7f80398da4/Screenshot%202025-06-17%20145631-20250617-125631.png?cb=ff2cd1d46dfbdd14eb3033e45632753e)

3. **Logical extraction \> Application analysis \> Applications**

   * Enable Advanced data extraction using the tick box, select the application(s) you wish to extract and analyse data from, and proceed.

### **Execution Details and Prompts**

* A pop-up reminder informs you that the device may restart, or our Forensic connector application may be installed on the device. You will need to confirm to continue. This warning is shown again during the extraction because if the device restarts and you do not know the PIN or pattern, you will be locked out.

* Once extraction begins, you will be prompted to enter the device's **screen lock password** or **pattern** if set. This is required because the device may **restart multiple times**, and the screen lock password/pattern is used to decrypt the app data.

* You will be notified that the device has disconnected, and it will reconnect automatically.

* During the extraction process, the **Summary_full** report will indicate **which method (1 or 2)** was successfully used to extract the data.

---
language: "en"
---
# Advanced techniques to get more information from the device

Some applications do not provide the information that you need (e.g. messages, call logs) by themselves since the information is encrypted by the developer/manufacturer.

**There are a few ways how to extract the information you need:**

1. Rooting / Jailbreaking your device

2. Creating a physical image of your device

3. Using an App downgrade function in our software MOBILedit Forensic

## Rooting / Jailbreaking

### Rooting

Most Android devices should be able to be rooted. However, the process of rooting is specific to each phone model, version of Android, and build number, so you always need to find the right tool according to your phone model.

You can root a majority of modern Android phones using an app called [KingoRoot](https://www.kingoapp.com/), if for some reason this method doesn't work for you (locked bootloader, Knox, etc.), you may be able to find help on how to root your phone at [XDA Developers](https://www.xda-developers.com/), which is a website with a large active user community dedicated entirely to Android smartphones.  
Please note that sometimes it is necessary to unlock your phone's bootloader in order to root it. You can find a step-by-step tutorial on how to unlock the bootloader on your phone manufacturer's webpage.

Once rooting has been completed successfully the phone is then switched to so-called "rooted mode", and you then will be able to extract and analyze the deleted data.

If you are in need of further assistance please let us know and we will look further to help resolve any issue you are experiencing.  
Rooting your phone may void the manufacturer's warranty and could cause security risks. Please take this into consideration before performing this process.

Rooting a Samsung device will trip the Knox Warranty void flag which will make the data stored in Knox permanently inaccessible.

### Jailbreaking

There are three ways of jailbreaking your iOS:

1. **Tethered**- This method requires you to connect your iPhone to your computer and use an external application to jailbreak it. Once you restart your iPhone, the jailbreak is undone, but please note: your device will not be usable until you jailbreak it again using the same method.

2. **Semi-tethered**- This method doesn't require you to connect your iPhone to a computer in order to jailbreak it, however, the jailbreak is still undone every time you reboot your device, or, after a certain amount of time passes.

3. **Untethered**- This method doesn't necessarily require a computer to perform a jailbreak on your device and also modifies the iOS on a deeper level which means that no matter how many times you reboot your device, it stays jailbroken until you manually "un-jailbreak" it.

There are specific known ways to jailbreak almost every iPhone, iPad or iPod Touch running on almost every iOS, except the latest releases - as it usually takes a few months to find a way of jailbreaking the newest version of iOS.

This means that there is no way of describing them all in a single article.

Currently, the most often used apps for jailbreaking iOS devices are Pangu or Cydia Impactor. You can learn more about how Cydia works on the app developer's official website [here](http://www.cydiaimpactor.com/), or you can read[this article](https://downloadcydia.org/cydia-impactor/) which describes a simplified process of iOS jailbreaking.

**You can see a full list of available jailbreaks for each device and version** [**here**](https://www.reddit.com/r/jailbreak/wiki/escapeplan/guides/jailbreakcharts)**.**  
Jailbreaking a device may void the manufacturer's warranty and could cause security risks.

Please take this into consideration before performing this process.

## Creating a physical image of your device

There are many ways to create a physical image from a device. You can, of course, use some tools of your own and use our software for extraction, but our product MOBILedit Forensic does offer some tools as well; however, these methods are exclusively available in MOBILedit Forensic ULTRA due to dual-use regulations:

### TWRP Method

The device has to have its bootloader unlocked in order to proceed with this method. Please be aware that unlocking the bootloader will delete ALL the user data.

Additionally, you need to be able to decrypt the physical image which is not possible in MOBILedit Forensic PRO and only possible in MOBILedit Forensic ULTRA.

Therefore, TWRP is not a suitable method for forensic investigations yet, can be useful for setting up test devices.

Every Android phone has a "recovery" partition which is by default used for performing factory resets using an OEM's preloaded tools. However, this partition can be modified in order to replace the default tools with third-party recovery tools such as TWRP.

These recoveries are (unlike the stock ones) capable of modifying all the internal system partitions of your phone or tablet (they need this capability in order to flash custom firmware).

TWRP even comes with a built-in file manager with unlimited root access so you can modify, add or delete any system files manually. This process allows you to gain a physical image, therefore bypassing the otherwise locked device´s protection.

However, if the image is encrypted by the system itself, we are only able to get the encrypted physical image.

More information about how to use the TWRP method can be found [here](https://forensic.manuals.mobiledit.com/MM/flash-phone-with-recovery-image-twrp.md).

### Rooting

In MOBILedit Forensic there are 5 methods for temporary rooting.

The root access is removed once the device is restarted or by pressing "Stop Communication service".

More information about how to use the Rooting exploits in MOBILedit Forensic can be found [here.](https://forensic.manuals.mobiledit.com/MM/rooting.md)

## Using an App downgrade function in our software MOBILedit Forensic

Due to better security, some application manufacturers made restrictions on what data can be acquired from their apps. This is especially relevant for non-rooted phones.

To bypass this we have introduced the App downgrade, feature in MOBILedit Forensic, which will downgrade the apps to a version, in which there was no problem in obtaining the data from them directly.  
Please note that only some apps support this feature as of yet, although we are working on expanding their list.

More information about how to use the App downgrade in MOBILedit Forensic can be found [here](https://forensic.manuals.mobiledit.com/MM/app-downgrade.md).

---
language: "en"
---
# AirTags & Bluetooth Beacons

## Overview

MOBILedit Forensic is able to identify **Apple AirTags and other Bluetooth tracking beacons** by analysing application databases stored on the device. These artefacts can indicate that a device has **detected, seen, or interacted with** nearby tracking accessories.

This analysis relies on **on-device application data**. Availability depends heavily on the platform, OS version, and extraction type.

*** ** * ** ***

### Apple AirTags -- Data Sources

#### **Android**

On Android devices, AirTag-related detections are stored within Google services responsible for Bluetooth and unwanted tracker alerts.

**Location in MOBILedit Forensic:**

`Applications > Google Play Services > Detected devices`

**Requirements:**

* Rooted device **or**

* Decrypted physical extraction **or**

* Advanced Data Extraction

Logical extractions alone are generally insufficient, as the relevant databases are protected within the Google Play Services sandbox.  
![image-20251213-110309.png](https://forensic.manuals.mobiledit.com/__attachments/a_830bceb26edb4303d07e5228f1cd640ecac51b457269f77670ff8a46ad894125/image-20251213-110309.png?cb=c240a9eda91b8bbb7800172a8d0cf917)

*** ** * ** ***

#### **iOS**

On iOS devices, AirTag data is managed by Apple's *Find My* framework.

**Location in MOBILedit Forensic:**

`Applications > Find My > AirTags`

This may include:

* Detected AirTags

* AirTags seen moving with the device

* Alerts related to unknown or nearby AirTags

![image-20251213-110420.png](https://forensic.manuals.mobiledit.com/__attachments/a_47dedcadb682c03742cb7e3db719992b6bc8db31a9de4fc427e568509caa1c82/image-20251213-110420.png?cb=04ede74fd1c907c97f4c68e36a58e101)

*** ** * ** ***

### iTunes Backup Limitation (iOS)

AirTag data **was not found in standard iTunes backups** during testing. This strongly suggests that the relevant *Find My* databases are **excluded from backups or stored in protected system locations**.

**Implication:**

Access to AirTag artefacts on iOS may require:

* A **jailbreak**, or

* Another extraction method that provides access beyond the iTunes backup scope

This behaviour is consistent with Apple's data protection model for sensitive location and tracking information.

*** ** * ** ***

### Key Points to Note

* AirTag evidence reflects **detection or proximity**, not ownership.

* Presence of records does **not** prove who placed or controlled the AirTag.

* Absence of data does **not** confirm that no AirTag was present.

* Results depend on OS version, device state, and extraction method.

*** ** * ** ***

### Summary Table

|      Platform       |              Data Location              |             Extraction Requirements             |
|---------------------|-----------------------------------------|-------------------------------------------------|
| Android             | Google Play Services → Detected devices | Root / Decrypted Physical / Advanced Extraction |
| iOS                 | Find My → AirTags                       | Jailbreak or equivalent access                  |
| iOS (iTunes backup) | Not available                           | Data not present in backups                     |

---
language: "en"
---
# Allow accessories to connect

## Allow Accessories to Connect

When connecting a device with MOBILedit Forensic, you may encounter situations where an iPhone, iPad, or iPod touch does not communicate with your forensic workstation. This is often due to Apple's security settings restricting accessory connections when the device is locked.

### **Unlocking the Device for Access**

To establish a connection with **MOBILedit Forensic**, ensure the device is unlocked before connecting:

1. **Unlock the Device** -- Use the passcode, Face ID, or Touch ID to unlock the iPhone, iPad, or iPod touch.

2. **Connect the Device** -- Plug the device into your forensic workstation via USB.

3. **Trust the Computer** -- If prompted, tap "Trust" to authorize the connection.

4. **Maintain Connectivity** -- Once connected and trusted, the device remains accessible even if it locks again.

If the device is not unlocked within **one hour** of its last connection, it may block communication with the forensic workstation, requiring re-authentication.  
Unlocking the device will usually be the first option however, if you are in a situation where you need to connect, disconnect and re-connect multiple times outside of the 1 hour window, you may choose to enable "Allowing Accessories When Locked".

If there are any issues with extraction or connectivity this setting should be enabled as part of the troubleshooting process.

#### **Allowing Accessories When Locked**

To prevent connection issues, you can enable accessory access even when the device is locked:

1. Open **Settings** on the iPhone or iPad.

2. Go to **Face ID \& Passcode** or **Touch ID \& Passcode**.

3. Enter the device **passcode** if prompted.

4. Scroll down and toggle **Accessories** under "Allow Access When Locked."

This setting is off by default for security reasons. If disabled, you must unlock the device before accessories (including forensic tools) can communicate.

![IMG_0086.PNG](https://forensic.manuals.mobiledit.com/__attachments/a_158dcc9ed36dfd6c4595f8a80d551611d393dab82d6b805d1fb645501f423f6e/IMG_0086.PNG?cb=b3876c6c1ab53da14a1f1c509d6d3eba)

**Supervised devices** (e.g., corporate or managed devices) may have restrictions controlled by **MDM (Mobile Device Management)**, preventing forensic tools from accessing data.

---
language: "en"
---
# Analyze - process photos

Once you have [created a reference sensor fingerprint](https://forensic.manuals.mobiledit.com/MM/learn-create-fingerprint.md) you can use the *Analyze* function to take a folder of photos as an input, and Camera Ballistics will determine whether they were actually taken by a certain camera (of which you have the fingerprint) or not. This process is automated and should not take long.

To start, click on the "Analyze" button on the home page.  
![image-20200710-093341.png](https://forensic.manuals.mobiledit.com/__attachments/a_d091b37bce44d959093019fd1f2a2eb81588952272587f40056913f4c163c683/image-20200710-093341.png?cb=db1ad5bfa2ceb1cad1f003cf8b7a8d44)

You will be asked to provide a folder of pictures - the subject photos in question you want to have analyzed.

The photos from the folder will immediately load and display in the software as a preview.  
![image-20200710-093600.png](https://forensic.manuals.mobiledit.com/__attachments/a_a5bf3958436ef0b265f03aeb9744e7389202d35e1b9ea0928f9f31695e4acbe6/image-20200710-093600.png?cb=843b9b1e9d41922191361cfd1660ad59)

Upon clicking the "Next" button you will be asked to provide a fingerprint. Please select the .fnp file you have previously created. Its detailed data will load and display to you. There is also some customization of the analysis available.  
![image-20200710-093639.png](https://forensic.manuals.mobiledit.com/__attachments/a_ef31c52afc504b663ac7094736a61e12f74989bf9ccad7049f52b1ab188d7124/image-20200710-093639.png?cb=47628916a5b5c1723e1a66063161bbea)

Click on "Next" to start the analysis process. This process will take up to a few minutes. The results will be then marked by green or red color.  
![image-20200710-094300.png](https://forensic.manuals.mobiledit.com/__attachments/a_2a1965d0f435375ed20ed8a691caf166a8c42522e40b21578a632503e38053c9/image-20200710-094300.png?cb=05532c299f3773fbb0251426b849091b)

Red color means the photo was not taken by the selected camera, while green means the photo is a positive match to the camera sensor.

The matched photos are placed in four categories of the probability of how accurate the match is (very high, high, medium, low). You can view this by hovering over the photo.  
![image-20200710-094527.png](https://forensic.manuals.mobiledit.com/__attachments/a_19c0505215a61d969380871ca8a66897e76711984d2b508b80349b71986818ae/image-20200710-094527.png?cb=5795ad51b56de1114b9d92ed4e12a189)

Clicking on "Show detail result" will show you all the info about the match as well as correlation.  
![image-20200710-094605.png](https://forensic.manuals.mobiledit.com/__attachments/a_76955484c1b30b1b2795657dc38dd966f0b638dcb10753b62a511db2093955b2/image-20200710-094605.png?cb=02535e11ac8f1addd389c95d348ffc1a)

Clicking on "Show in external viewer" will open the photo in your PC's default picture viewer.

The result page also offers you the option to filter the results - see the dropdown menu in the upper right corner for more details.  
![image-20200710-095153.png](https://forensic.manuals.mobiledit.com/__attachments/a_4114f7de4b78124dc609fe4af6a1cf83e7aab25d7660a07d6e479a59c8e21164/image-20200710-095153.png?cb=80d320a5261783eb331deca0a038f105)

If not selected earlier (in the step of loading the fingerprint) there is an option to create a PDF report available.

Simply click on the "Generate report" in the bottom right corner and select a location where you would like the .pdf file to be stored on your PC.

![image-20200710-095833.png](https://forensic.manuals.mobiledit.com/__attachments/a_0116c6d42e6cf857c7efde3414566a23415f1b725e5c8f6688d7b684758a6872/image-20200710-095833.png?cb=25725df030374c4c8fcd5816d43e7cc0)  
![image-20200710-095921.png](https://forensic.manuals.mobiledit.com/__attachments/a_20d06723a8ee50d29a43fdebf43973ba246fe41599dea825a7e4fded332d3ecd/image-20200710-095921.png?cb=97893619619c5ccfb121e1572acafa69)

A PDF report, similar to the one from [MOBILedit Forensic](https://www.mobiledit.com/forensic-express), will be created.

Camera Ballistics also allows you to have the Analysis available while extracting data from a phone in Forensic.

---
language: "en"
---
# Android

The following article will explain all the necessary steps that need to be undertaken to successfully connect an Android phone with MOBILedit Forensic. The procedure is required only for the first connection. An Android phone can be connected to a PC by USB cable, which transfers data faster, or via Wi-Fi, which is easier.

USB connection is the best method as it will allow better access to extract more data. The other methods should be used where a USB connection isn't possible due to a damaged port. With some devices, Wi-Fi or Bluetooth must be used to get certain data. However, this is generally not applicable to Android devices.

## Connecting Android phones via USB cable

[![How to connect Android to PC_Front.png](https://forensic.manuals.mobiledit.com/__attachments/a_18675f7124861000886e5ead2f0775acbe44da55f14905ad8e43a55f4c40448f/How%20to%20connect%20Android%20to%20PC_Front.png?cb=d3f89a48d56b4ebc9d64d91028e396bf)](https://www.youtube.com/watch?v=y_78HkdT_hw&feature=emb_logo)

[How to connect Android to PC](https://www.youtube.com/watch?v=y_78HkdT_hw&feature=emb_logo)

To connect to an Android phone, you need to know the PIN. If you don't know the PIN, please try one of the MOBILedit Forensic Security bypassing methods available in the Pro and ULTRA editions.

Once unlocked, follow the steps below:

1. Turn on [Developer options](#)

2. [Enable USB debugging](https://forensic.manuals.mobiledit.com/MM/how-to-enable-usb-debugging.md), so your phone can be connected to a PC

3. [Enable the "Stay awake" option](https://forensic.manuals.mobiledit.com/MM/how-to-enable-stay-awake-option.md), so the phone doesn't disconnect

4. For Windows 10 and above the pre-installed drivers are usually compatible. If not, download, install and use the [Universal Android driver](https://forensic.manuals.mobiledit.com/MM/how-to-install-a-universal-android-driver.md)

5. Connect your phone to a PC and start MOBILedit Forensic

6. [Confirm the RSA fingerprint](https://forensic.manuals.mobiledit.com/MM/how-to-confirm-rsa-fingerprint.md) on your phone's display

7. [Select MTP mode](https://forensic.manuals.mobiledit.com/MM/connecting-in-mtp-mode.md) on the phone's display. On some devices, it may be called a different name. For example, on Samsung devices, it can be called "Transferring files / Android Auto"

8. Now you should have successfully connected your phone and device details should be showing on the "Connect phone or import data" screen.

The MOBILedit Forensic Android Connector is required to fully communicate with the device and must have the correct [permissions](https://forensic.manuals.mobiledit.com/MM/connector-permissions)granted when it is installed.

The application is automatically installed by MOBILedit Forensic yet, if it cannot be installed automatically, download the MOBILedit Forensic Android Connector application from our [User Portal](https://portal.mobiledit.com/) and [install it manually](https://forensic.manuals.mobiledit.com/MM/connector-installation).  
In the cases where you connect your phone to the PC prior to step 3 above, the wrong driver might have been installed by Windows. That would cause MOBILedit to not recognize the phone. Click [here](https://forensic.manuals.mobiledit.com/MM/how-to-install-a-universal-android-driver.md) for a guide on disabling any incorrect Windows drivers for the device by using our Universal android driver.

## Connecting Android phones via Wi-Fi

Download the**MOBILedit Forensic Android Connector** application from our [++User Portal++](https://portal.mobiledit.com/)++**.**++

Now start the connection app on your phone and follow the steps below:

1. Ensure the Wi-Fi is turned on, and the device and workstation are connected to the same network.

2. Run MOBILedit Forensic and click on the Connect button.

3. Select Phone -- Wi-Fi Connection and then enter the IP address as displayed in the app on the phone.

4. Allow the connection on your phone if the key corresponds with the key in Connection Wizard.

5. Once your phone is identified, click on the "Finish" button and the device will connect automatically.

Be aware that it is not possible to activate a phone with Android 10 OS with a single phone licence through wifi. However, if you activate a phone through a cable, you will be able to use it with wifi later.  
If your working practises do not allow for your workstation or network to be internet connected (air-gapped), you can still connect via Wi-Fi by using a standalone Wi-Fi router not connected to the internet.

## If your phone doesn't connect

* MOBILedit will require the installation of the MOBILedit Forensic Connector app onto the phone. If it does not install automatically we recommend disconnecting the phone, restarting MOBILedit and then reconnecting the phone.

* Another option is to download the Connector app directly from the [++User Portal++](https://portal.mobiledit.com/).

* If you have a Xiaomi phone, you need to [allow the required settings](https://forensic.manuals.mobiledit.com/MM/how-to-enable-usb-debugging.md) before installation.

* USB debugging not turning on? Is the RSA key not showing on the screen? Try turning the USB debugging off and on again after connecting the phone. Changing the USB connection mode between MTP, charging only and back again may also help.

* Check that the phone is not set in Mass Storage, or other modes, not intended for file-level access.

* If you use any other phone tool, such as HTC Manager, Eclipse, or Android Studio, you should stop the ADB process or application from running in Task Manager. If you use MOBILedit Forensic more than the conflicting program, uninstall it.

* If you are using Windows 7 OS and your phone is not automatically connected, or not recognized, please follow the article of [manually changing the ADB driver](https://forensic.manuals.mobiledit.com/MM/how-to-install-a-universal-android-driver.md).

* Problems with connecting a Huawei phone? Go [here](https://forensic.manuals.mobiledit.com/MM/how-to-enable-usb-debugging.md) to read how to resolve them.

* Problems with connecting a Xiaomi phone? Go [here](https://forensic.manuals.mobiledit.com/MM/how-to-enable-usb-debugging.md) to read how to resolve them.

* On the latest Android OS versions "Auto Blocker" might be enabled and not allow USB debugging, it should be turned off in "Security and Privacy" settings.

---
language: "en"
---
# Android - Ativar a opção "Fique acordado"

A opção Fique Acordado deve estar definida no seu telefone para permitir a comunicação contínua entre o telefone e o software. Se o telefone não estiver definido como Permanecer Acordado e estiver, por exemplo, definido no modo de Economia de Energia, o telefone poderá se desconectar de outras fontes, incluindo nosso software, e interromper o processo de extração e análise.

1. Vá para Configurações no seu telefone.

![Screenshot_2019_01_17_13_11_45.png](https://forensic.manuals.mobiledit.com/__attachments/a_461e64426fdf0747873e2ebc5118e11f04a33600f1b04274f64da0a51dc351a3/Screenshot_2019_01_17_13_11_45.png?cb=74eeb5981ea7c9144f76180b88b22255)

2. Escolha "Geral" nos favoritos das Configurações.  
![Screenshot_2019_01_17_13_12_17.png](https://forensic.manuals.mobiledit.com/__attachments/a_3d1a5f82224541bdca8494c820b028ec9bf44a50725d0e70bb9fc88d09bd746f/Screenshot_2019_01_17_13_12_17.png?cb=73e3f43070b320fca1cbc12cb756e8ae)

3. Role para baixo para encontrar as "Opções do Desenvolvedor".

![Screenshot_2019_01_17_13_12_47.png](https://forensic.manuals.mobiledit.com/__attachments/a_f0ff543bedcf4ebf49fed43432c32741d07b626dfc0a3f600aae11541dbd7244/Screenshot_2019_01_17_13_12_47.png?cb=6cf7fc9e0d679a9a0d32aca231abf547)

Clique [aqui](https://support.mobiledit.com/portal/kb/articles/como-viabilizar-a-verifica%C3%A7%C3%A3o-do-usb#Veja_todas_as_instrues_com_imagens) para orientar como ativar as Opções do Desenvolvedor no seu telefone.

4. Abra as Opções do Desenvolvedor e encontre a linha de opção "Fique Acordado".  
![Screenshot_2019_01_17_13_13_39.png](https://forensic.manuals.mobiledit.com/__attachments/a_e01c3d95ac700fb82a773c9fc6578c2b5e34e126535a7e3c193c1de305865357/Screenshot_2019_01_17_13_13_39.png?cb=54f8bede60966f4ed400bb6f58a5f93e)

5. Clique no botão ao lado de Ficar Acordado para ativar a prevenção da tela escurecendo.

![Screenshot_2019_01_17_13_13_52.png](https://forensic.manuals.mobiledit.com/__attachments/a_a4bc8e712483920717da4e4274952f4820a3b5bd134f952d9c6c2c7b2e36e9d5/Screenshot_2019_01_17_13_13_52.png?cb=0939f4fef148f3378d08ea951eae6423)

---
language: "en"
---
# Android backups

The Android operating system is used by many different handset manufacturers. The native backup format for Android is an ADB (Android Debug Bridge) backup however, handset manufacturers often choose to support their own native backup formats. We have chosen to support the import of backups from the most popular device manufacturers.

Sometimes a backup may be all you have as a result of seizing a suspects computers. Depending on the SW tool used for examing the computer, it may or may not support proper and detailed analysis of mobile device backups.

Any mobile device backup should be analysed using a SW tool capable of importing and analysing mobile backups correct, like MOBILedit Forensic.

Below is an overview of the Android backups supported by MOBILedit Forensic.  
Importing of Android backups is NOT available for the Single Phone license of MOBILedit Forensic and is available only for the Unlimited license editions of MOBILedit Forensic; Standard, PRO \& ULTRA.

*** ** * ** ***

* [ADB backup (Import)](https://forensic.manuals.mobiledit.com/MM/adb-backup-import.md)

* [Huawei backup](https://forensic.manuals.mobiledit.com/MM/huawei-backup.md)

* [Xiaomi MIUI backup folder](https://forensic.manuals.mobiledit.com/MM/xiaomi-miui-backup.md)

* [Samsung Smart Switch backup](https://forensic.manuals.mobiledit.com/MM/samsung-smart-switch-backup.md)

* [Samsung feature phone backup](https://forensic.manuals.mobiledit.com/MM/samsung-feature-phone-s-backup-import.md)

---
language: "en"
---
# Android - Confirmar la huella digital RSA

Este mensaje le indica que necesita confirmar la huella digital RSA en la pantalla del teléfono. Debería aparecer una ventana emergente en la pantalla de su dispositivo. Si no aparece un cuadro de diálogo, vuelva a conectar el teléfono para que vuelva a aparecer.  
![Screenshot_2019_03_08_11_30_35_174_com_android_systemui.png](https://forensic.manuals.mobiledit.com/__attachments/a_59b2eb4c7f50e20ec948887f236daeac836937e5e7049e688098cf5f65e37389/Screenshot_2019_03_08_11_30_35_174_com_android_systemui.png?cb=ce6d0c278fbab587b8a4eb1af0529fcc)

Nota para usuarios multicuenta: Si utiliza un teléfono multicuenta, asegúrese de estar utilizando la cuenta principal. De lo contrario, no podrá utilizar nuestro software correctamente y tendrá dificultades al conectar su dispositivo.

---
language: "en"
---
# Android - Confirme a impressão digital da RSA

Esta mensagem informa que você precisa confirmar a impressão digital RSA na tela do telefone. Deve haver uma janela pop-up na tela do seu dispositivo. Se não houver diálogo, reconecte o telefone para que a caixa de diálogo seja exibida novamente.  
![RSA_Fingerprint.png](https://forensic.manuals.mobiledit.com/__attachments/a_40838264cd62d2f7d5c344219b457e238335ae5708fa2e7a011c4dc56d378b35/RSA_Fingerprint.png?cb=4a2aa0c49f5b35988c8c34258bcc19f0)

Observação para usuários com várias contas: se você estiver usando um telefone com várias contas, verifique se está usando a conta principal. Caso contrário, você não poderá usar nosso software adequadamente e terá dificuldades ao conectar seu dispositivo.

---
language: "en"
---
# Android - Español

Para conectar correctamente un teléfono, se deben completar algunos pasos fundamentales para esta herramienta o cualquier otra. Estos ajustes solo serán necesarios la primera vez. Después de realizarlos, podrá disfrutar de las funcionalidades de todos nuestros productos. Se puede conectar el teléfono Android a un PC por medio de un cable USB, que permite una transferencia de datos más rápida, o por wifi, que resulta más fácil.

[Descargue aquí nuestro folleto de instrucciones para imprimirlo](https://download.mobiledit.com/documents/connection%20sheet%20a4%20lt.%20america.pdf)  
[![How to connect Android to PC_Front.png](https://forensic.manuals.mobiledit.com/__attachments/a_408bdf6815e136b15cbd5813ed14615f68cfdd85728f815ecb61a6fa975ba2c4/How%20to%20connect%20Android%20to%20PC_Front.png?cb=d3f89a48d56b4ebc9d64d91028e396bf)](https://www.youtube.com/watch?v=y_78HkdT_hw&feature=emb_logo)

[How to connect Android to PC](https://www.youtube.com/watch?v=y_78HkdT_hw&feature=emb_logo)  
¡No conecte el teléfono a su PC antes del paso 3!

Habilite la depuración USB para que su teléfono se pueda conectar a un PC

1. [Habilite la opción Permanecer activo](https://forensic.manuals.mobiledit.com/MM/como-habilitar-la-depuracion-usb.md) para que su teléfono no se desconecte

2. Instale el controlador para dispositivos Windows para su teléfono, descargable [aquí](https://www.mobiledit.com/download-list/universal-android-driver)

3. Ahora conecte su teléfono a un PC que ejecute MOBILedit

4. [Confirme la huella digital RSA](https://forensic.manuals.mobiledit.com/MM/android-confirmar-la-huella-digital-rsa.md) en la pantalla de su teléfono

5. [Seleccione el modo MTP](https://forensic.manuals.mobiledit.com/MM/conexion-en-modo-mtp.md) en la pantalla del teléfono

¡Ya puede disfrutar de nuestro producto! No necesita hacer nada más, MOBILedit encontrará su teléfono automáticamente.

Si usted conectó su teléfono al PC antes del paso 3, es posible que Windows haya instalado el controlador equivocado. En ese caso, MOBILedit no podrá reconocer el teléfono. [Aqui](https://www.mobiledit.com/download-list/universal-android-driver) encontrará una guía para borrar el controlador incorrecto de Windows con nuestro controlador universal de Android.

## Si su teléfono no se conecta

* MOBILedit solicitará la instalación en su teléfono de una pequeña aplicación llamada Connector. Si no se instala automáticamente, recomendamos reconectar el teléfono y reiniciar MOBILedit, o descargar la app Connector directamente [aqui](https://www.mobiledit.com/downloads). Si su teléfono es de la marca Xiaomi, otorgue permisos para los ajustes necesarios antes de la instalación.

* ¿La depuración por USB no se activa? ¿La clave RSA no aparece en la pantalla? Intente desactivar la depuración por USB y reactivarla de nuevo después de conectar el teléfono.

* Asegúrese de que el teléfono no esté en modo de almacenamiento masivo.

* Si lo anterior no soluciona el problema y usted utiliza cualquier otra herramienta de teléfono, como HTC Manager, Eclipse o Android Studio, será necesario detener el proceso ADB en el Administrador de tareas, o desinstalar el software.

* Si utiliza el sistema operativo Windows 7 y su teléfono no se conecta automáticamente o no es detectado, siga [las instrucciones en el artículo](https://forensic.manuals.mobiledit.com/MM/como-instalar-o-driver-do-universal-android.md) sobre cómo cambiar manualmente el controlador ADB.

* ¿Problemas para conectar un teléfono Huawei? Haga clic [aquí](https://forensic.manuals.mobiledit.com/MM/como-habilitar-la-depuracion-usb.md) para averiguar cómo evitarlos.

* ¿Problemas para conectar un teléfono Xiaomi? Haga clic [aquí](https://forensic.manuals.mobiledit.com/MM/como-habilitar-la-depuracion-usb.md) para averiguar cómo evitarlos.

---
language: "en"
---
# Android - Habilitar la opción "Permanecer activo"

La opción Permanecer activo debería estar configurada en su teléfono para permitir una comunicación continua entre el teléfono y el software. Si el teléfono no está configurado en Permanecer activo, y está en modo Ahorro de energía, podría desconectarse de nuestro software, y de otras fuentes, e interrumpir el proceso de extracción y análisis.

1. Acceda a la Configuración de su teléfono.

![3ff5ddb5-5fd4-40ac-b436-2273169f7207.png](https://forensic.manuals.mobiledit.com/__attachments/a_d8340bfb5ff6a3170df1529103b8c4061452c8d6bcfc37514270a0fbe5ff7fe2/3ff5ddb5-5fd4-40ac-b436-2273169f7207.png?cb=b48728fe9850013ebb15c382197663e2)

2. Elija "General" en los Marcadores de Configuración.  
![QuickMemo _2016-08-05-14-12-35 (1).png](https://forensic.manuals.mobiledit.com/__attachments/a_1d0dae8c6f6d485487ceb12ba6dd10acd865299c50aa53926c6bea7575548def/QuickMemo%20_2016-08-05-14-12-35%20(1).png?cb=094b78e9f5f9bc8dd54bde56bdc7f31d)

3. Desplácese hacia abajo hasta encontrar las "Opciones del desarrollador".  
![QuickMemo _2016-08-05-14-12-43 (1).png](https://forensic.manuals.mobiledit.com/__attachments/a_70fa4a983c11abe376626b30fc16919903542cc638ce68ff9d4e1a0af56d891f/QuickMemo%20_2016-08-05-14-12-43%20(1).png?cb=8839e383cb551225124dc35854405ccb)  
Haga clic aquí para obtener una guía sobre cómo habilitar las Opciones del desarrollador en su teléfono.

4. Abra las Opciones del desarrollador y localice la opción "Permanecer activo".  
![QuickMemo _2016-08-05-14-12-54 (1).png](https://forensic.manuals.mobiledit.com/__attachments/a_5bb6fc6e419f013127104d84992cfc51570bc35db334401ba6c2dc79657b2dd4/QuickMemo%20_2016-08-05-14-12-54%20(1).png?cb=a46ee7d754f9fa381f88aa6711879675)

5. Haga clic en la caja junto a Permanecer activo para evitar que la pantalla se apague.  
![QuickMemo _2016-08-05-14-59-56 (1).png](https://forensic.manuals.mobiledit.com/__attachments/a_d6dcbff15361ec77d226169592e99a94f187d71f9b0ef6c3c63b27db73311bb1/QuickMemo%20_2016-08-05-14-59-56%20(1).png?cb=989c3cde9d23d86396aab100a98b6ec6)

---
language: "en"
---
# Android - Português

Para obter uma conexão telefônica bem-sucedida, há uns passos importantes que devem ser seguidos para essa ou qualquer outra ferramenta. Isso só é necessário pela primeira vez. Depois da primeira vez, você pode aproveitar a funcionalidade de todos os nossos produtos. Um telefone Android pode ser conectado a um PC por cabo USB, que transfere dados mais rapidamente ou através de Wi-Fi, o que é mais fácil.

[Faça o download da nossa folha de instruções para impressão aqui (em inglês)](https://download.mobiledit.com/documents/Connection%20sheet%20A4%20Europe.pdf)

## Como conectar o telefone por cabo USB

[![How to connect Android to PC_Front.png](https://forensic.manuals.mobiledit.com/__attachments/a_f4b08f23ccb667bdd42dd15baaf4826e4026cb31113164aa7c7adb2b1867fcae/How%20to%20connect%20Android%20to%20PC_Front.png?cb=d3f89a48d56b4ebc9d64d91028e396bf)](https://www.youtube.com/watch?v=y_78HkdT_hw&feature=emb_logo)

[How to connect Android to PC](https://www.youtube.com/watch?v=y_78HkdT_hw&feature=emb_logo)  
Não ligue o telefone ao seu PC antes do passo 3!

1. [Ative a verificação do USB](https://forensic.manuals.mobiledit.com/MM/como-viabilizar-a-verificacao-do-usb.md), para que seu telefone possa ser conectado a um PC

2. [Ative a opção Ficar Acordado](https://support.mobiledit.com/portal/kb/articles/4-android-ativar-a-op%C3%A7%C3%A3o-fique-acordado), para que o telefone não seja desconectado

3. Instale o driver de dispositivo do Windows para o seu telefone, [baixe aqui](https://download.mobiledit.com/documents/Connection%20sheet%20A4%20Europe.pdf)

4. Agora conecte seu telefone a um PC com MOBILedit ligado

5. [Confirme a impressão digital RSA](https://forensic.manuals.mobiledit.com/MM/android-confirme-a-impressao-digital-da-rsa.md) no ecrã do seu telefone

6. [Selecione o modo MTP](https://forensic.manuals.mobiledit.com/MM/conectando-no-modo-mtp.md) no display do celular

Agora aproveite nosso produto! Você não precisa fazer mais nada, o MOBILedit encontrará seu telefone automaticamente.

Caso você tenha conectado seu telefone ao PC antes da etapa 3 acima, Windows podia instalar um driver errado. Isso causaria que a MOBILedit não reconhece o telefone.

[Aqui](https://support.mobiledit.com/portal/kb/articles/como-instalar-o-driver-do-universal-android) está um guia sobre como remover o driver incorreto do Windows pelo nosso Universal Android One.

### Se o seu telefone não se conecta

* O MOBILedit exigirá a instalação de um pequeno aplicativo chamado Connector no seu telefone. Se ele não for instalado automaticamente, recomendamos reconectar o telefone e reiniciar o MOBILedit ou baixar o aplicativo Connector diretamente do [Google Play](https://play.google.com/store/apps/details?id=com.compelson.meconnector). Caso você tenha um telefone Xiaomi, [permita as configurações necessárias](https://forensic.manuals.mobiledit.com/MM/como-viabilizar-a-verificacao-do-usb.md) antes da instalação.

* Verificação do USB não se liga? Chave RSA não está aparecendo na tela? Tente desligar e ligar novamente a verificação do USB depois de conectar o telefone.

* Assegure-se de que o telefone não esteja definido no modo de armazenamento em massa.

* Se você usar qualquer outra ferramenta de telefone, como o HTC Manager, Eclipse, Android Studio, você precisa interromper o processo de ADB no Gerenciador de Tarefas ou desinstalar o software, se isso não ajudar.

* Caso você esteja usando o sistema operacional Windows 7 e seu telefone não esteja conectado automaticamente, nem seja reconhecido, siga o artigo [de Alteração manual do driver ADB](https://forensic.manuals.mobiledit.com/MM/como-instalar-o-driver-do-universal-android.md).

* Problemas com a conexão de um telefone Huawei? Vá [aqui](https://forensic.manuals.mobiledit.com/MM/como-viabilizar-a-verificacao-do-usb.md) para verificar como evitá-los.

* Problemas com a conexão de um telefone Xiaomi? Vá [aqui](https://forensic.manuals.mobiledit.com/MM/como-viabilizar-a-verificacao-do-usb.md) para verificar como evitá-los.

Todos os telefones Android são suportados, exceto alguns modelos especiais e incompatíveis. A maneira mais fácil de verificar se o seu telefone é suportado é baixar MOBILedit e conectar seu telefone.

## Como conectar o telefone por Wi-Fi

Você também pode conectar seu telefone Android por **Wi-Fi** , é mais fácil, mas o telefone e o PC precisam estar na mesma rede, por favor, leia as [instruções](https://forensic.manuals.mobiledit.com/MM/conexao-wi-fi-android.md).

---
language: "en"
---
# Android recovery data acquisition

Every Android phone has a "recovery" partition which is used for performing factory resets using an OEM's preloaded tools. However, this partition can be modified in order to replace the default tools by third-party recovery tools such as [TWRP](https://twrp.me/about/) or [CWM](https://forum.xda-developers.com/wiki/ClockworkMod_Recovery).

These recoveries are (unlike the stock ones) capable of modifying all the internal system partitions of your phone or tablet (they need this capability in order to flash custom firmware).

TWRP even comes with a built-in file manager with unlimited root access so you can modify, add, or delete any system files manually.

The most important thing is that TWRP has a working MTP connection and ADB enabled, which**allows us to extract almost all data stored on your device and create physical images from them**.

By default, you can flash TWRP (or another recovery) image files to almost any device with an unlocked bootloader (a locked bootloader prevents users from sideloading any software to system partitions, so in order to flash anything on such device, you need to unlock the bootloader first).

You can do so by using the "Fastboot" mode which allows the user to flash various system partitions including recovery. You can control your phone in the "fastboot" mode using Windows or Linux command line (similar to ADB).

The universal commands for flashing recovery images while in the "fastboot" mode are:

* **fastboot flash recovery "xxx.img"** -- flash certain recovery image

* **fastboot oem unlock** -- unlocks bootloader on supported devices

* **fastboot boot "xxx.img"** -- boots straight from IMG file

* **fastboot reboot recovery** -- reboots to recovery

* **fastboot reboot** -- reboots the device

Samsung phones are different. They have "Download mode" instead of regular fastboot. Therefore, they can be controlled using Odin, a tool for flashing software developed by Samsung, or its open-source alternative called Heimdall.

Samsung phones also don't have their own recovery partition like other Android smartphones. Instead, they have a special ramdisk (a small IMG partition mounted by the kernel before and while booting the system) as a part of "boot.img" dedicated specifically for recovery.

---
language: "en"
---
# Android - Rooting (Permanent)

---
language: "en"
---
# App downgrade (Android)

Before using App downgrade, it is advisable to try [Rooting](https://forensic.manuals.mobiledit.com/MM/rooting.md) or [Advanced data extraction](https://forensic.manuals.mobiledit.com/MM/advanced-data-extraction-android.md).  
App downgrade does not work on iOS devices; it only works with Android.

In some cases, the app might not be upgraded, yet the data will remain intact. In this situation, you can find the original .apk in the results folder and reinstall it manually. It will automatically integrate with the existing user data.

Due to improved security, some application manufacturers impose restrictions on what data can be acquired from their apps, outside the app UI. This is especially relevant for non-rooted phones. If it isn't possible to gain root access on a device or an unencrypted physical image, the App downgrade function is a way to get readable app data.

To bypass these restrictions, the App downgrade feature in MOBILedit Forensic will downgrade the apps to a version when it was possible to extract the data.

Before starting, please check for [Updates](https://forensic.manuals.mobiledit.com/MM/live-updates.md) and then select the App downgrade update if a new version is available.  
App downgrade was tested on WhatsApp and WeChat, where the app was installed but the account owner had signed out.

Both App downgrade and Advanced data extraction produced different results; this is the case even if the user was signed in.

Advanced data extraction produces better results than App downgrade.

Some of the more recent security patch levels may stop the App downgrade process from working. e.g. October 2024 may work, but May 2025 may not.

If the Downgradetest.apk fails to install, try turning off Google Play Protect.

App downgrade is not possible on Android 15 and higher, or on devices that have a 64-bit OS architecture.  
![image-20221006-124451.png](https://forensic.manuals.mobiledit.com/__attachments/a_7abf13e29b24e70805736ec5274ffa291569d24ca9aafb664a429794b5fa590c/image-20221006-124451.png?cb=7cb934d94b5b1dc74a2f310868fec47a)  
![appdow.png](https://forensic.manuals.mobiledit.com/__attachments/a_ec785c2d4e56fb29e0ef1ed9b29214438341f73020c30b9ad279cf3eb27e3fe8/appdow.png?cb=43ce29a0debed55b3bd0afb9589c2acd)

You will then be asked to download an extension for MOBILedit Forensic, which consists of the downloadtest.apk installation files. Please confirm the download and wait for it to be downloaded.  
![Screenshot_25.png](https://forensic.manuals.mobiledit.com/__attachments/a_a01e04923c5afa1f0f25070fd072b45a22a4cef688da651385224fc4e846c797/Screenshot_25.png?cb=732683d29d4988f4402b57538e532b05)

After the download, installation will start automatically. Once finished, the App Downgrade feature will be included in the Applications section of Specific Selection options when configuring a report.

You will need to restart MOBILedit Forensic after updating packages.

## Functionality

* Your phone must be properly prepared before downgrading the app. Turn on airplane mode, confirm [USB debugging](https://forensic.manuals.mobiledit.com/MM/How-to-enable-USB-debugging.1802698825.html), and for some phone manufacturers like Xiaomi, Oppo and others, the ["Install app via USB"](https://forensic.manuals.mobiledit.com/MM/How-to-enable-USB-debugging.1802698825.html) option must be checked.

* Also, only our "Forensic connector" app should be open and running on the phone. All other apps MUST be closed, including background apps and especially the app that you are trying to downgrade.

* Do not perform any other operations on the phone during the process, only when MOBILedit Forensic asks you to.

To use the App downgrade function, connect a phone to MOBILedit Forensic, select "Specific Selection", and choose Applications in the right-sided menu. You will now have the option to choose (tick) the App downgrade feature to use in the data extraction process.

If you do not select "Let me choose", all apps that can be downgraded will be downgraded. If you want to downgrade apps individually, select "Let me choose" and find the app in the list on the next screen after clicking "Next".

The option to perform App downgrade is also present in "Full content" and "Application analysis" in the Logical extraction menu. All apps that can be downgraded will be downgraded if you enable app downgrade in either option.

![image-20200709-105330.png](https://forensic.manuals.mobiledit.com/__attachments/a_2f4b7e519072b51df1ac8f5502f9fbba5976b41aefd3cdea6bd4395262885e2d/image-20200709-105330.png?cb=217af5c1880ddc701e1e56cd048a57d2)

There are two options of App downgrade available - Safe and Smart. The safe option works with Android 4.4+ and 5.0+, but not higher than 6.0, while the Smart option works with the other versions. In case the version of Android on your phone was automatically detected by MOBILedit Forensic, one of the App downgrade options will be greyed out accordingly, so you can be sure you are using the correct one.  
![https://desk.zoho.com/DocsDisplay?zgId=22686054&mode=inline&blockId=4137j318ffa0266c549b7b8872b4e3ad1d293](https://desk.zoho.com/DocsDisplay?zgId=22686054&mode=inline&blockId=4137j318ffa0266c549b7b8872b4e3ad1d293)

Upon continuing with the extraction, you will be asked to allow a test .apk file to be installed on your phone and downgraded. This allows us to check whether your phone supports the App downgrade feature.  
![https://desk.zoho.com/DocsDisplay?zgId=22686054&mode=inline&blockId=4137j3a077c30d2c84850b474ad29fc321d81](https://desk.zoho.com/DocsDisplay?zgId=22686054&mode=inline&blockId=4137j3a077c30d2c84850b474ad29fc321d81)

Please be mindful of the following warning message.  
![https://desk.zoho.com/DocsDisplay?zgId=22686054&mode=inline&blockId=4137j8a03d20f768d48afa354081b531fc1e5](https://desk.zoho.com/DocsDisplay?zgId=22686054&mode=inline&blockId=4137j8a03d20f768d48afa354081b531fc1e5)

When the extraction is started, you will see the downgrading progress on the left side of your screen. During the application downgrade, you may be required to confirm backup on the device more than once.

The list of supported apps for App downgrade can be found [here](https://www.mobiledit.com/forensic-express/details).  
Pre-installed apps from manufacturers cannot be downgraded, as they are embedded in the phone's firmware.

Here you can see how App downgrade works.  
[https://www.youtube.com/watch?v=HyeoOZJdZTA\&t=19s](https://www.youtube.com/watch?v=HyeoOZJdZTA&t=19s)  
**Samsung devices**

It is important to be patient when carrying out App downgrade on Samsung devices, as they need to restart in order to complete the process.

Once the device has restarted, it will take some time for the device to reconnect and for MOBILedit Forensic to identify the device again.

DO NOT STOP THE EXTRACTION! (By using the "Stop extraction" button in the UI.)

You may need to monitor the device screen and follow any on-screen prompts to ensure correct reconnection.

### Current supported Apps for downgrade

* AliExpress

* BBM

* Dolphin browser

* Dropbox

* Evernote

* Facebook

* Facebook Messenger

* Firefox

* Google Chrome

* Google Drive

* Google Maps

* Instagram

* KakaoTalk

* Keepsafe

* LINE

* MiTalk

* Periscope

* Skype (Legacy app)

* Snapchat

* Telegram

* Todoist

* Truecaller

* X (Twitter)

* Viber

* WeChat

* WhatsApp

* Wickr

* Wunderlist

---
language: "en"
---
# Apple sysdiagnose file

Sysdiagnose logs are iOS diagnostic logs that are manually generated on the device. They can be analyzed with a live-connected device or imported as a single file.

If the device is connected with MOBILedit Forensic and the sysdiagnose logs have been generated, the logs can be extracted with Full content or Specific selection extraction.

The logs can also be imported for analysis if the sysdiagnose file has been copied out from the device.

Click [here](https://forensic.manuals.mobiledit.com/MM/data-system-logs.md) to see how to generate and extract the logs and find out what data they contain.

## MOBILedit Forensic

After selecting import, choose "**Apple sysdiagnose file** ", navigate to the storage location and "**Select folder**" for import.  
![Choose_data_to_import_Apple_sysdiagnose.png](https://forensic.manuals.mobiledit.com/__attachments/a_a1fbad1cb00e04893dbcda4e02a9e9610899595f5aff10e056c1f4c268679bc3/Choose_data_to_import_Apple_sysdiagnose.png?cb=337276911e28439b25fa7bc767873667)

It is possible to extract and analyze the content of the sysdiagnose logs either with Full content or, Specific selection.

---
language: "en"
---
# Apple Watch

MOBILedit Forensic can connect and extract information from Apple Watches series 0 to 5 and SE 1st and 2nd generations by connecting them to your computer via an All-in-One Reader. Apple Watches series 7 to 10 and ULTRA 1st and 2nd generations via wireless adapter.  
Please note, working with the Apple Watch diagnostic port and readers requires **extreme care and delicate handling** during connection, as the procedure is intricate.

Apple watch extractions should **ONLY**be carried out by law enforcement and technical professionals who have been trained in using the specialist micro hardware equipment required to perform the extraction.

**The installation of iTunes is required**, since the communication requires Apple mobile device service rather than our direct driver.

You must know the PIN to unlock the watch and trust the connected computer.

It is advisable to turn off the passcode and wrist detection.

*** ** * ** ***

## Examples of artefacts you extract\*

* Synchronized Photos (with their geolocations, if they are available)

* Voice recordings (If available)

* Application list

* Files

* Device info

* MAC addresses

* UID

* SW revision

* Notes

\*Depending on the watch model and OS version.

*** ** * ** ***

Here is a quick reference table to show which Apple Watch goes with which reader:

| **Apple Watch model** |                                          **Reader**                                           |                            **SW/Driver**                            |
|-----------------------|-----------------------------------------------------------------------------------------------|---------------------------------------------------------------------|
| 0                     | [Apple Watch with physical diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-physical-diagnostic-port.md) | iTunes (Apple mobile device services plus **original**Apple driver) |
| 1                     | [Apple Watch with physical diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-physical-diagnostic-port.md) | iTunes (Apple mobile device services plus **original**Apple driver) |
| 2                     | [Apple Watch with physical diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-physical-diagnostic-port.md) | iTunes (Apple mobile device services plus **original**Apple driver) |
| 3                     | [Apple Watch with physical diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-physical-diagnostic-port.md) | iTunes (Apple mobile device services plus **original**Apple driver) |
| 4                     | [Apple Watch with physical diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-physical-diagnostic-port.md) | iTunes (Apple mobile device services plus **original**Apple driver) |
| 5                     | [Apple Watch with physical diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-physical-diagnostic-port.md) | iTunes (Apple mobile device services plus **original**Apple driver) |
| 6                     | [Apple Watch with physical diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-physical-diagnostic-port.md) | iTunes (Apple mobile device services plus **updated**Apple driver)  |
| 7                     | [Apple Watch with wireless diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-wireless-diagnostic-port.md) | iTunes (Apple mobile device services plus **updated**Apple driver)  |
| 8                     | [Apple Watch with wireless diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-wireless-diagnostic-port.md) | iTunes (Apple mobile device services plus **updated**Apple driver)  |
| 9                     | [Apple Watch with wireless diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-wireless-diagnostic-port.md) | iTunes (Apple mobile device services plus **updated**Apple driver)  |
| 10                    | [Apple Watch with wireless diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-wireless-diagnostic-port.md) | iTunes (Apple mobile device services plus **updated**Apple driver)  |
| SE 1                  | [Apple Watch with physical diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-physical-diagnostic-port.md) | iTunes (Apple mobile device services plus **original**Apple driver) |
| SE 2                  | [Apple Watch with physical diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-physical-diagnostic-port.md) | iTunes (Apple mobile device services plus **updated**Apple driver)  |
| SE 3                  | [Apple Watch with physical diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-physical-diagnostic-port.md) | iTunes (Apple mobile device services plus **updated**Apple driver)  |
| ULTRA 1               | [Apple Watch with wireless diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-wireless-diagnostic-port.md) | iTunes (Apple mobile device services plus **updated**Apple driver)  |
| ULTRA 2               | [Apple Watch with wireless diagnostic port](https://forensic.manuals.mobiledit.com/MM/apple-watch-with-wireless-diagnostic-port.md) | iTunes (Apple mobile device services plus **updated**Apple driver)  |

The updated driver must be installed to use the wireless reader; otherwise, it will not work.

The driver will be available via download within MOBILedit Forensic in version 9.9.

If the driver is not installed, you will see the notification message in the bottom left, "Driver updates available".

There are also options within settings to "Install" and "Uninstall" the updated Apple Watch driver.

If these options do not appear, [contact us](https://www.mobiledit.com/contact-sales).

---
language: "en"
---
# Apple Watch with physical diagnostic port

**Supported models:**

Apple Watches series 0 to 5 and SE 1st and 2nd generation

## All-in-one Apple Watch reader

1. To access the diagnostic port of your Apple Watch, first remove the watch strap. This will reveal the diagnostic port located at the bottom of the watch. Use a needle or a pair of tweezers to gently insert into the diagnostic hole. Apply careful pressure to remove the small cover concealing the port.

   ![watch_01_new.png](https://forensic.manuals.mobiledit.com/__attachments/a_a1814ff73f1ec5b795be551459fe9096dc614c7229cb34e961f6920c6411091b/watch_01_new.png?cb=dee5ae6a3b3eefd4c0fcdb71a6a71f35)

2. Next, select the appropriate adapter for your watch model. There are four distinct adapters, each marked with the corresponding model and dimension specifications on their top surface.

![Image from iOS (2).jpg](https://forensic.manuals.mobiledit.com/__attachments/a_805818163bf41ad233241a8d182773de44676dc1b684a678729f3e304addbc27/Image%20from%20iOS%20(2).jpg?cb=f9526fd2304679c23532ff91ad98dbcc)

3. Insert the chosen adapter into the strap channel of your Apple Watch.

![IMG_1205.jpg](https://forensic.manuals.mobiledit.com/__attachments/a_5cee5bbfd215f56c630a7c6d3e55bd36415fa937063cf6b59fa1fa629f3810f2/IMG_1205.jpg?cb=3ce900172c47554219ef301e2481116f)

4. Finally, attach the watch with the fitted adapter to the designated position on the diagnostic reader. The adapter has built-in magnets that ensure the watch is firmly and safely held in position.

![Image from iOS (4).jpg](https://forensic.manuals.mobiledit.com/__attachments/a_f38d11d8764357c5aed30976805b889676a76d62a9fea69ad64c05a7757e7056/Image%20from%20iOS%20(4).jpg?cb=158fd45df0d1b85af0f8e6de6df2c8ce)

After successfully connecting the watch to your computer, you should be prompted to enter a passcode to confirm the trust message.

At this point, you should proceed with the extraction as you would with any other device.

*** ** * ** ***

## iBus Apple Watch readers

For Apple watches series 0 and 1 an **iBUS S1** connector is needed.

For Apple watches series 2 and 3 an **iBUS S2** connector is needed.

For Apple watches series 4, 5 and SE an**iBUS S4/S5** connector is needed.

1. You will find the Apple Watch diagnostic port on the bottom of the watch after removing the strap. Place a needle or tweezers in the diagnostic hole and carefully remove the small cover.

![watch_01_new.png](https://forensic.manuals.mobiledit.com/__attachments/a_a1814ff73f1ec5b795be551459fe9096dc614c7229cb34e961f6920c6411091b/watch_01_new.png?cb=dee5ae6a3b3eefd4c0fcdb71a6a71f35)

2. Insert the iBUS adapter extension into the strap channel. The extension has a choice of two length options, you need to take into account the model and size of the watch you are working with.

![watch_02_new.png](https://forensic.manuals.mobiledit.com/__attachments/a_584415175b98a4090867624d29aeb8ea5f4106f5151c505c7d82cd9062e6bc49/watch_02_new.png?cb=757bddc46795c1745741e03a2dab5a21)

3. Then, very carefully, connect the iBUS adapter to the watch diagnostic port by inserting it through the adapter. The connected adapter should sit at an angle of approximately 134 degrees to the watch.

![watch04-01.png](https://forensic.manuals.mobiledit.com/__attachments/a_edc60f738fd6b8095a183e7198f843d42d5d25e8ad468986623169c5693aeae5/watch04-01.png?cb=69b6bdb134a4f27e2473c06790b83902)

4. Connect the USB lightning cable to the iBUS adapter and the USB-A connector to your workstation..

![watch05.png](https://forensic.manuals.mobiledit.com/__attachments/a_75b340e603f90e8fc69a390723271509894c6a20eac722c1757eb9ee4ee8f7f7/watch05.png?cb=d2979158a3b99948821cf69bdd1c1818)

After successfully assembling the iBUS reader and connecting the watch to your computer, you should be prompted to enter a passcode to confirm the trust message.

At this point, you should proceed with the extraction as you would with any other device.

[Video - How to connect iWatch to MOBILedit Forensic using iBus readers](https://youtu.be/gE6nNab0B4g)

![image-20250317-143437.png](https://forensic.manuals.mobiledit.com/__attachments/a_77c33196b25c96667be33c577ee61c12de40686e1ff22a3c08e7acb23268ac79/image-20250317-143437.png?cb=6f8ffc2a0d0b573a313659185d80657e)

If you see this pop up, physically disconnect and reconnect the USB cable and the extraction will continue from where it left off.

---
language: "en"
---
# Apple Watch with wireless diagnostic port

**Supported models:**

Apple Watches series 7 to 11 and ULTRA 1st, 2nd and 3rd generation

## How to connect Apple Watches with a wireless reader

1. Remove the straps from the watch

2. Place the watch on the reader, oriented as the pictograms show

   ![reader.png](https://forensic.manuals.mobiledit.com/__attachments/a_62d8ae5d2f36173abf3a663eacc4f6fbb34bed35e127b1910d49d293af3cd21e/reader.png)  
   ![reader with watch.png](https://forensic.manuals.mobiledit.com/__attachments/a_10663c94124dad8fb9442c634c1f53c9b1894253016826553384d9ebef387c19/reader%20with%20watch.png)
3. Check the LED lights for indication of the correct connection

4. Enter the passcode

   ![passcode.png](https://forensic.manuals.mobiledit.com/__attachments/a_c58f203ab7fb0bf29fecde18ed8471aa56d8342add85133404c00fade4b56b61/passcode.png)
5. Confirm the trust

   ![trust.png](https://forensic.manuals.mobiledit.com/__attachments/a_e2f4a59be5303c4476b676a5ff3e9e9129f4e50c7e07dc0d1b86d7a17b972dad/trust.png)

### LED light indicator status

1. Orange colour = ready to connect

2. Green colour = connected successfully

3. Orange/Red colour = connection issue

The updated driver must be installed to use the wireless reader; otherwise, it will not work.

The driver will be available via download within MOBILedit Forensic in version 9.9.

If the driver is not installed, you will see the notification message in the bottom left, "Driver updates available".

There are also options within settings to "Install" and "Uninstall" the updated Apple Watch driver.

If these options do not appear, [++contact us++](https://www.mobiledit.com/contact-sales).

---
language: "en"
---
# Application analysis

This option will extract and analyse all third-party applications and system applications and will not access data from outside the APK or IPA files, except for general device information.

It is also possible to run Advanced data extraction and App downgrade from this option.  
![image (8).png](https://forensic.manuals.mobiledit.com/__attachments/a_d94e039912bf164b3c4cedb51617e95f533693fb20d10453cf4096d49d0427f1/image%20(8).png?cb=8a0961fb4664a0c48f297b90441c4093)  
![image (9).png](https://forensic.manuals.mobiledit.com/__attachments/a_cbbd5ff35bf9116410abce0ccf9683d0bf37b02ab184763897a81250d8caaa26/image%20(9).png?cb=00e1cf9a69b0d83048af2f97fab009b0)

These user guide pages contain more detail about applications.

* Specific selection - [Data - Applications](https://forensic.manuals.mobiledit.com/MM/data-applications.md)

* Specific selection - [Data - Application list](https://forensic.manuals.mobiledit.com/MM/data-application-list.md)

* Specific selection - [Data - Application usage](https://forensic.manuals.mobiledit.com/MM/data-application-usage.md)

* [Applications](https://forensic.manuals.mobiledit.com/MM/applications.md)

  * [Supported applications](https://forensic.manuals.mobiledit.com/MM/supported-applications.md)

  * [Advanced techniques to get more information from the device](https://forensic.manuals.mobiledit.com/MM/advanced-techniques-to-get-more-information-from-t.md)

  * [How to make an application backup](https://forensic.manuals.mobiledit.com/MM/how-to-make-an-application-backup.md)

  * [Request to add support for analysis of an application](https://forensic.manuals.mobiledit.com/MM/request-to-add-support-for-analysis-of-an-applicat.md)

  * [App downgrade](https://forensic.manuals.mobiledit.com/MM/app-downgrade.md)

---
language: "en"
---
# Application Analysis Search

The Application Analysis Search feature can be accessed in the User portal and is linked to the [Supported apps](https://apps.mobiledit.com/) database available on our website. It shows information in a more limited view than the Supported apps database and apps will be listed if they are supported for extraction and analysis using MOBILedit Forensic. You will also be able to see which platform is supported and the categories of data that can be parsed.

Using the drop-down menu in the top right of the screen, select "Application Analysis Search".  
![image-20250613-090012.png](https://forensic.manuals.mobiledit.com/__attachments/a_7ddd4d546d5f57a6fe29ea6e35faa0621c2efdfdfd47123ad13dc4504981677a/image-20250613-090012.png?cb=8b9532c181b214d5ec185fa411618c9d)

Type in the name of the application you are searching for.  
![image-20250613-090041.png](https://forensic.manuals.mobiledit.com/__attachments/a_bf8e602d2c9fd52d632768917a99688e1700124f2c8ddaf982516807189f9b6c/image-20250613-090041.png?cb=d79abe87cca50ece5f9d90189c5945a0)

---
language: "en"
---
# Applications

Perform advanced application analysis using adaptive, in-depth methods to maximise the amount of application data recovered from each app, including deleted data and data from encrypted apps. We regularly update MOBILedit Forensic to support the latest applications, application versions, and changes to their data structures.

Application analysis depends on the data available within the selected extraction. Results may vary depending on the device, operating system, application version, acquisition method, encryption, and the data retained by the application.

Android runtime permissions are included for each application within the output report.

For Android apps, you may need to use [Rooting methods](https://forensic.manuals.mobiledit.com/MM/rooting), [Advanced data extraction](https://forensic.manuals.mobiledit.com/MM/advanced-data-extraction-android), or [Application downgrade](https://forensic.manuals.mobiledit.com/MM/app-downgrade) to obtain additional application data. This is due to Android application sandboxing and restrictions on accessing private application data. Some applications also do not export their data using an [ADB backup](https://forensic.manuals.mobiledit.com/MM/adb-backup).

For iOS apps, much of the application data can be obtained from an [encrypted iTunes backup](https://forensic.manuals.mobiledit.com/MM/itunes-backup). An unencrypted backup contains less data because some protected data is only included when backup encryption is enabled.

[MOBILedit Forensic ULTRA](https://forensic.manuals.mobiledit.com/MM/description-of-editions) provides additional advanced acquisition and decryption methods for supported devices. These methods can provide access to otherwise inaccessible or encrypted device and application data. Available methods depend on the device model, chipset, operating system, security patch level, and other device-specific factors. See [MOBILedit Forensic ULTRA](https://forensic.manuals.mobiledit.com/MM/first-page) and [ULTRA device compatibility](https://forensic.manuals.mobiledit.com/MM/mobiledit-forensic-ultra-device-compatibility-over) for further information.

Applications commonly store user data in [SQLite](https://forensic.manuals.mobiledit.com/MM/applications.md) or [LevelDB](https://forensic.manuals.mobiledit.com/MM/applications.md) databases, as well as configuration files, caches, logs, media, attachments, and other application-specific storage. Additional application information and metadata can also be obtained from the application installation package.

The database of supported applications is available at [apps.mobiledit.com](https://apps.mobiledit.com/).

---
language: "en"
---
# Password toolbox

## MOBILedit Forensic Standard \& PRO

MOBILedit Forensic allows you to extract iTunes backups from iOS devices and ADB backups from Android devices. You can even load historical backups that have been created previously for detailed analysis or comparison.

It is not uncommon to find backups that are protected with some form of password or a code. To analyze such a backup, a password must be obtained to gain access.

MOBILedit Forensic will prompt you to enter the backup password at the relevant stage of the extraction if the user has already set a password. However, it must be known by the examiner.

For iOS, if a password was not set by the user, MOBILedit Forensic will ask you to confirm automatically setting the backup password to "123". This will force the encryption of the iTunes backup which contains more data than an unencrypted backup, which you would get if you do not set a password.  
If you think your report is missing data, please check that an encrypted iTunes backup was acquired, this can be seen in the "Summary_full.txt" document in the report output folder.

For Android, MOBILedit Forensic will automatically enter a backup password on the device and you do not need to confirm this. Android passwords are set on an individual backup basis, iOS backup passwords are for all backups created from that device.

![image-20240103-122350.png](https://forensic.manuals.mobiledit.com/__attachments/a_f6cb9af58677b56506f1cd33a9d3273a64da301cf8ac81799e555eb565969379/image-20240103-122350.png?cb=2ff8fbbb0b58df81171521aab22280c3)

### Entering password directly

The password can be entered directly if it was obtained during an investigation or, through other means. There is an unrestricted number of attempts allowed to enter the password, so you can't get permanently locked out. You can also see the history of previously entered unsuccessful passwords.  
You can choose to include the password into the logs and reports.

With MOBILedit Forensic ULTRA you can brute force backup passwords. This feature was previously in MOBILedit Forensic PRO yet is now included in ULTRA due to dual-use regulations.

---
language: "en"
---
# Blackberry OS devices

Blackberry has a very unique and secured OS which is hard to work with, however, we have done the maximum to offer as much support as possible.

Phones with **Blackberry OS 10** can be connected to the MOBILedit Forensic via Bluetooth or WiFi.

Bluetooth connection allows you to read contacts stored on the device, nevertheless, this content is Read-Only.

WiFi connection will provide you with more data, however, the connection requires the installation of the [**Android Compatibility Layer**](https://www.blackberry.com/us/en/support/desktop-software-downloads). The amount of data depends on what will be allowed by the emulator itself.

Please follow our step-by-step instructions [here](https://forensic.manuals.mobiledit.com/MM/connect-blackberry-via-wi-fi.md).

Devices running **Blackberry OS 9 and earlier** can be connected to MOBILedit Forensic via cable connection.

This will allow you to manage and see the whole content of your Blackberry such as Messages, Phone book, Calendar, Application, and Media.

It is only necessary to install the correct drivers, MOBILedit Forensic should recognize your phone by itself.

---
language: "en"
---
# Bootable USB Flash Disk with Jailbreaking Capability

The bootable USB flash disk with jailbreaking capability is available in the [MOBILedit Forensic Connection Kit](https://www.mobiledit.com/connection-kit).

Depending on which version of the [MOBILedit Forensic Connection Kit](https://www.mobiledit.com/connection-kit) you own, the content of the USB flash disk varies. Since version 10 and above, it includes both checkra1n and palera1n capabilities. For kits up to version 9, only checkra1n is included. Alternatively, you can create your own bootable Linux USB flash disk with checkra1n, palera1n or both.

## Forensic workstation preparation

Bootra1n is a lightweight Linux distribution which enables users to boot checkra1n or palera1n on any PC without having to install additional software or an OS.

Bootra1n flash doesn't have a signed loader, which is why you will need to boot from the USB connected directly to your computer. This is a standard procedure on all modern computers with UEFI and Secure Boot.

To disable Secure Boot, you will need to enter computer firmware settings.

On some computers, you can enter the firmware with a hotkey once it is turned on. Usually, this is not possible because of fast boot technology, which boots directly into the installed operating system.

You can force your computer to allow you to enter the firmware directly from Windows.  
Firmware varies by manufacturer and model. We used HP ProBook 440G5 for our demonstration (many recent HP computers have similar firmware settings).

### How to enter firmware settings (BIOS)

1. Search for **Advanced startup** option.

   ![0-advancedstartupsearch.png](https://forensic.manuals.mobiledit.com/__attachments/a_486e828455158e8f077ad51cba5849c0430d27c71aa6f9e4fdf22e61d3dcb64e/0-advancedstartupsearch.png?cb=178863d2997f1175de0df30153c0df21)

2. When you go to the Advanced Startup, you should see the Windows setting screen with a startup option preselected. Click Restart now.

![1-advancedstartupsettings.png](https://forensic.manuals.mobiledit.com/__attachments/a_badb43a895e24d607313edb03ed64238c5b2b6a9d41d11122bff76720e0565e9/1-advancedstartupsettings.png?cb=b0b83d7031a53bdeedbc71bcf34dd410)

3. The computer will reboot into Advanced Startup mode, giving you the option to do various maintenance and recovery-related operations. Select **Troubleshoot.**

![bios4-600x361.png](https://forensic.manuals.mobiledit.com/__attachments/a_3b0ab458c54260cb1e7f2ab6d240d54e00550b604af6e4847d3fdff03bb27991/bios4-600x361.png?cb=e522d403b8ef88fd8e964f71eff775cc)

4. On the next screen, select **Advanced options**.

5. Select **UEFI** **Firmware Settings**.

![bios5-600x324.jpg](https://forensic.manuals.mobiledit.com/__attachments/a_4705b1f3076f05defe2a6c9b6b8e8f86a79d203228654760f56c8d664f183876/bios5-600x324.jpg?cb=d76899fe3da97d8c74153a57428167ef)

6. Restart your computer.

7. After restarting the computer, you will either enter firmware settings (BIOS) or you will be presented with further options. The correct option is **BIOS Setup**.

8. When you enter the BIOS, you need to search for the Secure Boot option and disable it. In our example of the BIOS, it's located under the Advanced settings page.

![disable secure boot.png](https://forensic.manuals.mobiledit.com/__attachments/a_d83d49f5e16f950f7dc05af42c4bfdbb46f2f37d353d54b26cb39d9eeb825eaa/disable%20secure%20boot.png?cb=d518b556578a0a4f8147e70d92f83a48)

9. Save your changes. The way how to do that depends on the computer that you are using (in our example, you can either click F10 or go to the main section and save it there).

Before you save your settings (which will effectively restart the computer), make sure that the USB flash drive with bootra1n is inserted into the computer.

10. When the secure boot is disabled, it effectively disables the fastboot as well, so you should be able to call the boot menu of your device with hotkey after powering up. Usually, it's one of the following keys: ESC, F2, F9, F10 (please refer to your device manual).

11. Once your computer enters the boot menu, you should be presented with an option to boot from the flash drive. On our HP ProBook, it is the **General Udisk** option.

12. When you boot from the flash drive, you will be presented with a boot menu for bootra1n. Select "**Void Linux (USB safe)**" and press Enter.  
![Capture 12.png](https://forensic.manuals.mobiledit.com/__attachments/a_453d171bcf7183be9d8e6ae44e5b4730414b534be32465454431b260ae80e2a0/Capture%2012.png?cb=ea66cfe7a60f3c4f54aa90b2bb40214e)  
Booting from a flash drive does not provide access to the computer's hard drive, only to the flash drive and whatever you have connected to the computer's USB port.

13. Once the boot sequence is finished, you will be presented with a login screen. Use login details:

void-live login: `root`

Password: `voidlinux`  
![obrazek-20240109-121917.png](https://forensic.manuals.mobiledit.com/__attachments/a_2bdfa415cced67213a34675e8d2c710ef46647446492f1c8bec2eba3ce6ea681/obrazek-20240109-121917.png?cb=853fd7eb5c0ab1fcc4f61c39410e961f)

14. There are currently two jailbreak options available:

[Jailbreaking with checkra1n](https://forensic.manuals.mobiledit.com/MM/jailbreaking-iphone-with-checkra1n.md)

[Jailbreaking with palera1n](https://forensic.manuals.mobiledit.com/MM/jailbreaking-with-palera1n.md)

Please ensure that these instructions are used in compliance with legal and ethical standards, especially considering their application in digital forensics and law enforcement contexts.

---
language: "en"
---
# Browse content

When a device is connected, or a file is imported, you can see the device file system or, the folder and file structure of the import.

This is viewed using our File Manager; more information can be read [here](https://forensic.manuals.mobiledit.com/MM/file-manager.md).  
![Untitled-20260701-130457.jpg](https://forensic.manuals.mobiledit.com/__attachments/a_6707bab9b1ac5ee5f52c926b745e5a9671bb44ae91f60864c684bf2985b2ded2/Untitled-20260701-130457.jpg?cb=861e550ec42af0b453530f752ff5b679)

Content can be browsed with or without installation of the Forensic Connector app, although there is a difference in accessible data; installing the Connector app is best.

You will be shown a pop-up reminder letting you know if the Forensic connector app isn't installed and asking if you would like to install it.

With the Connector app:  
![image-20241106-142743.png](https://forensic.manuals.mobiledit.com/__attachments/a_441e1310bed6f5eb467a8932a24a7e2c02a7b92c4ec7355dbe129b8176edf093/image-20241106-142743.png?cb=12f28b6bc051f90dafcf5e21391c70c7)

Without the Connector app:  
![image-20241106-142450.png](https://forensic.manuals.mobiledit.com/__attachments/a_ba5c516724a28b29e4147b0aedf472204f374f16391a50add466a86eb5410188/image-20241106-142450.png?cb=4aeac3f71a0343d477d8cd0638b74bae)

As you can see from the screenshots, you will not have access to the applications and their data without the Connector app. This is due to the additional permissions granted to the app.

Examples of directory names are:

* Internal (raw0)

* External (raw3)

* Multi root (raw4)

* Applications (applications0)

* Extra applications (applications1)

To see a description of what the named directories contain, please read the page on the [Output folder structure](https://forensic.manuals.mobiledit.com/MM/output-folders-structure.md)

---
language: "en"
---
# Built-in SIM Cloning

The purpose of cloning a SIM is to isolate the mobile device from the mobile network. It is used in cases where you have a feature phone or, a "dumb phone", that will only boot and start the operating system with a SIM inserted. It is not necessary to clone a SIM used in a Smartphone as these devices can be isolated from the network using airplane mode and other methods.

You can use the "i" button to preview the SIM data. The full information will not be displayed if the SIM is PIN-protected. To work around this, click next with the SIM inserted and you will be prompted to enter the PIN. Once entered you can return to the Connection screen and view all data by clicking "i".  
The built-in SIM Clone functionality enables you to copy the content of investigated SIM card to a rewritable MOBILedit SIM Clone Card directly from MOBILedit. This way you can isolate the phone from the mobile network while you don't have any issues regarding a missing or changed SIM within the phone.

**It is not possible to connect to a mobile network with a cloned SIM!**

SIM Cloning does bring three new possible options:

* Data extraction

* SIM card cloning

* Creating a custom SIM card

For successful work with our SIM clone tool we recommend the use of ACS or HID readers, which you can find in our MOBILedit connection kit.

The first step for every option is to insert the**SIM card reader** containing a SIM card:  
![Screenshot 2024-03-04 114734-20240304-105142.png](https://forensic.manuals.mobiledit.com/__attachments/a_65b76ab73481d5a9586557707331cb5b5bba52fbff7cf2c8e58aa9c93c0b56ef/Screenshot%202024-03-04%20114734-20240304-105142.png?cb=010546c202f4e2de2607f40013042915)

Type the PIN code if required and you can also change the PIN if you have the PUK:  
![Screenshot 2024-03-04 115252-20240304-105344.png](https://forensic.manuals.mobiledit.com/__attachments/a_30b57af98acd9f0a04127b61539b55173b73a61e39089f5b227471bb4b127f2a/Screenshot%202024-03-04%20115252-20240304-105344.png?cb=abcc75701133e6162d86fb01a4111204)

## Data extraction

Insert a SIM card you want to extract and you will see these options, select "Logical extraction":  
![3.PNG](https://forensic.manuals.mobiledit.com/__attachments/a_ee507115dd90270243fd86f20eff5083b5401d783fda29ab07862b9668f8b011/3.PNG?cb=bc8a1762eec41313acf155e106cb8949)

Now you can proceed with regular extraction.

## SIM Cloning

Select the **Clone SIM card** option:  
![image-20240304-105713.png](https://forensic.manuals.mobiledit.com/__attachments/a_28419738fbba08750850e723860980bdc2a2847b99966ef1b3ec34ae1bcc2fc0/image-20240304-105713.png?cb=f4af69c6e1db23a15ed49eb7f66c7bef)

Now insert the **destination SIM card** into the reader:  
![4.PNG](https://forensic.manuals.mobiledit.com/__attachments/a_d5e380d8283cc896f1fc30d003319eb480208b0aad4c4ee8cbd71e28e2dfced4/4.PNG?cb=b9f66a4817c79837914e04b1d6abfa60)

Choose the desired data to clone and click the **next** button:  
![5.PNG](https://forensic.manuals.mobiledit.com/__attachments/a_a87d453706f2cf51ff5c75138cf31c80ee38619f5209cbe47fe36ca1ce89ba2e/5.PNG?cb=48462e0d8ed9800ec7dc68323dfa7fd2)

You will be notified that the data is successfully copied:  
![6.PNG](https://forensic.manuals.mobiledit.com/__attachments/a_45a2002147995d6d8fc6dce70204c295d4b62d35902702fc5f88329ece24f83a/6.PNG?cb=30573128cdd7c5cace4ee9cc128d47d9)  
If you do not enter the PIN when cloning a SIM card, the identifiers (IMSI, ICCID, etc.) will still be copied but the user data will not be copied.

## Create a custom SIM card:

Choose the **Create custom SIM card** option:  
![image-20240304-105747.png](https://forensic.manuals.mobiledit.com/__attachments/a_61e077e799edc48ba84ca19cc07ac4332f5c0d6f96b4a13e081ed8392223ad99/image-20240304-105747.png?cb=86c6a1b95468d2ce3464e92a7de40ebb)

Fill in the properties then click the **next** button or, leave them blank if you wish to reset the re-writable SIM card to defaults.

ICCID = Integrated Circuit Card Identifier

IMSI = International Mobile Subscriber Identity

SPN = Service Provider Name

GID1 = Group Identifier Level 1  
![image-20240304-105819.png](https://forensic.manuals.mobiledit.com/__attachments/a_1ba7cd171ae791385025cc2a582eff69228d0b46ed9cf99f2afec535698a7186/image-20240304-105819.png?cb=8a6d1338283bb411f6f8ccbfbe981883)

You will see a pop-up stating that the SIM was successfully cloned.  
![image-20240304-105944.png](https://forensic.manuals.mobiledit.com/__attachments/a_8777979856ffc1fe61c7d6cb1dd2dbe9d8f15a5a2bef92642a35131d0bae5557/image-20240304-105944.png?cb=15b0abd8d50384ff689b0c79cc2650f1)  
If you are experiencing difficulties with connecting the USB readers or, MOBILedit Forensic is not loading the SIM \& reader or, you cannot click next to start to select the action, please connect the reader with a SIM inserted and restart MOBILedit Forensic leaving the reader connected. It will then be recognised.

---
language: "en"
---
# Camera and screen capture

Use "Camera and Screen Capture" to take screenshots from your device or import images to be projected into a message. This can be useful for retrieving data/chats from apps where you cannot obtain data using root access, get an unencrypted physical image, or use App downgrade.

Connect your phone to MOBILedit Forensic and click Next. Select Camera and Screen Capture from the list. Choose the required option from:

![image-20230411-102151.png](https://forensic.manuals.mobiledit.com/__attachments/a_3ff6ee83c1c7a5dbd53d47ec8bb42b26f4c5443347859a0bb87a7b47ea424646/image-20230411-102151.png?cb=d6665eab9b58aa4d6d2f85c1572f2aea)

*** ** * ** ***

## Options

Please click on the headings to jump to the dedicated page.

### [Smart screenshots (Android only)](https://forensic.manuals.mobiledit.com/MM/smart-screenshots.md)

### [Phone photo sequence (Android only)](https://forensic.manuals.mobiledit.com/MM/phone-photo-sequence.md)

### [Webcam (Computer)](https://forensic.manuals.mobiledit.com/MM/webcam.md)

### [Manual screenshots (iOS \& Android)](https://forensic.manuals.mobiledit.com/MM/manual-screenshots.md)

### [Import images (Computer)](https://forensic.manuals.mobiledit.com/MM/import-images.md)

*** ** * ** ***

## Camera and screen capture - managing pictures

Managing captured pictures is possible for all of the parts of "Camera and screen capture".

Each picture can be named a selected Type (Phone photo, Contacts, Emails, etc....).

* In some options, such as "Manual screenshots", images can be removed. This is not possible in the "Smart Screenshots" option....

* The result is created as a .csp file which can be re-imported in Specific selection to be included in an final evidential report.

![image-20230307-085658.png](https://forensic.manuals.mobiledit.com/__attachments/a_5f08719574d7a0bf709a26804aeb3e3e569e1aec370ddc7ed2a8e9de6e5d2ce6/image-20230307-085658.png?cb=b21b0c5868a6be404c02c90979c9f12b)

If MOBILedit Forensic is closed before the extraction and creation of the report output, and the processing and capture are completed, the screenshots will remain in the temporary folder until the next time MOBILedit Forensic is started.

---
language: "en"
---
# Camera Ballistics

Camera Ballistics uses a unique algorithmic method to determine whether a specific photo was taken by a specific camera. This feature is only available for users with a valid license of Camera Ballistics and both applications must be installed on the same machine using the same Windows user profiles.  
![intro.png](https://forensic.manuals.mobiledit.com/__attachments/a_e377be9c73969efa1513b28f7fff1808a681b497d1f634ca65d8e6c0f4d70a2a/intro.png?cb=04db93552b395a3930ebf650c92fe575)

Once you enable the Camera Ballistics feature by checking the "**Use Camera Ballistics photo analyzer?** " option, you can choose from 3 modes:

1. **Analyze all image files** - all image files (contacts photos, user photos, application images, cached images, thumbnails, ...) will be analyzed

2. **Analyze only photos in media folders** - only user-generated photos (DCIM folder) will be analyzed

3. **Analyze only application images** - only image files from applications filesystem will be analyzed

![image-20260701-135756.png](https://forensic.manuals.mobiledit.com/__attachments/a_3ffb76dfd187801eed4dedd8110297d9beae1143c1ba91522cbeacc0029608d0/image-20260701-135756.png?cb=4ed7c580c241378f4fb6f11cb724378e)

You can enter up to 2 fingerprint files previously generated by Camera Ballistics. These files will not be modified during the analysis process.

Learn how to generate a fingerprint .fnp file [here](https://forensic.manuals.mobiledit.com/MM/learn-create-fingerprint.md).  
![2020_01_15_11_07_49_MOBILedit_Forensic_Express.png](https://forensic.manuals.mobiledit.com/__attachments/a_34f8781bf8d473fb40069871b08010f2160fb448a1316380443006104adb98f1/2020_01_15_11_07_49_MOBILedit_Forensic_Express.png?cb=3df2c08adfc36defd746fb57813fa741)

Once the export is finished you can see the result of the analysis together with image files. A green icon in the top-right of the screen indicates a positive match and the details of both selected fingerprints are available in the **Camera Ballistics** section.  
![2020_01_15_11_48_22_Report_pdf_Adobe_Acrobat_Pro_DC.png](https://forensic.manuals.mobiledit.com/__attachments/a_c57f819500cf4e3a00b011aae647694bddb6d94d5f4e137495e1a5baeac798ff/2020_01_15_11_48_22_Report_pdf_Adobe_Acrobat_Pro_DC.png?cb=f877f5e2d1868722d1839af98f5a0227)

Learn more on how the analysis works [here](https://forensic.manuals.mobiledit.com/MM/analyze-process-photos.md).

---
language: "en"
---
# Camera Ballistics - Updates

Checking for updates and getting them is very simple.

There is an "Updates" button on the home screen.

Click on the "Update" button. A window called "New version available" will appear, with information about the possibility to download an update.

This window also contains information about the new version with the latest news (under the link "latest news").

You can confirm the update by clicking on "Yes" or select "No" to download it later.  
![2.PNG](https://forensic.manuals.mobiledit.com/__attachments/a_90f21934c1bf66dc0083d4947f4b0d14bbea3d45fca41ff4197f2f1ebc5e446d/2.PNG?cb=2b367900364a66119aad90965d6cc8ba)

![image (7hgffhfhfjh).png](https://forensic.manuals.mobiledit.com/__attachments/a_cc30c3129bc3f8ca39e4b142774e1d9314a57cf3814748223700e5b0d31bbc4b/image%20(7hgffhfhfjh).png?cb=b0140899fc183e44e6e983b25f1f83b7)

![image ugbghhjjhzjhjh7).png](https://forensic.manuals.mobiledit.com/__attachments/a_77405c1631f44733568569eaa0d3a13189d605c7c7acd7f4ebc97b97bec7e08b/image%20ugbghhjjhzjhjh7).png?cb=a90e07eb58bc100ab9ff4196d3adccd5)

The installation will run automatically after it is downloaded.

---
language: "en"
---
# Specify report details

This screen enables you to customise the settings and appearance of the report output.  
![image-20260701-135229.png](https://forensic.manuals.mobiledit.com/__attachments/a_33aecf906810b43b5c243a5c60b66871093c447189529f3fe6e86f85f09360d3/image-20260701-135229.png?cb=0c00c3377c4d3be987022bb990783257)

*** ** * ** ***

## Report settings

![image-20231030-100125.png](https://forensic.manuals.mobiledit.com/__attachments/a_30b7745ab15000dd88e7e8c62b3c978ac176e033e34ad47e8b051d2fbae4610d/image-20231030-100125.png?cb=32a5779a13956fa090983c3345a56c96)

Within report settings, you can customise the following options:

### Report time zone

This should be the time zone of your workstation according to your location.

#### Report language

You can choose the language of your report output by selecting one of the pre-installed languages.

If the language you require is not supported, you can manually [add your preferred language](https://forensic.manuals.mobiledit.com/MM/report-localisation) or contact [++support++](https://www.mobiledit.com/contact) to have it added.

Supported languages are:

* Arabic

* Czech

* German

* Spanish

* Estonian

* French

* Italian

* Japanese

* Korean

* Dutch

* Polish

* Portuguese

* Slovak

* Ukrainian

* Vietnamese

* Chinese

#### Time format

Within the list of time formats, you will see that they are shown according to the supported languages as well as generic options, including local time.

#### Show data sources

By selecting to show the data sources, the file path will be shown in the report output as to the location of the extracted file in the report output "Phone files" directory.

Examples of how the data source is shown in the reports:

PDF report  
![image-20231030-101332.png](https://forensic.manuals.mobiledit.com/__attachments/a_90a87807f62dd9025ddd8c73c293b94c33b661b8f8ba24a357c07f2b5da1a4b3/image-20231030-101332.png?cb=6f79ddd547669cf7878fc7d59c969d64)

HTML report  
![image-20231030-101509.png](https://forensic.manuals.mobiledit.com/__attachments/a_9b883ba5724d99f61adb270fc9f6c759f5bacd0e160851701e89ee24182cafe3/image-20231030-101509.png?cb=6c9c845e9d55cd98f0cb061ba388104c)

XLSX report  
![XLSX report.PNG](https://forensic.manuals.mobiledit.com/__attachments/a_6398e59f388860a36290089bf18304cc567d5b0ce44e73d55ee29abf672dc9b7/XLSX%20report.PNG?cb=009e6987f700d9aa273baf1072ac1a03)

#### Clutter filtering

When enabled, the final report does not contain duplicated data and clutter is reduced to a minimum. If set as no, all data records are displayed in the report.  
![clutter_2.png](https://forensic.manuals.mobiledit.com/__attachments/a_a49284f16739762deffc8f8044a40fc9c8b2da065e5b68c2b78943a2c8894d51/clutter_2.png?cb=6ed4aa43d521c0d2f4883d676d8576c3)  
Changes that you make in report details will be saved and remain the same even if MOBILedit Forensic is closed and re-opened or if the computer is restarted.

*** ** * ** ***

### Case details

![image-20231030-100146.png](https://forensic.manuals.mobiledit.com/__attachments/a_3553ab5c1fffd585f91a8218c3e9766b9d252ebd0725dc73a86bae41653fd4e4/image-20231030-100146.png?cb=6e718160bd2693e74dbe6a1bba1d314a)

To keep track of your cases you can enter specific case details. Once details are entered, these fields will remain populated until you change or delete them which is especially useful if you are examining multiple devices in the same case. All of the fields can hold unlimited text.

To clear the details, click on "Clear Case details".

Available fields and recommendations for use are shown below however, feel free to use them according to your organisational policies or procedures.

#### Case label

The operation name or type of offence.

#### Evidence number

The crime or case reference number.

#### Evidence details

A description of the offence or investigation.

#### Case notes

Any notes or instructions relating to the case.  
If you wish to use "Bates numbering" also known as "Bates labelling" we can offer this advice.

The "Case label", "Case Evidence" and "Device Lablel" can be populated with the prefix or suffix of the elements for each case or report and the elements can be:

* ID numbers

* Important dates

* Company names

* Client names

* Case numbers

For example, /41/RvSmith/#123456/2024 - \[Area/Case name/Case number/Year\]

These remain constant in the header and footer of each page within the PDF report and the page numbers are automatically generated.

*** ** * ** ***

### Phone details

![image-20231030-105126.png](https://forensic.manuals.mobiledit.com/__attachments/a_ce164bb91a107688632f0535a2af356df2aee0f415e25d65f21290b0eddae307/image-20231030-105126.png?cb=513a822bc7a66724c6ee48dd5f481541)

Here you can enter specific details about the device you are examining. The device name will always be populated according to the connected device or imported file.

Below are some recommendations for filling in the fields:

#### Device label

Description of the device according to the evidence label.

#### Device name

This should be auto-populated yet, it can be changed and should reflect the make and make model.

#### Device ID

If you wish to enter a specific device ID you can.

#### Device evidence number

This should be the evidential exhibit number that will be referred to in court or other prodceedings.

#### Owner name

This can be entered to attribute the device to an owner or user.

#### Owner phone number

The phone number should be entered if it has been obtained from the owner or other means. MOBILedit Forensic will detect the phone number of the device during the extraction.

#### Phone notes

This field can be used to enter details about the condition of the device, circumstances around the seizure or, any other useful information you would like to record and show in the report.

*** ** * ** ***

### Investigator details

Investigator details can be entered and saved as a global profile from within Home \> Settings. To clear details that have been populated using global settings just click on "Clear Investigator details" and then you can enter new details. The next time MOBIledit Forensic starts it will take the investigator's details as set up in Settings.  
![image-20260701-135335.png](https://forensic.manuals.mobiledit.com/__attachments/a_62f64b1705e4b8f26137d47ec449bfecb14cba7c8c87c7f85d8f7164dd3fe5e7/image-20260701-135335.png?cb=7928074b0fe5f10d6581322be8533ad7)

#### Investigator name

A full name can be used or a reference number in high-profile or sensitive cases.

#### Investigator designation

The job title or role performed by the examiner.

#### Investigator email

An email address for contact regarding any questions surrounding the case or examination.

#### Investigator phone number

A contact telephone of the department or individual.

#### Permission document

A reference number for a document or, relevant legislation that shows authorised permission to examine the device.

#### Investigator logo

This can be an individual avatar or profile picture or, the organisational logo.

*** ** * ** ***

### How information is shown in reports

The details you entered will be displayed in the final HTML/PDF report. On the Title Page, you will see the Case Label name, Case Evidence number and Case Evidence Notes will be displayed in the upper-right section of the page. Below this information on the Title Page will be the Device details. On the bottom of the Title Page, you will find the Investigator details such as the investigator's name, investigator logo, email, phone number and permission document.

In the header of each page of the PDF report, you will find the Case Label, the Case evidence number and the Device label.  
![image_blurred-20231027-110802.png](https://forensic.manuals.mobiledit.com/__attachments/a_9b03352c2b92f8d70070cd17d7b18b6e06402a9d2bff1745ae74309cdbc9d519/image_blurred-20231027-110802.png?cb=a19c91343134ac571182fc9351af1c06)

---
language: "en"
---
# Cellebrite filesystem backup

This feature enables users to import full filesystem extractions from Android and iOS devices where data has been acquired by Cellebrite UFED.

To read more about file system extractions read [here](https://forensic.manuals.mobiledit.com/MM/full-file-system-vs-file-system.md).

By selecting "Cellebrite filesystem backup", you will be able to import the following file types:

* .zip

* .dar

* .clbx

**DAR (Disk ARchive)** is a file format used by the "dar" utility to create backup archives. These archives can contain files, directories, and metadata from a filesystem, enabling both full and incremental backup as well as splitting the archive over a number of files.

**CLBX (Cellebrite Logical Extraction)** is a file format that contains data extracted at the logical level, which includes user-accessible files and information from a device, such as contacts, messages, photos, and application data.

We are not currently supporting importing .dar files created in any other software. If you would like support for other import formats, use the contact form on our website and select Technical Support.  
![Choose_data_to_import_cellebrite_fs.png](https://forensic.manuals.mobiledit.com/__attachments/a_5e4ce48aa7aadd3ab0d22a94a7ecd7ae71442b6022e2377533e4b87218e705a2/Choose_data_to_import_cellebrite_fs.png?cb=4a4b71490f0c58c085e389372ddcbb1f)

---
language: "en"
---
# Cellebrite imports

MOBILedit supports the import of 3 types of Cellebrite file formats:

* [Cellebrite UFD](https://forensic.manuals.mobiledit.com/MM/cellebrite-ufd.md) - "Universal Forensic Extraction Device" Physical Dump.

* [Cellebrite UFDR](https://forensic.manuals.mobiledit.com/MM/cellebrite-ufdr.md) - "Universal Forensic Extraction Device Report".

* [Cellebrite filesystem backup](https://forensic.manuals.mobiledit.com/MM/cellebrite-filesystem-backup.md) - CLBX "Cellebrite Logical Extraction"

With this option, you can load Cellebrite UFED, UFDR or CLBX to analyse applications and extract data that Cellebrite may not have been able to.  
These import options are available in the MOBILedit Forensic PRO and ULTRA versions.

---
language: "en"
---
# Cellebrite UFD

**UFD (.ufd)** is a file format used by Cellebrite's UFED (Universal Forensic Extraction Device) to store data extracted from a mobile device. A **.ufd** file typically contains a single phone extraction, while a **.ufdx** file may bundle extractions from multiple devices.

These files represent raw binary images, which may include a **full physical dump** of a device's memory or a **logical/file system extraction**, depending on the method used. They can contain system data, user data, application files, and potentially recoverable deleted content---making them valuable for in-depth forensic analysis.

In **MOBILedit Forensic** , UFD files can be imported for analysis by selecting **Import data \> Cellebrite UFD**. Once imported, supported data types can be parsed and presented as part of a standard logical analysis.  
![Choose_data_to_import_ufd.png](https://forensic.manuals.mobiledit.com/__attachments/a_b498a7bfc09bb3fa27dfc7e839ce97426f33f12dccafa85b511b0b0bdd54b68e/Choose_data_to_import_ufd.png?cb=db2c550f99e9a8025340b837124a2b55)

By using **MOBILedit Forensic** to analyze the content of a UFD file, it is possible to extract and categorize data from a wider range of applications than Cellebrite may support. This often results in more app data being parsed and less content appearing as "uncategorized," enhancing the completeness and clarity of the final analysis.

**Automatic Use of Backup Passwords**

When importing UFD files into MOBILedit Forensic, any embedded ADB or iTunes backup passwords are automatically detected and applied. This removes the need for manual password input during import, streamlining the workflow and ensuring faster access to encrypted backup content where supported.  
This import option is only available in the MOBILedit Forensic PRO and ULTRA versions.

---
language: "en"
---
# Cellebrite UFDR

UFDR stands for "Universal Forensic Extraction Device Report".

The file extension is\*.ufdr.

This is a report generated by Cellebrite's UFED tool. A UFDR file contains the extracted data from a mobile device in a human-readable format, such as text messages, call logs, contacts, and application data. UFDR files are often used to present forensic findings in a structured format that can be reviewed by investigators, lawyers, or other stakeholders.

The UFDR file can be imported into MOBILedit Forensic for a logical extraction by selecting "Import data and then "Cellebrite UFDR". Encrypted UFDR files can also be imported.  
![Choose_data_to_import_ufdr.png](https://forensic.manuals.mobiledit.com/__attachments/a_453a268b51b4f09e3b07f75f011495a106827b2a9f87d570df6840d13c5159cf/Choose_data_to_import_ufdr.png?cb=477f2ecc7c5f8806f1fb3bf4c28808d6)

By using MOBILedit Forensic to analyse the content of a UFDR file it is possible to analyse applications and extract data that Cellebrite may not have been able to.  
This import option is only available in the MOBILedit Forensic PRO and ULTRA versions.

---
language: "en"
---
# Cloud Forensic standalone product

MOBILedit Cloud Forensic standalone software product is for investigating cloud storage and cloud services without the need to examine mobile devices. Access to clouds using this method requires a password and a username or a token imported from another source.

![image (11)-20220613-105319.png](https://forensic.manuals.mobiledit.com/__attachments/a_4d9ed62abba87c71db380aa4e817a540753bdf217a73c083ac81db60416e619a/image%20(11)-20220613-105319.png?cb=2c7ceb4cf2978a49e5875094b7772a7b)  
To be able to use this feature, it is necessary to have a computer connected to the internet.

Information about Cloud Forensic integrated with MOBILedit Forensic PRO can be found [here](https://forensic.manuals.mobiledit.com/MM/data-cloud.md)

## Requirements:

To utilize the cloud module, you will need to have at least one of the following :

* The sign-in credentials for the cloud service (user name \& password)

* Import generated cloud_credentials.json file

Instagram Cloud. When "Account blocked" appears at login, you must log in to Instagram via the web to unblock it, it will require a code from an email or text message and may or may not require a password change.

### The ways to extract data from Clouds:

1. Directly enter the sign-in credentials by using the username and password for the selected cloud

2. Import cloud credentials

### 1. Using sign-in credentials

* ![image-20220613-122327.png](https://forensic.manuals.mobiledit.com/__attachments/a_fd51b5580293203e89dee954179aa9c187ce3c3e14587f15c802118d0510ecd6/image-20220613-122327.png?cb=e0bf819ed64963594d05cd85214f4eb5)

  Select the Cloud you want to extract data from and enter the credentials for only one cloud at a time using this method
* Configure your report by selecting what type of data you want to extract

* Use filters if you looking for a particular time, size, or extension

After the extraction starts, you can click the "Connect more" button and select another cloud for extraction.

Data from Clouds is copied to the computer, if the cloud contains 2TB of data, for example, then the user needs to make sure that they have enough free disk space on the computer. Therefore we advise you to use local filters to select what data you are interested in extracting.

Tokens are only valid for a limited period of time.

### 2. Import cloud credentials

1. On the Start page click on "Connect cloud"

![cloud sep.png](https://forensic.manuals.mobiledit.com/__attachments/a_49f1f45b862180662aa60aa98c586a1e003e69e96bd3f188b9a3c7d3c196c051/cloud%20sep.png?cb=cafd6b0fac4a8d95d2d9c5edcccb150b)

2. Click "Import cloud credentials":  
![cloud im.png](https://forensic.manuals.mobiledit.com/__attachments/a_def3d33ab4d0327200cb4e272ad15808d14973e37a04e10dfcaaaf2d64ea39c6/cloud%20im.png?cb=624be5c6104b7519d5e3213d47c738b5)

3. Select the cloud credentials file that has been previously extracted from the device. This is stored in the file "cloud_credentials.json":  
![ccccloud.png](https://forensic.manuals.mobiledit.com/__attachments/a_94aaa6a6d1af72a62ede9df7a652c2f9da6d12f60996aacf95463292e71b864a/ccccloud.png?cb=d7273a309a577dc6b1d778c8110d7679)

4. Select the cloud you want to extract data from, you can select multiple clouds at once. Then click "Next".  
![cloud sep 2.png](https://forensic.manuals.mobiledit.com/__attachments/a_ddb4c57915d599eb9e03a540cb10e6431a45dcbcdb3a16016022093488aef742/cloud%20sep%202.png?cb=86255488018abc49fc5b81fa18a02c27)

5. On the next page you will see which cloud services MOBILedit Cloud Forensic was able to log in to. Select what cloud(s) you would like to extract, and continue to the next page where you can use the filters to choose what type of data you want to extract. Then specify the report details and choose one or more output formats.  
![cloud sep 3_blurred.png](https://forensic.manuals.mobiledit.com/__attachments/a_74f72b0da8c57eb5f96ac07b3c1b558973a626e51c553c0905adb52d26dde3be/cloud%20sep%203_blurred.png?cb=dfb8ff300331e163453ea8b926192383)

---
language: "en"
---
# CMD method - Flashing TWRP on non-Samsung devices

## Requirements:

1. Your Android device

2. Unlocked bootloader

3. ADB and Fastboot installed on your PC

4. Computer with Windows 7 and above or Linux

5. All the correct drivers for your phone installed

6. TWRP image file for your device (ends with ".IMG")

## How to

If your device is locked or you cannot boot into the system, use the hotkey combination for your phone to boot into Fastboot mode and skip straight to step 6.

1. Make sure you have USB debugging enabled on your device.

2. Connect your phone to your PC via USB.

:a:

Open command line (CMD) in the folder you have your ADB and Fastboot installed or use Minimal ADB \& Fastboot.

3. Type *"adb devices"*into the command line to see if your device is recognized by ADB.  
![adb2 (1).PNG](https://forensic.manuals.mobiledit.com/__attachments/a_a44b47afbcde847e696b536757e622d015592f1ca7d38b1e6fbcedc01c8ddb14/adb2%20(1).PNG?cb=aab9a01dbde22941d96258955bdc5eb0)

4. Type *"adb reboot bootloader"*into the command line and wait until your device reboots into Fastboot mode.  
![adb3 (1).PNG](https://forensic.manuals.mobiledit.com/__attachments/a_9c92a566984bff64d9058d940143fd78e59a8747fb8e17ff01eaba1271cb9d07/adb3%20(1).PNG?cb=7417d4c7703b443d21a6366bfadf0ed3)

5. Copy the TWRP image file to the folder where your ADB and fastboot is installed

(for example: C:\\Program Files (x86)\\Minimal ADB \& Fastboot).

6. Rename the file to "twrp.img"

7. Type *"fastboot flash recovery twrp.img"*into the command line and wait for the process to finish.  
![adb4.PNG](https://forensic.manuals.mobiledit.com/__attachments/a_83510cc552d6aba024c3bf99249c31c90253f7da77420c2f4979589286d40a10/adb4.PNG?cb=749a77c50c3cd6dac71feaf3b3c27059)

8. After the process has finished, you can type *"fastboot reboot"*to reboot your phone back to Android, or, switch it off and use hotkey combination to boot straight into your newly flashed TWRP.  
Flashing custom recoveries may void your warranty!  
You can also try to use our in-built flashing tool for TWRP, more information is available [here](https://forensic.manuals.mobiledit.com/MM/flash-phone-with-recovery-image-twrp.md).

---
language: "en"
---
# Common issues preventing the installation and operation of MOBILedit Forensic software

If you are experiencing issues when installing MOBILedit Forensic, here are some commonly reported issues with easy solutions! These solutions can also be applicable if you are experiencing communication issues between MOBILedit Forensic software and our server.

The software needs to communicate with the server for licensing and updates.

**Windows 7**

If something on your computer is blocking access, it might be because of one or more of the following:

* Your computer's operating system is using old root certificates

  * Root certificates for Windows 7 are no longer issued. If this is the only issue you are experiencing and all other potential issues have been checked and are ok, you will need to update your operating system.

* Setup of your firewall or anti-virus

  * You will need to check your firewall and anti-virus settings to allow the installation of MOBILedit Forensic. MOBILedit Forensic needs to be allowed to connect to the internet for license activation and if you would like to install live updates. It does not require an internet connection to operate, and the USB dongle license version is intended for offline air-gapped network use.

* TLS is disabled

  * Please open internet properties and select the advanced tab. Check the boxes for Use TLS 1.0, 1.1 and 1.2 (Shown below - if you change other settings it is at your own risk.

* ![image-20230201-095856.png](https://forensic.manuals.mobiledit.com/__attachments/a_eb1e03641e5f6c4924cb2de9b96dd3bac9770f6cb1bfbe0ae15df2e0b2e163f8/image-20230201-095856.png?cb=9d06732ef5337a4bd2884e3415fc1c18)

**Windows 10 \& 11**

* Setup of your firewall or anti-virus

  * You will need to check your firewall and anti-virus settings to allow the installation of MOBILedit Forensic and all its associated software. MOBILedit Forensic needs to be allowed to connect to the internet for license activation and if you would like to install live updates. It does not require an internet connection to run extractions and analysis, and the USB dongle license version is intended for offline air-gapped network use.

* TLS is disabled

  * Please open internet properties and select the advanced tab. Check the boxes for Use TLS 1.0, 1.1 and 1.2 (Shown below - if you make any other changes, it is at your own risk.

* Controlled folder access (CFA)

  * Controlled folder access in Windows Security reviews the apps that can change files in protected folders and blocks unauthorized or unsafe apps from accessing or changing files in those folders. If you wish to keep CFA enabled, you can add MOBILedit Forensic and its other associated programs to the list of safe or allowed apps to prevent them from being blocked. Otherwise, disable CFA if this is your choice.

![image-20230201-105738.png](https://forensic.manuals.mobiledit.com/__attachments/a_e2c66bcfac7a83bf59d7cf441fd2a37b349b44d5af795d6752dcca4f023e6279/image-20230201-105738.png?cb=61b83fe60c5daecf43e8a6ba4f970002)

---
language: "en"
---
# Remove connector / Stop communication service

If ADB has no root privileges, to get root access, our communication service is started by using our Forensic connector app installed and running on the device. The user is prompted to allow installation of the Forensic Connector app for operations where it is required, or where more data could be obtained by installing it.

Even if ADB has root privileges, we recommended installing and using the connector app for faster and more reliable communication. The communication service is started automatically whenever possible and if our connector application is installed on the device.

The "Stop communication service" button can be used to stop our communication service and remove any artefacts remaining on the phone after the operation of the service. The Forensic Connector app can also be removed by selecting "Remove connector". We also recommend restarting the device to clear any remaining traces.

![image-20250613-094306.png](https://forensic.manuals.mobiledit.com/__attachments/a_503e7dae33c39de71d859a257414c5cc012fd88851c8c18f4ad2578875beb8c5/image-20250613-094306.png?cb=adf4fa8b84f2bedc5e77660a87518552)

---
language: "en"
---
# Cómo habilitar la depuración USB

La depuración por USB se encuentra en las "Opciones del desarrollador", pero está oculto. Primero tendrá que hacerlo visible:

1. Acceda a Configuración -\> Acerca del teléfono

2. Acceda a "Número de compilación" al final de la lista desplegable.

3. Presione 7 veces el "Número de compilación" ("Versión Android" en algunos dispositivos). Al presionar por tercera vez, aparecerá un mensaje indicando que tras presionar 4 veces más accederá al "modo desarrollador".

4. Vuelva a la página de Configuración. Ahora debería aparecer una Opción para desarrolladores en la lista de configuración.

5. Seleccione las Opciones del desarrollador y active la Depuración por USB -\> ON

## Ver todas las instrucciones con imágenes

1. Acceda a la Configuración de su teléfono.

![Screenshot_2019_03_08_08_58_06.png](https://forensic.manuals.mobiledit.com/__attachments/a_8b29433dc3c69717ab7157ead07910264b45d542e87ce1990850c1b36da23d94/Screenshot_2019_03_08_08_58_06.png?cb=49ab9cef0417409d4335bf8cc80dbb7a)

2. Elija "General" en los Marcadores de Configuración.  
![Screenshot_2019_03_08_08_58_22.png](https://forensic.manuals.mobiledit.com/__attachments/a_60f5789a9a40290fec909a01cad89f92fdaeea3e3e50aa39db9cf70efb5cfccd/Screenshot_2019_03_08_08_58_22.png?cb=3f10a3f60a2c377d74468b659f29a99f)

3. Acceda a la sección Acerca del teléfono.  
![Screenshot_2019_03_08_08_58_38.png](https://forensic.manuals.mobiledit.com/__attachments/a_ac6611aee4a18f30e40a574d23f42c25410f06c568eeadbb6c098e6e0a673390/Screenshot_2019_03_08_08_58_38.png?cb=60dcc31d12cd4af06563ff42f781479b)

4. Acceda a la información del software  
![Screenshot_2019_03_08_09_01_30.png](https://forensic.manuals.mobiledit.com/__attachments/a_6ab68e875390e2a61f8386fde5edd3a7e3c38f3c792510ed860dd471bcded04f/Screenshot_2019_03_08_09_01_30.png?cb=f2324b5a434be40da492ef398b2444df)

5. Presione 7 veces el "Número de compilación", para que aparezca el siguiente mensaje  
![Screenshot_2019_03_08_09_04_32.png](https://forensic.manuals.mobiledit.com/__attachments/a_1b772b822ea98600f9621aa6d37af608cb6973f361e22af4289f51de36259ecc/Screenshot_2019_03_08_09_04_32.png?cb=f9e5107777812abaeaa0c072ed488da4)

6. Vuelva atrás y desplácese hacia abajo hasta encontrar las "Opciones del desarrollador".  
![Screenshot_2019_03_08_09_04_43.png](https://forensic.manuals.mobiledit.com/__attachments/a_8600dc3911052be91b5fef5d4bfbfb83fbd8437a005757fb278b0a60fb94c665/Screenshot_2019_03_08_09_04_43.png?cb=9894fd7bf16ce6ace91f0eb6e219de17)

7. Haga clic en la opción "Depuración por USB" y confirme el mensaje que aparece en la pantalla  
![Screenshot_2019_03_08_09_05_12.png](https://forensic.manuals.mobiledit.com/__attachments/a_e895735dec8df29641ecccdba6830f2ba6a55100adda17b72104f86b5d21fb95/Screenshot_2019_03_08_09_05_12.png?cb=ac681e6da4119c1f1af350e022d0da9f)

### Dispositivos Huawei

ISi está activando la depuración por USB en un dispositivo Huawei, asegúrese también de "permitir depuración ADB en modo solo carga" en la sección de Depuración en las Opciones del desarrollador. Esto evitará la mayoría de los casos, cuando la depuración por USB se apague automáticamente a causa del EMUI.  
![Screenshot_20190308_104542.png](https://forensic.manuals.mobiledit.com/__attachments/a_0a8989f05513604bde0929aebb7f3bc7a2f93d0c535651cdedf21ce5deee6524/Screenshot_20190308_104542.png?cb=a229fdb0a3009744221f4506f4a727c5)  
Para EMUI 5.0 o superior, quizá sea necesario conectar el teléfono al PC antes de habilitar la depuración por USB, ya que de lo contrario podría seguir apagándose automáticamente.

### Dispositivos Xiaomi

Si está activando la depuración por USB en un dispositivo Xiaomi, asegúrese también de habilitar todas las categorías en la sección de Depuración en las Opciones del desarrollador. Esto permitirá que la app Connector se pueda instalar en su teléfono.

![Screenshot_2019_03_08_11_08_12_991_com_android_settings.png](https://forensic.manuals.mobiledit.com/__attachments/a_e5a422fcc36d5bb74dc4eb8e9968aa29ad9f7ca8b6db389f7e6445eeae8413eb/Screenshot_2019_03_08_11_08_12_991_com_android_settings.png?cb=e31f76d05c1f7eb97ec0793f71e07c57)  
Para habilitar estas dos opciones, necesitará insertar una tarjeta SIM en el teléfono y haber iniciado sesión en Mi Cuenta.

[Next Page](https://forensic.manuals.mobiledit.com/llms-full.txt/1)
