Smartphones are increasing worldwide rapidly. It works as a personal assistant that helps us master our everyday life. This is the reason why forensic experts always try to get the most crucial evidence from smartphones. While doing a forensic analysis of smartphones there is a need to identify the programs/files containing malicious actions or activity. Most of the users’ information resides inside the digital device and should be extracted carefully as it is needed for further users’ entity and behavior analytics. In this study, we used the most famous forensic tools MOBILedit and Autopsy for efficient extraction of potential evidence from the Android file system. The file system images from different android devices (rooted and unrooted) are extracted on multiple analyses (type-based, size-based). Additionally, a timeline of the log files has also been made, which can assist the investigator in locating any log files that were updated or altered at the scene of the crime by suspects or victims.
Copyrights © 2022