Android Free Forens...
 
Notifications
Clear all

Android Free Forensic Toolkit [Alpha]

4 Posts
2 Users
0 Reactions
495 Views
(@fivetwozero)
Active Member
Joined: 11 years ago
Posts: 6
Topic starter  

Hi guys.

I'm writing a toolkit to help automate the imaging process and ease the analysis of communications and activity. It's totally free to download, although I cant guarantee everything will work as of yet (hence, alpha release).

If you are wondering why the last non-packaging commit was so long ago, that was because of my masters degree, which I have now (mostly) finished. Work will resume on the project as soon as I am back from Holland.

Current feature set

- Assists in imaging via dd (any method of gaining root access can be used, I prefer temp-booting devices to the TWRP recovery image myself)
- Mounts images in a forensically safe manner (Linux only)
- Extracts and analyses databases from a number of Android Applications (primarily social media at this time)
- Maintains a database of the 'getprop' settings at the time of imaging, can be used to prove some of the conditions under which the device was imaged
- Creates HTML reports of user activity by application, translating the data from the databases into human-readable information
- Creates a timeline of recorded usage of said applications in both HTML and SQLite database format

TODO

- Dropbox support
- Option for filesystem timeline
- Support for encrypted filesystems

You can find the latest Windows binary in the repository (https://github.com/AFFT-520/Android-Free-Forensic-Toolkit/blob/master/dist/Alpha3/Android_Free_Forensic_Toolkit_Alpha_3.exe). This program will work on Linux and *should* work on OSX (I don't have a Mac to test it on).

Let me know what you think.


   
Quote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

Just in case, previous topic
http//www.forensicfocus.com/Forums/viewtopic/p=6576929/

jaclaz


   
ReplyQuote
(@fivetwozero)
Active Member
Joined: 11 years ago
Posts: 6
Topic starter  

Just in case, previous topic
http//www.forensicfocus.com/Forums/viewtopic/p=6576929/

jaclaz

Yeah, I didn't think it was wise to necro a year-old topic, and a lot has changed with the tool. The tool was rewritten almost completely in Python, supports a lot more applications and has a lot of new functionality.


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

Yeah, I didn't think it was wise to necro a year-old topic, and a lot has changed with the tool. The tool was rewritten almost completely in Python, supports a lot more applications and has a lot of new functionality.

Sure ) , but it seemed like it was a brand new thingy, not an evolution of something that was already announced here.
This way you have the best of both worlds, a brand new topic and a link to "previous art".

jaclaz


   
ReplyQuote
Share: