N00b here. I starting with forensics and I am working on a project to do a forensic analysis on Android phones including deleted data and memory dump. Any suggestions on free tools or demos I can use? I looked around and there is not a whole lot I can see.
Any help is appreciated.
Hey,
For Android memory acquisition have a look at Linux Memory Extractor (LiME).
As far as open source tools for Android you can check out Via Forensics's Santoku (free linux distro for mobile forensics) and Open Source Android Forensics (OSAF).
As for accessing deleted content, it depends what content you are looking for. If it's data stored on the SD Card (pictures, application data, etc.) you can acquire the card with FTK Imager, dd, or any other acquisition tool and then use a data carving program like photorec, scalpel, or foremost.
If rooting the device is a possibility, you will have additional options such as extracting the text message database and using sqlite and a hex editor to try to identify and recover deleted content. Unfortunately this is a manual and time consuming process but it will also help you learn a great deal.
Hope this points you in the right direction, good luck!
In addition to what LilPopps21 said you can also use TSK (The sleuth kit) or it's GUI based version Autopsy.
Thanks guys. I really appreciate it.
I'm still getting used to the forum, so if I need to award points, let me know. Thanks again.
You used to be able to get a 6 month free trial of Oxygen Forensics for mobile phones. Not sure if you still can but that would be worth a look too.
I read you post find more information. Best prototyping tool to create clickable wireframes and web apps 100% free forever because always reference links. Thanks for sharing with us.
Thanking you !!!
Quantel
You may want to consider getting a copy of Andrew Hoog's book on Android Forensics. I know it is dated, but it still contains pertinent information. Speaking of demos You should also try to get a demo of Susteen's Secure View3 as well http//
Disclaimer I am a contract instructor for Sumuri, LLC
Regards,
Chris Currier


