Mobile and Cloud Forensics: iOS, Android & Cloud Provider Evidence
More evidence now lives on phones and in cloud provider logs than on local disks alone. This chapter covers both, plus the acquisition and legal complications that come with evidence you don't physically control.
Mobile Forensics Fundamentals
Mobile acquisition is usually described in tiers, from a quick manual look to a full bit-for-bit copy. Each tier trades off completeness against what the device and its encryption will actually allow.
| Acquisition Tier | What It Recovers |
|---|---|
| Manual | Examiner navigates the device UI directly and photographs or notes what's visible. Minimal, but sometimes the only option on a locked or unsupported device. |
| Logical | Extracts accessible files and databases through the OS's normal APIs, similar in concept to a live triage collection rather than a raw disk copy. |
| Filesystem | A fuller extraction of the accessible filesystem. More than logical, but still not everything on the device. |
| Physical | Ideally a full bit-for-bit copy of the device's storage, though modern device encryption makes true physical acquisition increasingly hard or impossible without device-specific support. |
Encryption and secure hardware enclaves on modern iOS and Android devices have pushed most real-world acquisitions toward the logical and filesystem tiers. Full physical acquisition still happens, but it increasingly depends on vendor-specific tooling and known device vulnerabilities rather than being a routine option.
iOS and Android Artifact Categories
Once data is extracted, it groups into a handful of recurring artifact categories across both platforms. These categories are where an examiner starts looking, not an exhaustive list.
| Artifact Category | Example |
|---|---|
| Communications | Call logs, SMS, iMessage, and RCS messages. |
| App data | Most apps store data in SQLite databases on-device, covering everything from chat history to app-specific settings. |
| Location history | Cached location data tied to individual apps and to OS-level location services. |
| Deleted-item recovery | SQLite databases often retain deleted records in unallocated pages or write-ahead log files until overwritten, similar in spirit to the deleted-file recovery covered in chapter 2. |
Cloud Forensics Fundamentals
Cloud forensics operates inside the shared responsibility model rather than something separate from it. What an examiner can access and acquire depends on which layer the organization actually controls.
The key forensic difference from on-prem is where the evidence lives. Instead of a disk the organization holds, evidence sits in provider-side logs whose retention the examiner doesn't control.
This ties back to the order-of-volatility idea from chapter 1. Cloud log retention windows can be short, which makes some cloud evidence effectively more volatile than a local disk sitting untouched on a shelf.
Cloud Provider Evidence Sources
Each major cloud and productivity platform exposes its own audit log format. The specific fields retained vary and change over time, but the general purpose of each source is stable.
| Source | What It Captures |
|---|---|
| M365 Unified Audit Log | User and admin activity across Exchange, SharePoint, and Teams. |
| Azure AD / Entra ID sign-in logs | Authentication attempts and conditional access decisions. |
| AWS CloudTrail | API calls made against an AWS account. |
| GCP Audit Logs | API and admin activity in Google Cloud. |
Legal Complexity Across Jurisdictions
Mobile and cloud evidence introduces legal wrinkles that an on-prem disk the organization already owns doesn't have.
- Data residency: where the data physically sits can determine whose law applies to it.
- Provider cooperation: getting data from a cloud provider or mobile carrier typically requires going through their own legal request process, not direct access.
- Earlier legal involvement: because of the above, legal counsel needs to be looped in earlier for mobile and cloud evidence requests than for a disk the organization already controls.
This legal complexity is a major reason cloud and mobile evidence takes longer to obtain than the host evidence covered in earlier chapters.
Key Takeaways
- Mobile acquisition tiers run manual, logical, filesystem, physical, with encryption pushing most real-world work toward logical and filesystem.
- iOS and Android artifacts group into communications, app data, location history, and deleted-item recovery from SQLite databases.
- Cloud forensics sits inside the shared responsibility model; what you can acquire depends on which layer you control.
- Cloud evidence lives in provider logs the examiner doesn't control the retention of, which can make it more volatile than a local disk.
- Key cloud evidence sources include the M365 Unified Audit Log, Entra ID sign-in logs, AWS CloudTrail, and GCP Audit Logs.
- Data residency and provider cooperation requirements mean legal counsel needs to be involved earlier for mobile and cloud evidence.
Knowledge Check
Click an answer to reveal the explanation.
A logical acquisition of a mobile device recovers which of the following?
What does AWS CloudTrail primarily capture?
Why can cloud provider logs be considered more volatile than a local disk in some cases?