CHAPTER 07 40 MIN READ ADVANCED

Mobile and Cloud Forensics: iOS, Android & Cloud Provider Evidence

More evidence now lives on phones and in cloud provider logs than on local disks alone. This chapter covers both, plus the acquisition and legal complications that come with evidence you don't physically control.

mobile forensicscloud forensicsiOS acquisitioncloud audit logs

Mobile Forensics Fundamentals

Mobile acquisition is usually described in tiers, from a quick manual look to a full bit-for-bit copy. Each tier trades off completeness against what the device and its encryption will actually allow.

Acquisition TierWhat It Recovers
ManualExaminer navigates the device UI directly and photographs or notes what's visible. Minimal, but sometimes the only option on a locked or unsupported device.
LogicalExtracts accessible files and databases through the OS's normal APIs, similar in concept to a live triage collection rather than a raw disk copy.
FilesystemA fuller extraction of the accessible filesystem. More than logical, but still not everything on the device.
PhysicalIdeally a full bit-for-bit copy of the device's storage, though modern device encryption makes true physical acquisition increasingly hard or impossible without device-specific support.

Encryption and secure hardware enclaves on modern iOS and Android devices have pushed most real-world acquisitions toward the logical and filesystem tiers. Full physical acquisition still happens, but it increasingly depends on vendor-specific tooling and known device vulnerabilities rather than being a routine option.

Note: the tier you can achieve is a device and case-specific decision, not a preference. Document why a given tier was chosen alongside what it recovered.

iOS and Android Artifact Categories

Once data is extracted, it groups into a handful of recurring artifact categories across both platforms. These categories are where an examiner starts looking, not an exhaustive list.

Artifact CategoryExample
CommunicationsCall logs, SMS, iMessage, and RCS messages.
App dataMost apps store data in SQLite databases on-device, covering everything from chat history to app-specific settings.
Location historyCached location data tied to individual apps and to OS-level location services.
Deleted-item recoverySQLite databases often retain deleted records in unallocated pages or write-ahead log files until overwritten, similar in spirit to the deleted-file recovery covered in chapter 2.
Note: app data artifacts are the largest and fastest-moving category. New apps and app updates change database schemas often, so tooling and known artifact locations need regular revalidation.

Cloud Forensics Fundamentals

Cloud forensics operates inside the shared responsibility model rather than something separate from it. What an examiner can access and acquire depends on which layer the organization actually controls.

For the full shared responsibility breakdown and cloud attack techniques, see the Cloud Security module.

The key forensic difference from on-prem is where the evidence lives. Instead of a disk the organization holds, evidence sits in provider-side logs whose retention the examiner doesn't control.

This ties back to the order-of-volatility idea from chapter 1. Cloud log retention windows can be short, which makes some cloud evidence effectively more volatile than a local disk sitting untouched on a shelf.

Cloud Provider Evidence Sources

Each major cloud and productivity platform exposes its own audit log format. The specific fields retained vary and change over time, but the general purpose of each source is stable.

SourceWhat It Captures
M365 Unified Audit LogUser and admin activity across Exchange, SharePoint, and Teams.
Azure AD / Entra ID sign-in logsAuthentication attempts and conditional access decisions.
AWS CloudTrailAPI calls made against an AWS account.
GCP Audit LogsAPI and admin activity in Google Cloud.
Note: treat exact field names and retention defaults as something to verify per engagement. They shift as providers update their logging products.

Key Takeaways

  • Mobile acquisition tiers run manual, logical, filesystem, physical, with encryption pushing most real-world work toward logical and filesystem.
  • iOS and Android artifacts group into communications, app data, location history, and deleted-item recovery from SQLite databases.
  • Cloud forensics sits inside the shared responsibility model; what you can acquire depends on which layer you control.
  • Cloud evidence lives in provider logs the examiner doesn't control the retention of, which can make it more volatile than a local disk.
  • Key cloud evidence sources include the M365 Unified Audit Log, Entra ID sign-in logs, AWS CloudTrail, and GCP Audit Logs.
  • Data residency and provider cooperation requirements mean legal counsel needs to be involved earlier for mobile and cloud evidence.

Knowledge Check

Click an answer to reveal the explanation.

A logical acquisition of a mobile device recovers which of the following?

Correct answer: B. Logical acquisition uses the OS's own APIs to pull accessible files and databases. A full bit-for-bit copy is physical acquisition, and on-screen-only review is manual acquisition.

What does AWS CloudTrail primarily capture?

Correct answer: B. CloudTrail logs API calls made against the account, which is the cloud equivalent of an activity trail rather than packet or endpoint telemetry.

Why can cloud provider logs be considered more volatile than a local disk in some cases?

Correct answer: B. A local disk can sit untouched, but provider-side retention windows are set by the provider and can roll evidence off before it's collected, which is why it needs to be treated with urgency similar to other volatile evidence.