Digital forensics and analysis for Android devices

With the widely use of smart phones, Android devices have become an important data source in forensic investigation, and many tools which collecting data from Android devices have also been introduced. However, most current studies consider only flashing the NAND card, nearly paying attention to eMMC card. Therefore, based on Android Recovery Mode, our paper designed a general forensic tool giving consideration to both NAND and eMMC card. And after exploring the possibility of data recovery when application is uninstalled from Android device which is formatted as Ext4 file system, finally a method for data recovery based on hash value matching of journal file is put forward.