Key points are not available for this paper at this time.
Mobile devices are now so ubiquitous that they have revolutionized the way we do most of our activities. As a result, the mobile device is now a huge repository of confidential and personal information about its owner. This has led to the development of mobile forensics, which focuses on the recovery and investigation of mobile data. The purpose of the diagnostic process is to retrieve and recover any information from a mobile device without changing the data on the device. Over the years, digital forensics has expanded with the rapid growth of mobile devices. There are different branches of digital forensics depending on the type of digital device, such as computer forensics, network forensics, mobile forensics, etc. Data obtained from telephones becomes an invaluable source of evidence for investigations in criminal and civil cases. It's rare to conduct digital forensics without using a phone. Third-party applications are an integral part of the investigation mobile device. This requires understanding where app data is stored on the device, what app data is stored for that platform, and which tool best helps uncover the evidence. Although some commercial tools, such as Magnet IEF, are known for supporting application parsing, no tool is perfect, and it is nearly impossible for tools to keep up with the frequent updates that are released for each application. The most commonly available commercial tools analyze the most popular programs on the market. For example, when Facebook acquired WhatsApp, Cellebrite, IEF, and Oxygen Forensics started supporting the app. This is where all programs differ.
Olha V. Isachenko (2024) studied this question.