performing-mobile-device-forensics-with-cellebrite

Extract mobile device data from Android and iOS sources using Cellebrite UFED workflows.

Updated Apr 23, 2026
One-click install
npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill performing-mobile-device-forensics-with-cellebrite
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: performing-mobile-device-forensics-with-cellebrite
Source: https://github.com/YukiIto1999/ctf-sleuth/tree/main/.claude/skills/performing-mobile-device-forensics-with-cellebrite
Command: npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill performing-mobile-device-forensics-with-cellebrite

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This skill helps investigators rapidly acquire and analyze mobile-device data from smartphones and tablets to uncover communications, locations, and application artifacts that support investigations.

Core Features & Use Cases

  • Logical extraction: Extracts accessible data from device APIs and apps to build a coherent evidence timeline.
  • File system & physical extraction: Provides full data access, including databases and potential deleted content where available.
  • Communications & artifacts: Collects messages, call logs, location history, app data, and media for case reconstruction.
  • Compatibility: Works with Cellebrite UFED and open-source parsers like ALEAPP, iLEAPP, and libimobiledevice.
  • Real-world use: Supports criminal investigations, corporate investigations, and OSINT tasks involving mobile data.

Quick Start

Run the agent to parse a mobile device extraction and generate a comprehensive forensics report.

Frequently Asked Questions about performing-mobile-device-forensics-with-cellebrite

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I extract and analyze mobile data from iOS and Android devices for forensics?

Mobile forensics extraction identifies and extracts data from Android and iOS sources using Cellebrite UFED workflows alongside open-source parsers like ALEAPP and iLEAPP to produce structured artifacts and reports.

Does this mobile forensics workflow support both logical and physical extraction?

Yes, the workflow supports logical extraction from device APIs and apps to build timelines, as well as file system and physical extraction for full data access including databases and potential deleted content.

What types of digital evidence can I recover during a mobile device investigation?

Mobile forensics investigations recover communications, call logs, location history, app data, and media artifacts, reconstructing case evidence for criminal investigations, corporate inquiries, and OSINT tasks.

Can I use open-source parsers like ALEAPP and iLEAPP with Cellebrite UFED extractions?

Yes, the workflow leverages Cellebrite UFED extractions and processes them with open-source parsers like ALEAPP, iLEAPP, and libimobiledevice to generate comprehensive structured forensics reports.

What is the best way to generate a forensics report from a mobile device extraction?

The best way to generate a forensics report is to run the agent on a mobile device extraction, parsing messages, call logs, and app artifacts into structured data for final case reconstruction.

When should I use physical extraction instead of logical extraction for mobile forensics?

Use file system and physical extraction when you need full data access beyond device APIs, including databases and potential deleted content, whereas logical extraction focuses on accessible app data and timeline building.