Menu

#1 Development Test

None
open
nobody
help wanted (1)
2015-02-13
2015-02-12
Anonymous
No

Originally created by: AFFT-520
Originally owned by: AFFT-520

AFFT is currently in Alpha, and only works fully on Linux. The extraction toolset will NOT work under Windows (even with Cygwin), and won't work under OSX, due to Window's lack of loopback interfaces and both OSes lacking Ext4 support (for extracting data). This program is Live-CD compatible, and outputs in universal formats, so the results can be analysed on any system.

SUPPORTED APPS

Gmail
SMS/MMS
Contact List
Call Log
Skype
WhatsApp
Facebook (including Messenger)

REQUIREMENTS

Host PC:

Linux OS (tested on Ubuntu 14.04)
SQLite3
'pv' command
ADB, as distributed via the Google Android SDK. This must also be in your $PATH

Requirements for the client Android device:

Must be rooted
Must have BusyBox
Must have USB Debug enabled

To install, either install the Debian archive or rename the 'afft-src' folder to 'afft' and put it in /opt/. To execute, run /opt/afft/main.sh. All case files, including Android images and extracted data are held in the user's home directory under 'afft-cases'.

BUG-REPORTS

I am interested in all bug reports and contributions. All contributions must be under the GPLv2 license (or compatible) to be considered for merging into mainline. Of particular importance are the following:

Phone compatibility reports patches - This is only tested on the Google Nexus 5 phone and Google Nexus 7 (2012 model) tablet. As many manufacturers diverge from stock Android, compatibility issues are of paramount concern.

Extractor scripts for particular apps, and any compatibility issues surrounding them (I have provide a template with instructions for writing your own scripts)

TO-DO

Support for the full AOSP app stack
Full Google Applications stack support (currently only Gmail is supported)
Adapt the extraction scripts for use on removable media on the device itself (sans PC)
Tinder Support
Twitter Support

Discussion

  • Android Free Forensic Toolkit

    • Description has changed:

    Diff:

    --- old
    +++ new
    @@ -28,7 +28,7 @@
     Must have BusyBox
     Must have USB Debug enabled
    
    -To install, put the 'afft' folder in /opt/. To execute, run /opt/afft/main.sh. All case files, including Android images and extracted data are held in the user's home directory under 'afft-cases'.
    +To install, either install the Debian archive or rename the 'afft-src' folder to 'afft' and put it in /opt/. To execute, run /opt/afft/main.sh. All case files, including Android images and extracted data are held in the user's home directory under 'afft-cases'.
    
     BUG-REPORTS
    
    • Milestone: -->
     

Log in to post a comment.

MongoDB Logo MongoDB