A Novel Framework for Mobile Forensics Investigation Process

preprint OA: closed
Full text JSON View at publisher

Abstract

Abstract Investigating digital evidence by gathering, examining, and maintaining evidence that was stored in smartphones has attracted tremendous attention and become a key part of digital forensics. The mobile forensics process aims to recover digital evidence from a mobile device in a way that will preserve the evidence in a forensically sound condition, this evidence might be used to prove to be a cybercriminal or a cybercrime victim. To do this, the mobile forensics process lifecycle must establish clear guidelines for safely capturing, isolating, transporting, storing, and proving digital evidence originating from mobile devices. There are unique aspects of the mobile forensics procedure that must be taken into account. It is imperative to adhere to proper techniques and norms in order for the testing of mobile devices to produce reliable results. In this paper, we develop a novel methodology for the mobile forensics process model lifecycle named Mobile Forensics Investigation Process Framework (MFIPF) which encompasses all the necessary stages and data sources used to construct the crime case. The developed framework contributes to identifying common concepts of mobile forensics through the development of the mobile forensics model that simplifies the examination process and enables forensics teams to capture and reuse specialized forensic knowledge. Furthermore, the paper provides a list of the most commonly used forensics tools and where can we use them in our proposed mobile forensic process model.
Full text 180,725 characters · extracted from preprint-html · click to expand
A Novel Framework for Mobile Forensics Investigation Process | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article A Novel Framework for Mobile Forensics Investigation Process Mohammed Moreb, Saeed Salah, Belal Amro This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-2611927/v1 This work is licensed under a CC BY 4.0 License Status: Published Journal Publication published 20 Apr, 2024 Read the published version in International Journal of Computing and Digital Systems → Version 1 posted You are reading this latest preprint version Abstract Investigating digital evidence by gathering, examining, and maintaining evidence that was stored in smartphones has attracted tremendous attention and become a key part of digital forensics. The mobile forensics process aims to recover digital evidence from a mobile device in a way that will preserve the evidence in a forensically sound condition, this evidence might be used to prove to be a cybercriminal or a cybercrime victim. To do this, the mobile forensics process lifecycle must establish clear guidelines for safely capturing, isolating, transporting, storing, and proving digital evidence originating from mobile devices. There are unique aspects of the mobile forensics procedure that must be taken into account. It is imperative to adhere to proper techniques and norms in order for the testing of mobile devices to produce reliable results. In this paper, we develop a novel methodology for the mobile forensics process model lifecycle named Mobile Forensics Investigation Process Framework (MFIPF) which encompasses all the necessary stages and data sources used to construct the crime case. The developed framework contributes to identifying common concepts of mobile forensics through the development of the mobile forensics model that simplifies the examination process and enables forensics teams to capture and reuse specialized forensic knowledge. Furthermore, the paper provides a list of the most commonly used forensics tools and where can we use them in our proposed mobile forensic process model. Mobile Forensics Digital Forensics Forensic tools Acquisition iOS Android Extraction Artifacts Figures Figure 1 Figure 2 1. Introduction In the current era of the digital age, it is undoubtedly shown that mobile applications have profoundly transformed every aspect of human lives. Users are now relying on mobile applications to do many online activities such as browsing the internet, shopping, transferring money, doing business, communicating using audio or video calls, texting, entertainment, and education. This massive growth of smartphone usage is still incredibly popular and will continue to be for the foreseeable future. According to Fig. 1, The annual sales of smartphones have tremendously increased to around (1.56) billion devices worldwide, smartphones running the Android operating system hold an (87%) share of the global market in 2019 and this is expected to increase over the forthcoming years, while Apple iOS; the second most popular operating system has a (13%) market share across all devices. Figure 1: Share of global smartphone shipments by operating system from 2014 to 2023 [ 1 ] With this tremendous use of smartphones worldwide, the wide adoption of these devices to carry out technology-oriented services, and the uncontrolled use of mobile applications have turned the mobile environment into a fertile spot to carry out many unethical and illegal activities. Consequently, smartphones became a famous target for cyber-attacks bearing in mind that these devices contain private data [ 2 ]. The portability of these devices and the sensitivity of the data they contain raised great concern about the feasibility of using traditional digital forensic methodologies and to what extent they fit this field [ 3 ]. Smartphones are equipped with many capabilities that make forensic steps difficult to be handled and require great attention. These capabilities include the availability of different communication technologies such as SMS, 3G, Wi-Fi, GPS, …, etc., the ability to remotely instruct the device to switch on or off, and the ability to remotely wipe data using different mobile applications. These issues and others created a big challenge for the investigators when dealing with mobile digital evidence [ 4 ]. In this regard, a set of terminologies, definitions, and legal issues have appeared that describe the new criminal situations raised due to this new computing paradigm. One of these terminologies is digital forensics which refers to the process of collecting digital evidence from a digital device and analyzing it to prove the guilt or innocence of persons [ 5 ]. Mobile forensics is another terminology derived from digital forensics, it aims to recover digital evidence from a smartphone in a way that will preserve the evidence in a forensically sound condition. To conduct mobile forensics analysis, the mobile forensic process lifecycle needs to set out precise rules that will seize, isolate, transport, store, and proof of digital evidence safely originating from smartphones. The process of digital forensics has become an important issue and systematic approaches were proposed and adopted by many specialized governmental and private organizations and institutions such as The American Academy of Forensic Sciences (ACFS), the European Network of Forensic Science Institutes (ENFSI), the International Institute of Certified Forensic Investigation Professionals (IICFIP), and many other institutions worldwide. Besides, there are some well-known standards and good practices designed for digital forensics such as the two standards provided by ATSM [ 6 ], where issues related to digital forensics education challenges are provided as well as specifying the digital forensics steps with details about the requirements for each step. As thoroughly explained in the literature, the digital forensics process is divided into the following steps, these steps are common in most references with some slight modifications of the details and functionalities of each step (i) identification: this step involves finding the evidence and where the required data is located; (ii) preservation: in this step, the evidence is isolated, secured, and data is preserved as well. Access to the evidence and data is allowed only for investigators who are working on the case to prevent people from tampering with the data and hence making the evidence illegal; (iii) analysis: in this step, the reconstruction of evidence fragments is performed and conclusions about the evidence are found; (iv) documentation: a record of all the required data is preserved; this record can be used to recreate the crime scene; (v) presentation: a summary of the case and the conclusion are performed at this step, (vi) case closure: in this step, the case is closed by having a legal decision and the evidence is returned or archived accordingly. These steps may vary in their details from one institution to another; however, all of them will lead to a similar sequence of steps that will finally lead to a successful handling of a digital crime. The mobile forensics process has its particularities that need to be considered. Thus, following a correct methodology and guidelines are vital preconditions for the examination of smartphones to yield good results. In this paper, we develop a novel methodology for the mobile forensics process lifecycle called Mobile Forensics Investigation Process Framework (MFIPF) encompassing all the necessary stages and data sources used to construct the crime case. The developed methodology will contribute to identifying common concepts of mobile forensics through the development of the mobile forensics model that simplifies the examination process and enables forensics teams to capture and reuse specialized forensic knowledge, Furthermore, it reduces the difficulty and ambiguity in mobile forensics’ domain. Unlike other models, this proposal divides the evidence lifecycle into several modules and describes each module along with its main components, data sources, tools, intra-module, and inter-module interactions easily and clearly. The rest of the paper is organized as follows. Section 2 discusses the related work including the most common mobile forensic process models as well as common mobile forensics tools. Section 3 details the proposed mobile forensics process model (MFIPF), describing its various modules and sub-modules and their connectivity and the associated data sources, mechanisms, and tools. In section 4, the common mobile forensic tools are classified and mapped to our proposed model based on their applicability at different stages. In Section 5 , we conclude the paper and outline some ongoing and future research lines. 2. Related Work In this section, a brief review of the related literature will be conducted. First, we introduce the work done in mobile forensics models and stages, and then, we will talk about the common tools used in mobile forensics. 1. Mobile Forensics models and phases: Due to the previously mentioned reasons and challenges, many researchers have proposed some specific mobile forensics procedures and methods to deal with special mobile investigation cases. The existence of such methods is important for the success probability of an investigation and the avoidance of corrupting the evidence or failing to extract some necessary information. Among these proposed models is a model proposed by Moreb [7], where the author discussed the four process phases used for conducting mobile forensics, they are (i) the identification phase which includes many details such as identifying, acquiring, and protecting the data collected at the crime scene; ( ii) the collection phase which starts by processing the collected data or evidence, then extracting the relevant information; (iii) the analysis phase analyzes the extracted information to connect the dots and be able to build a robust and admissible case; and (iv) the reporting phase is the final step that presents the findings of the analysis stage into an admissible and understandable format. In [8], the authors mentioned that there are five phases in the forensic process (identification, preservation, acquisition, analyzing, and reporting) which are similar to what was proposed by Moreb [7]. The study of [9] concentrated on android forensics and proposed a framework of seven stages namely: Intake, Identification, Preparation, Isolation, Processing, Verification, and Documentation. A comparative analysis of five common process models was provided in [10], these models are SFIPM, WMDFM, NIST, HDFI, and USFIPM & NIST. The authors also proposed a secure model by deploying blockchain using Ethereum or a hyper ledger platform In [11] the authors proposed ERFF, which helps the investigator to securely obtain evidence more easily, ERFF is an efficient and reliable forensics framework as compared with other frameworks such as SNIF, LFCCF, and LRFF. It uses edge computing to improve reliability, efficiency, and accuracy. Moreover, it helps identify criminal activities more quickly using low-cost edge devices and involves a detective module and a validation model that detect the interaction between a client terminal and the edge resource. In [12] an analysis of the forensic-by-design framework is proposed which includes investigating the limits of the forensic-by-design and its insufficiencies in a Cloud systems context, and it proposes three new forensic-by-design key factors and associated standards and best practices, it also suggests a new generic systems and software engineering driven forensic-by-design framework. Reference [13] demonstrates the DFWM that provides a general and updated description of the DF investigation process at the workflow level and can be used as a management tool for unboxing the procedures, tasks, and risks involved in the workflow of the individual DF investigations. Using the investigative strategy for the specific case, DFWM serves as a framework for packaging the digital forensic investigation process, providing a detailed structure and visualization of the physical and investigative chores and decisions. DF workflow which guided by the overall investigative strategy of the particular case as follows: (i) review of client requirements and planning stage, (ii) evaluation of deployed workflow stage, (iii) identify the physical and cognitive tasks, and (iv) make decisions and their associated risks at the respective stage. Based on the existing process and models, the layered framework for mobile forensics is proposed in [14], the results have shown that using only one tool is not sufficient to complete the investigation process, the four layers organize as a framework, the number of layers can be increased or reduced as per the case type, the six layers can be grouped to small categories with tools to use for each one as acquisition process with various tools such as MOBILedit, Bulk extractor; analyze the data with various tools like Autopsy and CellDEK, and reporting the case can be generated using MOBILedit Forensic and CellDEK. In [15] the authors reviewed about 100 Mobile forensics models with the main conclusion that suggests improving and validating the investigation process model, develop of a meta-modeling language, and develop of a definite mobile forensics source to store and retrieve the knowledge formed in the mobile forensics field. Many forensics investigation process models are used for the Internet of Things (IoTs) such as CIPM for IoTFs [16], the proposed model assists IoTFs users to facilitate, manage, and organize the investigation tasks, it consists of four common investigation processes, preparation process, collection process, analysis process and report process. The proposed CIPM. The roadmap of DFIP discovery of tools [17] discussed in detail the challenges and opportunities for the digital forensics process concerning different fields such as networks, IoT, cloud computing, database system, big data, mobile and handheld devices, disk and different storage media, and operating system As seen from the literature, there is a necessity for adopting a robust model to carry out mobile forensic investigations efficiently, a comparison of well-known proposed models is provided in Table 1, we also included our proposed model MFIP in this table as proof of its usability. Table 1: A comparative analysis of five common forensics process models with the proposed one. Phases Functionality SFIPM WMDFM NIST HDFI USFIPM & NIST MFIPF Phase 1: Data Preparation Preparation ✓ ✓ ✕ ✓ ✓ ✓ Handling and securing the evidence scene ✓ ✓ ✕ ✕ ✕ ✕ Mode selection shielding ✓ ✕ ✕ ✕ ✕ ✓ Offset/online storage ✓ ✕ ✕ ✕ ✕ ✕ Phase 2: Information Analysis Examination and analysis ✓ ✓ ✓ ✓ ✓ ✓ Cell state analysis ✓ ✕ ✕ ✕ ✕ ✓ Non-volatile evidence collection ✓ ✓ ✕ ✕ ✕ ✓ Volatile evidence collection ✓ ✓ ✕ ✕ ✕ ✓ Evidence validation ✓ ✓ ✓ ✓ ✓ ✓ Phase 3: Case Construction Presentation ✓ ✓ ✓ ✓ ✓ ✕ Communication Scheduling ✕ ✓ ✕ ✕ ✕ ✕ Phase 4: Case Closing Review ✓ ✓ ✓ ✕ ✓ ✕ Documentation ✕ ✕ ✓ ✕ ✓ ✕ Survey and Recognition ✓ ✓ ✕ ✕ ✕ ✕ 2) Mobile forensics tools The definition of mobile phone forensics is the science of extracting digital evidence from a mobile device [18]. It provided a wonderful list of resources for catching online criminals who utilize mobile devices for illegal purposes. With their vast number of applications and current properties, mobile devices' ever-increasing storage and processing power provide new hurdles for digital forensics [19]. In order to collect digital evidence for use in court trials, mobile forensic tools and applications are essential. They can unearth call metadata, SMS, GPS data, application data, and locally stored files. A set of mobile forensics tools [20] can be used such as Cellebrite UFED Physical Analyzer and Oxygen Forensic Suite to get details about the mobile device, the results have shown that the device has a name and type, and iOS version Oxygen and UFED forensic tools [21] used to recover app data. In general, digital forensic tools for data extraction are categorized into three types manual, logical, and physical [22]. Many mobile forensics tools [23] such as Belkasoft Evidence Center [24], FINALMobile Forensics [25], 3uTools [26], and Magnet [27] are used to extract artifacts from both Android and iOS devices. The SDCA [28] tool is designed to perform the analysis of the differences automatically between two versions of SQL schema, in addition to its ability to analyze the query. In [29]aid forensic investigation in general, by developing a model and a platform to secure potential digital evidence, the SecureRS model can help to prevent unauthorized access and comply with regulations and privacy policies, the result shows a method of ensuring forensically sound digital evidence for DFR as well as for digital forensics processes in general. In [7] the authors discussed the tools used to acquire the data from iOS or Android devices for both rooted and jailbreak mobile; the results have shown that the XRY software tool can recover deleted materials and can be able to extract all the data from the phone but it cannot retrieve deleted data for not jailbroken iPhone, The work in [30] found out that the data used in the media directory did not have any change even after jailbreaking the device, which means that the integrity of the data remained unchanged by examining the matching hash value before and after the jailbreak. But by analyzing the source code of the exploit used where voucher swap as jailbreak code. It turned out that there was a change in the system data, where a fake kernel task was created instead of the original kernel task that works inside memory to give the privileges to extract the data. As a result of this study, jailbreaking is considered acceptable to help forensic tools extract more data while preserving user data. There was a previous study in the use of forensic tools in the process of acquiring data on iOS, Android, and Windows using forensic tools Oxygen and UFED to recover applications’ data, and the tools were able to restore the list of contacts that WhatsApp installed on iOS and Android, and unable to recover anything from the Windows device. In addition to the ability of the tools to restore and decrypt the backups of the Android and iOS devices, and unable to find the encryption key for the Windows device. The result was that it could restore conversations even if the application has been deleted if there are backup copies stored on the device for WhatsApp [21]. In [28] it is noted that the developers of forensic tools have limited knowledge of the changes that have occurred to the SQL Lite schema for iOS backups and need to preserve the tools' compatibility with recent versions. The SDCASQLite Database Comparison Analyzer (SDCA) tool is designed to perform the analysis of the differences automatically between two versions of SQL schema, in addition to its ability to analyze the query, it also demonstrates that using the tool is feasible to update the Forensic Targeted Data Extraction Application called FTDEA developed by the authors. As mentioned in [31] the growth of using smartphones from 2016 until 2021 increased from 2.5 to 3.8 billion smartphones. Also, in the report found in [32], the number of users who use social media is about 4.20 billion active users worldwide. According to the comparison as shown in Table 2 [33–35], the forensic tools deployed for mobile device investigations are considered very different from that available to investigate personal computers in terms of availability. These differences in the operating system and file systems structures create difficult challenges for the whole mobile forensic tools’ developers and investigators. Commercial and open-source forensic tools are available for mobile device investigations. The availability of many mobile forensics tools might cause some dilemmas in the selection of the best tool, for this reason, for this we will provide a mapping table that helps select the suitable tool for each step of our proposed model MFIP. 3. Proposed Mobile Forensics Framework In this section, we will deeply describe our MFIPF provided in Figure 2. The stages of the framework (Data Preparation, Information Analysis, Case construction, and Case Closing) will be explained showing the detailed steps at each phase. Figure 2: The Proposed Forensics Investigation Process Framework (MFIPF) 3.1. Data Preparation The data preparation phase aims to generate a processed dataset that is technically usable for the analysis phase. In this phase, four steps are carried out to guarantee that the acquainted data is gathered systematically and legally. The four steps shown in Figure 2 are described below: Resource seizure : In this step, the mobile device is seized in a way that guarantees that the device will not be modified and there should be no ability to connect with the device. To achieve this step, we have to follow the following process [36]: (i) issuance of research warrant from legal representatives; (ii) turning off all wireless communications and putting the mobile device in Airplane Mode; (iii) shieling the mobile device in a Faraday bag that prohibits any external signals to reach the mobile, and (iv) Document these steps and send the mobile device to the digital forensics lab for investigations. Resource identification : Once the mobile device arrives at the digital forensics lab, the resource identification process is carried out. The process aims to identify the mobile device under investigation and choose the suitable tools that can be used for the data extraction phase. A description of the mobile device is provided here, the description includes the model and type, physical status (if the device is broken), and logical status (the device is on or off, the device is functioning or not). Based on this information, the investigator will be able to determine the suitable tools required for the data extraction process. This process should be formally documented [37]. Data extraction: This is a very important process where the data is extracted from the mobile device, the extracted data will then be used in further stages to extract evidence. The information gathered in the identification phase is the basis of the data extraction method to be used, these methods include: Manual data extraction : here the investigator manually navigates the mobile device to search for the required evidence; documentation of this process is essential and might be done by video recording of the screen of the mobile device during the navigation process [37]. It is important here for the investigator to conduct the boundaries of the research warrant and never explore data that is not included in the research warrant. This process requires the ability of the investigator to access the device by having the password or pattern. It is worth mentioning here that manual data extraction will affect the integrity of the files and hence the investigator should precisely document the steps he did and the findings as well. Logical extraction : When applying this method, the investigator will be able to generate a copy of the file system that can be used later to extract data using some tools designed for this purpose. This copy will enable the investigator to view the same data that can be generated using manual extraction [38]. However, this method does not affect the integrity of the files of the mobile device and the investigator can only work on the copy of the files and the original device will be kept safely in an evidence container. Physical extraction : in this method, a raw image in a binary format of the mobile device’s memory is generated, and the output is a bitwise copy of the memory of the mobile device [39]. This copy includes all system files and can also be used to retrieve some of the deleted files as well. However, to generate this copy usually we need to root the device which will affect the integrity of the evidence, so the investigator has to document the details of this step. The generated copy can then be used to retrieve system files as well as some of the deleted files using dedicated data analysis tools. It is worth noting that the aforementioned methods can be applied only when the mobile device is functional, i.e., not broken, and does not work for broken or malfunctioning mobile devices. In such a case some other methods might be used such as chip-off by which the memory chip of the mobile device is physically removed and attached to a memory reader or a similar device and the data is then extracted [40]. This method requires high skills in electronic device maintenance and may cause the chip to be destroyed if not removed or attached correctly. Another extremely hard method that might be used in very rare cases such as national security is called Micro-read where an electronic microscope is used to read the contents of the memory on gate level base [41]. This method is very expensive and takes too much time but might be used to extract some data from broken devices. 3.1.4 Data preprocessing : In this process, the characteristics of the mobile device operating system are studied, and data is categorized based on applications to pinpoint potential evidence(s). Classification techniques are used here to group data based on file system analysis and system log analysis. The output of this process is a well-prepared dataset that can be used in the analysis stage to extract evidence. The preprocessing step might also include putting the data in a proper file format that is compatible with mobile forensics tools in the analysis phase [42]. 3.2 Information analysis In the analysis phase, evidence(s) is/are extracted by formally interpreting the information generated by the previous phase – data extraction-. The investigator should follow standards and best practices in the field of forensic analysis so that the evidence will be intact, and results are reproducible and acceptable. For a robust mobile forensic analysis, the following steps are suggested to be followed: 3.2.1 Forensic Tools: The first step in the analysis includes the selection of a forensic tool. The selection of the tool depends on many factors including cost, user interface, the familiarity of the examiner, computing platform and environment, and legislative –whether the tool is legally approved or not [43]. A list of mobile forensics analysis tools and their properties are provided in Table [1]. Typically, the examiner may use different tools to generate different information and events, there is also a possibility to use different tools to generate the same event to make sure that the event is reproducible and to prove its validity [44] Therefore, an examiner should be familiar with different tools to conduct his analysis successfully. 3.2.2 Information examination: After selecting the appropriate tool(s), the examiner will feed the tool with the data preprocessed data and perform a variety of tests and processing tasks against the data. The processing aims to generate an event from the evidence file. There might be many events generated from the same or multiple tools. These events are then stored and fed to the next step which is evidence validation [45] Events in a mobile device might be found at different locations according to the information the examiner is trying to find. Some of the events might be found in SMS and call logs, others might be found in saved pictures or emails. Some complex events might require retrieving deleted files using special tools while other events require the use of different tools and gathering information to reconstruct that event. The selection of the tool and the process depends on the examiner and requires skilled persons to successfully perform the task [41]. 3.2.3 Evidence validation: According to [46], validation is the process of proving the validity of the evidence to a jury. The process implies proving acceptable error rates as well as using scientifically proven valid data, applications, and results. The validation process is applied to all stages in mobile forensics and covers data collection and storage, system, application, user, and algorithm applicability validation. A very important issue related to validation is the use and following up of standards and best practices developed for this purpose. Many countries have developed standards for digital and mobile forensics through their dedicated institutions such as NIST in the states. Besides, some well-known digital forensics developers have also proposed some best practices that are proven to generate valid evidence with an acceptable error rate [47]. The examiner must follow these standards and verify the validity of the evidence during the entire investigation process. 3.2.4 Evidence correlation: Correlation involves the ability to extract the semantics from different sources such as SMS, social media messaging, emails, …, etc, and to generate a knowledge base that clearly shows the correlation among these generated events. Domain and application ontologies might be used to correlate different events to a knowledge base [48]. Event correlation and reconstruction might be carried out using different techniques and technologies including rule-based, semantic models, tree/graph-based, timestamp-based, finite state machines, and live event construction [49], such techniques aim to construct valid evidence from different sources of events with acceptable error rate. The output of this stage will be used as input for the next phase which is case construction. 3.3. Case Construction The output of the second stage - information analysis - is fed as an input to the case construction stage, which takes the evidence list to prepare results and move towards closing the case. Four steps are necessary in the process of case construction: results analysis, results examination, results reporting, and results dissemination. In what follows, a detailed explanation is provided for each step. 3.3.1 Results analysis: In this step, examiners must analyze all the technical findings extracted from the information analysis phase consistently and clearly. When analyzing the results, examiners can divide the analysis sequential logical parts divided into multiple headings and comment on results as they are described to ease the decision-making process, the results could be supported by figures, tables, and equations to enrich the findings. In addition, the results’ conclusion must be kept very brief that aggregates the findings with robust paragraphs [50]. During the process of validating the results of a mobile forensic scene, several methods can be used to verify the validity of the results such as calculating the hash value with two different forensics tools, or the various steps might be revisited using the same tool to obtain the digital evidence and recalculated the hash value to validate the results. At some point, the results generated using experimental and validation stages must be repeatable. Any variable that might affect the outcome of the validation should be determined after several test runs. However, some cases require more runs to generate valid results, besides; examiners need to utilize the literature to assess the results’ validations [51] 3.3.2 Results reporting: The most fruitful result that should be created following the forensic process is the documentation of the findings. Once completed, investigators can use the report to their advantage in a number of ways, including (i) sharing the results with other investigators and decision-makers for use in making decisions, (ii) communicating the facts that may support the investigation of other cases, (iii) offering a clear justification for gathering more digital evidence, and (iv) using the report to evaluate the specific case. The final report must be written by digital examiners taking into account all conditions and guidelines established by national law. To ensure that the report complies with the law, they must first independently review it. Any divergent opinions will eventually be examined for flaws to bolster the assertions. In general, there is no set format or structure for reporting the findings, but any final report must include the bare minimum of the following data: jurisdiction, the nature of the case, the court's document format, and the reason ID, calendar of all depositions (timestamps), deponent’s name and ID, and other details like time and date the case created, phone physical situation, the phone status on or off, mobile manufacturer information, pictures for each accessory and the phone itself, which tools used in the investigation, any additional data added during an examination. Many forensics reporting tools provide ways to automatically annotate evidence fragments and generate automatic reports according to the examiner’s configuration. These tools enable the examiner to perform sub-functions such as tagging, bookmarking, log reports, or even report generation. The report relies on solid documentation, photos, notes, and tool-generated content. The examiner should then check the report and edit his configuration if necessary [52] 3.3.3 Results disseminationIt describes the procedure the examiner uses to communicate to policy-makers the findings from the analysis phase. The major goal of this method is to provide action reports for each detected artifact and its analysis. The investigator's defensive strategy and any potential implementation difficulties can also be included in the presentation phase. In an iterative approach, the results from this phase might be used to conduct additional acquisitions. As a result, each process produces more analytical artifacts, which are then provided as feedback to other processes. For lengthy criminal investigations, this feedback iterative procedure may go through numerous iterations. This step might help other investigators working on similar cases to proceed with their cases accordingly, or to criticize the case, and hence further steps might be required to be performed for the disseminated case [53]. 3.4. Case Closing Case closing is the last stage in the mobile forensics investigation process framework (MFIPF) which undergoes three main steps to ensure the successful termination of the process model. They are case closing, making the legal decision, and case archiving. Understanding how to close and archive the case is also crucial to perform a targeted analysis of the data for future updates. It is important that the digital examiner must have good knowledge of how to store and collect similar cases which might help in case examination. 3.4.1 Legal decision: The constructed case should be finally put in its legal context, here, the final legal decision should be a judicial determination of all parties rights and obligations reached by a court based on facts and law. A decision can mean either the act of delivering a court's order or the text of the court's opinion on the case and the accompanying court after you complete a case. Since every user owns his/her data and digital device, forensic examiners face ethical and legal issues in accessing and collecting the required information [54] 3.4.2 Review: The final step in the lifecycle is to review the case to identify successful decisions and actions and determine how the system performance should be improved in terms of time, and accuracy. Critique the case, self-evaluation and peer review are essential parts of professional growth. Investigators must keep the OS and digital forensics tools current in order for everything to be consistent. This necessitates updating the OS frequently, installing all new system updates and patches, and regularly checking the tools' websites for new updates or patches. [55] 3.4.3 Case archiving: When work on a case is completed and immediate access to it is no longer necessary, that case can be archived. This step aims at closing the case after its resolution. Digital forensics case achieving includes the storage of the electronic copies of evidence as well as the case report and the generated artifacts and the documentation of the whole stages of the case. The aim of case archiving is to enable examiners to review the procedures carried out to use them in similar cases. The case archive should enable the examiner to reconstruct the case from scratch based on the available copies of the case evidence which will help if the case was legally re-opened [56]. Many tools might be used in case archiving that enable ease of use and retrieval of cases, some of these tools will be provided in Section 4. 4. Common Mobile Forensics Tools Used In Mobile Forensic Investigation: In this section, we will explain a list of 4 commonly used mobile forensics tools, and map them to our proposed model MFIPF. Common tools: In the following, we list the common forensics investigation tools and compare and reflect on their operations with the modules of the proposed MFIPF framework. Belkasoft Evidence Center: It is a comprehensive forensic tool for locating, retrieving, and analyzing digital evidence stored on desktops and mobile devices. This tool makes it simple for investigators to collect, examine, analyze, preserve, and share digital evidence from computers and mobile devices. By analyzing hard disks, drive pictures, memory dumps, iOS, Blackberry, Android backups, UFED, JTAG, and chip-off dumps, the toolkit will efficiently extract digital evidence from many sources. It evaluates the data source automatically and lays out the most forensically significant artifacts for the investigator to study the case or add to the report [24]. FINALMobile: It is a powerful software and mobile solution for legal inspectors that provides the legal community with the most cutting-edge data mining and information extraction capabilities. Thanks to its extensive understanding of system files and information patterns, this software can transform raw data into executable and ready files in just a few clicks. On mobile devices, data is stored in specialized forms and is frequently left behind after a device is entirely cleaned. The FINALMobile forensics software can easily retrieve deleted (hidden) files by scanning for specific patterns. Additionally, as the majority of mobile devices adhere to the same pattern, data can be gathered for upcoming mobile devices. [25]. 3uTools: It is a program for flashing and jailbreaking Apple's iPhone, iPad, and iPod touch. It offers three ways to flash Apple mobile devices: easy mode, professional mode, or multiple flash. It automatically selects the proper firmware and supports a fast download speed. 3uTools Free Download for Windows PC Latest Version. It has a complete 3uTools offline setup installer [26]. Magnet ACQUIRE: This tool combines an easy user interface with dependable and speedy extractions to provide you with the information you need quickly and effortlessly. Furthermore, the data quality will be maximized, and activity logging and documentation will help to understand which procedures were employed [27]. 2) Mapping tools to MFIPF: Table 2 provides a comparative analysis between iOS and Android forensic tools for mobile forensics tools with their functionalities based on MFIPF. 5. Conclusion And Future Work Cybercrimes are rapidly increasing due to the tremendous reliance on information and telecommunication technologies. This rapid increase is being faced by developing the necessary tools and legislation to fight against these crimes. One of the most challenging investigation issues is mobile device forensics. This challenge is because mobile device is becoming more powerful with tremendous processing and communication capabilities as well as containing sensitive data related to the mobile user. For these reasons, a framework for mobile device forensics must be developed to systematically engineer the investigation process and avoid any issues that might cause to reject the investigation. In this paper, we proposed a mobile forensics lifecycle called Mobile Forensics Investigation Process Framework (MFIPF). MFIPF encompasses all forensics stages and steps that must be followed in each stage. Furthermore, we also proposed a list of the most commonly used mobile forensics tools that might be used in each stage or step. In future work, we will apply this model to different investigation scenarios with different mobile platforms and report the finding and if necessary we will update the model accordingly. In future work, we will test the utility of using our model MFIPF with different mobile digital forensics scenarios and compare our utility results against other models. Declarations Acknowledgements: Not applicable Authors’ contributions: All authors read and approved the manuscript. Funding: Not applicable Availability of data and materials Not applicable Ethics approval and consent to participate: Not applicable Competing interests: The authors declare that they have no competing interests. References Www.statista.com, Share of Global Smartphone Shipments by Operating System from 2014 to 2023 , https://www.statista.com/statistics/272307/market-share-forecast-for-smartphone-operating-systems/. S. N. Zakaria and M. F. Zolkipli, Review on Mobile Attacks: Operating System, Threats and Solution , Borneo International Journal EISSN 2636-9826 4 , (2021). A. M. Alashjaee, N. Almolhis, and M. Haney, Mobile Malware Forensic Review: Issues and Challenges , 367 (2021). M. Kumar, Mobile Phone Forensics – A Systematic Approach, Tools, Techniques and Challenges , International Journal of Electronic Security and Digital Forensics 13 , 53 (2021). O. Ameerbakhsh, F. M. Ghabban, I. M. Alfadli, A. N. Abuali, A. Al-Dhaqm, and M. A. Al-Khasawneh, Digital Forensics Domain and Metamodeling Development Approaches , 2021 2nd International Conference on Smart Computing and Electronic Enterprise: Ubiquitous, Adaptive, and Sustainable Computing Solutions for New Normal, ICSCEE 2021 67 (2021). J. Howe, M. Baylor, and R. H. Liu, Advancing the Practice of Forensic Science in the United States--Practitioners’ Efforts. , Forensic Sci Rev 34 , 7 (2022). M. Moreb, Introduction to Android Forensics , Practical Forensic Analysis of Artifacts on IOS and Android Devices 71 (2022). H. H. Lwin, W. P. Aung, and K. K. Lin, Comparative Analysis of Android Mobile Forensics Tools , 2020 IEEE Conference on Computer Applications, ICCA 2020 1 (2020). A. Al-Sabaawi and E. Foo, A Comparison Study of Android Mobile Forensics for Retrieving Files System , Ernest Foo International Journal of Computer Science and Security (IJCSS) 2019 (2019). W. Asghari, A. Suresh Kumar, A. S. Singh, and K. Thirunavukkarasu, A Comparison Analysis of Mobile Forensic Investigation Framework , 595 (2021). A. Razaque, M. Aloqaily, M. Almiani, Y. Jararweh, and G. Srivastava, Efficient and Reliable Forensics Using Intelligent Edge Computing , Future Generation Computer Systems 118 , 230 (2021). A. Akilal and M. T. Kechadi, An Improved Forensic-by-Design Framework for Cloud Computing with Systems Engineering Standard Compliance , Forensic Science International: Digital Investigation 40 , (2022). G. Horsman and N. Sunde, Unboxing the Digital Forensic Investigation Process , Science and Justice 62 , 171 (2022). M. Goel and V. Kumar, Layered Framework for Mobile Forensics Analysis, n.d. A. Al-Dhaqm, S. A. Razak, R. A. Ikuesan, V. R. Kebande, and K. Siddique, A Review of Mobile Forensic Investigation Process Models , IEEE Access 8 , 173359 (2020). M. A. Saleh, S. Hajar Othman, A. Al-Dhaqm, and M. A. Al-Khasawneh, Common Investigation Process Model for Internet of Things Forensics , 2021 2nd International Conference on Smart Computing and Electronic Enterprise: Ubiquitous, Adaptive, and Sustainable Computing Solutions for New Normal, ICSCEE 2021 84 (2021). A. Patil, S. Banerjee, D. Jadhav, and G. Borkar, Roadmap of Digital Forensics Investigation Process with Discovery of Tools , Cyber Security and Digital Forensics 241 (2021). K. Curran, A. Robinson, S. Peacocke, and S. Cassidy, Mobile Phone Forensic Analysis , International Journal of Digital Crime and Forensics 2 , 15 (2010). D. Hamdi, F. Iqbal, T. Baker, and B. Shah, Multimedia File Signature Analysis for Smartphone Forensics , Proceedings - 2016 9th International Conference on Developments in ESystems Engineering, DeSE 2016 130 (2017). M. Al-Hadadi and A. AlShidhani, Smartphone Forensics Analysis: A Case Study , International Journal of Computer and Electrical Engineering 5 , 576 (2013). A. Shortall and M. A. H. Bin Azhar, Forensic Acquisitions of WhatsApp Data on Popular Mobile Platforms , Proceedings - 2015 6th International Conference on Emerging Security Technologies, EST 2015 13 (2016). M. Moreb, Introduction to IOS Forensics , Practical Forensic Analysis of Artifacts on IOS and Android Devices 37 (2022). H. Azhar, \ Cox, R., and A. Chamberlain, Forensic Investigations of Popular Ephemeral Messaging Applications on Android and IOS Platforms , International Journal on Advances Security 13 , 41 (2020). Belkasoft.com, Belkasoft Evidence Center , https://belkasoft.com/ru/bec/en/Evidence_Center.asp. Finaldata, FINALMobile Forensics , https://finaldata.com/mobile/. uTools, Http://Www.3u.Com/ , http://www.3u.com/. Magnet, Magnet ACQUIRE , https://www.magnetforensics.com/resources/magnet-acquire/. S. S. Shimmi, G. Dorai, U. Karabiyik, and S. Aggarwal, Analysis of IOS SQLite Schema Evolution for Updating Forensic Data Extraction Tools , 8th International Symposium on Digital Forensics and Security, ISDFS 2020 (2020). A. Singh, R. A. Ikuesan, and H. Venter, Secure Storage Model for Digital Forensic Readiness , IEEE Access 10 , 19469 (2022). A. Aenurahman Ali, N. Dwi Wahyu Cahyani, and E. Musthofa Jadied, Digital Forensic Analysis on IDevice: Jailbreak IOS 12.1.1 as a Case Study , Indonesia Journal of Computing 4 , 205 (2019). A. Turner, How Many People Have Smartphones Worldwide (April 2021) , https://www.bankmycell.com/blog/how-many-phones-are-in-the-world. S. Kemp, Digital 2021: Global Overview Report — DataReportal – Global Digital Insights , https://datareportal.com/reports/digital-2021-global-overview-report. M. Moreb, Mobile Forensic Investigation for WhatsApp , Practical Forensic Analysis of Artifacts on IOS and Android Devices 281 (2022). M. Moreb, Detecting Privacy Leaks Utilizing Digital Forensics and Reverse Engineering Methodologies , Practical Forensic Analysis of Artifacts on IOS and Android Devices 195 (2022). M. Moreb, Forensic Investigations of Popular Applications on Android and IOS Platforms , Practical Forensic Analysis of Artifacts on IOS and Android Devices 109 (2022). A. Hrenak, Mobile Device Forensics : An Introduction , Cyber Forensics 291 (2021). C. Arumugam and S. Shunmuganathan, Digital Forensics: Essential Competencies of Cyber-Forensics Practitioners , 843 (2021). A. el Majdoub, C. Saadi, and H. Chaoui, Mobile Forensics Data Acquisition , ITM Web of Conferences 46 , 02006 (2022). L. A. Herrera, Challenges of Acquiring Mobile Devices While Minimizing the Loss of Usable Forensics Data , 8th International Symposium on Digital Forensics and Security, ISDFS 2020 (2020). A. M. da Costa, A. O. de Sa, and R. C. S. Machado, Data Acquisition and Extraction on Mobile Devices-A Review , 2022 IEEE International Workshop on Metrology for Industry 4.0 and IoT, MetroInd 4.0 and IoT 2022 - Proceedings 294 (2022). M. Kumar, Mobile Forensics : Tools, Techniques and Approach , Crime Science and Digital Forensics 102 (2021). D. Kim and S. Lee, Study of Identifying and Managing the Potential Evidence for Effective Android Forensics , Forensic Science International: Digital Investigation 33 , 200897 (2020). M. Lovanshi and P. Bansal, Comparative Study of Digital Forensic Tools , Data, Engineering and Applications 195 (2019). Jr. E. Oliveira, T. J. Silva, A. F. Zorzo, and C. V. Neu, Digital Forensics Experimentation: Analysis and Recommendations. , Forensic Sci Rev 34 , 21 (2022). S. Dogan and E. Akbal, Analysis of Mobile Phones in Digital Forensics , 2017 40th International Convention on Information and Communication Technology, Electronics and Microelectronics, MIPRO 2017 - Proceedings 1241 (2017). R. F. Erbacher, Validation for Digital Forensics , ITNG2010 - 7th International Conference on Information Technology: New Generations 756 (2010). H. Arshad, A. bin Jantan, and O. I. Abiodun, Digital Forensics: Review of Issues in Scientific Validation of Digital Evidence , Journal of Information Processing Systems 14 , 346 (2018). H. Arshad, A. Jantan, G. K. Hoon, and I. O. Abiodun, Formal Knowledge Model for Online Social Network Forensics , Comput Secur 89 , (2020). L. F. Sikos, AI in Digital Forensics: Ontology Engineering for Cybercrime Investigations , Wiley Interdisciplinary Reviews: Forensic Science 3 , e1394 (2021). M. R. Al-Mousa, Analyzing Cyber-Attack Intention for Digital Forensics Using Case-Based Reasoning , International Journal of Advanced Trends in Computer Science and Engineering 8 , 3243 (2021). H. Page, G. Horsman, A. Sarna, and J. Foster, A Review of Quality Procedures in the UK Forensic Sciences: What Can the Field of Digital Forensics Learn? , Sci Justice 59 , 83 (2019). A. R. Javed, W. Ahmed, M. Alazab, Z. Jalil, K. Kifayat, and T. R. Gadekallu, A Comprehensive Survey on Computer Forensics: State-of-the-Art, Tools, Techniques, Challenges, and Future Directions , IEEE Access 10 , 11065 (2022). G. Horsman, Tool Testing and Reliability Issues in the Field of Digital Forensics , Digit Investig 28 , 163 (2019). G. Horsman and N. Sunde, Part 1: The Need for Peer Review in Digital Forensics , Forensic Science International: Digital Investigation 35 , 301062 (2020). G. Horsman, Tool Testing and Reliability Issues in the Field of Digital Forensics , Digit Investig 28 , 163 (2019). Z. Bartliff, Y. Kim, F. Hopfgartner, and G. Baxter, Leveraging Digital Forensics and Data Exploration to Understand the Creative Work of a Filmmaker: A Case Study of Stephen Dwoskin’s Digital Archive , Inf Process Manag 57 , (2020). Table 2 Table 2 is available in Supplementary Files section. Supplementary Files Table2.docx Cite Share Download PDF Status: Published Journal Publication published 20 Apr, 2024 Read the published version in International Journal of Computing and Digital Systems → Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-2611927","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":180511899,"identity":"11a55838-4118-4bb5-9c79-58d3d7b02972","order_by":0,"name":"Mohammed Moreb","email":"","orcid":"","institution":"Birzeit University","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Mohammed","middleName":"","lastName":"Moreb","suffix":""},{"id":180511900,"identity":"c004c542-e955-4366-8618-55b8bca942c3","order_by":1,"name":"Saeed Salah","email":"","orcid":"","institution":"Alquds University: Al-Quds University","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Saeed","middleName":"","lastName":"Salah","suffix":""},{"id":180511901,"identity":"d3413837-d79e-442e-a079-62d42cb85184","order_by":2,"name":"Belal Amro","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAxElEQVRIiWNgGAWjYBACA2bmBoYHDDYJDBIQAcYGwlqAahIY0kjRwgDWcpgELebsjI0fEmrO5/FL9z58XMBgI7vhAAEtls2MzRIJx24XS845bmw8gyHNmKAWg8OMDRIJbLcTN9xIY5PmYTicSIyW5h8J/84l7odo+U+UljaJxLYDiRskwFoOENYC9EubRWJfcuKMO8eYjXkMko1nEtJizn/48I0P3+wS+2e3MT7mqbCT7SOkBd2dpCkfBaNgFIyCUYADAADDK0QUTfsQCQAAAABJRU5ErkJggg==","orcid":"https://orcid.org/0000-0003-0421-4404","institution":"Hebron University","correspondingAuthor":true,"submittingAuthor":false,"prefix":"","firstName":"Belal","middleName":"","lastName":"Amro","suffix":""}],"badges":[],"createdAt":"2023-02-21 11:46:50","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-2611927/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-2611927/v1","draftVersion":[],"editorialEvents":[{"content":"https://doi.org/10.12785/ijcds/160110","type":"published","date":"2024-04-21T00:00:00+00:00"}],"editorialNote":"","failedWorkflow":false,"files":[{"id":33966117,"identity":"55993057-0752-4d0c-a09d-13d5193fec23","added_by":"auto","created_at":"2023-03-08 15:07:51","extension":"png","order_by":1,"title":"Figure 1","display":"","copyAsset":false,"role":"figure","size":61828,"visible":true,"origin":"","legend":"\u003cp\u003eShare of global smartphone shipments by operating system from 2014 to 2023 \u0026nbsp;[1]\u003c/p\u003e","description":"","filename":"1.png","url":"https://assets-eu.researchsquare.com/files/rs-2611927/v1/836fc69b374a7a00c1719612.png"},{"id":33966118,"identity":"7f8d3d8f-17d7-4e85-b3c6-d09a64951a1a","added_by":"auto","created_at":"2023-03-08 15:07:51","extension":"png","order_by":2,"title":"Figure 2","display":"","copyAsset":false,"role":"figure","size":240495,"visible":true,"origin":"","legend":"\u003cp\u003e\u003cstrong\u003eThe Proposed Forensics Investigation Process Framework (MFIPF)\u003c/strong\u003e\u003c/p\u003e","description":"","filename":"2.png","url":"https://assets-eu.researchsquare.com/files/rs-2611927/v1/57a4c5b93aea03ae5ce5a518.png"},{"id":55315374,"identity":"2998cd24-b4d6-4aa1-ac0a-4d500ffda5c0","added_by":"auto","created_at":"2024-04-25 15:37:14","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":653038,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-2611927/v1/8e089861-b22d-40a3-8875-b36d3fe7e4e4.pdf"},{"id":33966116,"identity":"fb006c88-f268-4ec7-9edf-c8ef63cd5c01","added_by":"auto","created_at":"2023-03-08 15:07:51","extension":"docx","order_by":1,"title":"","display":"","copyAsset":false,"role":"supplement","size":157878,"visible":true,"origin":"","legend":"","description":"","filename":"Table2.docx","url":"https://assets-eu.researchsquare.com/files/rs-2611927/v1/f59c4db4354227a3423d3ca2.docx"}],"financialInterests":"","formattedTitle":"A Novel Framework for Mobile Forensics Investigation Process","fulltext":[{"header":"1. Introduction","content":"\u003cp\u003eIn the current era of the digital age, it is undoubtedly shown that mobile applications have profoundly transformed every aspect of human lives. Users are now relying on mobile applications to do many online activities such as browsing the internet, shopping, transferring money, doing business, communicating using audio or video calls, texting, entertainment, and education. This massive growth of smartphone usage is still incredibly popular and will continue to be for the foreseeable future. According to Fig.\u0026nbsp;1, The annual sales of smartphones have tremendously increased to around (1.56) billion devices worldwide, smartphones running the Android operating system hold an (87%) share of the global market in 2019 and this is expected to increase over the forthcoming years, while Apple iOS; the second most popular operating system has a (13%) market share across all devices.\u003c/p\u003e \u003cp\u003eFigure 1: Share of global smartphone shipments by operating system from 2014 to 2023\u0026nbsp;[\u003cspan citationid=\"CR1\" class=\"CitationRef\"\u003e1\u003c/span\u003e]\u003c/p\u003e \u003cp\u003eWith this tremendous use of smartphones worldwide, the wide adoption of these devices to carry out technology-oriented services, and the uncontrolled use of mobile applications have turned the mobile environment into a fertile spot to carry out many unethical and illegal activities. Consequently, smartphones became a famous target for cyber-attacks bearing in mind that these devices contain private data\u0026nbsp;[\u003cspan citationid=\"CR2\" class=\"CitationRef\"\u003e2\u003c/span\u003e]. The portability of these devices and the sensitivity of the data they contain raised great concern about the feasibility of using traditional digital forensic methodologies and to what extent they fit this field\u0026nbsp;[\u003cspan citationid=\"CR3\" class=\"CitationRef\"\u003e3\u003c/span\u003e]. Smartphones are equipped with many capabilities that make forensic steps difficult to be handled and require great attention. These capabilities include the availability of different communication technologies such as SMS, 3G, Wi-Fi, GPS, \u0026hellip;, etc., the ability to remotely instruct the device to switch on or off, and the ability to remotely wipe data using different mobile applications. These issues and others created a big challenge for the investigators when dealing with mobile digital evidence\u0026nbsp;[\u003cspan citationid=\"CR4\" class=\"CitationRef\"\u003e4\u003c/span\u003e].\u003c/p\u003e \u003cp\u003eIn this regard, a set of terminologies, definitions, and legal issues have appeared that describe the new criminal situations raised due to this new computing paradigm. One of these terminologies is digital forensics which refers to the process of collecting digital evidence from a digital device and analyzing it to prove the guilt or innocence of persons\u0026nbsp;[\u003cspan citationid=\"CR5\" class=\"CitationRef\"\u003e5\u003c/span\u003e]. Mobile forensics is another terminology derived from digital forensics, it aims to recover digital evidence from a smartphone in a way that will preserve the evidence in a forensically sound condition. To conduct mobile forensics analysis, the mobile forensic process lifecycle needs to set out precise rules that will seize, isolate, transport, store, and proof of digital evidence safely originating from smartphones.\u003c/p\u003e \u003cp\u003eThe process of digital forensics has become an important issue and systematic approaches were proposed and adopted by many specialized governmental and private organizations and institutions such as The American Academy of Forensic Sciences (ACFS), the European Network of Forensic Science Institutes (ENFSI), the International Institute of Certified Forensic Investigation Professionals (IICFIP), and many other institutions worldwide. Besides, there are some well-known standards and good practices designed for digital forensics such as the two standards provided by ATSM\u0026nbsp;[\u003cspan citationid=\"CR6\" class=\"CitationRef\"\u003e6\u003c/span\u003e], where issues related to digital forensics education challenges are provided as well as specifying the digital forensics steps with details about the requirements for each step.\u003c/p\u003e \u003cp\u003eAs thoroughly explained in the literature, the digital forensics process is divided into the following steps, these steps are common in most references with some slight modifications of the details and functionalities of each step \u003cem\u003e(i)\u003c/em\u003e identification: this step involves finding the evidence and where the required data is located; \u003cem\u003e(ii)\u003c/em\u003e preservation: in this step, the evidence is isolated, secured, and data is preserved as well. Access to the evidence and data is allowed only for investigators who are working on the case to prevent people from tampering with the data and hence making the evidence illegal; \u003cem\u003e(iii)\u003c/em\u003e analysis: in this step, the reconstruction of evidence fragments is performed and conclusions about the evidence are found; \u003cem\u003e(iv)\u003c/em\u003e documentation: a record of all the required data is preserved; this record can be used to recreate the crime scene; \u003cem\u003e(v)\u003c/em\u003e presentation: a summary of the case and the conclusion are performed at this step, \u003cem\u003e(vi)\u003c/em\u003e case closure: in this step, the case is closed by having a legal decision and the evidence is returned or archived accordingly. These steps may vary in their details from one institution to another; however, all of them will lead to a similar sequence of steps that will finally lead to a successful handling of a digital crime.\u003c/p\u003e \u003cp\u003eThe mobile forensics process has its particularities that need to be considered. Thus, following a correct methodology and guidelines are vital preconditions for the examination of smartphones to yield good results. In this paper, we develop a novel methodology for the mobile forensics process lifecycle called Mobile Forensics Investigation Process Framework (MFIPF) encompassing all the necessary stages and data sources used to construct the crime case. The developed methodology will contribute to identifying common concepts of mobile forensics through the development of the mobile forensics model that simplifies the examination process and enables forensics teams to capture and reuse specialized forensic knowledge, Furthermore, it reduces the difficulty and ambiguity in mobile forensics\u0026rsquo; domain. Unlike other models, this proposal divides the evidence lifecycle into several modules and describes each module along with its main components, data sources, tools, intra-module, and inter-module interactions easily and clearly.\u003c/p\u003e \u003cp\u003eThe rest of the paper is organized as follows. Section 2 discusses the related work including the most common mobile forensic process models as well as common mobile forensics tools. Section \u003cspan refid=\"Sec3\" class=\"InternalRef\"\u003e3\u003c/span\u003e details the proposed mobile forensics process model (MFIPF), describing its various modules and sub-modules and their connectivity and the associated data sources, mechanisms, and tools. In section 4, the common mobile forensic tools are classified and mapped to our proposed model based on their applicability at different stages. In Section \u003cspan refid=\"Sec9\" class=\"InternalRef\"\u003e5\u003c/span\u003e, we conclude the paper and outline some ongoing and future research lines.\u003c/p\u003e"},{"header":"2. Related Work","content":"\u003cp\u003eIn this section, a brief review of the related literature will be conducted. First, we introduce the work done in mobile forensics models and stages, and then, we will talk about the common tools used in mobile forensics.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u0026nbsp;1.\u0026nbsp;\u003c/strong\u003eMobile Forensics models and phases:\u003c/p\u003e\n\u003cp\u003eDue to the previously mentioned reasons and challenges, many researchers have proposed some specific mobile forensics procedures and methods to deal with special mobile investigation cases. The existence of such methods is important for the success probability of an investigation and the avoidance of corrupting the evidence or failing to extract some necessary information. Among these proposed models is a model proposed by Moreb \u0026nbsp;[7], where the author discussed the four process phases used for conducting mobile forensics, they are \u003cem\u003e(i)\u003c/em\u003e the identification phase which includes many details such as identifying, acquiring, and protecting the data collected at the crime scene; (\u003cem\u003eii)\u003c/em\u003e the collection phase which starts by processing the collected data or evidence, then extracting the relevant information; \u003cem\u003e(iii)\u003c/em\u003e the analysis phase analyzes the extracted information to connect the dots and be able to build a robust and admissible case; and \u003cem\u003e(iv)\u003c/em\u003e the reporting phase is the final step that presents the findings of the analysis stage into an admissible and understandable format.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eIn \u0026nbsp;[8], the authors mentioned that there are five phases in the forensic process (identification, preservation, acquisition, analyzing, and reporting) which are similar to what was proposed by Moreb \u0026nbsp;[7]. The study of \u0026nbsp;[9] concentrated on android forensics and proposed a framework of seven stages namely: Intake, Identification, Preparation, Isolation, Processing, Verification, and Documentation. A comparative analysis of five common process models was provided in \u0026nbsp;[10], these models are SFIPM, WMDFM, NIST, HDFI, and USFIPM \u0026amp; NIST. The authors also proposed a secure model by deploying blockchain using Ethereum or a hyper ledger platform\u003c/p\u003e\n\u003cp\u003e\u0026nbsp;In \u0026nbsp;[11] \u0026nbsp; the authors proposed ERFF, which helps the investigator to securely obtain evidence more easily, ERFF is an efficient and reliable forensics framework as compared with other frameworks such as SNIF, LFCCF, and LRFF. It uses edge computing to improve reliability, efficiency, and accuracy. Moreover, it helps identify criminal activities more quickly using low-cost edge devices and involves a detective module and a validation model that detect the interaction between a client terminal and the edge resource. In \u0026nbsp;[12] an analysis of the forensic-by-design framework is proposed which includes investigating the limits of the forensic-by-design and its insufficiencies in a Cloud systems context, and it proposes three new forensic-by-design key factors and associated standards and best practices, it also suggests a new generic systems and software engineering driven forensic-by-design framework.\u003c/p\u003e\n\u003cp\u003eReference \u0026nbsp;[13] demonstrates the DFWM that provides a general and updated description of the DF investigation process at the workflow level and can be used as a management tool for unboxing the procedures, tasks, and risks involved in the workflow of the individual DF investigations. Using the investigative strategy for the specific case, DFWM serves as a framework for packaging the digital forensic investigation process, providing a detailed structure and visualization of the physical and investigative chores and decisions. DF workflow which guided by the overall investigative strategy of the particular case as follows: \u003cem\u003e(i)\u003c/em\u003e review of client requirements and planning stage, (ii) evaluation of deployed workflow stage, \u003cem\u003e(iii)\u003c/em\u003e identify the physical and cognitive tasks, and \u003cem\u003e(iv)\u003c/em\u003e make decisions and their associated risks at the respective stage. Based on the existing process and models, the layered framework for mobile forensics is proposed in \u0026nbsp;[14], the results have shown that using only one tool is not sufficient to complete the investigation process, the four layers organize as a framework, the number of layers can be increased or reduced as per the case type, the six layers can be grouped to small categories with tools to use for each one as acquisition process with various tools such as MOBILedit, Bulk extractor; analyze the data with various tools like Autopsy and CellDEK, and reporting the case can be generated \u0026nbsp;using MOBILedit Forensic and CellDEK.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eIn\u0026nbsp;\u0026nbsp;[15]\u0026nbsp; \u0026nbsp;the authors reviewed about 100 Mobile forensics models with the main conclusion that suggests improving and validating the investigation process model, develop of a meta-modeling language, and develop of a definite mobile forensics source to store and retrieve the knowledge formed in the mobile forensics field.\u0026nbsp;\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eMany forensics investigation process models are used for the Internet of Things (IoTs) such as CIPM for IoTFs \u0026nbsp;[16], the proposed model assists IoTFs users to facilitate, manage, and organize the investigation tasks, it consists of four common investigation processes, preparation process, collection process, analysis process and report process. The proposed CIPM. The roadmap of DFIP discovery of tools \u0026nbsp;\u0026nbsp;[17] discussed in detail the challenges and opportunities for the digital forensics process concerning different fields such as networks, IoT, cloud computing, database system, big data, mobile and handheld devices, disk and different storage media, and operating system\u003c/p\u003e\n\u003cp\u003eAs seen from the literature, there is a necessity for adopting a robust model to carry out mobile forensic investigations efficiently, a comparison of well-known proposed models is provided in Table 1, we also included our proposed model MFIP in this table as proof of its usability.\u003c/p\u003e\n\u003cp\u003eTable 1: A comparative analysis of five common forensics process models with the proposed one.\u003c/p\u003e\n\u003cp\u003e\u003cbr\u003e\u003c/p\u003e\n\u003ctable style=\"width: 4.9e+2pt;border-collapse:collapse;border:none;\"\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 91.9pt;border-width: 1pt 1pt 1.5pt;border-style: solid;border-color: rgb(219, 219, 219) rgb(219, 219, 219) rgb(201, 201, 201);border-image: initial;padding: 0in 5.4pt;height: 19.95pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;'\u003ePhases\u003c/span\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 135.2pt;border-top: 1pt solid rgb(219, 219, 219);border-left: none;border-bottom: 1.5pt solid rgb(201, 201, 201);border-right: 1pt solid rgb(219, 219, 219);padding: 0in 5.4pt;height: 19.95pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;'\u003eFunctionality\u003c/span\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: 1pt solid rgb(219, 219, 219);border-left: none;border-bottom: 1.5pt solid rgb(201, 201, 201);border-right: 1pt solid rgb(219, 219, 219);padding: 0in 5.4pt;height: 19.95pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;'\u003eSFIPM\u003c/span\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: 1pt solid rgb(219, 219, 219);border-left: none;border-bottom: 1.5pt solid rgb(201, 201, 201);border-right: 1pt solid rgb(219, 219, 219);padding: 0in 5.4pt;height: 19.95pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;'\u003eWMDFM\u003c/span\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: 1pt solid rgb(219, 219, 219);border-left: none;border-bottom: 1.5pt solid rgb(201, 201, 201);border-right: 1pt solid rgb(219, 219, 219);padding: 0in 5.4pt;height: 19.95pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;'\u003eNIST\u003c/span\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: 1pt solid rgb(219, 219, 219);border-left: none;border-bottom: 1.5pt solid rgb(201, 201, 201);border-right: 1pt solid rgb(219, 219, 219);padding: 0in 5.4pt;height: 19.95pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;'\u003eHDFI\u003c/span\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: 1pt solid rgb(219, 219, 219);border-left: none;border-bottom: 1.5pt solid rgb(201, 201, 201);border-right: 1pt solid rgb(219, 219, 219);padding: 0in 5.4pt;height: 19.95pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;'\u003eUSFIPM\u0026nbsp;\u003c/span\u003e\u003c/strong\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;'\u003e\u0026amp;\u003c/span\u003e\u003c/strong\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;'\u003e\u0026nbsp;NIST\u003c/span\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: 1pt solid rgb(219, 219, 219);border-left: none;border-bottom: 1.5pt solid rgb(201, 201, 201);border-right: 1pt solid rgb(219, 219, 219);padding: 0in 5.4pt;height: 19.95pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;'\u003eMFIPF\u003c/span\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd rowspan=\"4\" style=\"width: 91.9pt;border-right: 1pt solid rgb(219, 219, 219);border-bottom: 1pt solid rgb(219, 219, 219);border-left: 1pt solid rgb(219, 219, 219);border-image: initial;border-top: none;background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003e\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003ePhase 1:\u003c/span\u003e\u003c/strong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003e\u0026nbsp;\u003cstrong\u003eData Preparation\u003c/strong\u003e\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003ePreparation \u0026nbsp;\u003c/span\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003e\u0026nbsp;\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003eHandling and securing the evidence scene \u0026nbsp;\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003eMode selection shielding\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003eOffset/online storage\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(23, 48, 28);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd rowspan=\"5\" style=\"width: 91.9pt;border-right: 1pt solid rgb(219, 219, 219);border-bottom: 1pt solid rgb(219, 219, 219);border-left: 1pt solid rgb(219, 219, 219);border-image: initial;border-top: none;background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003e\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003e\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003ePhase 2: Information Analysis\u003c/span\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003eExamination and analysis \u0026nbsp;\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 10.6pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 12pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003eCell state analysis\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 12pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 12pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 12pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 12pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 12pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 12pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.65pt;vertical-align: bottom;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003eNon-volatile evidence collection\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.65pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.65pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.65pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.65pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.65pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.65pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003eVolatile evidence collection\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003eEvidence validation\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(55, 147, 146);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd rowspan=\"2\" style=\"width: 91.9pt;border-right: 1pt solid rgb(219, 219, 219);border-bottom: 1pt solid rgb(219, 219, 219);border-left: 1pt solid rgb(219, 219, 219);border-image: initial;border-top: none;background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003e\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003ePhase 3: Case Construction\u003c/span\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003ePresentation\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003eCommunication Scheduling\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 134, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd rowspan=\"3\" style=\"width: 91.9pt;border-right: 1pt solid rgb(219, 219, 219);border-bottom: 1pt solid rgb(219, 219, 219);border-left: 1pt solid rgb(219, 219, 219);border-image: initial;border-top: none;background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;margin-bottom:10.0pt;line-height:200%;'\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family: \"Times New Roman\",serif;color:white;'\u003ePhase 4: Case Closing\u003c/span\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cstrong\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003e\u0026nbsp;\u003c/span\u003e\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003eReview\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 11.1pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003eDocumentation\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 135.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Times New Roman\",serif;color:white;'\u003eSurvey and Recognition\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.4pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✓\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 35.2pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 42.55pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 63.75pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 45.6pt;border-top: none;border-left: none;border-bottom: 1pt solid rgb(219, 219, 219);border-right: 1pt solid rgb(219, 219, 219);background: rgb(79, 176, 198);padding: 0in 5.4pt;height: 16.45pt;vertical-align: top;\"\u003e\n \u003cp style='margin:0in;font-size:16px;font-family:\"Calibri\",sans-serif;line-height:200%;'\u003e\u003cspan style='font-size:13px;line-height:200%;font-family:\"Segoe UI Symbol\",sans-serif;color:white;'\u003e✕\u003c/span\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n\u003c/table\u003e\n\u003cp\u003e\u003cstrong\u003e2)\u0026nbsp; Mobile forensics tools\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe definition of mobile phone forensics is the science of extracting digital evidence from a mobile device [18]. It provided a wonderful list of resources for catching online criminals who utilize mobile devices for illegal purposes. With their vast number of applications and current properties, mobile devices\u0026apos; ever-increasing storage and processing power provide new hurdles for digital forensics \u0026nbsp;[19]. In order to collect digital evidence for use in court trials, mobile forensic tools and applications are essential. They can unearth call metadata, SMS, GPS data, application data, and locally stored files.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eA set of mobile forensics tools\u0026nbsp;\u0026nbsp;[20]\u0026nbsp;can be used such as Cellebrite UFED Physical Analyzer and Oxygen Forensic Suite to get details about the mobile device, the results have shown that the device has a name and type, and iOS version Oxygen and UFED forensic tools\u0026nbsp;\u0026nbsp;[21]\u0026nbsp;used to recover app data. In general, digital forensic tools for data extraction are categorized into three types manual, logical, and physical\u0026nbsp;\u0026nbsp;[22].\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eMany mobile forensics tools\u0026nbsp;\u0026nbsp;[23]\u0026nbsp;such as Belkasoft Evidence Center\u0026nbsp;\u0026nbsp;[24], FINALMobile Forensics\u0026nbsp;\u0026nbsp;[25], 3uTools\u0026nbsp;\u0026nbsp;[26], and Magnet\u0026nbsp;\u0026nbsp;[27]\u0026nbsp;are used to extract artifacts from both Android and iOS devices.\u0026nbsp;The SDCA\u0026nbsp;\u0026nbsp;[28]\u0026nbsp;tool is designed to perform the analysis of the differences automatically between two versions of SQL schema, in addition to its ability to analyze the query. In\u0026nbsp;\u0026nbsp;[29]aid\u0026nbsp;forensic investigation in general, by developing a model and a platform to secure potential digital evidence, the\u0026nbsp;SecureRS\u0026nbsp;model can help to prevent unauthorized access and comply with regulations and privacy policies, the result shows a method of ensuring forensically sound digital evidence for DFR as well as for digital forensics processes in general. In\u0026nbsp;\u0026nbsp;[7]\u0026nbsp;the authors discussed the tools used to acquire the data from iOS or Android devices for both rooted and jailbreak mobile; the results have shown that the XRY software tool can recover deleted materials and can be able to extract all the data from the phone but it cannot retrieve deleted data\u0026nbsp;for not jailbroken\u0026nbsp;iPhone,\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eThe work in \u0026nbsp;[30] found out that the data used in the media directory did not have any change even after jailbreaking the device, which means that the integrity of the data remained unchanged by examining the matching hash value before and after the jailbreak. But by analyzing the source code of the exploit used where voucher swap as jailbreak code. It turned out that there was a change in the system data, where a fake kernel task was created instead of the original kernel task that works inside memory to give the privileges to extract the data. As a result of this study, jailbreaking is considered acceptable to help forensic tools extract more data while preserving user data.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eThere was a previous study in the use of forensic tools in the process of acquiring data on iOS, Android, and Windows using forensic tools Oxygen and UFED to recover applications\u0026rsquo; data, and the tools were able to restore the list of contacts that WhatsApp installed on iOS and Android, and unable to recover anything from the Windows device. In addition to the ability of the tools to restore and decrypt the backups of the Android and iOS devices, and unable to find the encryption key for the Windows device. The result was that it could restore conversations even if the application has been deleted if there are backup copies stored on the device for WhatsApp\u0026nbsp;[21]. \u0026nbsp; In \u0026nbsp;[28] it is noted that the developers of forensic tools have limited knowledge of the changes that have occurred to the SQL Lite schema for iOS backups and need to preserve the tools\u0026apos; compatibility with recent versions. The SDCASQLite Database Comparison Analyzer (SDCA) tool is designed to perform the analysis of the differences automatically between two versions of SQL schema, in addition to its ability to analyze the query, it also demonstrates that using the tool is feasible to update the Forensic Targeted Data Extraction Application called FTDEA developed by the authors.\u003c/p\u003e\n\u003cp\u003eAs mentioned in \u0026nbsp;[31] the growth of using smartphones from 2016 until 2021 increased from 2.5 to 3.8 billion smartphones. Also, in the report found in \u0026nbsp;[32], the number of users who use social media is about 4.20 \u0026nbsp;billion active users worldwide. According to the comparison as shown in Table 2 \u0026nbsp;[33\u0026ndash;35], the forensic tools deployed for mobile device investigations are considered very different from that available to investigate personal computers in terms of availability. These differences in the operating system and file systems structures create difficult challenges for the whole mobile forensic tools\u0026rsquo; developers and investigators. Commercial and open-source forensic tools are available for mobile device investigations.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eThe availability of many mobile forensics tools might cause some dilemmas in the selection of the best tool, for this reason, for this we will provide a mapping table that helps select the suitable tool for each step of our proposed model MFIP.\u003c/p\u003e\n"},{"header":"3. Proposed Mobile Forensics Framework","content":"\u003cp\u003eIn this section, we will deeply describe our MFIPF provided in Figure 2. The stages of the framework (Data Preparation, Information Analysis, Case construction, and Case Closing) will be explained showing the detailed steps at each phase.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFigure 2: The Proposed Forensics Investigation Process Framework (MFIPF)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u0026nbsp;\u003cstrong\u003e3.1. Data Preparation\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe data preparation phase aims to generate a processed dataset that is technically usable for the analysis phase. In this phase, four steps are carried out to guarantee that the acquainted data is gathered systematically and legally. The four steps shown in Figure 2 are described below:\u003c/p\u003e\n\u003col class=\"decimal_type\"\u003e\n \u003cli\u003e\u003cem\u003eResource seizure\u003c/em\u003e: In this step, the mobile device is seized in a way that guarantees that the device will not be modified and there should be no ability to connect with the device. To achieve this step, we have to follow the following process \u0026nbsp;[36]: \u003cem\u003e(i)\u003c/em\u003e issuance of research warrant from legal representatives; \u003cem\u003e(ii)\u003c/em\u003e turning off all wireless communications and putting the mobile device in Airplane Mode; \u003cem\u003e(iii)\u003c/em\u003e shieling the mobile device in a Faraday bag that prohibits any external signals to reach the mobile, and \u003cem\u003e(iv)\u003c/em\u003e Document these steps and send the mobile device to the digital forensics lab for investigations.\u003c/li\u003e\n \u003cli\u003e\u003cem\u003eResource identification\u003c/em\u003e\u003cstrong\u003e:\u0026nbsp;\u003c/strong\u003eOnce the mobile device arrives at the digital forensics lab, the resource identification process is carried out. The process aims to identify the mobile device under investigation and choose the suitable tools that can be used for the data extraction phase. A description of the mobile device is provided here, the description includes the model and type, physical status (if the device is broken), and logical status (the device is on or off, the device is functioning or not). \u0026nbsp;Based on this information, the investigator will be able to determine the suitable tools required for the data extraction process. This process should be formally documented \u0026nbsp;[37].\u003c/li\u003e\n \u003cli\u003e\u003cem\u003eData extraction:\u003c/em\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003eThis is a very important process where the data is extracted from the mobile device, the extracted data will then be used in further stages to extract evidence. The information gathered in the identification phase is the basis of the data extraction method to be used, these methods include:\u003c/li\u003e\n\u003c/ol\u003e\n\u003cul\u003e\n \u003cli\u003e\u003cstrong\u003eManual data extraction\u003c/strong\u003e: here the investigator manually navigates the mobile device to search for the required evidence; documentation of this process is essential and might be done by video recording of the screen of the mobile device during the navigation process \u0026nbsp;[37]. It is important here for the investigator to conduct the boundaries of the research warrant and never \u0026nbsp; explore data that is not included in the research warrant. This process requires the ability of the investigator to access the device by having the password or pattern. It is worth mentioning here that manual data extraction will affect the integrity of the files and hence the investigator should precisely document the steps he did and the findings as well.\u003c/li\u003e\n \u003cli\u003e\u003cstrong\u003eLogical extraction\u003c/strong\u003e: When applying this method, the investigator will be able to generate a copy of the file system that can be used later to extract data using some tools designed for this purpose. This copy will enable the investigator to view the same data that can be generated using manual extraction \u0026nbsp;[38]. However, this method does not affect the integrity of the files of the mobile device and the investigator can only work on the copy of the files and the original device will be kept safely in an evidence container.\u003c/li\u003e\n \u003cli\u003e\u003cstrong\u003ePhysical extraction\u003c/strong\u003e: in this method, a raw image in a binary format of the mobile device\u0026rsquo;s memory is generated, and the output is a bitwise copy of the memory of the mobile device \u0026nbsp;[39]. This copy includes all system files and can also be used to retrieve some of the deleted files as well. However, to generate this copy usually we need to root the device which will affect the integrity of the evidence, so the investigator has to document the details of this step. The generated copy can then be used to retrieve system files as well as some of the deleted files using dedicated data analysis tools.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eIt is worth noting that the aforementioned methods can be applied only when the mobile device is functional, \u003cem\u003ei.e.,\u003c/em\u003e not broken, and does not work for broken or malfunctioning mobile devices. In such a case some other methods might be used such as chip-off by which the memory chip of the mobile device is physically removed and attached to a memory reader or a similar device and the data is then extracted \u0026nbsp;[40]. This method requires high skills in electronic device maintenance and may cause the chip to be destroyed if not removed or attached correctly. Another extremely hard method that might be used in very rare cases such as national security is called Micro-read where an electronic microscope is used to read the contents of the memory on gate level base \u0026nbsp;[41]. This method is very expensive and takes too much time but might be used to extract some data from broken devices.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e3.1.4 Data preprocessing\u003c/em\u003e: In this process, the characteristics of the mobile device operating system are studied, and data is categorized based on applications to pinpoint potential evidence(s). Classification techniques are used here to group data based on file system analysis and system log analysis. The output of this process is a well-prepared dataset that can be used in the analysis stage to extract evidence. The preprocessing step might also include putting the data in a proper file format that is compatible with mobile forensics tools in the analysis phase \u0026nbsp;[42].\u003c/p\u003e\n\u003cp\u003e\u0026nbsp;3.2 \u003cstrong\u003eInformation analysis\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eIn the analysis phase, evidence(s) is/are extracted by formally interpreting the information generated by the previous phase \u0026ndash; data extraction-. The investigator should follow standards and best practices in the field of forensic analysis so that the evidence will be intact, and results are reproducible and acceptable. For a robust mobile forensic analysis, the following steps are suggested to be followed:\u003c/p\u003e\n\u003cp\u003e\u0026nbsp;\u003cem\u003e3.2.1 \u0026nbsp;Forensic Tools:\u003c/em\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003eThe first step in the analysis includes the selection of a forensic tool. The selection of the tool depends on many factors including cost, user interface, the familiarity of the examiner, computing platform and environment, and legislative \u0026ndash;whether the tool is legally approved or not \u0026nbsp;[43]. \u0026nbsp; A list of mobile forensics analysis tools and their properties are provided in Table [1].\u003c/p\u003e\n\u003cp\u003eTypically, the examiner may use different tools to generate different information and events, there is also a possibility to use different tools to generate the same event to make sure that the event is reproducible and to prove its validity \u0026nbsp;[44] Therefore, an examiner should be familiar with different tools to conduct his analysis successfully.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e3.2.2 Information examination:\u003c/em\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003eAfter selecting the appropriate tool(s), the examiner will feed the tool with the data preprocessed data and perform a variety of tests and processing tasks against the data. The processing aims to generate an event from the evidence file. There might be many events generated from the same or multiple tools. These events are then stored and fed to the next step which is evidence validation \u0026nbsp;[45]\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e\u0026nbsp;\u003c/em\u003eEvents in a mobile device might be found at different locations according to the information the examiner is trying to find. Some of the events might be found in SMS and call logs, others might be found in saved pictures or emails. Some complex events might require retrieving deleted files using special tools while other events require the use of different tools and gathering information to reconstruct that event. The selection of the tool and the process depends on the examiner and requires skilled persons to successfully perform the task \u0026nbsp;[41]. \u0026nbsp;\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e\u003cem\u003e3.2.3\u0026nbsp;\u003c/em\u003eEvidence validation:\u003c/em\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003eAccording to \u0026nbsp;[46], validation is the process of proving the validity of the evidence to a jury. The process implies proving acceptable error rates as well as using scientifically proven valid data, applications, and results. The validation process is applied to all stages in mobile forensics and covers data collection and storage, system, application, user, and algorithm applicability validation.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eA very important issue related to validation is the use and following up of standards and best practices developed for this purpose. Many countries have developed standards for digital and mobile forensics through their dedicated institutions such as NIST in the states. Besides, some well-known digital forensics developers have also proposed some best practices that are proven to generate valid evidence with an acceptable error rate \u0026nbsp;[47]. The examiner must follow these standards and verify the validity of the evidence during the entire investigation process.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e\u003cem\u003e3.2.4\u0026nbsp;\u003c/em\u003eEvidence correlation:\u003c/em\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003eCorrelation involves the ability to extract the semantics from different sources such as SMS, social media messaging, emails, \u0026hellip;, etc, and to generate a knowledge base that clearly shows the correlation among these generated events. Domain and application ontologies might be used to correlate different events to a knowledge base \u0026nbsp;[48].\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eEvent correlation and reconstruction might be carried out using different techniques and technologies including rule-based, semantic models, tree/graph-based, timestamp-based, finite state machines, and live event construction \u0026nbsp;[49], such techniques aim to construct valid evidence from different sources of events with acceptable error rate. The output of this stage will be used as input for the next phase which is case construction.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.3. Case Construction\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe output of the second stage - information analysis - is fed as an input to the case construction stage, which takes the evidence list to prepare results and move towards closing the case. Four steps are necessary in the process of case construction: results analysis, results examination, results reporting, and results dissemination. In what follows, a detailed explanation is provided for each step. \u0026nbsp; \u0026nbsp;\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e\u003cem\u003e3.3.1\u0026nbsp;\u003c/em\u003eResults analysis:\u0026nbsp;\u003c/em\u003eIn this step, examiners must analyze all the technical findings extracted from the information analysis phase consistently and clearly. When analyzing the results, examiners can divide the analysis sequential logical parts divided into multiple headings and comment on results as they are described to ease the decision-making process, the results could be supported by figures, tables, and equations to enrich the findings. In addition, the results\u0026rsquo; conclusion must be kept very brief that aggregates the findings with robust paragraphs \u0026nbsp;[50].\u003c/p\u003e\n\u003cp\u003eDuring the process of validating the results of a mobile forensic scene, several methods can be used to verify the validity of the results such as calculating the hash value with two different forensics tools, or the various steps might be revisited using the same tool to obtain the digital evidence and recalculated the hash value to validate the results. At some point, the results generated using experimental and validation stages must be repeatable. Any variable that might affect the outcome of the validation should be determined after several test runs. However, some cases require more runs to generate valid results, besides; examiners need to utilize the literature to assess the results\u0026rsquo; validations \u0026nbsp;[51]\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e\u003cem\u003e\u003cem\u003e3.3.2\u0026nbsp;\u003c/em\u003e\u003c/em\u003eResults reporting:\u0026nbsp;\u003c/em\u003eThe most fruitful result that should be created following the forensic process is the documentation of the findings. Once completed, investigators can use the report to their advantage in a number of ways, including (i) sharing the results with other investigators and decision-makers for use in making decisions, (ii) communicating the facts that may support the investigation of other cases, (iii) offering a clear justification for gathering more digital evidence, and (iv) using the report to evaluate the specific case. The final report must be written by digital examiners taking into account all conditions and guidelines established by national law. To ensure that the report complies with the law, they must first independently review it. Any divergent opinions will eventually be examined for flaws to bolster the assertions.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eIn general, there is no set format or structure for reporting the findings, but any final report must include the bare minimum of the following data: jurisdiction, the nature of the case, the court\u0026apos;s document format, and the reason ID, calendar of all depositions (timestamps), deponent\u0026rsquo;s name and ID, and other details like time and date the case created, phone physical situation, the phone status on or off, mobile manufacturer information, pictures for each accessory and the phone itself, which tools used in the investigation, any additional data added during an examination. Many forensics reporting tools provide ways to automatically annotate evidence fragments and generate automatic reports according to the examiner\u0026rsquo;s configuration. These tools enable the examiner to perform sub-functions such as tagging, bookmarking, log reports, or even report generation. The report relies on solid documentation, photos, notes, and tool-generated content. The examiner should then check the report and edit his configuration if necessary \u0026nbsp;[52]\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e\u003cem\u003e\u003cem\u003e3.3.3\u0026nbsp;\u003c/em\u003e\u003c/em\u003eResults disseminationIt\u0026nbsp;\u003c/em\u003edescribes the procedure the examiner uses to communicate to policy-makers the findings from the analysis phase. The major goal of this method is to provide action reports for each detected artifact and its analysis. The investigator\u0026apos;s defensive strategy and any potential implementation difficulties can also be included in the presentation phase. In an iterative approach, the results from this phase might be used to conduct additional acquisitions. As a result, each process produces more analytical artifacts, which are then provided as feedback to other processes. For lengthy criminal investigations, this feedback iterative procedure may go through numerous iterations.\u003c/p\u003e\n\u003cp\u003eThis step might help other investigators working on similar cases to proceed with their cases accordingly, or to criticize the case, and hence further steps might be required to be performed for the disseminated case \u0026nbsp;[53]. \u0026nbsp; \u0026nbsp; \u0026nbsp;\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.4. Case Closing\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eCase closing is the last stage in the mobile forensics investigation process framework (MFIPF) which undergoes three main steps to ensure the successful termination of the process model. They are case closing, making the legal decision, and case archiving. Understanding how to close and archive the case is also crucial to perform a targeted analysis of the data for future updates. It is important that the digital examiner must have good knowledge of how to store and collect similar cases which might help in case examination.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e\u003cem\u003e\u003cem\u003e3.4.1\u0026nbsp;\u003c/em\u003e\u003c/em\u003eLegal decision:\u003c/em\u003e The constructed case should be finally put in its legal context, here, the final legal decision should be a judicial determination of all parties rights and obligations reached by a court based on facts and law. A decision can mean either the act of delivering a court\u0026apos;s order or the text of the court\u0026apos;s opinion on the case and the accompanying court after you complete a case. Since every user owns his/her data and digital device, forensic examiners face ethical and legal issues in accessing and collecting the required information \u0026nbsp;[54]\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e\u003cem\u003e\u003cem\u003e\u003cem\u003e3.4.2\u0026nbsp;\u003c/em\u003e\u003c/em\u003e\u003c/em\u003eReview:\u0026nbsp;\u003c/em\u003eThe final step in the lifecycle is to review the case to identify successful decisions and actions and determine how the system performance should be improved in terms of time, and accuracy. Critique the case, self-evaluation and peer review are essential parts of professional growth. Investigators must keep the OS and digital forensics tools current in order for everything to be consistent. This necessitates updating the OS frequently, installing all new system updates and patches, and regularly checking the tools\u0026apos; websites for new updates or patches. \u0026nbsp;[55] \u0026nbsp;\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e\u003cem\u003e\u003cem\u003e\u003cem\u003e3.4.3\u0026nbsp;\u003c/em\u003e\u003c/em\u003e\u003c/em\u003eCase archiving:\u0026nbsp;\u003c/em\u003eWhen work on a case is completed and immediate access to it is no longer necessary, that case can be archived. This step aims at closing the case after its resolution. Digital forensics case achieving includes the storage of the electronic copies of evidence as well as the case report and the generated artifacts and the documentation of the whole stages of the case. The aim of case archiving is to enable examiners to review the procedures carried out to use them in similar cases. The case archive should enable the examiner to reconstruct the case from scratch based on the available copies of the case evidence which will help if the case was legally re-opened \u0026nbsp;[56]. Many tools might be used in case archiving that enable ease of use and retrieval of cases, some of these tools will be provided in Section 4.\u003c/p\u003e"},{"header":"4. Common Mobile Forensics Tools Used In Mobile Forensic Investigation:","content":"\u003cp\u003eIn this section, we will explain a list of 4 commonly used mobile forensics tools, and map them to our proposed model MFIPF.\u003c/p\u003e\n\u003col\u003e\n \u003cli\u003e\u003cstrong\u003eCommon tools:\u003c/strong\u003e\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eIn the following, we list the common forensics investigation tools and compare and reflect on their operations with the modules of the proposed MFIPF framework.\u0026nbsp;\u003c/p\u003e\n\u003cul\u003e\n \u003cli\u003eBelkasoft Evidence Center: It is a comprehensive forensic tool for locating, retrieving, and analyzing digital evidence stored on desktops and mobile devices. This tool makes it simple for investigators to collect, examine, analyze, preserve, and share digital evidence from computers and mobile devices. By analyzing hard disks, drive pictures, memory dumps, iOS, Blackberry, Android backups, UFED, JTAG, and chip-off dumps, the toolkit will efficiently extract digital evidence from many sources. It evaluates the data source automatically and lays out the most forensically significant artifacts for the investigator to study the case or add to the report \u0026nbsp;[24].\u003c/li\u003e\n \u003cli\u003eFINALMobile: It is a powerful software and mobile solution for legal inspectors that provides the legal community with the most cutting-edge data mining and information extraction capabilities. Thanks to its extensive understanding of system files and information patterns, this software can transform raw data into executable and ready files in just a few clicks. On mobile devices, data is stored in specialized forms and is frequently left behind after a device is entirely cleaned. The FINALMobile forensics software can easily retrieve deleted (hidden) files by scanning for specific patterns. Additionally, as the majority of mobile devices adhere to the same pattern, data can be gathered for upcoming mobile devices. \u0026nbsp;[25].\u003c/li\u003e\n \u003cli\u003e3uTools: It is a program for flashing and jailbreaking Apple\u0026apos;s iPhone, iPad, and iPod touch. It offers three ways to flash Apple mobile devices: easy mode, professional mode, or multiple flash. It automatically selects the proper firmware and supports a fast download speed. 3uTools Free Download for Windows PC Latest Version. It has a complete 3uTools offline setup installer \u0026nbsp;[26].\u003c/li\u003e\n \u003cli\u003eMagnet ACQUIRE: This tool combines an easy user interface with dependable and speedy extractions to provide you with the information you need quickly and effortlessly. Furthermore, the data quality will be maximized, and activity logging and documentation will help to understand which procedures were employed \u0026nbsp;[27].\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e2) Mapping tools to MFIPF:\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eTable 2 provides a comparative analysis between iOS and Android forensic tools for mobile forensics tools with their functionalities based on MFIPF.\u003c/p\u003e"},{"header":"5. Conclusion And Future Work","content":"\u003cp\u003eCybercrimes are rapidly increasing due to the tremendous reliance on information and telecommunication technologies. This rapid increase is being faced by developing the necessary tools and legislation to fight against these crimes. One of the most challenging investigation issues is mobile device forensics. This challenge is because mobile device is becoming more powerful with tremendous processing and communication capabilities as well as containing sensitive data related to the mobile user. For these reasons, a framework for mobile device forensics must be developed to systematically engineer the investigation process and avoid any issues that might cause to reject the investigation. In this paper, we proposed a mobile forensics lifecycle called Mobile Forensics Investigation Process Framework (MFIPF). MFIPF encompasses all forensics stages and steps that must be followed in each stage. Furthermore, we also proposed a list of the most commonly used mobile forensics tools that might be used in each stage or step. In future work, we will apply this model to different investigation scenarios with different mobile platforms and report the finding and if necessary we will update the model accordingly.\u003c/p\u003e \u003cp\u003eIn future work, we will test the utility of using our model MFIPF with different mobile digital forensics scenarios and compare our utility results against other models.\u003c/p\u003e"},{"header":"Declarations","content":"\u003cp\u003e\u003cstrong\u003eAcknowledgements:\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eNot applicable\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003cstrong\u003eAuthors\u0026rsquo; contributions:\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eAll authors read and approved the manuscript.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003cstrong\u003eFunding:\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eNot applicable\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003cstrong\u003eAvailability of data and materials\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eNot applicable \u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eEthics approval and consent to participate:\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eNot applicable \u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eCompeting interests:\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe authors declare that they have no competing interests.\u003cstrong\u003e\u0026nbsp;\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e"},{"header":"References","content":"\u003col\u003e\n\u003cli\u003eWww.statista.com, \u003cem\u003eShare of Global Smartphone Shipments by Operating System from 2014 to 2023\u003c/em\u003e, https://www.statista.com/statistics/272307/market-share-forecast-for-smartphone-operating-systems/.\u003c/li\u003e\n\u003cli\u003eS. N. Zakaria and M. F. Zolkipli, \u003cem\u003eReview on Mobile Attacks: Operating System, Threats and Solution\u003c/em\u003e, Borneo International Journal EISSN 2636-9826 \u003cstrong\u003e4\u003c/strong\u003e, (2021).\u003c/li\u003e\n\u003cli\u003eA. M. Alashjaee, N. Almolhis, and M. Haney, \u003cem\u003eMobile Malware Forensic Review: Issues and Challenges\u003c/em\u003e, 367 (2021).\u003c/li\u003e\n\u003cli\u003eM. Kumar, \u003cem\u003eMobile Phone Forensics \u0026ndash; A Systematic Approach, Tools, Techniques and Challenges\u003c/em\u003e, International Journal of Electronic Security and Digital Forensics \u003cstrong\u003e13\u003c/strong\u003e, 53 (2021).\u003c/li\u003e\n\u003cli\u003eO. Ameerbakhsh, F. M. Ghabban, I. M. Alfadli, A. N. Abuali, A. Al-Dhaqm, and M. A. Al-Khasawneh, \u003cem\u003eDigital Forensics Domain and Metamodeling Development Approaches\u003c/em\u003e, 2021 2nd International Conference on Smart Computing and Electronic Enterprise: Ubiquitous, Adaptive, and Sustainable Computing Solutions for New Normal, ICSCEE 2021 67 (2021).\u003c/li\u003e\n\u003cli\u003eJ. Howe, M. Baylor, and R. H. Liu, \u003cem\u003eAdvancing the Practice of Forensic Science in the United States--Practitioners\u0026rsquo; Efforts.\u003c/em\u003e, Forensic Sci Rev \u003cstrong\u003e34\u003c/strong\u003e, 7 (2022).\u003c/li\u003e\n\u003cli\u003eM. Moreb, \u003cem\u003eIntroduction to Android Forensics\u003c/em\u003e, Practical Forensic Analysis of Artifacts on IOS and Android Devices 71 (2022).\u003c/li\u003e\n\u003cli\u003eH. H. Lwin, W. P. Aung, and K. K. Lin, \u003cem\u003eComparative Analysis of Android Mobile Forensics Tools\u003c/em\u003e, 2020 IEEE Conference on Computer Applications, ICCA 2020 1 (2020).\u003c/li\u003e\n\u003cli\u003eA. Al-Sabaawi and E. Foo, \u003cem\u003eA Comparison Study of Android Mobile Forensics for Retrieving Files System\u003c/em\u003e, Ernest Foo International Journal of Computer Science and Security (IJCSS) 2019 (2019).\u003c/li\u003e\n\u003cli\u003eW. Asghari, A. Suresh Kumar, A. S. Singh, and K. Thirunavukkarasu, \u003cem\u003eA Comparison Analysis of Mobile Forensic Investigation Framework\u003c/em\u003e, 595 (2021).\u003c/li\u003e\n\u003cli\u003eA. Razaque, M. Aloqaily, M. Almiani, Y. Jararweh, and G. Srivastava, \u003cem\u003eEfficient and Reliable Forensics Using Intelligent Edge Computing\u003c/em\u003e, Future Generation Computer Systems \u003cstrong\u003e118\u003c/strong\u003e, 230 (2021).\u003c/li\u003e\n\u003cli\u003eA. Akilal and M. T. Kechadi, \u003cem\u003eAn Improved Forensic-by-Design Framework for Cloud Computing with Systems Engineering Standard Compliance\u003c/em\u003e, Forensic Science International: Digital Investigation \u003cstrong\u003e40\u003c/strong\u003e, (2022).\u003c/li\u003e\n\u003cli\u003eG. Horsman and N. Sunde, \u003cem\u003eUnboxing the Digital Forensic Investigation Process\u003c/em\u003e, Science and Justice \u003cstrong\u003e62\u003c/strong\u003e, 171 (2022).\u003c/li\u003e\n\u003cli\u003eM. Goel and V. Kumar, Layered Framework for Mobile Forensics Analysis, n.d.\u003c/li\u003e\n\u003cli\u003eA. Al-Dhaqm, S. A. Razak, R. A. Ikuesan, V. R. Kebande, and K. Siddique, \u003cem\u003eA Review of Mobile Forensic Investigation Process Models\u003c/em\u003e, IEEE Access \u003cstrong\u003e8\u003c/strong\u003e, 173359 (2020).\u003c/li\u003e\n\u003cli\u003eM. A. Saleh, S. Hajar Othman, A. Al-Dhaqm, and M. A. Al-Khasawneh, \u003cem\u003eCommon Investigation Process Model for Internet of Things Forensics\u003c/em\u003e, 2021 2nd International Conference on Smart Computing and Electronic Enterprise: Ubiquitous, Adaptive, and Sustainable Computing Solutions for New Normal, ICSCEE 2021 84 (2021).\u003c/li\u003e\n\u003cli\u003eA. Patil, S. Banerjee, D. Jadhav, and G. Borkar, \u003cem\u003eRoadmap of Digital Forensics Investigation Process with Discovery of Tools\u003c/em\u003e, Cyber Security and Digital Forensics 241 (2021).\u003c/li\u003e\n\u003cli\u003eK. Curran, A. Robinson, S. Peacocke, and S. Cassidy, \u003cem\u003eMobile Phone Forensic Analysis\u003c/em\u003e, International Journal of Digital Crime and Forensics \u003cstrong\u003e2\u003c/strong\u003e, 15 (2010).\u003c/li\u003e\n\u003cli\u003eD. Hamdi, F. Iqbal, T. Baker, and B. Shah, \u003cem\u003eMultimedia File Signature Analysis for Smartphone Forensics\u003c/em\u003e, Proceedings - 2016 9th International Conference on Developments in ESystems Engineering, DeSE 2016 130 (2017).\u003c/li\u003e\n\u003cli\u003eM. Al-Hadadi and A. AlShidhani, \u003cem\u003eSmartphone Forensics Analysis: A Case Study\u003c/em\u003e, International Journal of Computer and Electrical Engineering \u003cstrong\u003e5\u003c/strong\u003e, 576 (2013).\u003c/li\u003e\n\u003cli\u003eA. Shortall and M. A. H. Bin Azhar, \u003cem\u003eForensic Acquisitions of WhatsApp Data on Popular Mobile Platforms\u003c/em\u003e, Proceedings - 2015 6th International Conference on Emerging Security Technologies, EST 2015 13 (2016).\u003c/li\u003e\n\u003cli\u003eM. Moreb, \u003cem\u003eIntroduction to IOS Forensics\u003c/em\u003e, Practical Forensic Analysis of Artifacts on IOS and Android Devices 37 (2022).\u003c/li\u003e\n\u003cli\u003eH. Azhar, \\ Cox, R., and A. Chamberlain, \u003cem\u003eForensic Investigations of Popular Ephemeral Messaging Applications on Android and IOS Platforms\u003c/em\u003e, International Journal on Advances Security \u003cstrong\u003e13\u003c/strong\u003e, 41 (2020).\u003c/li\u003e\n\u003cli\u003eBelkasoft.com, \u003cem\u003eBelkasoft Evidence Center\u003c/em\u003e, https://belkasoft.com/ru/bec/en/Evidence_Center.asp.\u003c/li\u003e\n\u003cli\u003eFinaldata, \u003cem\u003eFINALMobile Forensics\u003c/em\u003e, https://finaldata.com/mobile/.\u003c/li\u003e\n\u003cli\u003euTools, \u003cem\u003eHttp://Www.3u.Com/\u003c/em\u003e, http://www.3u.com/.\u003c/li\u003e\n\u003cli\u003eMagnet, \u003cem\u003eMagnet ACQUIRE\u003c/em\u003e, https://www.magnetforensics.com/resources/magnet-acquire/.\u003c/li\u003e\n\u003cli\u003eS. S. Shimmi, G. Dorai, U. Karabiyik, and S. Aggarwal, \u003cem\u003eAnalysis of IOS SQLite Schema Evolution for Updating Forensic Data Extraction Tools\u003c/em\u003e, 8th International Symposium on Digital Forensics and Security, ISDFS 2020 (2020).\u003c/li\u003e\n\u003cli\u003eA. Singh, R. A. Ikuesan, and H. Venter, \u003cem\u003eSecure Storage Model for Digital Forensic Readiness\u003c/em\u003e, IEEE Access \u003cstrong\u003e10\u003c/strong\u003e, 19469 (2022).\u003c/li\u003e\n\u003cli\u003eA. Aenurahman Ali, N. Dwi Wahyu Cahyani, and E. Musthofa Jadied, \u003cem\u003eDigital Forensic Analysis on IDevice: Jailbreak IOS 12.1.1 as a Case Study\u003c/em\u003e, Indonesia Journal of Computing \u003cstrong\u003e4\u003c/strong\u003e, 205 (2019).\u003c/li\u003e\n\u003cli\u003eA. Turner, \u003cem\u003eHow Many People Have Smartphones Worldwide (April 2021)\u003c/em\u003e, https://www.bankmycell.com/blog/how-many-phones-are-in-the-world.\u003c/li\u003e\n\u003cli\u003eS. Kemp, \u003cem\u003eDigital 2021: Global Overview Report \u0026mdash; DataReportal \u0026ndash; Global Digital Insights\u003c/em\u003e, https://datareportal.com/reports/digital-2021-global-overview-report.\u003c/li\u003e\n\u003cli\u003eM. Moreb, \u003cem\u003eMobile Forensic Investigation for WhatsApp\u003c/em\u003e, Practical Forensic Analysis of Artifacts on IOS and Android Devices 281 (2022).\u003c/li\u003e\n\u003cli\u003eM. Moreb, \u003cem\u003eDetecting Privacy Leaks Utilizing Digital Forensics and Reverse Engineering Methodologies\u003c/em\u003e, Practical Forensic Analysis of Artifacts on IOS and Android Devices 195 (2022).\u003c/li\u003e\n\u003cli\u003eM. Moreb, \u003cem\u003eForensic Investigations of Popular Applications on Android and IOS Platforms\u003c/em\u003e, Practical Forensic Analysis of Artifacts on IOS and Android Devices 109 (2022).\u003c/li\u003e\n\u003cli\u003eA. Hrenak, \u003cem\u003eMobile Device Forensics : An Introduction\u003c/em\u003e, Cyber Forensics 291 (2021).\u003c/li\u003e\n\u003cli\u003eC. Arumugam and S. Shunmuganathan, \u003cem\u003eDigital Forensics: Essential Competencies of Cyber-Forensics Practitioners\u003c/em\u003e, 843 (2021).\u003c/li\u003e\n\u003cli\u003eA. el Majdoub, C. Saadi, and H. Chaoui, \u003cem\u003eMobile Forensics Data Acquisition\u003c/em\u003e, ITM Web of Conferences \u003cstrong\u003e46\u003c/strong\u003e, 02006 (2022).\u003c/li\u003e\n\u003cli\u003eL. A. Herrera, \u003cem\u003eChallenges of Acquiring Mobile Devices While Minimizing the Loss of Usable Forensics Data\u003c/em\u003e, 8th International Symposium on Digital Forensics and Security, ISDFS 2020 (2020).\u003c/li\u003e\n\u003cli\u003eA. M. da Costa, A. O. de Sa, and R. C. S. Machado, \u003cem\u003eData Acquisition and Extraction on Mobile Devices-A Review\u003c/em\u003e, 2022 IEEE International Workshop on Metrology for Industry 4.0 and IoT, MetroInd 4.0 and IoT 2022 - Proceedings 294 (2022).\u003c/li\u003e\n\u003cli\u003eM. Kumar, \u003cem\u003eMobile Forensics : Tools, Techniques and Approach\u003c/em\u003e, Crime Science and Digital Forensics 102 (2021).\u003c/li\u003e\n\u003cli\u003eD. Kim and S. Lee, \u003cem\u003eStudy of Identifying and Managing the Potential Evidence for Effective Android Forensics\u003c/em\u003e, Forensic Science International: Digital Investigation \u003cstrong\u003e33\u003c/strong\u003e, 200897 (2020).\u003c/li\u003e\n\u003cli\u003eM. Lovanshi and P. Bansal, \u003cem\u003eComparative Study of Digital Forensic Tools\u003c/em\u003e, Data, Engineering and Applications 195 (2019).\u003c/li\u003e\n\u003cli\u003eJr. E. Oliveira, T. J. Silva, A. F. Zorzo, and C. V. Neu, \u003cem\u003eDigital Forensics Experimentation: Analysis and Recommendations.\u003c/em\u003e, Forensic Sci Rev \u003cstrong\u003e34\u003c/strong\u003e, 21 (2022).\u003c/li\u003e\n\u003cli\u003eS. Dogan and E. Akbal, \u003cem\u003eAnalysis of Mobile Phones in Digital Forensics\u003c/em\u003e, 2017 40th International Convention on Information and Communication Technology, Electronics and Microelectronics, MIPRO 2017 - Proceedings 1241 (2017).\u003c/li\u003e\n\u003cli\u003eR. F. Erbacher, \u003cem\u003eValidation for Digital Forensics\u003c/em\u003e, ITNG2010 - 7th International Conference on Information Technology: New Generations 756 (2010).\u003c/li\u003e\n\u003cli\u003eH. Arshad, A. bin Jantan, and O. I. Abiodun, \u003cem\u003eDigital Forensics: Review of Issues in Scientific Validation of Digital Evidence\u003c/em\u003e, Journal of Information Processing Systems \u003cstrong\u003e14\u003c/strong\u003e, 346 (2018).\u003c/li\u003e\n\u003cli\u003eH. Arshad, A. Jantan, G. K. Hoon, and I. O. Abiodun, \u003cem\u003eFormal Knowledge Model for Online Social Network Forensics\u003c/em\u003e, Comput Secur \u003cstrong\u003e89\u003c/strong\u003e, (2020).\u003c/li\u003e\n\u003cli\u003eL. F. Sikos, \u003cem\u003eAI in Digital Forensics: Ontology Engineering for Cybercrime Investigations\u003c/em\u003e, Wiley Interdisciplinary Reviews: Forensic Science \u003cstrong\u003e3\u003c/strong\u003e, e1394 (2021).\u003c/li\u003e\n\u003cli\u003eM. R. Al-Mousa, \u003cem\u003eAnalyzing Cyber-Attack Intention for Digital Forensics Using Case-Based Reasoning\u003c/em\u003e, International Journal of Advanced Trends in Computer Science and Engineering \u003cstrong\u003e8\u003c/strong\u003e, 3243 (2021).\u003c/li\u003e\n\u003cli\u003eH. Page, G. Horsman, A. Sarna, and J. Foster, \u003cem\u003eA Review of Quality Procedures in the UK Forensic Sciences: What Can the Field of Digital Forensics Learn?\u003c/em\u003e, Sci Justice \u003cstrong\u003e59\u003c/strong\u003e, 83 (2019).\u003c/li\u003e\n\u003cli\u003eA. R. Javed, W. Ahmed, M. Alazab, Z. Jalil, K. Kifayat, and T. R. Gadekallu, \u003cem\u003eA Comprehensive Survey on Computer Forensics: State-of-the-Art, Tools, Techniques, Challenges, and Future Directions\u003c/em\u003e, IEEE Access \u003cstrong\u003e10\u003c/strong\u003e, 11065 (2022).\u003c/li\u003e\n\u003cli\u003eG. Horsman, \u003cem\u003eTool Testing and Reliability Issues in the Field of Digital Forensics\u003c/em\u003e, Digit Investig \u003cstrong\u003e28\u003c/strong\u003e, 163 (2019).\u003c/li\u003e\n\u003cli\u003eG. Horsman and N. Sunde, \u003cem\u003ePart 1: The Need for Peer Review in Digital Forensics\u003c/em\u003e, Forensic Science International: Digital Investigation \u003cstrong\u003e35\u003c/strong\u003e, 301062 (2020).\u003c/li\u003e\n\u003cli\u003eG. Horsman, \u003cem\u003eTool Testing and Reliability Issues in the Field of Digital Forensics\u003c/em\u003e, Digit Investig \u003cstrong\u003e28\u003c/strong\u003e, 163 (2019).\u003c/li\u003e\n\u003cli\u003eZ. Bartliff, Y. Kim, F. Hopfgartner, and G. Baxter, \u003cem\u003eLeveraging Digital Forensics and Data Exploration to Understand the Creative Work of a Filmmaker: A Case Study of Stephen Dwoskin\u0026rsquo;s Digital Archive\u003c/em\u003e, Inf Process Manag \u003cstrong\u003e57\u003c/strong\u003e, (2020).\u003c/li\u003e\n\n\u003c/ol\u003e"},{"header":"Table 2","content":"\u003cp\u003eTable 2 is available in Supplementary Files section.\u003c/p\u003e"}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":true,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":true,"isAuthorSuppliedPdf":false,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Mobile Forensics, Digital Forensics, Forensic tools, Acquisition, iOS, Android, Extraction, Artifacts","lastPublishedDoi":"10.21203/rs.3.rs-2611927/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-2611927/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eInvestigating digital evidence by gathering, examining, and maintaining evidence that was stored in smartphones has attracted tremendous attention and become a key part of digital forensics. The mobile forensics process aims to recover digital evidence from a mobile device in a way that will preserve the evidence in a forensically sound condition, this evidence might be used to prove to be a cybercriminal or a cybercrime victim. To do this, the mobile forensics process lifecycle must establish clear guidelines for safely capturing, isolating, transporting, storing, and proving digital evidence originating from mobile devices. There are unique aspects of the mobile forensics procedure that must be taken into account. It is imperative to adhere to proper techniques and norms in order for the testing of mobile devices to produce reliable results. In this paper, we develop a novel methodology for the mobile forensics process model lifecycle named Mobile Forensics Investigation Process Framework (MFIPF) which encompasses all the necessary stages and data sources used to construct the crime case. The developed framework contributes to identifying common concepts of mobile forensics through the development of the mobile forensics model that simplifies the examination process and enables forensics teams to capture and reuse specialized forensic knowledge. Furthermore, the paper provides a list of the most commonly used forensics tools and where can we use them in our proposed mobile forensic process model.\u003c/p\u003e","manuscriptTitle":"A Novel Framework for Mobile Forensics Investigation Process","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2023-03-08 15:07:46","doi":"10.21203/rs.3.rs-2611927/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"c780f199-64a9-4067-bad2-e143c25d22f1","owner":[],"postedDate":"March 8th, 2023","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"published-in-journal","subjectAreas":[],"tags":[],"updatedAt":"2024-04-25T15:37:05+00:00","versionOfRecord":{"articleIdentity":"rs-2611927","link":"https://doi.org/10.12785/ijcds/160110","journal":{"identity":"international-journal-of-computing-and-digital-systems","isVorOnly":true,"title":"International Journal of Computing and Digital Systems"},"publishedOn":"2024-04-21 00:00:00","publishedOnDateReadable":"April 21st, 2024"},"versionCreatedAt":"2023-03-08 15:07:46","video":"","vorDoi":"10.12785/ijcds/160110","vorDoiUrl":"https://doi.org/10.12785/ijcds/160110","workflowStages":[]},"version":"v1","identity":"rs-2611927","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-2611927","identity":"rs-2611927","version":["v1"]},"buildId":"rHA-KDH7Qsr4HCuvH75dn","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. The paper's references may be in our DB but unresolved to ``paper_id`` (resolution happens at ingest when the cited DOI matches a row we already have). Run the cross-source citation reconcile pass to retry.

Source provenance

europepmc
last seen: 2026-05-19T01:45:01.086888+00:00