Mobius Forensic Toolkit

Mobius Forensic Toolkit retrieves the following evidence types from VFS and UFDR datasources, so far:



Evidence TypeDescriptionUFDRVFS
AutofillAutofill data
Bookmarked URLsURLs bookmarked by users
Call LogsRegular phone calls and VOIP phone calls metadata
Chat MessagesInstant chat messages
ContactsContact of friends and parties
CookiesHTTP cookies data
Crypto WalletsCrypto Wallets addresses
Encryption KeysEncryption keys used to protect data
Installed ProgramsPrograms installed on Operating System
Instant MessagesSMS/MMS and other instant messages
IP AddressesExternal IP addresses recorded by applications
Local FilesFiles that are/were in suspect disk, according to applications records
Opened FilesFiles opened by users
Password HashesPassword hashes, such as NTLM and LM
PasswordsUser passwords
Received FilesFiles received by users, including donwloaded files and message attachments
Searched TextsTexts searched by users
Sent FilesFiles sent by users, including donwloaded files and message attachments
Shared FilesFiles shared by local users
Trash Can EntriesOperating System's trash can entries
User AccountsUser accounts
Visited URLsURLs visited by users using browser applications
Wireless ConnectionsWireless connections, with date/time information
Wireless NetworksWireless networks that were connected, including password information