Mobius Forensic Toolkit

Mobius Forensic Toolkit retrieves the following evidence types from VFS and UFDR datasources, so far:



Evidence TypeDescriptionUFDRVFS
AutofillAutofill data
Bookmarked URLsURLs bookmarked by users
Call LogsRegular phone calls and VOIP phone calls metadata
Chat MessagesInstant chat messages
CookiesHTTP cookies data
Encryption KeysEncryption keys used to protect data
Installed ProgramsPrograms installed on Operating System
Instant MessagesSMS/MMS and other instant messages
IP AddressesExternal IP addresses recorded by applications
Opened FilesFiles opened by users
Password HashesPassword hashes, such as NTLM and LM
PasswordsUser passwords
Received FilesFiles received by users, including donwloaded files and message attachments
Searched TextsTexts searched by users
Sent FilesFiles sent by users, including donwloaded files and message attachments
Trash Can EntriesOperating System's trash can entries
User AccountsUser accounts
Visited URLsURLs visited by users using browser applications
Wireless ConnectionsWireless connections, with date/time information
Wireless NetworksWireless networks that were connected, including password information