Comparative Evaluation of Mobile Forensic Acquisition Methods on iOS 17: A Study of Cellebrite Basic and Premium in Digital Artifact Recovery
DOI:
https://doi.org/10.59261/jbt.v7i3.706Keywords:
Digital Forensics, Mobile Forensics, Logical Acquisition, Full File System, Forensic Tool EvaluationAbstract
Background: The advancement of security systems in modern smartphones, particularly iOS devices, has introduced significant challenges to digital forensic investigations. At the same time, law enforcement agencies increasingly rely on digital evidence, making the completeness and reliability of acquisition methods critical factors in forensic examinations.
Objective: This study aims to evaluate the differences in the completeness of digital artifacts obtained through logical acquisition and full file system (FFS) extraction methods on an iPhone 13 running the latest iOS version.
Methods: An experimental methodology was employed by developing a ground-truth dataset based on user activity scenarios, including communications, media exchanges, and application usage. The acquisition results were subsequently analyzed to measure the recovery rate of digital artifacts, including deleted data and application-related artifacts.
Results: The findings indicate that the FFS extraction method is capable of recovering a more comprehensive set of artifacts than logical acquisition, particularly data that cannot be accessed through conventional methods. However, this method involves greater complexity and depends on advanced forensic tools. Specifically, the FFS method recovered 64,057 files compared to 959 files obtained through Advanced Logical Extraction, representing a 6,580% increase in artifact volume. Notable differences were observed in web history (1,466 vs. 43 entries), images (13,140 vs. 367 files), and database artifacts (997 vs. 188 records).
Conclusion: This research highlights the importance of selecting appropriate acquisition methods to support investigative processes and legal evidence examination, while also identifying a research gap in the forensic evaluation of devices running the latest versions of iOS.
References
Agboola, V., Osamor, J., & Olajide, F. (2024). Evaluating the Efficiency of FTK, Autopsy, and Mobile Forensic Tools: A Comparative Study in Criminal Investigations. International Journal of Intelligent Computing Research, 15(1).
Al-Dhaqm, A., Razak, S., Othman, S. H., & al., et. (2020). CDBFIP: Common database forensic investigation processes for Internet of Things. IEEE Access.
Anglano, C., Canonico, M., & Guazzone, M. (2020). The Android forensic automator (AnForA): A tool for the automated forensic analysis of Android applications. Computers & Security.
Ayers, R., Brothers, S., & Jansen, W. (2014). Guidelines on Mobile Device Forensics: Revision 1. National Institute of Standards and Technology.
Aziza, M., & Salman, M. (2026). Validation of the Harmonized Mobile Forensic Investigation Process Model (HMFIPM) on Android Devices. Equivalent: Jurnal Ilmiah Sosial Teknik (Jequi), 8(2), 477.
Bhushan, H. H. B., & Florance, S. M. (2022). An overview on handling anti forensic issues in android devices using forensic automator tool. 2022 IEEE International Conference on Signal Processing, Informatics, Communication and Energy Systems (SPICES), 1, 425–430.
Bilbao, A., Varesio, E., Luban, J., Strambio‐De‐Castillia, C., Hopfgartner, G., Müller, M., & Lisacek, F. (2015). Processing strategies and software solutions for data‐independent acquisition in mass spectrometry. Proteomics, 15(5–6), 964–980.
Casey, E. (2011). Digital evidence and computer crime: Forensic science, computers, and the internet. Academic press.
Chamim, M., Widodo, K., Riyadi, S., Achyarsyah, P., & Faisal, F. (2025). The role of digital evidence in criminal law enforcement: Challenges of authentication and admissibility in court. Research Horizon, 5(6), 2987–2998.
Cooper, G. S., & Meterko, V. (2019). Cognitive bias research in forensic science: A systematic review. Forensic Science International, 297, 35–46.
Da Costa, A. M., De Sà, A. O., & Machado, R. C. S. (2022). Data acquisition and extraction on mobile devices-a review. 2022 IEEE International Workshop on Metrology for Industry 4.0 & IoT (MetroInd4. 0&IoT), 294–299.
Dorai, G., Rad, P., Breitinger, F., Bardhan, R., & Ramasamy, V. (2025). Mapping the research landscape-an exploratory analysis of ai applications in digital forensics. International Conference on Availability, Reliability and Security, 113–130.
Dutra, A. H. (2021). Forensic acquisition of file systems with parallel processing of digital artifacts to generate an early case assessment report.
Elangovan, R., & Manoharan, S. (2023). Comparative analysis of mobile forensic tools: Magnet AXIOM, Cellebrite, and Oxygen Forensics. International Journal of Information Security. https://scholar.google.com/scholar?q=Comparative+analysis+of+mobile+forensic+tools:+Magnet+AXIOM,+Cellebrite,+and+Oxygen+Forensics.
Fukami, A., Stoykova, R., & Geradts, Z. (2021). A new model for forensic data extraction from encrypted mobile devices. Forensic Science International: Digital Investigation, 38, 301169.
Garfinkel, S. L. (2010). Digital forensics research: The next 10 years. Digital Investigation, 7, S64–S73.
Gary, P. (2001). A road map for digital forensic research. Digital Forensics Research Workshop.
Goergen, C. J., Tweardy, M. J., Steinhubl, S. R., Wegerich, S. W., Singh, K., Mieloszyk, R. J., & Dunn, J. (2022). Detection and monitoring of viral infections via wearable devices and biometric data. Annual Review of Biomedical Engineering, 24(1), 1–27.
Guide, I. H. (2007). Techniques into Incident Response. Citeseer.
Gupta, K., Oladimeji, D., Varol, C., Rasheed, A., & Shahshidhar, N. (2023). A comprehensive survey on artifact recovery from social media platforms: approaches and future research directions. Information, 14(12), 629.
Hoog, A. (2011). Android forensics: investigation, analysis and mobile security for Google Android. Elsevier.
Horvath, M., Pietrikova, E., & Spinellis, D. (2026). Bridging Behavioral Biometrics and Source Code Stylometry: A Survey of Programmer Attribution. ArXiv Preprint ArXiv:2603.11150.
Iqbal, A., Alobaidli, H., & Jones, A. (2022). Analysis of forensic artifacts from mobile applications: A comparative study. Digital Investigation.
Iyengar, S. S., Nabavirazavi, S., Hariprasad, Y., HB, P., & Mohan, C. K. (2025). Digital Forensics: Tools, Techniques, and Methodologies. In Artificial Intelligence in Practice: Theory and Application for Cyber Security and Forensics (pp. 89–137). Springer.
Javed, A. R., Ahmed, W., Alazab, M., Jalil, Z., Kifayat, K., & Gadekallu, T. R. (2022). A comprehensive survey on computer forensics: State-of-the-art, tools, techniques, challenges, and future directions. IEEE Access, 10, 11065–11089.
Keyogeg, B., Thompson, M., Dawson, G., Wagner, D., Johnson, G., & Elliott, B. (2024). Automated detection of ransomware in windows active directory domain services using log analysis and machine learning. Authorea Preprints.
Khan, A. A., Shaikh, A. A., Laghari, A. A., Dootio, M. A., Rind, M. M., & Awan, S. A. (2022). Digital forensics and cyber forensics investigation: security challenges, limitations, open issues, and future direction. International Journal of Electronic Security and Digital Forensics, 14(2), 124–150.
Kikerpill, K. (2023). The crime-as-communication approach: Challenging the idea of online routine activities by taking communication seriously. Journal of Economic Criminology, 2, 100035.
Klier, S., & Baier, H. (2025). Metrics Matter—Source Camera Forensics for Large-Scale Investigations. Digital Threats: Research and Practice, 6(4), 1–21.
Lessard, J., & Kessler, G. (2010). Android forensics: Simplifying cell phone examinations.
Maratsi, M. I., Popov, O., Alexopoulos, C., & Charalabidis, Y. (2022). Ethical and legal aspects of digital forensics algorithms: the case of digital evidence acquisition. Proceedings of the 15th International Conference on Theory and Practice of Electronic Governance, 32–40.
Nussbaumer-Streit, B., Sommer, I., Hamel, C., Devane, D., Noel-Storr, A., Puljak, L., Trivella, M., & Gartlehner, G. (2023). Rapid reviews methods series: Guidance on team considerations, study selection, data extraction and risk of bias assessment. BMJ Evidence-Based Medicine, 28(6), 418–423.
Quick, D., & Choo, K.-K. R. (2018). Digital forensic intelligence: Data subsets and Open Source Intelligence (DFINT+ OSINT): A timely and cohesive mix. Future Generation Computer Systems, 78, 558–567.
Riadi, I., & Rafiq, I. A. (2022). Forensic Mobile Analysis on Social Media Using National Institute Standard of Technology Method. International Journal of Safety & Security Engineering, 12(6), 707.
Salamh, F. E., Karabiyik, U., & Rogers, M. K. (2020). Asynchronous forensic investigative approach to recover deleted data from instant messaging applications. 2020 International Symposium on Networks, Computers and Communications (ISNCC), 1–6.
Scanlon, M. (2016). Battling the digital forensic backlog through data deduplication. ArXiv Preprint ArXiv:1610.00248.
Shafik, W. (2025). Data Loss Software Reason and Hardware Reason. In Data Recovery Techniques for Computer Forensics (pp. 27–61). Bentham Science Publishers.
Shahid, J., Ahmad, R., Kiani, A. K., Ahmad, T., Saeed, S., & Almuhaideb, A. M. (2022). Data protection and privacy of the internet of healthcare things (IoHTs). Applied Sciences, 12(4), 1927.
Sun, D., Hu, J., Wu, H., Wu, J., Yang, J., Sheng, Q. Z., & Dustdar, S. (2023). A comprehensive survey on collaborative data-access enablers in the IIoT. ACM Computing Surveys, 56(2), 1–37.
Tawil, S., & Tarawneh, A. (2025). Technology and the law: countering cybercrime and fraud in the digital age. In Artificial Intelligence in the Digital Era: Economic, Legislative and Media Perspectives (pp. 1095–1105). Springer.
Widatama, K. (2025). Mobile Device Digital Forensics for Supporting Cybercrime Investigation and Evidence Presentation. Forensics & Security Journal, 1(1).
Xie, M., Hu, X., Ozer, A., & Karabiyik, U. (2026). Mobile forensics and security analysis of RedNote: A cross-platform investigation on Android and iOS. Forensic Science International: Digital Investigation, 58, 302166.
Yang, Y., Chai, H., Shao, S., Song, Y., Qi, S., Rui, R., & Zhang, W. (2026). Agentnet: Decentralized evolutionary coordination for llm-based multi-agent systems. Advances in Neural Information Processing Systems, 38, 107309–107336.
Yin, Z., Wang, Z., Xu, W., Zhuang, J., Mozumder, P., Smith, A., & Zhang, W. (2025). Digital forensics in the age of large language models. In Artificial Intelligence Driven Forensics (pp. 55–82). Springer.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Ghifari Amanar, Ruki Harwahyu

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA). that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.



