Mobile Verification Toolkit
Analyze simulated iOS backups, iOS filesystem dumps, AndroidQF acquisitions, Android backups, and Android intrusion logs. Load synthetic STIX indicators and distinguish IOC matches from broader forensic anomalies.
Interactive teaching environment
A coordinated set of safe, standalone browser laboratories for Android device communication, mobile compromise triage, and iOS/Android artifact analysis.
This suite models four complementary mobile-device workflows. Students configure synthetic Android devices, issue realistic ADB commands, work with synthetic iOS and Android acquisitions, choose parsing modules, inspect evidence, correlate events, document limitations, and export reports. Every operation stays inside the browser.
Use independently or as a four-lab sequence
Analyze simulated iOS backups, iOS filesystem dumps, AndroidQF acquisitions, Android backups, and Android intrusion logs. Load synthetic STIX indicators and distinguish IOC matches from broader forensic anomalies.
Parse synthetic iOS and iPadOS extractions through a GUI-style workflow or a simulated command line. Select profiles, inspect plist and SQLite-derived artifacts, build a timeline, and export HTML, TSV, JSON, CSV, and KML products.
Parse synthetic Android extractions and investigate system, application, browser, communications, location, notification, usage, and authorized-debugging artifacts. Correlate records rather than relying on a single source.
Configure selectable Android phones, releases, build types, host systems, USB or wireless transports, and injected failures. Practice authorization, shell commands, application deployment, file transfer, logcat, bugreports, multiple-device targeting, and limited live triage.
Different purposes, overlapping evidence, complementary outputs
MVT is designed to extract forensic traces relevant to potential mobile compromise and compare supported records with STIX indicators.
iLEAPP parses acquired iOS and iPadOS data into structured reports for examination and timeline analysis.
ALEAPP parses Android logs, events, databases, properties, protobuf data, and application artifacts from an existing extraction.
ADB provides a host command interface to an enabled Android device or emulator for communication, shell access, deployment, transfer, and diagnostics.
What students should be able to demonstrate
Document the acquisition type, source path, case identifier, consent basis, and cryptographic hash before analysis.
Choose commands and input types that fit an iOS backup, full filesystem, AndroidQF collection, or Android extraction.
Explain what a parsed record supports, what it does not establish, and which source file produced it.
Build conclusions from multiple independent records and account for time-zone and retention limitations.
Describe why a match requires validation and why no public-IOC match cannot establish that a device is clean.
Export a report, timeline, analyst notes, and a concise statement of scope and limitations.
Identify transports and serials, authorize the intended host, select the correct target, and distinguish diagnostic access from a complete forensic acquisition.
Designed for classroom use
The terminal is a JavaScript command interpreter. It never invokes Python, ADB, libimobiledevice, MVT, iLEAPP, ALEAPP, a filesystem, or a network service.
All names, phone numbers, domains, IP addresses, messages, coordinates, hashes, package identifiers, and timestamps are fabricated for instruction.
Real mobile-device examinations require appropriate consent or legal authority, documented scope, and procedures suitable for the organization and jurisdiction.
Open these links when Internet access is available; the simulators themselves remain offline