Interactive teaching environment

Mobile Forensics Simulation Lab Suite

A coordinated set of safe, standalone browser laboratories for Android device communication, mobile compromise triage, and iOS/Android artifact analysis.

Light modern interfaceStandalone HTMLStudent-safe simulation
Course-ready browser laboratories

Practice mobile-device triage and artifact analysis without connecting a physical phone.

This suite models four complementary mobile-device workflows. Students configure synthetic Android devices, issue realistic ADB commands, work with synthetic iOS and Android acquisitions, choose parsing modules, inspect evidence, correlate events, document limitations, and export reports. Every operation stays inside the browser.

Begin with MVT

Interactive simulators

Use independently or as a four-lab sequence

0% complete
MVT

Mobile Verification Toolkit

Analyze simulated iOS backups, iOS filesystem dumps, AndroidQF acquisitions, Android backups, and Android intrusion logs. Load synthetic STIX indicators and distinguish IOC matches from broader forensic anomalies.

IOC triageiOS + AndroidCLI
Saved progress0%
iL

iLEAPP

Parse synthetic iOS and iPadOS extractions through a GUI-style workflow or a simulated command line. Select profiles, inspect plist and SQLite-derived artifacts, build a timeline, and export HTML, TSV, JSON, CSV, and KML products.

iOS artifactsGUI + CLITimeline
Saved progress0%
AL

ALEAPP

Parse synthetic Android extractions and investigate system, application, browser, communications, location, notification, usage, and authorized-debugging artifacts. Correlate records rather than relying on a single source.

Android artifactsGUI + CLICorrelation
Saved progress0%
ADB

Android Debug Bridge

Configure selectable Android phones, releases, build types, host systems, USB or wireless transports, and injected failures. Practice authorization, shell commands, application deployment, file transfer, logcat, bugreports, multiple-device targeting, and limited live triage.

Android 8.1–17CLI + device UIDiagnostics
Saved progress0%

How the tools relate

Different purposes, overlapping evidence, complementary outputs

MVT

Compromise-focused triage

MVT is designed to extract forensic traces relevant to potential mobile compromise and compare supported records with STIX indicators.

  • iOS backup and filesystem workflows
  • AndroidQF and other Android workflows
  • IOC matching and anomaly review
  • JSON-oriented analysis results
iL

Broad iOS artifact parsing

iLEAPP parses acquired iOS and iPadOS data into structured reports for examination and timeline analysis.

  • Finder/iTunes backups and filesystem extractions
  • System and application artifacts
  • HTML, TSV, timeline, KML, and LAVA-oriented output
  • Profile-based module selection
AL

Broad Android artifact parsing

ALEAPP parses Android logs, events, databases, properties, protobuf data, and application artifacts from an existing extraction.

  • Filesystem and archive inputs
  • System and application artifact modules
  • HTML, TSV, timeline, KML, and LAVA-oriented output
  • Profile-based module selection
ADB

Host-to-device operations

ADB provides a host command interface to an enabled Android device or emulator for communication, shell access, deployment, transfer, and diagnostics.

  • USB authorization and wireless pairing
  • Device targeting and interactive shell
  • Install, push, pull, logcat, and bugreport
  • Version-aware access and forensic limitations

Learning outcomes

What students should be able to demonstrate

Preserve and verify

Document the acquisition type, source path, case identifier, consent basis, and cryptographic hash before analysis.

Select the right workflow

Choose commands and input types that fit an iOS backup, full filesystem, AndroidQF collection, or Android extraction.

Interpret artifacts

Explain what a parsed record supports, what it does not establish, and which source file produced it.

Correlate evidence

Build conclusions from multiple independent records and account for time-zone and retention limitations.

Separate IOC matches from proof

Describe why a match requires validation and why no public-IOC match cannot establish that a device is clean.

Produce an examination record

Export a report, timeline, analyst notes, and a concise statement of scope and limitations.

Operate Android Debug Bridge safely

Identify transports and serials, authorize the intended host, select the correct target, and distinguish diagnostic access from a complete forensic acquisition.

Safe simulation boundary

Designed for classroom use

No device or host access

The terminal is a JavaScript command interpreter. It never invokes Python, ADB, libimobiledevice, MVT, iLEAPP, ALEAPP, a filesystem, or a network service.

Synthetic evidence only

All names, phone numbers, domains, IP addresses, messages, coordinates, hashes, package identifiers, and timestamps are fabricated for instruction.

Consent and authority

Real mobile-device examinations require appropriate consent or legal authority, documented scope, and procedures suitable for the organization and jurisdiction.

Official references

Open these links when Internet access is available; the simulators themselves remain offline