Analysis of Tools and Technologies for Obtaining Data from Mobile Devices in the Context of Cybercrime Investigations
Keywords
Abstract
The article presents the analysis of modern technologies for obtaining data from mobile devices in the context of digital forensics and cybercrime investigation. The growing role of mobile devices as key carriers of digital evidence in criminal proceedings related to illegal activities in cyberspace is substantiated. The classification of the main data extraction methods and their technical features is presented, which allows choosing the optimal approaches to their use. The specific features of the application of current technological solutions for mobile forensics in Ukraine are analyzed, taking into account institutional, technical, legal and educational aspects, European integration, martial law, the constant complication of technical challenges related to data protection, and the adaptation of the legal field to the realities of digital evidence. The functional capabilities of leading commercial, open and auxiliary solutions in ensuring the completeness and reliability of digital analysis are investigated. Particular attention is paid to the procedural suitability of digital evidence, as well as the adaptation of tools to the conditions of national legal practice and the specifics of scientific and research work in the field of cybersecurity. The author presents his own experience in integrating university education with national projects that are part of the general cybersecurity ecosystem in Ukraine and combine education and interaction with law enforcement officers. The role of cloud forensics in terms of the possibility of increasing the completeness of the evidence base and compliance with national procedural requirements for access to personal data is noted. The feasibility of an integrated approach to the use of mobile forensics tools to increase the efficiency, reliability and objectivity of investigations in the digital environment is substantiated. Promising directions for the development of methods for obtaining evidence in the context of increased cryptographic protection are identified.
