The Gap in Mobile Forensic Workflows

▶ Watch (2:58)

Mobile forensics has no write blocker. Examiners gain device access and extract everything via MTP. Goh argued that tools like Cellebrite, Magnet AXIOM, and Belkasoft assume a cooperative device. They ignore “second layer countermeasures” — anti-forensic measures that run silently during extraction. This idea is not new: Moxie Marlinspike threatened to attack Cellebrite in 2019. Goh published anti-forensic research in 2011. The team’s approach hides the countermeasures from the examiner entirely.

Honey Tokens as Trip Wires

▶ Watch (8:45)

Isaac Soon explained honey tokens — bait files filled with rubbish data, hidden in directories like Pictures and Documents. Normal users never see them. Forensic tools performing bulk acquisition read every file. When a token is accessed, Android’s inotify subsystem (available since Android 6) sends a notification to a custom system app. The app then triggers an anti-forensic payload. The team tested two payloads: file encryption and factory reset. Honey tokens can be deployed programmatically when new apps are installed, covering app-specific directories like Telegram.

Demo: Encryption Against Three Tools

▶ Watch (11:44)

Joseph Lim showed three demos. Against Cellebrite UFED, a honey token in the Pictures directory triggered encryption of crown-jewel files before extraction completed. Contacts and SMSs, accessed directly via agent, were untouched. Against Belkasoft over MTP, the first file downloaded was a honey token, triggering encryption of all protected data. Against Magnet AXIOM, a hidden file in Documents triggered the same encryption. The team verified encryption via ADB shell and hexdump. All three tools failed to retrieve the original data.

What Forensic Examiners Must Change

▶ Watch (19:45)

Goh concluded that current workflows need rethinking. The demos work only over MTP, but the trip-wire concept is generic. Defenders should use selective acquisition instead of bulk, but that requires knowledge of the anti-forensic technique. Encryption needs time — Magnet AXIOM’s slow extraction gave enough. Cold system forensics (chip-off, bootloader) might bypass these measures. The fundamental problem: examiners often trust their tools without testing them against adversarial environments. Goh urged tool verification and awareness of second-layer countermeasures.

Notable Quotes

we’ve developed some anti forensic techniques and, uh, it works against, uh, forensic tools like Celbrite, Axium, and uh, Belosoft Weihan Goh · ▶ 0:10

the problem with that is that uh there’s something that these workflows don’t really think about which is what we call second layer countermeasures Weihan Goh · ▶ 3:01

gaining device success is just the beginning all right what happens next all right during for forensic extraction may not be what we all think Weihan Goh · ▶ 22:34

Key Takeaways

  • Honey tokens with inotify silently trigger anti-forensic payloads during forensic extraction.
  • Bulk MTP acquisition reads all files, making honey tokens effective against Cellebrite, Belkasoft, and Magnet AXIOM.
  • Forensic examiners must test tools in adversarial environments and consider selective acquisition.

About the Speaker(s)

Weihan Goh is an Associate Professor at the Singapore Institute of Technology (SIT). His research interests include digital forensics, anti-forensics, security testing, as well as technologies for cybersecurity education such as cyber ranges, CTF / CDX, remote proctoring, and anti-fraud / anti-cheat systems. Beyond teaching and research, Dr Goh participates in capture-the-flag exercises, going by the CTF handler ‘icebear’.

Joseph Lim is an Information Security undergraduate at the Singapore Institute of Technology, with a diploma in Infocomm Security Management from Singapore Polytechnic. With a strong foundation in cybersecurity, he is particularly interested in mobile security and digital forensics. Joseph has also previously presented research on mobile malware at the 14th ACM Conference on Data and Application Security and Privacy (2024).

Soon Leung Isaac is currently pursuing a degree in Information and Communication Technology, specializing in Information Security, at the Singapore Institute of Technology. Previously, he served as a SOC analyst in the Singapore Armed Forces for two years, where he was responsible for safeguarding Singapore’s military network. His main areas of research include offensive security and mobile security.