Abstract
The widespread adoption of Android devices and their open-source nature have led to increasingly sophisticated anti-forensic techniques. This literature review presents a comprehensive analysis of Android anti-forensics, focusing on the classification of techniques, the evaluation of anti-forensic applications, and the limitations of current forensic methodologies. Key strategies, such as data hiding, trail obfuscation, encryption, and artefact wiping, are examined alongside the forensic acquisition methods they aim to circumvent. The review also assesses the capabilities and constraints of widely used forensic tools, highlighting issues related to tool transparency, compatibility with modern Android versions, and support for encrypted or obfuscated data. Methodological shortcomings in the literature, such as inconsistent reporting of Android versions and device models, are identified as barriers to reproducibility and generalisability. Recommendations are provided to improve forensic access to private storage, enhance tool performance, and standardise research practices. This review contributes to a clearer understanding of the current state of Android anti-forensics and outlines priorities for future research and tool development in the field of mobile digital forensics.
| Original language | English |
|---|---|
| Article number | 302159 |
| Number of pages | 25 |
| Journal | Forensic Science International: Digital Investigation |
| Volume | 58 |
| DOIs | |
| Publication status | Published - 8 Jul 2026 |
Fingerprint
Dive into the research topics of 'Android anti-forensics: A systematic review of applications, techniques, and investigative challenges'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver