Mobile Device Triage Toolkit: Deterministic, Read-only Forensic Pre-Assessment

dc.contributor.advisorTorres Batista, Nelliud D.
dc.contributor.authorJusino Alamo, Luis F.
dc.date.accessioned2026-03-16T18:11:35Z
dc.date.issued2025
dc.descriptionDesign Project Article for the Graduate Programs at Polytechnic University of Puerto Rico
dc.description.abstractMobile investigations face evidence backlogs and limited time to decide whether a device merits full imaging. We present the Mobile Device Triage Toolkit, a read-only, deterministic workflow that inspects disk images (RAW and E01 via pytsk3/pyewf or E01 export) or backups/logical folders and summarizes high-value artifacts. MDTK provides a filesystem summary, app inventory, SQLite table counts, endpoint-pattern hits, and a mini-timeline, exporting both JSON and a uniform PDF. For forensic defensibility, MDTK records an append-only JSONL audit log, refuses writable mounts, pins the runtime environment, and fixes timestamps to UTC seconds; Ed25519 signing is supported. We evaluate MDTK on a manifest of sample images and report runtime, artifact coverage, and reproducibility by comparing JSON/PDF hashes across repeated runs. Results show byte-identical outputs, median execution under 8.33s and fast visibility into artifacts such as messaging and browser histories. MDTK targets triage escalation, not full analysis, and runs on Windows via WSL. Keywords − Digital Forensics, Evidence Integrity, SQLite Artifacts, Triage.
dc.identifier.citationJusino Alamo, L. F. (2025). Mobile Device Triage Toolkit: Deterministic, Read-only Forensic Pre-Assessment [Unpublished manuscript]. Graduate School, Polytechnic University of Puerto Rico.
dc.identifier.urihttps://hdl.handle.net/20.500.12475/3267
dc.language.isoen
dc.publisherPolytechnic University of Puerto Rico
dc.relation.haspartSan Juan
dc.relation.ispartofComputer Science Program
dc.relation.ispartofseriesWinter-2025
dc.rights.holderPolytechnic University of Puerto Rico, Graduate School
dc.rights.licenseAll rights reserved
dc.subject.lcshPolytechnic University of Puerto Rico--Graduate students--Research
dc.subject.lcshPolytechnic University of Puerto Rico--Graduate students--Posters
dc.subject.lcshPolytechnic University of Puerto Rico--Subject headings--Unassigned
dc.titleMobile Device Triage Toolkit: Deterministic, Read-only Forensic Pre-Assessment
dc.typeArticle
dc.typePoster

Files

Original bundle

Now showing 1 - 2 of 2
Loading...
Thumbnail Image
Name:
PUPR_CEAH_SJU_WI25_MCS_Luis Jusino_Article.pdf
Size:
395.46 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
PUPR_CEAH_SJU_WI25_MCS_Luis Jusino_Poster.pdf
Size:
566.53 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
License Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description:

Collections