Blog >> Android Bluetooth

Investigating Android Bluetooth

04/08/2023 Friday

Bluetooth is a wireless communication technology that allows different devices to connect to one another, such as smartphones, tablets, laptops, headsets, and smartwatches. In the most widely used mode, its transmission power allows the communication to be established within a very short range, up to 10 meters only.

Digital Forensics Value of Bluetooth


When conducting digital forensic evidence of an Android device, analyzing Bluetooth-related data can yield valuable information that can be relevant to the investigation. Bluetooth left-behind artifacts store valuable metadata related to device connections, pairing history, communication logs, and exchanged files information. Digital forensic examiners can use this information to reconstruct the Bluetooth-related activities on the Android device.

Location of Android Bluetooth Artifacts


Android Bluetooth App artifacts can be found at the following locations:
data/misc/bluedroid/bt_config.conf
com.android.bluetooth/database/btopp.db

Analyzing Android Bluetooth Artifacts with ArtiFast


This section will discuss how to use ArtiFast to extract Android Bluetooth artifacts from Android machines’ files and what kind of digital forensics insights we can gain from the artifacts.

After you have created your case and added evidence for the investigation, at the Artifact Selection phase, you can select Android Bluetooth artifacts:






Once ArtiFast parser plugins complete processing the artifact for analysis, it can be reviewed via “Artifact View” or “Timeline View,” with indexing, filtering, and searching capabilities. Below is a detailed description of Android Bluetooth artifacts in ArtiFast.


Android Bluetooth Transferred Files


Android Bluetooth Devices




For more information or suggestions please contact: kalthoum.karkazan@forensafe.com