# AvillaDaniel/AvillaForensics

Avilla Forensics FREE

Repository: https://github.com/AvillaDaniel/AvillaForensics
Canonical: https://ross.abutalabs.com/products/avillaforensics
Language: C#
License: NOASSERTION
License Family: other
Topics: mobile, forensics, whatsapp, telegram, signal, adb, android, adb-commands, ios, apktool, forensics-tools, downgrade, downgrade-attack, forensic-analysis, devices, instagram, extrator, mobile-forensics, digital-forensics, whatsapp-parser
Last push: 2026-04-04T18:02:34+00:00

## Health v2 (maintenance only)
Score: 70/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 75, release rhythm 46, longevity 100
- inputs: {"age_days": 1615, "days_push": 151, "days_rel": 151, "gap_med": null, "n_releases_24m": 1}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1116, forks 221 (observed 2026-08-28T04:03:38.839668+00:00)

## What it is
Avilla Forensics is a free Windows-based mobile forensic application for logical data extraction from Android and iOS devices, built in C# and driven via ADB. It includes an APK downgrade module for collecting app data (WhatsApp, Telegram, Signal, Instagram, and 400+ apps) without root, plus AES-256 encrypted integrity logs compatible with tools like IPED and Cellebrite.

## Use cases
- extract whatsapp data from an android phone for an investigation
- downgrade an app on a non-rooted android device to access its data
- collect evidence from multiple mobile devices simultaneously
- convert mobile backups into formats for IPED or Cellebrite analysis
- generate tamper-evident encrypted logs of forensic acquisitions
- extract app data from the DATA partition without root
- forensic analysis of telegram or signal chats

## When to choose
- you need free logical extraction from Android devices without root
- you are a forensic investigator working on Windows 10/11
- you need integrity-verified, hash-signed acquisition logs
- you must collect data from many messaging apps via APK downgrade

## When to avoid
- you need full physical extraction or advanced commercial forensic features
- you work on Linux or macOS - it targets Windows only
- you need a general-purpose device management tool rather than forensics
- your use case is not lawful forensic investigation

## Facets
- artifact type: application
- maturity: active
- function: security, parser, developer-tools
- domain: security, android-tools, mobile-development, privacy
- platform: windows
- tags: digital-forensics, mobile-forensics, adb, apk-downgrade, data-extraction, law-enforcement, whatsapp, telegram, signal, evidence-collection, csharp, android, ios, desktop

## Member repositories
- AvillaDaniel/AvillaForensics (main) score 70

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:38.839668+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:41:55.737507+00:00, confidence not recorded.
  - readme: https://github.com/AvillaDaniel/AvillaForensics (fetched 2026-08-28T04:03:38.839668+00:00, sha 97fc1c7ddb29)
- Data as of 2026-08-30T08:39:29.467469+00:00.
