TikTok Forensics: Unveiling the Local Artifacts of a Social Media Giant
Post-mortem digital forensic artifacts of TikTok Android App
This paper presents a comprehensive post-mortem digital forensic analysis of the TikTok Android application. The authors identify critical data artifacts stored in SQLite databases and XML files, and introduce "Tiktok.py," an open-source module for the Autopsy Android Analyzer to automate evidence extraction.
TL;DR
As TikTok became the most downloaded app of the decade, it also became a critical node in digital investigations. This paper provides the first deep-dive into the local artifacts of the TikTok Android app, revealing how investigators can recover messages, user lists, and even "deleted" videos by navigating the app’s complex SQLite and XML structures.
Context: Why TikTok Forensics Matters
In the digital forensic landscape, the smartphone is the "black box" of human activity. TikTok, being the platform of choice for Generation Z, is frequently involved in cases ranging from missing persons to the dissemination of extremist content. However, because TikTok is cloud-centric, many practitioners assumed local data would be sparse. This research proves otherwise, showing that a wealth of "post-mortem" (data residing on the device after use) information survives.
The Forensic Obstacle: Root Access vs. Public Data
The authors distinguish between two tiers of data:
- Easily Accessible: Located in
/sdcard/Android/data/. This contains mostly video posters and public thumbnails managed by the Fresco library. - Private App Storage: Located in
/data/data/com.zhiliaoapp.musically/. This is the "gold mine" containing messages and account links, but it requires root privileges to access.
Methodology: Decoding the TikTok Schema
The researchers analyzed TikTok version 16.0.41, which utilizes a staggering 28 SQLite databases and over 100 XML files.
1. The Messaging Engine (userID_im.db)
The core of the social evidence lies in the msg table. The authors identified a crucial forensic detail: the type field, which differentiates between text (7), video (8), and audio (22).
Key Discovery: The deleted field in the database indicates that TikTok doesn't immediately "wipe" deleted messages from the local disk; it simply toggles a flag, allowing investigators to recover deleted conversations.

2. The Video Cache Mystery (cachev2)
Perhaps the most technical contribution of the paper is the analysis of cached videos. TikTok stores videos in two places:
- cache: Standard MP4 files.
- cachev2: Files with
.mdlextensions that appear unplayable.
The authors discovered that .mdl files are actually MP4s with their first 128 bytes zeroed out. By extracting the header from the companion .mdlnodeconf file and patching the .mdl file, they were able to restore and play the cached videos.

Automation: The Tiktok.py Module
To bridge the gap between academic research and field application, the team developed a module for Autopsy, the industry-standard open-source forensic tool. This module automates the parsing of the userID_im.db (messages) and db_im_xx (contacts), generating communication graphs that show who the user interacted with most frequently.

Critical Insight & Conclusion
This paper serves as a foundational manual for TikTok forensics. The most significant takeaway is that local storage is more persistent than user-facing interfaces suggest. Even when a user logs out, their userID_im.db remains on the device, potentially holding months of historical data.
Limitations: The primary hurdle remains the requirement for a rooted device. As Android security (like File-Based Encryption) hardens, obtaining the initial physical dump becomes the bottleneck, rather than the parsing of the databases themselves.
For future work, the integration of OSINT (Open Source Intelligence) with these local artifacts—cross-referencing local UIDs with live web profiles—represents the next frontier in comprehensive social media investigation.
