Mobile Forensics: Advanced Investigative Strategies by Oleg Afonin & Vladimir Katalov

Mobile Forensics: Advanced Investigative Strategies by Oleg Afonin & Vladimir Katalov

Author:Oleg Afonin & Vladimir Katalov [Afonin, Oleg & Katalov, Vladimir]
Language: eng
Format: epub, azw3
Published: 0101-01-01T00:00:00+00:00


Specify the file name: The path is relative to the home directory:

Wait while the filesystem is being extracted: This can be a lengthy process, especially when acquiring devices with a large amount of data (in our lab, it took us about 10 minutes to pull 7.5 GB of data):

When the process is finished, disconnect the device and proceed to analyze the data:

What is available via 64-bit physical acquisition

The 64-bit acquisition process returns the full filesystem of the device, including the keychain (which, unfortunately, cannot be decrypted). We were able to access all the following data that is not available in either iTunes or iCloud backups:

Location data (/private/var/root/Library/Caches/locationd)

Downloaded mail (/private/var/mobile/Library/Mail)

Health data (/private/var/mobile/Library/Health)

Music (/private/var/mobile/Media/iTunes_Control/Music)

Detailed battery usage (/private/var/mobile/Library/BatteryLife)

Application data and caches (/private/var/mobile/Containers/Data/Application/, /private/var/mobile/Library/Caches)

Mobile Safari cache—history, recent searches, and more (/private/var/mobile/Containers/Data/Application/4FF7BF97-4B3B-4964-ACD8-974AADB8D4F8/Library/Safari)

Lockdown certificate info (/private/var/root/Library/Lockdown)

CPU usage data (/private/var/mobile/Library/CoreDuet)

Push notifications (/private/var/mobile/Library/ApplePushService)

Battery usage (/private/var/mobile/Library/BatteryLife)

Configuration files (/private/var/mobile/Library/Preferences)

Network and data usage (/private/var/networkd, /private/var/wireless/Library/Databases)

Various log files (/private/var/log, /private/var/logs, /private/var/wireless/Library/Logs, /private/var/mobile/Library/Logs)

SHM and WAL files for all SQLite databases (delayed transactions)

Applications activity (/private/var/mobile/Library/AggregateDictionary)

Spotlight data (/private/var/mobile/Library/Spotlight)

Keyboard cache (/private/var/mobile/Library/Keyboard)



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.