Practical Mobile Forensics - Second Edition by Heather Mahalik & Rohit Tamma & Satish Bommisetty

Practical Mobile Forensics - Second Edition by Heather Mahalik & Rohit Tamma & Satish Bommisetty

Author:Heather Mahalik & Rohit Tamma & Satish Bommisetty [Mahalik, Heather]
Language: eng
Format: azw3
Publisher: Packt Publishing
Published: 2016-05-20T04:00:00+00:00


Here, you will find exact copies of files found on the iPhone. If the case relies upon determining what happened on the Apple Watch versus the iPhone, it may be impossible to solve. As of Watch 2.0, the files that are used by both the iPhone and the watch are exact copies of one another, and they do not contain status flags stating where the activity was initiated. This is one of the hardest topics to cover in all aspects of data synchronization. For example, if you examine my iPhone backup that contains my Apple Watch data, you will see map information in mobile /Library/DeviceRegistry/NanoMaps/GeoHistory.Mapsdata that occurs before the Apple Watch was released. This should be impossible, but it's simply because Apple is copying the iPhone maps database and placing a copy in the Apple Watch data location. The following is an example of what data in the GeoHistory.Mapsdata file looks like when being examined in UFED Physical Analyzer. While this tool is expensive, it is one of the best analytical platforms for manually carving and hunting artifacts that relate to your investigation. In this example, a keyword search was run for the term "current location" within the GeoHistory.Mapsdata file. From these results, we can ascertain that the user was at the address highlighted in the following screenshot when asking for or researching directions on the iPhone or the Watch. Remember, this is an exact copy of the same file, so we currently cannot say whether this location was stamped by the watch or the iPhone:

The GeoHistory.Mapsdata in Physical Analyzer



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.