Forensic tools are helpful for an examiner as they not only save time, but also make the process a lot easier. However, not everyone has a budget large enough to purchase commercial tools to obtain iOS acquisition. While free tools exist for acquisition, support may be limited and multiple extractions may be required to obtain the same amount of data as a commercial tool.
For jailbroken devices, the iOS device could be connected to a Mac for live examination through SSH, which is how some of the tools acquire the data. However, this is not a method that is recommended for those new to digital forensics. For such purposes, this chapter introduced you to several available iOS forensic tools and included the steps to perform acquisition from an iOS device.
Examiners should take further steps to validate and understand each tool that might be used as part of an investigation. We recommend acquiring test devices with known data to ensure that nothing is overlooked, evidence is not altered...