Book Image

Practical Mobile Forensics - Second Edition

By : Heather Mahalik, Rohit Tamma, Satish Bommisetty
Book Image

Practical Mobile Forensics - Second Edition

By: Heather Mahalik, Rohit Tamma, Satish Bommisetty

Overview of this book

Mobile phone forensics is the science of retrieving data from a mobile phone under forensically sound conditions. This book is an update to Practical Mobile Forensics and it delves into the concepts of mobile forensics and its importance in today's world. We will deep dive into mobile forensics techniques in iOS 8 - 9.2, Android 4.4 - 6, and Windows Phone devices. We will demonstrate the latest open source and commercial mobile forensics tools, enabling you to analyze and retrieve data effectively. You will learn how to introspect and retrieve data from cloud, and document and prepare reports for your investigations. By the end of this book, you will have mastered the current operating systems and techniques so you can recover data from mobile devices by leveraging open source solutions.
Table of Contents (19 chapters)
Practical Mobile Forensics - Second Edition
Credits
About the Authors
About the Reviewer
www.PacktPub.com
Preface

Potential evidence stored on mobile phones


The range of information that can be obtained from mobile phones is detailed in this section. Data on a mobile phone can be found in a number of locations: SIM card, external storage card, and phone memory. In addition, the service provider also stores communication-related information. The book primarily focuses on data acquired from the phone memory. Mobile device data extraction tools recover data from the phone's memory. Even though data recovered during a forensic acquisition depends on the mobile model, in general, the following data is common across all models and useful as evidence. Note that most of the following artifacts contain date and timestamps:

  • Address Book: This stores contact names, numbers, e-mail addresses, and so on

  • Call History: This contains dialed, received, missed calls, and call durations

  • SMS: This contains sent and received text messages

  • MMS: This contains media files such as sent and received photos and videos

  • E-mail: This contains sent, drafted, and received e-mail messages

  • Web browser history: This contains the history of websites that were visited

  • Photos: This contains pictures that are captured using the mobile phone camera, those downloaded from the Internet, and the ones transferred from other devices

  • Videos: This contains videos that are captured using the mobile camera, those downloaded from the Internet, and the ones transferred from other devices

  • Music: This contains music files downloaded from the Internet and those transferred from other devices

  • Documents: This contains documents created using the device's applications, those downloaded from the Internet, and the ones transferred from other devices

  • Calendar: This contains calendar entries and appointments

  • Network communication: This contains GPS locations

  • Maps: This contains looked-up directions, and searched and downloaded maps

  • Social networking data: This contains data stored by applications, such as Facebook, Twitter, LinkedIn, Google+, and WhatsApp

  • Deleted data: This contains information deleted from the phone