Book Image

Mobile Forensics Cookbook

By : Igor Mikhaylov
Book Image

Mobile Forensics Cookbook

By: Igor Mikhaylov

Overview of this book

Considering the emerging use of mobile phones, there is a growing need for mobile forensics. Mobile forensics focuses specifically on performing forensic examinations of mobile devices, which involves extracting, recovering and analyzing data for the purposes of information security, criminal and civil investigations, and internal investigations. Mobile Forensics Cookbook starts by explaining SIM cards acquisition and analysis using modern forensics tools. You will discover the different software solutions that enable digital forensic examiners to quickly and easily acquire forensic images. You will also learn about forensics analysis and acquisition on Android, iOS, Windows Mobile, and BlackBerry devices. Next, you will understand the importance of cloud computing in the world of mobile forensics and understand different techniques available to extract data from the cloud. Going through the fundamentals of SQLite and Plists Forensics, you will learn how to extract forensic artifacts from these sources with appropriate tools. By the end of this book, you will be well versed with the advanced mobile forensics techniques that will help you perform the complete forensic acquisition and analysis of user data stored in different devices.
Table of Contents (18 chapters)
Title Page
Credits
About the Author
About the Reviewer
www.PacktPub.com
Customer Feedback
Preface

Android physical dumps and backups parsing with Autopsy


The undeniable advantage of Autopsy over other mobile forensics tools is that it is free, meaning that it is available for anyone who wants to analyze his mobile device. Physical dumps of mobile devices running Android operating systems can be analyzed via Autopsy.

Getting ready

Go to the website of the program. In the website's menu select Autopsy | Download and click Download Now. On the download page, select the version of the program that corresponds to your operating system by clicking on Download 64-bit or Download 32-bit. When the installation file is downloaded, go to the directory on your computer where the downloaded files are saved, and double-click the icon of the downloaded file. Follow the instructions during installation of the program.

How to do it…

  1. Double click on the icon of the program. In the Welcome window, click on the Create New Case icon; it will open the New Case Information window. Enter Case Name and enter Base...