The purpose of this chapter is to provide an overview of the forensic approach of an iOS device. We will introduce iOS architecture components and the filesystem. This chapter will indicate methodology, techniques, and tools used to acquire evidences from iOS devices, it will also point out the difference between different modes (DFU, recovery, and more), introduce the jailbreaking concept, and discuss the biometric aspect of iOS devices.
In this chapter, we will cover the following topics:
The iOS architecture
The iOS filesystem
iOS platform and hardware security
Identifying stored data
iOS acquisition and forensic approaches
iOS artifact recovery
It's going biometric!
Third-party application forensics