Book Image

Practical Mobile Forensics - Third Edition

By : Rohit Tamma, Oleg Skulkin, Heather Mahalik, Satish Bommisetty
Book Image

Practical Mobile Forensics - Third Edition

By: Rohit Tamma, Oleg Skulkin, Heather Mahalik, Satish Bommisetty

Overview of this book

Covering up-to-date mobile platforms, this book will focuses on teaching you the most recent techniques for investigating mobile devices. We delve mobile forensics techniques in iOS 9-11, Android 7-8 devices, and Windows 10. We will demonstrate the latest open source and commercial mobile forensics tools, enabling you to analyze and retrieve data effectively. You will learn how to introspect and retrieve data from the cloud, and document and prepare reports of your investigations. By the end of this book, you will have mastered the current operating systems and the relevant techniques to recover data from mobile devices by leveraging open source solutions.
Table of Contents (19 chapters)
Title Page
Copyright and Credits
Packt Upsell
Contributors
Preface
5
iOS Data Analysis and Recovery

Working with Magnet AXIOM


Magnet AXIOM is one of the most useful digital forensics tools on the market. It can be used both for computer and mobile forensics; the recent version of the suite introduced the newest feature—cloud forensics. As for iOS forensics, it can be used both for logical and filesystem acquisitions, and supports all iOS versions—from the oldest to the latest. Of course, it can be used for parsing iTunes backups and physical images created by third-party tools, for example, Elcomsoft iOS Forensic Toolkit.

One of the best features of Magnet AXIOM is its ability to start processing extraction data on the fly, so you don't have to wait for the acquisition process to be finished to start your forensic analysis.

Features of Magnet AXIOM

The following are features of Magnet AXIOM:

  • It supports logical and filesystem (for jailbroken devices) acquisitions
  • It supports both encrypted and unencrypted iTunes backups
  • It recovers more than 500 artifact types
  • It's designed to work with other...