Chapter 11: Locked Devices, iTunes Backups, and iCloud Forensics

Up to this point in the book, we have learned how to perform an iOS acquisition using different methods and how to analyze the extracted data to gain meaningful insights, such as interpreting location artifacts, parsing through media files, or analyzing pattern-of-life data. Everything we have covered so far relies on the fact that the iOS device that is being examined is unlocked, or the passcode is known; however, this is not always the case. There are some occasions in which the investigator may have to deal with locked devices, and that will be the focus of this chapter.

We will start the chapter by learning how to deal with locked devices, what options the examiner has, and ...

Get iOS Forensics for Investigators now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.