December 2018
Beginner to intermediate
328 pages
8h 29m
English
The short answer is: everything. Since a physical acquisition is an exact image of the device, every bit of data on the device is in the image file. As mentioned in the preceding section, with a physical extraction, an examiner is usually only limited by their ability to find the relevant data. Generally, this is due to a lack of good image analysis tools in the mobile forensics space. To further compound the matter, applications have been known to encode or otherwise obfuscate user data, so simply browsing through the image in a hex editor will frequently miss valuable evidence. In this chapter, we will cover various methods for mounting or otherwise viewing the file system of a physical extraction, ...
Read now
Unlock full access