December 2018
Beginner to intermediate
328 pages
8h 29m
English
The most common problem we see on many forensic forums and email lists is examiners obtaining a physical dump and then not being able to load that dump into a tool that claims to support the device. The vast majority of the time, this is because the examiner fails to account for the out-of-band (OOB) area.
The OOB area, sometimes called spare area, is a small section of the flash memory that's been reserved for metadata. The metadata usually consists of error-correcting code (ECC), information about bad blocks, and in some cases, information about the file system. This causes an issue for examiners because most mobile forensic tools do not account for the OOB area; they expect it to not be included in ...
Read now
Unlock full access