Recovery Mode

In order to truly be forensically sound, ADB data extractions shouldn't be used against a phone while it is turned on. While the device is running, timestamps can be modified and applications may be running and updating files in the background. To avoid this, an examiner should place the device into a custom Recovery Mode as shown in Chapter 2, Setting Up the Android Forensic Environment, if possible. ADB access isn't available through the stock Android Recovery Mode. Typically, the first step in the rooting process is to flash a custom Recovery Mode to allow a method for repairing the device if something goes wrong. Rooted devices are far more likely to contain a custom recovery, but it is possible to flash a custom recovery ...

Get Learning Android Forensics - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.