Data acquisition

Acquiring data from a Windows Phone is challenging for forensic examiners, as the Physical, File System, and Logical methods that were defined in previous chapters are not greatly supported. In addition to this, the phone may need to be at a specific battery charge state (%) in order for the commercial tool to recognize and acquire the device. This is often one of the most difficult steps in acquiring Windows Phones. You will hear stories of seasoned examiners using the flashlight app on the phone to drain the battery. Yes, actually using a feature of a phone just to get the device into a state where forensic methods will allow access.

One of the most common techniques implemented by commercial tools attempting data acquisition ...

Get Practical Mobile Forensics - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.