Data acquisition
Acquiring data from a Windows Phone is challenging for forensic examiners, as the Physical, File System, and Logical methods that were defined in previous chapters are not greatly supported. In addition to this, the phone may need to be at a specific battery charge state (%) in order for the commercial tool to recognize and acquire the device. This is often one of the most difficult steps in acquiring Windows Phones. You will hear stories of seasoned examiners using the flashlight app on the phone to drain the battery. Yes, actually using a feature of a phone just to get the device into a state where forensic methods will allow access.
One of the most common techniques implemented by commercial tools attempting data acquisition ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access