It's time to perform a filesystem acquisition. We are going to use Elcomsoft iOS Forensic Toolkit to do it. Here is how to do it:
- First of all, connect the device to your workstation (don't forget to tap Trust on the device) and start Toolkit-JB.command (Mac) or Toolkit-JB.cmd (Windows).
- You will see a window with available options. As we are planning to perform filesystem acquisition now, we are interested in the TAR FILES option. This option enables the examiner to extract the filesystem from the user partition and save it in a TAR archive. This archive can be imported in most modern mobile forensics tools for processing. To choose this option, type 8.
- Now, you should ...