Sign In Start Free Trial
Account

Add to playlist

Create a Playlist

Modal Close icon
You need to login to use this feature.
  • Book Overview & Buying Mobile Forensics Cookbook
  • Table Of Contents Toc
  • Feedback & Rating feedback
Mobile Forensics Cookbook

Mobile Forensics Cookbook

By : Mikhaylov
5 (1)
close
close
Mobile Forensics Cookbook

Mobile Forensics Cookbook

5 (1)
By: Mikhaylov

Overview of this book

Considering the emerging use of mobile phones, there is a growing need for mobile forensics. Mobile forensics focuses specifically on performing forensic examinations of mobile devices, which involves extracting, recovering and analyzing data for the purposes of information security, criminal and civil investigations, and internal investigations. Mobile Forensics Cookbook starts by explaining SIM cards acquisition and analysis using modern forensics tools. You will discover the different software solutions that enable digital forensic examiners to quickly and easily acquire forensic images. You will also learn about forensics analysis and acquisition on Android, iOS, Windows Mobile, and BlackBerry devices. Next, you will understand the importance of cloud computing in the world of mobile forensics and understand different techniques available to extract data from the cloud. Going through the fundamentals of SQLite and Plists Forensics, you will learn how to extract forensic artifacts from these sources with appropriate tools. By the end of this book, you will be well versed with the advanced mobile forensics techniques that will help you perform the complete forensic acquisition and analysis of user data stored in different devices.
Table of Contents (12 chapters)
close
close

iOS backup parsing with Encase Forensic


The Encase Forensic program has already been described in Chapter 8, Analyzing Physical Dumps and Backups of Android Devices. In this recipe, we will describe how to analyze an iTunes backup via Encase Forensic.

How to do it…

  1. Double-click the icon of the program. Pay attention to the title of the program window when it starts. If the title of the program window says Encase Forensic, then the program runs in full-function mode. If the title of the window says Encase Acquire, it means that the program did not find the license.
  2. To get started, you will need to create a new case. In the program’s toolbar, select Case | New Case .... In the opened Options window, fill in the Name field and click the OK button. Then, in the toolbar, select Add Evidence | Acquire MobileAcquire From File….

Appearance of the Add Evidence drop-down menu

  1. In the opened Output File Settings, fill in the following fields: Notes, Evidence Number, and Examiner Name. Specify the path...

Unlock full access

Continue reading for free

A Packt free trial gives you instant online access to our library of over 7000 practical eBooks and videos, constantly updated with the latest in tech
bookmark search playlist font-size

Change the font size

margin-width

Change margin width

day-mode

Change background colour

Close icon Search
Country selected

Close icon Your notes and bookmarks

Delete Bookmark

Modal Close icon
Are you sure you want to delete it?
Cancel
Yes, Delete

Confirmation

Modal Close icon
claim successful

Buy this book with your credits?

Modal Close icon
Are you sure you want to buy this book with one of your credits?
Close
YES, BUY