BFU acquisition of locked devices
In Chapter 2, Data Acquisition from iOS Devices, we introduced the Checkm8 vulnerability and the checkra1n jailbreak, which allows the examiner to gain full access to the filesystem of devices ranging from the iPhone 5s to the iPhone X. This vulnerability can be exploited to perform an acquisition from locked or disabled devices, even if the passcode is unknown. This kind of acquisition is called a BFU acquisition.
It's important to understand that a BFU acquisition only allows a partial extraction of the device's data, as most files remain encrypted until the passcode is entered. Still, a partial extraction, including data from the keychain, is definitely better than nothing, as this could include notable evidence.
The following table lists some of the most popular artifacts that can be extracted through a BFU acquisition:
As you can see from the...