Search icon CANCEL
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Mobile Forensics Cookbook

You're reading from   Mobile Forensics Cookbook Data acquisition, extraction, recovery techniques, and investigations using modern forensic tools

Arrow left icon
Product type Paperback
Published in Dec 2017
Publisher
ISBN-13 9781785282058
Length 302 pages
Edition 1st Edition
Concepts
Arrow right icon
Author (1):
Arrow left icon
Igor Mikhaylov Igor Mikhaylov
Author Profile Icon Igor Mikhaylov
Igor Mikhaylov
Arrow right icon
View More author details
Toc

Table of Contents (12) Chapters Close

Preface 1. SIM Card Acquisition and Analysis FREE CHAPTER 2. Android Device Acquisition 3. Apple Device Acquisition 4. Windows Phone and BlackBerry Acquisition 5. Clouds are Alternative Data Sources 6. SQLite Forensics 7. Understanding Plist Forensics 8. Analyzing Physical Dumps and Backups of Android Devices 9. iOS Forensics 10. Windows Phone and BlackBerry Forensics 11. JTAG and Chip-off Techniques

iOS backup parsing with Encase Forensic


The Encase Forensic program has already been described in Chapter 8, Analyzing Physical Dumps and Backups of Android Devices. In this recipe, we will describe how to analyze an iTunes backup via Encase Forensic.

How to do it…

  1. Double-click the icon of the program. Pay attention to the title of the program window when it starts. If the title of the program window says Encase Forensic, then the program runs in full-function mode. If the title of the window says Encase Acquire, it means that the program did not find the license.
  2. To get started, you will need to create a new case. In the program’s toolbar, select Case | New Case .... In the opened Options window, fill in the Name field and click the OK button. Then, in the toolbar, select Add Evidence | Acquire MobileAcquire From File….

Appearance of the Add Evidence drop-down menu

  1. In the opened Output File Settings, fill in the following fields: Notes, Evidence Number, and Examiner Name. Specify the path...
lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at R$50/month. Cancel anytime