Introducing email forensics
In the first part of this chapter, we will introduce email forensics and we will focus on the Apple Mail application. It's safe to say that Apple Mail is certainly the most popular email client on iOS devices; however, investigators should keep in mind that there are many more third-party email apps available, such as Outlook, Spark, Gmail, and Airmail. Analyzing third-party apps is covered in Chapter 10, Analyzing Third-Party Apps. A comprehensive forensic analysis of email artifacts should entail analyzing Apple Mail and any third-party clients that have been installed on the device.
The first step in investigating Apple Mail data is locating the artifacts: these can be found in the folder located at /private/var/mobile/Library/Mail
. Please note that a full filesystem extraction is required. The following is a list of the most relevant files and their description:
- For each email account configured on the device, there will be a corresponding...