Dynamic application analysis
Third-party applications can be a huge source of evidential artifacts since most apps collect, store, and process a tremendous amount of data from their users. Unfortunately, investigators will most likely have to resort to manually analyzing these applications, as forensic tools cannot possibly support each update of every app. Even if a tool does support a certain application, a manual examination should still be carried out to validate the tool's results and to ensure that all the data was parsed correctly.
Often, before the examination can be performed, the examiner will have to do some research on the application of interest to understand how it works, what data it stores, and where it stores it. This entails using a research device to install the app and analyze it.
When analyzing mobile applications, there is no standard process that an investigator should take to examine the data since each application performs differently; in this chapter...