Introducing iCloud forensics
In October 2011, Apple introduced iCloud, a cloud-based platform that allows users to store and share files between their devices, and backup their data. iCloud is integrated directly into iOS and is accessible from Windows machines, macOS computers, or directly from the web by browsing to https://www.icloud.com.
From a forensic viewpoint, cloud forensics is arguably the future of mobile forensics as it allows investigators to access data that may not even be stored on the device itself. As the majority of new devices do not (yet) support jailbreaks and full filesystem acquisitions, performing a cloud acquisition is a great alternative.
Before we dive deep into the technical details of extracting data from iCloud, it's important to understand exactly what kind of data we can expect to find, starting with iCloud backups.
iCloud backups
Since the release of iOS 5 in 2011, Apple allows users to back up their devices automatically to their...