Chapter 3: Using Forensic Tools
In the previous chapter, we learned all about the different acquisition techniques and how to use forensic tools to extract data from iOS devices. In this chapter, we will learn which are the most popular tools for data analysis, and their features and limitations.
Although using forensic tools for data analysis is not strictly required since theoretically it is possible to examine files manually, using these tools has many advantages. The most evident benefit of using forensic tools compared to manually parsing artifacts is time: if used correctly, these tools are huge time savers as they're programmed to automatically search for relevant files, look for patterns, analyze known data structures, and extract meaningful insights from common artifacts. Using the appropriate tools ensures that precious artifacts are not missed, although the investigator should always validate the output of such tools and know their limitations. There are no perfect...