A key aspect of iOS-device forensics is to examine and analyze the data acquired to interpret the evidence. In the previous chapters, you learned various techniques to acquire data from iOS devices. Any type of acquired image contains hundreds of data files that are often parsed by the tools described in earlier chapters. Even when the data is parsed by the forensic tool, a manual analysis may be required to uncover additional artifacts or to simply validate your findings.
This chapter will help you understand how data is stored on iOS devices, and it will walk you through the key artifacts that should be examined in each investigation to recover the most data possible.
In this chapter, we will be covering the following topics:
- Interpreting iOS timestamps
- Working with SQLite databases
- Key artifacts – important iOS database files
- Property...