Understanding the importance of validation
In Chapter 3, Using Forensic Tools, we learned about some of the features of software such as Cellebrite Physical Analyzer and Magnet AXIOM, and gained a better understanding of what data we can expect to see analyzed by these tools.
You may be wondering why an examiner would invest time in learning how to manually analyze data found on a device when these tools do all the hard work for you. Well, for starters, while this software is an essential item in the investigator's toolbox, the investigator should also understand the limitations of these tools and how to deal with artifacts that are not automatically parsed; while forensic tools claim to support a variety of different apps and artifacts, this does not mean that the products can actually parse all of the data that pertains to a specific application that is being examined. With the rate at which mobile apps are updated, it is quite common for a forensic tool to not support a...