Windows Phone physical dump and backup parsing with Oxygen Forensic
The Oxygen Forensic program has already been described in Chapter 1, SIM Cards Acquisition and Analysis. In this recipe, we will describe data extraction from the physical dump of Windows Phone via Oxygen Forensic.
How to do it…
- Oxygen Forensic has functionality that allows you to recover the screen lock password from a physical dump of a Windows Phone device. A physical dump can be obtained by the JTAG and chip-off methods.
- In order to import data from a Windows Phone physical dump, click the arrow that is located to the right of the
Import File
button on the Oxygen Forensic toolbar. In the drop-down menu, go toImport Windows Phone JTAG image ...
.
Selection of the type of data import
- In the opened window, specify the path to the physical dump. Click the
Open
button. - In the new window, fill in the details of the case, such as
Device alias
,Case number
,Evidence number
,Place
,Incident number
,Inspector
,Device owner
, andOwner...