The first step in iOS device forensic examination is to acquire the data from the device. There are several different ways to acquire data from an iOS device. This chapter covered logical and filesystem acquisition techniques, as well as jailbreaking and methods to bypass passcodes.
While filesystem acquisition is the best method for forensically obtaining a majority of the data from iOS devices, backup files may exist or be the only method to extract data from the device.
The next chapter will discuss iOS device backup files in detail, including user, forensic, encrypted, and iCloud backup files, and the methods that you can perform to conduct your forensic examination.