Timestamps
Before examining the data, it is important to understand the different timestamps that are used on iOS devices. Timestamps found on iOS devices are presented either in the UNIX timestamp or Mac absolute time format. The examiner must ensure that the tools properly convert the timestamps for the files. Access to the raw SQLite files will allow the examiner to verify these timestamps manually. Further information on iOS timestamps can be found at http://www.zdziarski.com/blog/wp-content/uploads/2013/05/iOS-Forensic-Investigative-Methods.pdf.
UNIX timestamps
A UNIX timestamp is the number of seconds that offsets the UNIX epoch time, which starts on January 1, 1970. A UNIX timestamp can be converted easily using the date
command on a Mac workstation or using an online UNIX epoch converter on a Windows workstation. The date
command is as follows:
$date -r 1455070351 Tues Feb 9 21:12:31 EST 2016
Mac absolute time
iOS devices adopted the use of Mac absolute time with iOS 5 for...