Artifacts that can be collected from devices
Most enterprise systems provide services through endpoints. Individuals access systems too through endpoints. When you access any system, including a cloud system, an on-premises system, or even an application, there are many artifacts collected by a device. If the device is lost or stolen, a third person can have direct access to these artifacts, unless the device is encrypted as per industry standards. During investigations, forensic investigators can use forensic tools to recover many artifacts and obtain information.
If an attacker has access to a device in the event of it being lost or stolen, they can collect the following information from it:
- Contact information and the phone book can be exported or downloaded.
- Messages, including SMS and application-based text messages.
- Multimedia content, including pictures, videos, and sensitive multimedia content.
- Call history, including incoming and outgoing calls. ...