Making complex data simple and compelling
From digital device to digital evidence
Unlock your vehicle's digital evidence potential
Forensic Analysis and Enhancement
Investigating and analyzing financial records
Gain access to the online accounts of deceased loved ones
Clear, precise evidence for a messy world
Expert reports to suit your specific needs
We can locate people anywhere
Stop worrying and learn the truth
Prevent, Detect, Respond To Cyberattacks
First response is crucial. Every minute counts.
The first response is critical to reduce liability
Detection & Removing Spyware Services
Reduce your electronic risk from digital transmittals
Find out who you are really talking to
Experienced, Confidential Services
Swift, professional incident response
Complicated cases require compelling digital facts
Find, recover and document digital evidence
Bring solid evidence before a judge
Cases can be investigated using Social Media
Divorce, custody battles, and other
Win the most important battle of your life
Everything you need
Effective Expert Witness in Court
Evidence shows who is telling the truth
Subpoena power yields strong evidence
Digital evidence can build a strong defense
Go to court with compelling digital evidence
Mobile devices of Apple such as iPhones and iPads are 15% of the mobile market. Therefore, it is often on research in forensic laboratories.
In this article we will consider two key points of forensic analysis of such devices:
1) Extracting data from Apple mobile devices;
2) Forensic analysis of these data.
Extracting data from Apple mobile devices
There are four basic types of data extraction in mobile forensics:
For making iPhone forensic images (in case of iPad the process of creating a forensic image and analysis of data will be similar), use the free utility “Belkasoft Acquisition Tool.”
A free utility ‘Belkasoft Acquisition Tool’ and a trial version of the software ‘Belkasoft Evidence Center’ are available at http://belkasoft.com/get
Run the program, and click on the icon ‘Mobile device’ in the opened window.
Fig. 1. The main window of the program ‘Belkasoft Acquisition Tool’.
On the next window, click on the icon ‘Apple’.
Fig. 2. The window for selecting device type (‘Apple’ or ‘Android’).
Unlock the device from which you need to extract the data, connect it to the computer and, in response to the request on the screen of the device, click ‘Trust’. On the next window you must specify the path where the returned data will be stored and click ‘Next’.
Fig. 3. The window for connecting a mobile device.
The data extraction process starts. When the extraction is completed, a window with information about the extracted data will be displayed. You can go to the extracted data by clicking on the ‘Open target folder’ label in this window.
Fig. 4. The window with information about the performed extraction.
Analysis of extracted data
For the analysis of data retrieved one could use the software ‘Belkasoft Evidence Center’. Run the program. Define the parameters of the new case such as: name, path, where to place the data of the case, the name of the researcher (expert), case description, time zone. Click on the button ‘New case’.
Fig. 5. The window for setting up a new case.
On the next window, we specify the path to the data from the mobile device that was extracted earlier. Click the ‘Next’ button.
Fig. 6. The window for data source selection.
In the next window, specify the data types (chats, email messages images, videos, calls, SMS messages, etc.) that must be removed. The more data types are specified for extraction, the longer the analysis will be performed. However, for the analysis of mobile data, the analysis time is not critical. Thus, the analysis of the device used as an example took 12 minutes.
Fig. 7. The window for selecting data types to be found
Upon completion of the analysis process, the detected data types will be displayed.
Fig. 8. Data extracted from the analyzed device.
Is it possible to recover deleted data from an iTunes backup. Yes. It is possible. ‘Belkasoft Evidence Center’ can recover deleted records of Phonebook, Calls, SMS messages, Web Browser History, etc.
Thumbnails can provide info about images and video files which were deleted on the investigated device.
The extracted and recovered data can be viewed and analyzed in the ‘Belkasoft Evidence Center’ program. Also, one can create forensic reports for them, which, including, can be presented as evidence in a court.
In this article, we looked at the types of data retrieval from mobile devices. An example of extracting and analyzing data extracted from the iPhone with the help of available programs, such as ‘Belkasoft Acquisition Tool’ and ‘Belkasoft Evidence Center’, is given.
Igor Mikhaylov & Oleg Skulkin
A detective told me that there’s an order to opening files. He said pictures/videos must be opened first? Is this the case? It appears that the files only open up when clicked on.
Save my name, email, and website in this browser for the next time I comment.
Speak to a Specialist Now