iPhone forensics can be performed on the backups made by iTunes (escrow key attack) or directly on the live device. This video and article (http://resources.infosecinstitute.com/iphone-forensics/) explain the technical procedure and the challenges involved in extracting data from the live iPhone.
iPhone 4 GSM model with iOS 5 is used for forensics.
GOAL
Extracting data and artifacts from iPhone without altering the information on the device
Researchers at Sogeti Labs have released open source forensic tools (with the support of iOS 5) to recover low level data from the iPhone. The details shown below outline their research and give an overview on the usage of iPhone forensic tools.
Steps involved in iPhone forensics include: Creating & Loading a forensic toolkit on to the device without damaging the evidence Establishing a communication between the device and the computer Bypassing the iPhone passcode restrictions Reading the encrypted file system Recovering the deleted files
very interesting thanks for this video. I got a question if anybody here could help answer. if you perform forensics on itunes backup does it give you the same amount of data such as getting all deleted files or is it better to perform on a live device?
J0k3rr662 3 weeks ago
ios 5
Dude1Dudette 1 month ago
hey can you make a video on decrypting an Iphone backup
Dude1Dudette 1 month ago
Only runs on Mac.....another reason I need to get my boss to buy me one.
chuckylicious19 1 month ago