Practical Mobile Forensics: Forensically Investigate and Analyze iOS, Android, and Windows 10 Devices
Rohit Tamma, Oleg Skulkin, Heather Mahalik, Satish Bommisetty · Packt Publishing · Fourth edition · 2020
Identifier: ISBN 978-1-83864-752-0
Access and status
Cost
Paid
Costs money to buy outright — a book, a licence, a registration.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A device-by-device walkthrough of mobile acquisition and analysis: iOS and Android internals and file systems, logical and physical extraction, app and SQLite artifacts, cloud extraction, mobile malware and reporting.
Who it is for, and when
The best available single-volume orientation to where mobile data lives and how the acquisition tiers differ — logical versus file system versus physical, and what each one forecloses. Read it for the artifact geography and the vocabulary you need when a vendor tool report has to be explained; verify every extraction procedure against current tooling.
What it does not cover
The publisher scopes it to iOS 11-13 and Android 8-10 and it still devotes space to Windows 10 Mobile, a dead platform. It therefore predates the current checkm8 and full-file-system landscape, mature Android Scoped Storage, and today's Cellebrite and GrayKey realities. Note also that Packt's storefront lists only three authors; the title page carries four, including Oleg Skulkin.
Go to the source
Open at packtpub.com (opens in a new tab)https://www.packtpub.com/en-us/product/practical-mobile-forensics-fourth-edition-9781838647520
Details
- Type
- Book
- Written for
- Working examinerWorking examiner
- Author
- Rohit Tamma, Oleg Skulkin, Heather Mahalik, Satish Bommisetty
- Publisher
- Packt Publishing
- Version verified
- Fourth edition
- Year
- 2020
- Identifier
- ISBN 978-1-83864-752-0
- Topics
- mobile, ios, android, sqlite, imaging, cloud
- Checked at source
Related entries
A family of open-source Python parsers for mobile and returns data: iLEAPP for iOS logs, events and plists, ALEAPP for Android, and RLEAPP for returns and records from cloud and carrier providers. All three are released very frequently and are among the most actively maintained tools in mobile forensics.
Cellebrite's mobile forensics flagship, now branded Inseyets and positioned within the company's broader Case-to-Closure platform. The familiar component names persist inside it rather than having been retired: UFED, Physical Analyzer, Kiosk, CFID, Reader, and C-TEK are all listed as parts of the Inseyets suite.
Hexordia Blog
FreeThe research blog of Hexordia, a mobile forensics training and consulting firm, with posts from a named group of contributors including Jessica Hyde, Adam Hachem, Nicholas Dubois, Elizabeth McPherson, Debbie Garner and Kim Gatson.
Alexis Brignoni's blog on mobile forensics and open-source tooling, closely tied to the xLEAPP family of parsers — iLEAPP, ALEAPP, RLEAPP and VLEAPP — which he maintains with others.
MSAB XRY
PaidA commercial mobile forensics family from the Swedish vendor MSAB, sold as separate modules rather than one product: XRY Logical for live and file system extraction, XRY Physical for bypassing the operating system, XRY Pro combining advanced extraction and decryption, plus XRY Cloud, XRY Photon for screen-scraping app data, and XRY Camera for device documentation.