Legal Cyber Academy
BookPaidCurrent

Practical Mobile Forensics: Forensically Investigate and Analyze iOS, Android, and Windows 10 Devices

Rohit Tamma, Oleg Skulkin, Heather Mahalik, Satish Bommisetty · Packt Publishing · Fourth edition · 2020

Identifier: ISBN 978-1-83864-752-0

Access and status

Cost

Paid

Costs money to buy outright — a book, a licence, a registration.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A device-by-device walkthrough of mobile acquisition and analysis: iOS and Android internals and file systems, logical and physical extraction, app and SQLite artifacts, cloud extraction, mobile malware and reporting.

Who it is for, and when

The best available single-volume orientation to where mobile data lives and how the acquisition tiers differ — logical versus file system versus physical, and what each one forecloses. Read it for the artifact geography and the vocabulary you need when a vendor tool report has to be explained; verify every extraction procedure against current tooling.

What it does not cover

The publisher scopes it to iOS 11-13 and Android 8-10 and it still devotes space to Windows 10 Mobile, a dead platform. It therefore predates the current checkm8 and full-file-system landscape, mature Android Scoped Storage, and today's Cellebrite and GrayKey realities. Note also that Packt's storefront lists only three authors; the title page carries four, including Oleg Skulkin.

Go to the source

Open at packtpub.com (opens in a new tab)

https://www.packtpub.com/en-us/product/practical-mobile-forensics-fourth-edition-9781838647520

Details

Type
Book
Written for
Working examinerWorking examiner
Author
Rohit Tamma, Oleg Skulkin, Heather Mahalik, Satish Bommisetty
Publisher
Packt Publishing
Version verified
Fourth edition
Year
2020
Identifier
ISBN 978-1-83864-752-0
Topics
mobile, ios, android, sqlite, imaging, cloud
Checked at source
  • A family of open-source Python parsers for mobile and returns data: iLEAPP for iOS logs, events and plists, ALEAPP for Android, and RLEAPP for returns and records from cloud and carrier providers. All three are released very frequently and are among the most actively maintained tools in mobile forensics.

  • Cellebrite's mobile forensics flagship, now branded Inseyets and positioned within the company's broader Case-to-Closure platform. The familiar component names persist inside it rather than having been retired: UFED, Physical Analyzer, Kiosk, CFID, Reader, and C-TEK are all listed as parts of the Inseyets suite.

  • The research blog of Hexordia, a mobile forensics training and consulting firm, with posts from a named group of contributors including Jessica Hyde, Adam Hachem, Nicholas Dubois, Elizabeth McPherson, Debbie Garner and Kim Gatson.

  • Alexis Brignoni's blog on mobile forensics and open-source tooling, closely tied to the xLEAPP family of parsers — iLEAPP, ALEAPP, RLEAPP and VLEAPP — which he maintains with others.

  • A commercial mobile forensics family from the Swedish vendor MSAB, sold as separate modules rather than one product: XRY Logical for live and file system extraction, XRY Physical for bypassing the operating system, XRY Pro combining advanced extraction and decryption, plus XRY Cloud, XRY Photon for screen-scraping app data, and XRY Camera for device documentation.