mobile forensics - dataspecialistgroup.com · “mobile device forensics is a branch of digital...

13
Text Mobile Forensics The Basics

Upload: others

Post on 19-Aug-2020

16 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: Mobile Forensics - dataspecialistgroup.com · “Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under

Text

Mobile ForensicsThe Basics

Page 2: Mobile Forensics - dataspecialistgroup.com · “Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under

– http://en.wikipedia.org/wiki/Forensic

“Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under forensically sound conditions. The phrase mobile device usually refers to mobile phones; however, it can also relate to any

digital device that has both internal memory and communication ability, including PDA devices, GPS

devices and tablet computers.”

Page 3: Mobile Forensics - dataspecialistgroup.com · “Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under

Variables Smart Phone firmware and software varies by carrier (Verizon, AT&T, Sprint, etc)

Android phone firmware and software varies by manufacturer (LG, HTC, Samsung, etc)

Android software versions are Alpha, Beta, Cupcake, Donut, Eclair, Froyo, Gingerbread, Honeycomb, Ice Cream Sandwich, Jelly Bean, KitKat, Lollipop

iPhone versions 1x thru 8x

Some Android phones have internal memory as well as external memory

iPhones, iPads and iPods have internal memory only (16gb-128gb)

There are millions of Apps available from Google Play, App Store, and third party websites ( including jail breaking).

Page 4: Mobile Forensics - dataspecialistgroup.com · “Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under

Other Variables “Jail Breaking”

Decoy Apps

Pre-paid phones

Spyware

Malware

User Apps created via open source SDK

Wifi only users (no carrier)

Users

Encryption

Screen locks / Passwords

Page 5: Mobile Forensics - dataspecialistgroup.com · “Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under

Our Mobile Lab

XRY

Cellbrite

Lantern

Mobiledit

EnCase

MPE+

dSolo

IEF

Data Pilot

Hex-editor

Wireless sand box

Faraday bags/cages

Packet capturing software

Open source tools

No one program does the job!

Page 6: Mobile Forensics - dataspecialistgroup.com · “Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under

Before you choose a mobile forensics lab?

In theory, a mobile forensics lab can process the subject device with one tool and truthfully state that they conducted a forensic examination

Some tools are better at uncovering deleted texts, other tools are better at recovering photos. Those tools may not uncover third party apps

A reputable lab will process the subject device with multiple tools to validate their findings

Page 7: Mobile Forensics - dataspecialistgroup.com · “Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under

Alternative Data CollectionAndroid data can be extracted from a SD card using an APK

f-Respose provides forensic extraction over the Internet

iTunes back up from computer and or iCloud backup

Page 8: Mobile Forensics - dataspecialistgroup.com · “Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under

Wireless sand boxingA controlled environment that allows the examiner to monitor communications from the subject device

Allows examiner to see which websites/IP addresses the phone is communicating with

Provides insight to hidden apps and spyware

Page 9: Mobile Forensics - dataspecialistgroup.com · “Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under

FAQsQ: Can we bypass the screen lock code?

A: Depends on the of the phone and software version

Q: How far back can we go to collect deleted text messages?

A: Text messages are stored in a SQL-lite database and the text history is relevant to how often the user deletes and receives text as well as the memory size

Page 10: Mobile Forensics - dataspecialistgroup.com · “Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under

Q: Can an iDevice that was remotely wiped be recovered?

A: No, as such it’s imperative to keep devices in a faraday cage or in airplane mode

Q: Can spyware be installed without physical access to the phone?

A: Yes and No. Androids phones are vulnerable to remote spyware deployment. iDevices are not, however new spyware tools can collect data via iCloud

Q: Can the fingerprint reader be bypassed?

A: Yes, particularly if you are a heavy sleeper. Also a judge can compel you to place your finger on the phone

Page 11: Mobile Forensics - dataspecialistgroup.com · “Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under

Text

Cyber Bullying and StalkingWe offer free mobile forensics to parents who believe that their children are victims of these offenses.

Page 12: Mobile Forensics - dataspecialistgroup.com · “Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under

What should you do if you suspect evidence is on a mobile device?

Immediately place the phone in airplane mode

The battery should only be removed if you can’t figure out how to place the phone in airplane mode

Never attempt to conduct your own investigation by looking through the device

Read our guide for first responders

Page 13: Mobile Forensics - dataspecialistgroup.com · “Mobile device forensics is a branch of digital forensics relating to recovery of digital evidence or data from a mobile device under

Your Questions

Other questions can be emailed to:

[email protected]