Hi all,
I have collected an dd image of all partitions of android device. I recover deleted files like images using salpel on dd.
What other information I can recover from dd image.
What are the opensource tools I can use for.
Here I want to emphasize open source tools or manual analysis.
Hope my question is clear.
Many thanks
You could try recovering whatsapp dbase. it's in WhatsApp/Database folder is located in your external microSD card.
http//
http//
Autopsy 3.1.0 can read Android images (see thread here).
Was just about to suggest this, instead I'll just second it.
Thanks for all answers
You could try recovering whatsapp dbase. it's in WhatsApp/Database folder is located in your external microSD card.
http//
forum.xda-developers.com/showthread.php?t=1583021
http//prophethacker.blogspot.com/2014/05/extractdecrypt-whatsapp-backup-messages.html
However in order to use this kind of analysis I need sqlite db files. Now question is
If I do not do logical acquisition, I only have dd image from physical acquisition then How to extract sqlite database files.
Basically I want to know how to interpret dd image as a disk so that it shows me files and folders.
I am doing a mobile forensic university project using opensource tools. In there I would like to show the collected image organized in files and folders apart form hex view.
Could you please some one guide me and help me here.
You mean that Autopsy doesn't open those partition images?