You can recover deleted items as you will have a physical acquisition of the flash memory. Some tools like Cellebrite P.A. and XRY Complete will parse out the password, you can also use the CCL Forensics Python scripts to get them. Some of the JTAG tools will put the physical dump into a logical file system for you and you can export out the SQLite Databases for pretty much anything and recover data form call logs, text messages, contact, user data from applications, phone setting, gps and other location type data, and much much more….. (- I sound like a commercial (- As you have a physical dump, the items you can recover are endless. More so with Chipoff and it goes a bit deeper and the Pare Area is in place to allow Cellebrite P.A. and XRY Complete to rebuilt the logical file system on supported phones. Getting the deleted data form the physical dump can take some time, you need to use techniques to find the data and then decode it at the HEX Level to get date and time stamps, attributes, details (eg. incoming, outgoing, dialed, missed etc.) and other information related to the artifact you have found, again time consuming be very rewarding……
Notifications
Clear all
General (Technical, Procedural, Software, Hardware etc.)
11
Posts
7
Users
0
Reactions
6,743
Views
09/02/2013 11:03 am
Page 2 / 2
Prev