Does anyone know of any good harware/software for mobile phone forenics, apart from what guidance provide? Prices and limitations would also be very useful
Thanks
There are nearly (or perhaps more than) 2,000 varieties of phones "in the wild". There are packages they say they support many of them. My experience has been that no tool can support all phones and that all are a bit over zealous in describing what they support.
I'd start by narrowing things down a bit (GSM, CDMA, smart phones or just phone/SMS/etc.) and then target an established tool and get a demo. See if it works for yours needs.
An important step in this process is that *you* have faith in the tool, have tested it and can explain what it does, how it performs the acquisition/analysis, what it might miss, etc.
Unlike computer (hard drive) forensics, the mobile forensics field is much less mature. This is due, in part, to the sheer number of devices and that you can't just remove the memory, image it read-only and then analyze it based on a rather finite set of documented, known file systems.
Good luck.
EnCase Neutrino
http//
here's an idea…
Go to Mobile Forensics World and get a test drive of all the various tools…
I'm just saying…it's a great opportunity to meet each and everyone specifically in the field…
Check it out
here's an idea…
Go to Mobile Forensics World
Probably best to disclose an interest when making this kind of recommendation, Rick. Thanks.
Jamie
Sure Jamie
<disclosure>
As the Conference Director of Mobile Forensics World, I'd like to disclose my interest in having all members of this forensics community know about the only concentrated conference for Mobile Forensics…
This post is in no way endorsing any one product, vendor, forum, presenter, or paper. It is however endorsing a conference that is being presented through Purdue University's College of Technology, the Computer & Information Technology Department, and the
Questions, comments, or concerns can be sent via PM.
</disclosure>
HTH,
Rick
Interesting definition of disclosure…
I try…
"the act of making something evident"
I think you've certainly succeeded in that respect.
Thanks. Like I said, "I try…"