The GrayKey Difference: Logical vs File System

Originally posted here.

Law Enforcement agencies perform logical acquisitions of unlocked iOS devices when they do not have access to GrayKey.  The logical acquisition has been an industry-leading iOS acquisition method used by investigators and forensic examiners because of its simplicity and level of support. However, one of the biggest roadblocks for successfully completing logical acquisitions is device security. For a logical acquisition to take place, device access needs to be granted using a passcode and a trusted connection is required in most instances.

Logical acquisitions are created through use of the Apple File Connection protocol which is also used by iTunes. This method is designed to manage an iOS device and more specifically transfer user-data from one device to the next. This protocol allows an iOS device user to experience a seamless transition whenever upgrading their equipment, without the use of cloud services. For those of you involved in computer forensic extractions, a logical extraction of a mobile device is very similar to a targeted file collection on a computer hard drive. Data stored within logical collections is limited when compared to a full file system extraction.

Many limitations associated with logical extractions.

Logical extractions can be beneficial as they are generally supported directly following the release of an iOS update and you won’t have to wait too long for collection support, but unfortunately there are many limitations to them. The largest and most important limitation is the depth and quality of the data collection. These types of iTunes-style backup deliverables are negatively impacted by application developer limitations and data from third-party applications are often limited. Furthermore, never-before-seen forensic artifacts like the KnowledgeC database and supporting data like the Keychain file are rendered unrecoverable. Lastly, backup encryption passwords enforced by the end-user may create significant hurdles for digital forensic investigations by denying access to the data stored once the extraction is completed and ready for analysis.

In comparison, GrayKey is a purpose-built solution for mobile device forensics, specializing in access and extraction.  Moreover, it is powered by Grayshift’s Advanced Vulnerability Research Team, which has pioneered the development of full filesystem acquisition methods from mobile devices.


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

Logical acquisitions fail in comparison to the depth and quality provided by GrayKey extractions.

Digital evidence is growing in importance and proving increasingly critical. To that end, investigators and examiners must be mindful of the collection methods used in any digital investigation. While the logical acquisition is better than nothing, it fails in comparison to the depth and quality that GrayKey customers have come to expect. We encourage you to experience the GrayKey difference on all lawfully seized iOS devices and with the proper legal authority, regardless of their lock state. We know that you will be pleasantly surprised at the additional data and actionable intelligence collected via GrayKey.

Leave a Comment

Latest Videos

Throughout the past few years, the way employees communicate with each other has changed forever.

69% of employees note that the number of business applications they use at work has increased during the pandemic.

Desk phones, LAN lines and even VOIP have become technologies of the past workplace environment as employees turn to cloud applications on their computers and phones to collaborate with each other in today’s workplace environment.

Whether it’s conversations in Teams, file uploads in Slack chats, or confidential documents stored in Office 365, the amount of data stored and where it is stored, is growing quicker than IT and systems administrators can keep up with.

Corporate investigators and eDiscovery professionals need to seamlessly collect relevant data from cloud sources and accelerate the time to investigative and discovery review.

With the latest in Cellebrite’s remote collection suite of capabilities, investigators and legal professionals can benefit from secure collection with targeted capabilities for the most used workplace applications.

Join Monica Harris, Product Business Manager, as she showcases how investigators can:

- Manage multiple cloud collections through a web interface
- Cull data prior to collection to save time and money by gaining these valuable insights of the data available
- Collect data from the fastest growing cloud collaboration applications like Office365, Google Workspace, Slack and Box
- Login to a single source for workplace app collection without logging into every app and pulling data from multiple sources for every employee
- Utilize a single unified collection workflow for computer, mobile and workplace cloud applications without the need to purchase multiple tools for different types of collections – a solution unique to Cellebrite’s enterprise solution capabilities

Throughout the past few years, the way employees communicate with each other has changed forever.

69% of employees note that the number of business applications they use at work has increased during the pandemic.

Desk phones, LAN lines and even VOIP have become technologies of the past workplace environment as employees turn to cloud applications on their computers and phones to collaborate with each other in today’s workplace environment.

Whether it’s conversations in Teams, file uploads in Slack chats, or confidential documents stored in Office 365, the amount of data stored and where it is stored, is growing quicker than IT and systems administrators can keep up with.

Corporate investigators and eDiscovery professionals need to seamlessly collect relevant data from cloud sources and accelerate the time to investigative and discovery review.

With the latest in Cellebrite’s remote collection suite of capabilities, investigators and legal professionals can benefit from secure collection with targeted capabilities for the most used workplace applications.

Join Monica Harris, Product Business Manager, as she showcases how investigators can:

- Manage multiple cloud collections through a web interface
- Cull data prior to collection to save time and money by gaining these valuable insights of the data available
- Collect data from the fastest growing cloud collaboration applications like Office365, Google Workspace, Slack and Box
- Login to a single source for workplace app collection without logging into every app and pulling data from multiple sources for every employee
- Utilize a single unified collection workflow for computer, mobile and workplace cloud applications without the need to purchase multiple tools for different types of collections – a solution unique to Cellebrite’s enterprise solution capabilities

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_g6nTjfEMnsA

Tips And Tricks Data Collection For Cloud Workplace Applications

Forensic Focus 3 hours ago

In this episode of the Forensic Focus podcast, Si and Desi explore the cutting-edge technology of deepfake videos and image manipulation. In addition to discussing the latest technological developments and efforts being made to detect manipulated media, they also examine the associated legal and ethical implications.<br /><br />Show notes:<br /><br />Boris Johnson image - https://www.theguardian.com/politics/2023/jan/10/spot-the-difference-boris-johnson-appears-scrubbed-from-photo-posted-by-grant-shapps<br /><br />Deep Fake Neighbour Wars - https://m.imdb.com/title/tt21371376/<br /><br />Stalin image - https://www.history.com/news/josef-stalin-great-purge-photo-retouching<br /><br />Nvidia eye contact AI - https://www.polygon.com/23571376/nvidia-broadcast-eye-contact-ai and https://www.youtube.com/watch?v=xl87WTDrReo<br /><br />Birthday problem - https://en.wikipedia.org/wiki/Birthday_problem<br /><br />Same frightening woman in AI images - https://petapixel.com/2022/09/09/the-same-frightening-woman-keeps-appearing-in-ai-generated-images/<br /><br />Inherent mysogeny of AI portraits - https://www.theguardian.com/us-news/2022/dec/09/lensa-ai-portraits-misogyny<br /><br />Midjourney - https://www.midjourney.org/<br /><br />Deepfake porn legality - https://www.theverge.com/2022/11/25/23477548/uk-deepfake-porn-illegal-offence-online-safety-bill-proposal and https://www.technologyreview.com/2021/02/12/1018222/deepfake-revenge-porn-coming-ban/<br /><br />AIATSIS - https://aiatsis.gov.au/cultural-sensitivity<br /><br />Fake tiger porn story - https://www.dailydot.com/unclick/tiger-porn-britain-law/<br /><br />Group photo with no blinking - https://www.countrylife.co.uk/comment-opinion/curious-questions-group-photo-179102<br /><br />Emma Watson deefake audio - https://www.thetimes.co.uk/article/ai-4chan-emma-watson-mein-kampf-elevenlabs-9wghsmt9c<br /><br />Domestika - https://www.domestika.org/en/courses/981-introduction-to-interviewing-the-art-of-conversation<br /><br />Investigative Interviewing - https://www.amazon.co.uk/dp/0199681899?ref=ppx_pop_mob_ap_share<br /><br />Forensic Focus events calendar - https://www.forensicfocus.com/events/<br /><br />Si Twitter - https://twitter.com/si_biles

In this episode of the Forensic Focus podcast, Si and Desi explore the cutting-edge technology of deepfake videos and image manipulation. In addition to discussing the latest technological developments and efforts being made to detect manipulated media, they also examine the associated legal and ethical implications.

Show notes:

Boris Johnson image - https://www.theguardian.com/politics/2023/jan/10/spot-the-difference-boris-johnson-appears-scrubbed-from-photo-posted-by-grant-shapps

Deep Fake Neighbour Wars - https://m.imdb.com/title/tt21371376/

Stalin image - https://www.history.com/news/josef-stalin-great-purge-photo-retouching

Nvidia eye contact AI - https://www.polygon.com/23571376/nvidia-broadcast-eye-contact-ai and https://www.youtube.com/watch?v=xl87WTDrReo

Birthday problem - https://en.wikipedia.org/wiki/Birthday_problem

Same frightening woman in AI images - https://petapixel.com/2022/09/09/the-same-frightening-woman-keeps-appearing-in-ai-generated-images/

Inherent mysogeny of AI portraits - https://www.theguardian.com/us-news/2022/dec/09/lensa-ai-portraits-misogyny

Midjourney - https://www.midjourney.org/

Deepfake porn legality - https://www.theverge.com/2022/11/25/23477548/uk-deepfake-porn-illegal-offence-online-safety-bill-proposal and https://www.technologyreview.com/2021/02/12/1018222/deepfake-revenge-porn-coming-ban/

AIATSIS - https://aiatsis.gov.au/cultural-sensitivity

Fake tiger porn story - https://www.dailydot.com/unclick/tiger-porn-britain-law/

Group photo with no blinking - https://www.countrylife.co.uk/comment-opinion/curious-questions-group-photo-179102

Emma Watson deefake audio - https://www.thetimes.co.uk/article/ai-4chan-emma-watson-mein-kampf-elevenlabs-9wghsmt9c

Domestika - https://www.domestika.org/en/courses/981-introduction-to-interviewing-the-art-of-conversation

Investigative Interviewing - https://www.amazon.co.uk/dp/0199681899?ref=ppx_pop_mob_ap_share

Forensic Focus events calendar - https://www.forensicfocus.com/events/

Si Twitter - https://twitter.com/si_biles

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_i41eg24YGZg

Deepfake Videos And Altered Images - A Challenge For Digital Forensics?

Forensic Focus 13th February 2023 10:30 am

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles

Share to...