Order of Volatility in Modern Smartphone Forensics

Поділитися
Вставка
  • Опубліковано 31 сер 2021
  • When dealing with modern smartphone devices, both Android and iOS, we often rely on native communication protocols (for example, ADB on Android and iTunes Backup service on iOS) to extract data and we often need to interact "live" with the device to allow communications. As mentioned since 2002 in the RFC 3227 "When collecting evidence you should proceed from the volatile to the less volatile". The aim of this presentation is to show how to leverage native Android and iOS communication protocols to extract as much data as possible, in the proper order.
    View upcoming Summits: www.sans.org/u/DuS
    Download the presentation slides (SANS account required) at www.sans.org/u/1h3C
    #DFIR #DigitalForensics #SmartphoneForensics
  • Наука та технологія

КОМЕНТАРІ • 1

  • @peppigue
    @peppigue Рік тому

    Great stuff indeed