iphone forensics

Is there any free software that can analyse iphone forensics.

Also - as with PC's what hardware is required to take a replica copy of the device (are there specific write blockers just for smartphones?)
LVL 3
pma111Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

coke_ruCommented:
Yes there is one software which can be used.Please check out the link below for more details:

http://www.oxygen-forensic.com/en/compare/devices/software-for-iphone
0
pma111Author Commented:
Is it free
0
btanExec ConsultantCommented:
there will not be an one tools for just iphone forensic and the two paper guide you through for iOS device
http://www.sans.org/reading-room/whitepapers/forensics/forensic-analysis-ios-devices-34092
http://www.zdziarski.com/blog/wp-content/uploads/2013/05/iOS-Forensic-Investigative-Methods.pdf
(above pls do check out the "Acquisition" and "Forensic Recovery" sections to find out the logical and physical aspects - you probably have to acquire the solid state of the phone as image.)
The iPhone (and iPad) use solid-state NAND chips to store user data. These chips act as a type of hard drive for the device. Physical chip dumps have shown that memory is stored in 512K chunks in various locations of the chip. The solid state disk firmware attempts to minimize writes to the same portions of NAND, and even attempts to move blocks of memory around on the physical chip to ensure that the entire chip is used. This process results in dormant data generally lasting longer periods of time on the
device before it is eventually overwritten. Due to the hardware-based encryption present on the iPhone
3G[s], iPhone 4, and iPad, chip-off forensics has proven extremely difficult.
You can’t simply remove the hard disk out of an iPhone or iPad, connect it to a write blocker, and image it
the way you would a desktop machine. Even if you could rip out the disk (or perform a chip-off), you’d
have to content with an encrypted file system. Mobile forensics requires limited interaction with the device
to extract data from it. On iOS based devices, a forensic imaging agent is instituted as a process in the
device’s memory – a portion of remote code containing the instructions to transfer the file system,
encryption keys, or raw disk from the device to a connected desktop machine. The agent is injected into a
protected system area on the device, where it will not affect the user disk or any user data. This is
necessary, especially on newer devices, to allow the device itself to handle hardware-based decryption
transparently, or to obtain otherwise restricted information from the device, such as secret encryption keys.

some key one (and free) include

iphone-dataprotection - https://code.google.com/p/iphone-dataprotection/
– Brute force PIN code on device
– Recover device encryption keys
– Decrypt the keychain, all dataprotection encrypted files
– Scrape the HFS journal for deleted content
– Decrypt the entire raw disk

iPhone-Backup-Analyzer - http://www.ipbackupanalyzer.com/

The Sleuth Kit - http://sleuthkit.org/
– Supports NTFS, FAT, UFS 1, UFS 2, EXT2FS, EXT3FS, and ISO 9660

Other programs can include
– mmls – Media Management ls, generally partition info:
• fsstat – File system info and • fls – Forensic list
– Scalpel / Grep  / hexedit  / strings  /  exams on iPhone dmg

Worth considering though commerical
http://www.elcomsoft.com/ios-forensic-toolkit.html
http://www.oxygen-forensic.com/en/compare/devices/software-for-iphone

Check out more in this Foresnic wiki - http://www.forensicswiki.org/wiki/Apple_iPhone
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Rich RumbleSecurity SamuraiCommented:
The forensics packages offered by companies, and Zardanski, require you to prove your are in law enforcement. They all come with special add-on dongles that control what you can and can't do with your software as well as provide an interface into the devices.I'm not sure about Oxygen however, I do see they have a dongle too, but I don't know if they sell only to law enforcement.
ohh wait, looks like Elcomsoft changed!
Q. Do you limit usage of this product to law enforcement agencies only?
A. We used to, but not anymore.
Well I'll have to look into that option again.
I use XRY
http://forensicswiki.org/wiki/.XRY
I've tried most tools listed here: http://forensicswiki.org/wiki/Apple_iPhone (or tried to try them:)
You get most information from an iTunes backup file however, the other information on the phone pertains to the apps themselves and some position/geo-location data. The iTunes backup has what most people find the most important.
-rich
0
btanExec ConsultantCommented:
thanks for sharing, indeed most required LE based, other possibilities
iphone analyser (free) - http://www.crypticbit.com/zen/products/iphoneanalyzer
as a whole, i see that mixture and commercial available is worth the investment if going to do it on a perm basis and the recognition (or credibility) of such tool is critical as part of having to present a sound chain of evidence perspective, also evidence is more likely to be admissable if it is produced by a professional computer forensic analyst.

below is another longer list targeting free forensic software (there is mobile and MAC OS tools)
https://forensiccontrol.com/resources/free-software/
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Digital Forensics

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.