§ Guide, full text

IOS App Data And Third Party Application Forensics

iOS apps are individual worlds of evidence, each storing data uniquely. This guide explores how to recover and interpret this data, address in g common mistakes and technical limitations. It provides guidance on when to involve a digital forensic expert for third-party application forensics.

17 pages · 25 min read

Loading the PDF reader

IOS App Data And Third Party Application Forensics

IOSAPPDATA · A GUIDE FOR UK LAWYERS iOS App Data and Third-Party Application Forensics Every App Is Its Own World: Dating Apps, Marketplaces, Rideshare, Banking and the Rest COMPUTER FORENSICS LAB

§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM

§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: every app is its own world 03 How iOS apps store their data 04 What different apps record 05 Recovering and understanding app data 06 Interpretation, attribution and honest limits 07 Deployment: the evidence inside the apps 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist

§ 01 · ORIENTATION Executive summary The headline point: a phone is a collection of apps, each its own world of evidence, dating, marketplace, rideshare, payment, journal and more, and because every app stores its data differently there is no single correctly rather than guess.

§ 02 · FIRST PRINCIPLES The problem in plain English: every app is its own world

§ 03 · HOWAPPSSTOREDATA How iOS apps store their data

§ 04 · WHATAPPSRECORD What different apps record

§ 05 · RECOVERINGANDUNDERSTANDING Recovering and understanding app data

§ 06 · INTERPRETATIONANDHONESTLIMITS Interpretation, attribution and honest limits

§ 07 · DEPLOYMENT Deployment: the evidence inside the apps

§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE COUNTERPART APP ON APP CLOUD / BACKUPS / PAIRED PROVIDER PHONE ACCOUNT ICLOUD MAC / IPAD RECORDS

§ 09 · IN THE WILD Worked examples EXAMPLE1 · THEDATINGAPPTHATEVIDENCEDTHEMEETING EXAMPLE2 · THEMISREADFIELDTHATNEARLYMISLED EXAMPLE3 · THERIDESHAREANDPAYMENTAPPSTHATTRACEDTHEDAY

§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations

§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider SUGGESTED WORDING · INSTRUCTIONFORATHIRD - PA RTYAPPANA LY SIS

§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The third-party app checklist Red flags When to involve a digital forensic expert

§ 13 · COMMON QUESTIONS Frequently asked questions Why isn't there one method for reading all apps? What kind of evidence do apps hold? How do you avoid misreading an unfamiliar app? Can deleted app data be recovered? Do we need to look beyond the phone for app data? Does app activity prove the phone's owner did it?

§ 14 · REFERENCE Glossary Sources and authoritative references DISCLAIMER

§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY

Cite as: Joseph Naghdi, IOS App Data And Third Party Application Forensics, Computer Forensics Lab, https://e-discovery.uk/library/ios-app-data-and-third-party-application-forensics/pdf.

Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp