Chip-Off
Definition
NIST SP 800-101 R1 Level 5 acquisition. Desoldering the NAND or eMMC chip from the PCB and reading it directly with a NAND reader (UFI Box, eMMC Pro, Medusa Pro). Destructive to the device and effective when JTAG access is unavailable or the board is damaged.
- Technique type
- Destructive physical acquisition
- Components accessed
- NAND or eMMC memory chips
- NIST classification
- Level 5 acquisition per NIST SP 800-101 R1
Common questions
What is chip-off in mobile forensics?+
Chip-off is a destructive physical acquisition technique where the NAND or eMMC memory chip is desoldered from the phone's circuit board, then read directly with a specialist programmer. It is used when other acquisition methods are unavailable or the device is physically damaged.
When would a forensic examiner use chip-off?+
Chip-off is employed when JTAG access is unavailable or the phone's motherboard is too damaged for other techniques. Because it destroys the device, examiners use it as a last resort to recover data from a phone that cannot be accessed through non-destructive methods.
What tools are used for chip-off acquisition?+
Specialist NAND readers and programmers are used to read the desoldered memory chip directly. Common tools include UFI Box, eMMC Pro, and Medusa Pro, each designed to interface with and extract the raw data from mobile memory chips.
Related terms
- Faraday Bag
- A signal-blocking pouch with conductive mesh lining that prevents cellular, Wi-Fi, Bluetooth and NFC signals from reaching a seized phone. The standard...
- CDR
- Call Detail Record. Telco-side log of A-party, B-party, start time, duration, IMEI, IMSI and serving cell ID. Lawful-intercept output under the IT...
- Cellebrite UFED
- Cellebrite Universal Forensic Extraction Device. The dominant commercial mobile forensics platform in Indian state cyber cells and at CFSL Hyderabad. Combines acquisition...
- FDE
- Full Disk Encryption. Default on modern Android (file-based encryption since Nougat) and iOS. Encryption keys are tied to the user passcode and...
- ICCID
- Integrated Circuit Card Identifier. The serial number of the physical SIM card itself, stored in EF_ICCID. It identifies the card as a...
- IMEI
- International Mobile Equipment Identity, a 15-digit identifier of the handset hardware. Format is 8-digit TAC + 6-digit serial + 1-digit Luhn check....
- IMSI
- International Mobile Subscriber Identity. A 15-digit number stored in EF_IMSI on the SIM that uniquely identifies the subscriber account on the mobile...
- JTAG
- Joint Test Action Group standard (IEEE 1149.1) for chip-level debugging. The test access port left on a phone's PCB lets a forensic...
- Logical Extraction
- NIST SP 800-101 R1 Level 2 acquisition. Uses the OS-exposed backup APIs (Android ADB backup, iOS iTunes/Finder backup, MTP for media) to...
- MSISDN
- Mobile Station International Subscriber Directory Number. The dialable phone number. Stored on the HLR, not always on the SIM.
- Physical Extraction
- An acquisition method that reads the raw storage medium, producing a bit-for-bit image from which allocated and deleted data can both be...
Explained in these topics
- Mobile Phone Forensics: Acquisition and ExaminationDestructive physical acquisition. The NAND or eMMC chip is desoldered from the PCB, read on a specialist programmer, and the raw image is parsed offline.
- Mobile Phone Forensics: Acquisition, JTAG and Chip-OffNIST SP 800-101 R1 Level 5 acquisition. Desoldering the NAND or eMMC chip from the PCB and reading it directly with a NAND reader (UFI Box, eMMC Pro, Medusa Pr...