File-System Extraction
Definition
A deeper form of extraction that retrieves the full accessible directory tree by mounting the file system or using a privileged API layer, yielding app containers and cache files beyond the backup API scope but still excluding unallocated sectors.
- Method
- Mounts the file system or uses a privileged API layer
- Yields
- App containers and cache files
- Excludes
- Unallocated sectors
- Depth
- Beyond backup API scope, short of full physical extraction
Common questions
How does file-system extraction sit between logical and physical acquisition?+
Logical or backup extraction pulls only what an app's backup API exposes, physical extraction images the whole storage chip including deleted and unallocated data, and file-system extraction sits in between, exposing the full accessible directory tree without reaching unallocated space.
What kind of evidence does file-system extraction reach that logical extraction misses?+
It reaches app-specific cache files, internal databases, and container directories that backup APIs deliberately exclude, which often hold richer usage history than what an app chooses to back up.
Related terms
- AFC (Apple File Conduit)
- The iOS service that exposes the media partition for file transfer during synchronisation. In standard form it only surfaces the media partition;...
- Android Debug Bridge (ADB)
- A command-line tool included in the Android SDK that allows communication with an Android device over USB or Wi-Fi. Used for logical...
- iTunes Backup Protocol
- Apple's proprietary protocol for transferring device data to a computer. Used by forensic tools to conduct logical acquisition of iOS devices; backup...
- Logical Acquisition
- An extraction method that uses the device's own operating system interfaces, such as iTunes backup or Android Debug Bridge, to export the...
- Trust Relationship (iOS)
- The pairing between an iOS device and a computer established when the user taps 'Trust' after connecting. A forensic logical or file-system...