Logical Acquisition
Definition
An extraction method that uses the device's own operating system interfaces, such as iTunes backup or Android Debug Bridge, to export the data the OS makes available. Fast and non-invasive, but limited to data the OS exposes and cannot recover deleted content from unallocated storage.
- Method
- Uses OS interfaces (e.g., iTunes backup, ADB)
- Speed
- Fast and non-invasive
- Limitation
- Limited to data the OS exposes
- Cannot recover
- Deleted content from unallocated storage
Common questions
When would an examiner choose logical acquisition over a full physical extraction?+
Logical acquisition is often chosen when time is limited, the device cannot be jailbroken or rooted safely, or the investigation only needs data the user account can already see, such as contacts, messages, and app data. It is also the lowest-risk option for devices where a physical extraction attempt could brick or lock the device.
What kinds of evidence are missed by a logical acquisition?+
Deleted files still sitting in unallocated space, data hidden by apps outside the standard OS backup scope, and some system-level artefacts are not captured, because logical acquisition only exports what the device's own backup or debugging interface chooses to expose. A physical or file-system acquisition is needed to reach that additional data.
Does logical acquisition alter data on the source device?+
It can, to a limited extent, since triggering a backup or debug connection may update timestamps or trigger synchronisation processes on the device. Examiners document the exact interface and commands used, and where possible use device settings or write-blocking measures to minimise any change.
Related terms
- Chain of Custody
- The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
- Packet Capture (PCAP)
- The interception and recording of network packets as they traverse an interface. The raw data is stored in PCAP format and analysed...
- Physical Acquisition
- An extraction method that reads the raw flash storage of a mobile device, bypassing the operating system. Produces a bit-for-bit image of...
- AFC (Apple File Conduit)
- The iOS service that exposes the media partition for file transfer during synchronisation. In standard form it only surfaces the media partition;...
- Android Debug Bridge (ADB)
- A command-line tool included in the Android SDK that allows communication with an Android device over USB or Wi-Fi. Used for logical...
- Cell Site Analysis
- The use of records from mobile network operators showing which cell towers a device connected to and when, allowing investigators to establish...
- Faraday Isolation
- Shielding a mobile device from radio frequency signals (cellular, Wi-Fi, Bluetooth, GPS) using a Faraday bag or cage, preventing network connections that...
- File-System Extraction
- A deeper form of extraction that retrieves the full accessible directory tree by mounting the file system or using a privileged API...
- IMEI (International Mobile Equipment Identity)
- A unique 15-digit number permanently assigned to a mobile device's hardware. Used by networks to identify and block stolen devices, and by...
- iTunes Backup Protocol
- Apple's proprietary protocol for transferring device data to a computer. Used by forensic tools to conduct logical acquisition of iOS devices; backup...
- Trust Relationship (iOS)
- The pairing between an iOS device and a computer established when the user taps 'Trust' after connecting. A forensic logical or file-system...
- Write Blocker
- A hardware or software device interposed between a digital storage medium and the forensic workstation that prevents any write commands from reaching...
Explained in these topics
- Digital Evidence in Mobile and Network ContextsAn extraction method that accesses a mobile device through its operating system interfaces (such as USB backup protocols or vendor forensic APIs) to retrieve f...
- Logical and File-System AcquisitionExtraction of mobile device data through the operating system's own synchronisation or backup API. Returns a structured set of files and records the OS is will...
- Mobile and Network Forensics: Scope and Discipline