Logical Extraction
Definition
NIST SP 800-101 R1 Level 2 acquisition. Uses the OS-exposed backup APIs (Android ADB backup, iOS iTunes/Finder backup, MTP for media) to copy files the OS chooses to expose. Fast and non-destructive but limited to what the OS reveals; system files, deleted records and many app sandboxes are not included.
Related terms
- Physical Extraction
- An acquisition method that reads the raw storage medium, producing a bit-for-bit image from which allocated and deleted data can both be...
- Cellebrite UFED
- Cellebrite Universal Forensic Extraction Device. The dominant commercial mobile forensics platform in Indian state cyber cells and at CFSL Hyderabad. Combines acquisition...
- Chip-Off
- NIST SP 800-101 R1 Level 5 acquisition. Desoldering the NAND or eMMC chip from the PCB and reading it directly with a...
- Device Profile
- A vendor-maintained database entry describing how to communicate with a specific make, model, and firmware version of a mobile device. The profile...
- Faraday Bag
- A signal-blocking pouch with conductive mesh lining that prevents cellular, Wi-Fi, Bluetooth and NFC signals from reaching a seized phone. The standard...
- JTAG
- Joint Test Action Group standard (IEEE 1149.1) for chip-level debugging. The test access port left on a phone's PCB lets a forensic...
- NIST CFTT
- The National Institute of Standards and Technology Computer Forensics Tool Testing programme. It publishes independent test reports for digital forensic tools, including...
- PCAP File
- A packet capture file storing raw network frames in the libpcap format. PCAP files are the standard exchange format between network forensic...
- Zeek (Formerly Bro)
- An open-source network analysis framework that processes live traffic or PCAP files and produces structured per-session log files covering DNS, HTTP, SSL,...
Explained in these topics
- Mobile and Network Forensics ToolchainsAn acquisition method that retrieves data through the device's operating system or backup interface, producing only what the OS exposes. Faster and less invasi...
- Mobile Phone Forensics: Acquisition, JTAG and Chip-OffNIST SP 800-101 R1 Level 2 acquisition. Uses the OS-exposed backup APIs (Android ADB backup, iOS iTunes/Finder backup, MTP for media) to copy files the OS choo...