Physical Extraction
Definition
An acquisition method that reads the raw storage medium, producing a bit-for-bit image from which allocated and deleted data can both be recovered. Requires bypassing device security and is not always achievable on modern encrypted devices without an exploit or the device passcode.
Related terms
- Logical Extraction
- NIST SP 800-101 R1 Level 2 acquisition. Uses the OS-exposed backup APIs (Android ADB backup, iOS iTunes/Finder backup, MTP for media) to...
- Cellebrite UFED
- Cellebrite Universal Forensic Extraction Device. The dominant commercial mobile forensics platform in Indian state cyber cells and at CFSL Hyderabad. Combines acquisition...
- Chip-Off
- NIST SP 800-101 R1 Level 5 acquisition. Desoldering the NAND or eMMC chip from the PCB and reading it directly with a...
- Device Profile
- A vendor-maintained database entry describing how to communicate with a specific make, model, and firmware version of a mobile device. The profile...
- Faraday Bag
- A signal-blocking pouch with conductive mesh lining that prevents cellular, Wi-Fi, Bluetooth and NFC signals from reaching a seized phone. The standard...
- JTAG
- Joint Test Action Group standard (IEEE 1149.1) for chip-level debugging. The test access port left on a phone's PCB lets a forensic...
- NIST CFTT
- The National Institute of Standards and Technology Computer Forensics Tool Testing programme. It publishes independent test reports for digital forensic tools, including...
- PCAP File
- A packet capture file storing raw network frames in the libpcap format. PCAP files are the standard exchange format between network forensic...
- Zeek (Formerly Bro)
- An open-source network analysis framework that processes live traffic or PCAP files and produces structured per-session log files covering DNS, HTTP, SSL,...
Explained in these topics
- Mobile and Network Forensics ToolchainsAn acquisition method that reads the raw storage medium, producing a bit-for-bit image from which allocated and deleted data can both be recovered. Requires by...
- Mobile Phone Forensics: Acquisition, JTAG and Chip-OffNIST SP 800-101 R1 Level 4 acquisition. Bit-for-bit image of the device's NAND flash, including unallocated space, system partitions and app sandboxes. Require...