Android Forensic Setup and Pre-Data Extraction Techniques

In the previous chapter, we covered the fundamentals of the Android architecture, security features, filesystems, and other capabilities. Having an established forensic environment before the start of an examination is important, as it ensures that the data is protected while you, as the examiner, maintain control of the workstation. This chapter will explain the process of—and what to consider when—setting up a digital forensic examination environment. It is paramount that you maintain control of the forensic environment at all times; this prevents the introduction of contaminants that could affect the forensic investigation.

We will cover the following topics in this chapter:

Get Practical Mobile Forensics - Fourth Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.