Setting up a forensic environment for Android

As a forensic examiner, you may encounter a wide range of mobiles over the course of your investigation. Therefore, it is necessary to have a basic environment set up on top of which you can build based on requirements. It is also very important that you maintain complete control over the environment at all times to avoid any unexpected situations. Setting up a proper lab environment is an essential part of the forensic process. The Android forensic setup usually involves the following steps:

  1. Start with a fresh or forensically sterile computer environment. This means that other data is either not present on the system or is contained in a manner that prevents it from contaminating the present investigation.
  2. Install the basic software necessary to connect to the device. Android forensic tools and methodologies will work on the Windows, Linux, and macOS platforms.
  3. Obtain access to the device. You must be able to enable settings or bypass them in order to allow the data to be extracted from the Android device.
  4. Issue commands to the device using the methods defined in this chapter and in Chapter 9, Android Data Extraction Techniques.

The following sections provide guidance on setting up a basic Android forensic workstation.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.218.129.100