Elcomsoft iOS Forensic Toolkit

06.07.2012

Here you'll find everything from music, to SMS messages, Address Book Contacts, and even recorded Voice Mail messages (assuming they're using Visual Voicemail).

A lot of the files (like the Address Book) are stored as SQL database files, so you'll need an SQL browser to make sense of them. There's a pretty good one for the Firefox web browser called and an open source option called SQLite Database Browser . The User.dmg of an iPhone isn't exactly a user-friendly environment (it's not designed to be) so don't expect to be able to find everything at once, but it's all in there. Incidentally you can take a look at the contents of your user director from a backup using a program like .

We had a lot of success with our dead iPhone. In our case we found that we had to Jailbreak the device first, which managed to fix the battery problem and enable us to enter DFU mode to recover all the data. We could have just done an iTunes backup at this point, but then we wouldn't have figured out how to extract all data from an iPhone with forensics software. And we wanted to make sure we had it all safe and sound. After we had a decent backup of everything we did a Software Update to remove the Jailbreak and re-installed everything from the iTunes backup.

There are easier options available to you for data extraction that Elcomsoft's iOS Forensic Toolkit, and if you're just looking to backup and extract data you might want to investigate , which has a user-friendly interface and enables you to back up images, messages, emails, music and other content from an iOS device. Although PhoneView doesn't enable you to extract the passcode from the device, and only works if you have either the passcode or have synced the device with your computer. So it's okay for personal use but far less interesting to serious investigators.