The following presentation was delivered by Chris Triplett, viaForensics’ Sr. Forensics Engineer, at the HTCIA New York Chapter meeting on March 22, 2013.
Abstract: Forensic software can make your life as an investigator much simpler but is limited in scope when it comes to extracting all the evidence from an Android phone. A thorough understanding of how the underlying file system functions can give you additional capabilities when a case demands more than just typical point and click forensics. We will cover the various Android file systems and dive low-level into NAND memory and how data is being manipulated behind the scenes. We will also demonstrate some of the powerful capabilities of viaExtract, our Android logical tool.