Practical Mobile Forensics
上QQ阅读APP看书,第一时间看更新

Hex dump

A hex dump, also referred to as a physical extraction, is achieved by connecting a device to a forensic workstation and pushing unsigned code or a bootloader into the phone and instructing the phone to dump memory from the phone to the computer. Since the resulting raw image is in binary format, technical expertise is required to analyze it. The process is inexpensive, provides more data to the examiner, and allows the recovery of deleted files from the device-unallocated space on most devices.