08 - Logical / File System Examination Flashcards

1
Q

Name a few good online Mobile Device Research sites?

A
  • GSM Arena (www.gsmarena.com)
  • Phonescoop (phonescoop.com)
  • Phonearena (phonearena.com)
  • Cellphone Knowledge Base (cpkb.org)
  • IMEI Information Sites
    • GSMA device check
    • Numberingplans.com
    • IMEI.info
    • imeidata.net
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are local device identification options?

A
  • Type in to get IMEI: *#06#
  • Labelling on device
  • Use Mobile Device Forensic Tool
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Explain Logical / File System Examination?

A

Logical uses (vendor) API. Acquisition may provide limited data. Connects via cable or wireless methods. File system uses proprietary commands. May require multiple examination methods (Android: ADB + Android Backup + Android Backup APK Downgrade). Can provide some deleted data from databases.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does a examination tool validation include?

A

Evaluation reports, the use of test devices, comparison with other tools, comparison with network CDR or with app records.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Name the three types of SIM UICC Reader?

A
  • integrated into tool
  • standalone tool
  • clone SIM function
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Why is an examination log so important?

A

Can contain application Version, OS version, license key, type of examination. Identifies the cable used, the communication port used. Shows AT commands to read out data. Very good for fault finding.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Explain the following AT commands:

  • AT+CGMI
  • AT+CGMM
  • AT+CGMR
  • AT+CGSN
  • AT+CIMI
  • AT+CNUM
  • AT+CPBR
A
  • Request ME manufacturer identification
  • Request ME model identification
  • Request ME revision identification
  • Request ME IMEI
  • Request IMSI
  • Request MSISDN
  • Read Phonebook Entries
How well did you know this?
1
Not at all
2
3
4
5
Perfectly