IOS is the operating system using Apple's mobile devices before discussing what data can be extracted from an IOS device before you need to understand how Dad is written on its flash storage.
IOS devices used H F s X file system,
which is a very innovative EST plus file system developed by Apple.
It serves as the primary file system for Mac OS devices.
The main difference between H F S X and H F s Plus is that H F S X is case sensitive.
Where is H? F S Plus is not
h. F s plus is an improved version of a Professor Apples Legacy file system, also known as hierarchal file system.
The new version of H. F s has many improvements from the older version, especially in terms of space utilization.
H. F s farms are divided into logical blocks that are 512 bytes in size.
Logical blocks a group together its allocation blocks.
The allocation blocks contain one or more logical blocks, depending on the total size of the disc.
H F s used a 16 feet value for addressing allocation blocks, which became a limitation with the growing size of the disc
to overcome the addressing limitations of H. F S. Apple created H. F S plus
in this upgraded file system, Logical Blocks renamed two sectors but remained 500 bytes in size.
Allocation Block's still contained one of more sectors, depending upon the size of the disc.
with H F s plus a 32 bit value is used for addressing allocation blocks. Therefore, H F s plus is capable of addressing significantly more blocks.
H F s plus supports longer found names up to 255 characters, compared to 31 character's name. Profess larger file sizes and unicode for found name and coding in place of the Mac Roman and coating used in the H of X file system,
H F s plus also implemented journaling, which is a way of keeping track of every transaction made to the disk.
Journaling helps makes recovery faster in the event of a system crash or power failure.
A typical H F s plus volumes shown here consists of nine important segments.
Let's have a look at the H f s plus volume structure.
The 1st 2 sectors of the volume Serum one reserved his boot books
Sector two volume matter contains information about the volume itself,
such as the size of allocation blocks and size and location of other special files.
Next is the allocation file.
This important, Paul keeps track of the usage of allocation blocks, noting which ones are free and which ones are e news.
It also maintains a bit map with each bit represents an allocation block.
The biggest set a zero. The block is free if it set the one it's in use.
Another special filing nature fest, plus volume is a catalog file.
This file defines a folder and follow hierarchy of the volume and can be used to easily identify the location of a specific foul or folder within the file system.
The extents overflow foul stores Information about additional extents assigned to a foul
an extent is a contiguous allocation block that belongs to a file
and extended, represented with a pair of numbers starting allocation block and the number of allocation blocks it in the extent
the first aid extensive of foul recorded in the catalog foul or the remaining extents are stored in the extents overflow foe.
The Attributes file contains attribute information about files and folders on the file system.
The start of foul contains information that helps booting computers lack building support for H F S plus file systems.
Ultimate volume header is stored in the second to last sector of the volume.
It stores a backup copy of the volume header.
Finally, the last sector of the vote is reserved for use by Apple and is used during the computer manufacturing process.
Apart from these nine structures, the remainder of the volume is either occupied with foul data or it's free space.
Apple is always evolving its equipment and supporting software. The Apple file system was designed to replace the H. F S plus file system in all apples devices, including iPhones, IPADS, Apple watches, Apple TVs and Mac Books.
It was first released with Mac OS Sierra and I OS 10.3.
According to Apple, some of the features of this new phone system includes stronger encryption, space sharing, fast directory sizing and improved file system fundamentals.
Now let's look at foul system partitions.
There are two main partitions in an IOS device system partition, which is also called the route or firm, or partition and the data partition.
The system partition contains IOS operating system and the applications that come packaged with it.
This partition can be found a slash dev slash disc zero s one or slash dev slash disc zeros one s one and is mounted at the root of the foul system. Slash
It is mounted as read only unless enough great is in progress. Where the device is Joe broken.
The size of the partition is 1 to 4 gigabytes, depending on the size of the total storage.
Because it's partitions read only and contains OS and pre installed applications only. Hardly any evidence can be found in this partition.
But if the device is joe broken, this partition may hold user data.
Remainder of the file system is occupied by the data partition it good things user and sold applications and dad associate ID with the applications, which can be extremely crucial for investigations.
This partition is the gold mine for forensic analyst and has found a slash dev slash disc zero s too
slash dev slash disc zero es tu es tu In his mount of that slash private slash v a r,
they're too foul for mass commonly found in IOS devices.
There are the property list files used for storing configurations and the sq a light databases used for storing data.
Property list files, also called the Peerless Files, are an easy way to store simple structure data.
They're commonly used for storing application settings and operating system configurations.
These Air XML for mental files that can be analyzed using a simple text editor.
A number of free, simple text editors are available is what was property list editor for the Mac Environment and P List editor for the winners Environment.
All of these application can be used for analyzing Felix files.
An example. Peerless follows. Shown here,
it's been open using P List editor.
The file shows that a couple of key value pairs of the fine
some key value pairs are also bundled up in dictionary type class.
This *** symbol for matter of pillows folk can also be viewed in the text editor, as shown in the bottom section of the P list editor.
Ask your light database. Another important structure used in IOS devices stores large amounts of data such as user data created within a nap,
de bras of rescue, a light rest your light database browser or free throw is available for both Windows and Mac environments. It can't be used for analyzing its cure like that. A basis
as shown here, The Net Usage Daughter s Q. A light foul is open from an IOS device using database browser for rescue A light.
This example shows all the S S I d s the IOS devices connected to