MOBILE FORENSICS

The iOS file system explained in simple terms

An iPhone’s file system forms the basis of virtually all digital traces. Photos, messages, app data and system information are stored in a structured manner. In IT forensics, understanding this structure is crucial for correctly locating and analysing artefacts.

App sandboxes
System data
User data
Minutes
Databases (e.g. SQLite)
Cache and configuration files

TECHNICAL BACKGROUND

Technical Fundamentals

Current iPhones use the Apple File System (APFS). Applications run in separate sandboxes and are generally only granted access to their own data. The operating system automatically manages permissions, encryption and storage structures.

Areas of forensic relevance include, amongst others:

  • App sandboxes
  • System data
  • User data
  • Minutes
  • Databases (e.g. SQLite)
  • Cache and configuration files

OUR APPROACH

This is how your examination will be carried out

A transparent process – from the initial enquiry to the handover of the report.

1
Depending on the device, iOS version and backup method, the available file system data is analysed in a structured manner. Relevant artefacts are analysed using recognised forensic tools as well as manually. All findings are documented in a transparent manner.
2
LanCologne produces expert reports for private individuals, as well as for companies and solicitors. Our reports have already been used in court proceedings. In some cases, we have been directly commissioned to produce IT forensic reports. Upon request, we can provide anonymised or redacted reference reports or extracts.

TYPICAL QUESTIONS

When is this analysis required?

  • Where is app data stored?
  • What does ‘the sandbox’ mean?
  • Which artefacts can be examined?
  • Which data is encrypted?
  • How does the iOS version affect the analysis?

LIMITATIONS & CONCLUSION

What you should know

Not every device allows full access to the file system. The data available depends, amongst other things, on the device model, the version of iOS, the type of backup and the permissions in place.

A thorough understanding of the iOS file system is the foundation of any professional iPhone forensic investigation. Only then can digital evidence be correctly interpreted and reliably assessed.

CUSTOMER REVIEWS

What our customers say

4.8 out of 5 stars on Trustpilot · 54 reviews

★★★★★

“The highest standards of professionalism, prompt service and excellent communication. They made the seemingly impossible a reality. This is what genuine customer service is all about – unrivalled in Germany!”

idalein

Verified review on Trustpilot

★★★★★

“Very helpful advice, excellent responsiveness and communication. My problem was completely resolved and the lost data was recovered. I’m very satisfied and, of course, relieved!”

Layla Pankratz

Verified review on Trustpilot

★★★★★

“My problem was sorted out professionally and quickly; everyone I spoke to was always friendly, and I can still get in touch if I have any questions – I’m very grateful for that!”

a woman from Cologne

Verified review on Trustpilot

Enquire now – free initial consultation

Do you need a professional analysis of an iPhone file system or individual artefacts? LanCologne can assist you with an objective IT forensic investigation.

RELATED TOPICS

You might also be interested in

FREQUENTLY ASKED QUESTIONS

Frequently Asked Questions

Click on a question to see the answer.

What is a sandbox?
An isolated storage area in which each app manages its own data.
Does iOS use APFS?
Yes. Current iPhones use the Apple File System (APFS).
Is it always possible to scan the entire file system?
No. The scope depends on the technical capabilities of the data backup system.
Why are SQLite databases important?
Many apps store their data in SQLite databases.
Can an expert report be drawn up on this?
Yes, provided that this forms part of the terms of reference for the investigation.