Before you image anything, Nugget wants to know: locked or unlocked, and since when.
Mobile forensics rewards patience with device state and punishes assumptions about it. Most of what goes wrong in casework happens before the imaging tool even opens — someone treats a warrant for the handset as a warrant for the iCloud account behind it, or trusts a physical extraction on a locked iPhone that turns out to be mostly ciphertext. Nugget works through those decision points with you: what's your legal authority for this store, what state is this device really in, what can that acquisition method actually yield given the encryption underneath.
A session usually starts with a scaffold, not a blank question. Nugget lays out a device timeline or sketches how Data Protection classes map to BFU and AFU states, then asks you to reason across it — what changes the moment this phone gets its first unlock, why does that matter for what you can recover. From there it moves into the artifacts themselves: SQLite files, WAL frames, plists, the raw data behind whatever a vendor tool's report claims it found.
This isn't a replacement for your coursework or your lab's SOP — it's a place to rehearse the judgment calls those don't have time to slow down for: epoch conversions, freelist reasoning, scope boundaries, the difference between a polished timeline and the database it was built from.
Start exploring Mobile Device Forensics tonight — a 30-day trial, cancel anytime.
Start your 30-day trial