iXAMiner - The Key Features

Comprehensive acquisition file decoding and reporting

iXAMiner was designed to provide the forensic practitioner with an analysis and reporting tool which is able to securely extract data from downloads of iPhone devices. Its key features include:


• Non-invasive data analysis. No data is modified during the analysis process. Any new data created during analysis is stored in a completely separate folder tree, isolated from the input data. This, along with other features discussed below, preserves the forensic integrity of the data.


• Hash verification. iXAMiner keeps logs of all device data items which are used during the production of its report. Each class of data which is reported on includes a list of files used during its extraction, complete with MD5 and SHA1 hashes of those files.


• iTunes backup support. iXAMiner is able to expand the compressed iTunes backup format in order to reconstruct the original data as it was stored on the device, which it can then analyse in the normal way. Whenever a file derived from a backup in used in the analysis, the original backup file is also logged and hashed for verification purposes.


• Used and unused files. In order to expedite the generation of reports, iXAMiner produces, at the end of its analysis, a fully-hashed list of all files used during the analysis, plus a similar list of all files which were present in the download, but which were NOT used. It also produces logs of the analysis process itself, together with any and all issues which were detected during the analysis.


• iXAM® integration. iXAMiner can directly use an iXAM® download log as its data source. Thus, all the identification data which was captured by iXAM® is imported directly by iXAMiner, avoiding the need to re-enter the data and so eliminating a possible source of error. If an iXAM® download is used as the input data to iXAMiner, the contents of the iXAM® download log will be included in the iXAMiner analysis log.