With mobile devices, the acquisition method determines whether a case can even proceed. For iOS, Belkasoft X covers agent-based acquisition, checkm8, lockdown files, AFC, jailbroken devices, crash logs, and screen capture.
On the Android side, the range extends from ADB backup, agent-based methods, and rooted devices to EDL for Qualcomm, MTK, and Spreadtrum acquisition, APK downgrade, and wireless acquisition via an agent on the SD card. Chip-off and JTAG dumps, as well as images from GrayKey, UFED, and OFB, are also imported.
On the computer side, Windows, macOS, and Unix systems are included, along with disk images in EnCase, FTK, X-Ways, AFF4, L01, DD, DMG, and archive formats, virtual machines, RAM dumps, hibernation, and page files. File systems from APFS to BTRFS and NTFS to ext4 and XFS are read directly.