Need advice on getting a quick FFS extraction to recover deleted messages (passcode known)
Hi everyone,
I am trying to run some quick forensics on one of my own devices to recover some deleted messages. I already pulled a standard unencrypted backup, but the specific messages I need are not visible there at all.
Because I have the passcode, BFU and AFU states are not relevant for this. I really just need to grab a Full File System (FFS) extraction so I can dig deeper into the databases and see what is left behind.
Does anyone have recommendations on the quickest way to obtain the FFS and run the analysis? I would appreciate any advice on tools or workflows that are reliable and do not take a massive amount of time to get going.
Thanks in advance for any help!