Where possible a full file system or physical extraction of the device being examined should be taken, this ensures that all potentially relevant data is retrieved from the device as per 2.2.5 of the ACPO Guidelines for Computer Based Evidence, where it states:
2.2.5 This may be a physical / logical block image of the entire device, or a logical file image containing
partial or selective data (which may be captured as a result of a triage process). Investigators should
use their professional judgement to endeavour to capture all relevant evidence if this approach is
adopted.

Unless the case is particularly basic, the investigator is unlikely to be able to assess whether an area of the phone contains relevant evidence until it has been examined and it cannot be examined without first being downloaded.
However, differently to the acquisition of most computers, the ability to acquire a full file system or physical extraction can vary greatly from device to device.
If either type of extraction is possible then the investigator should have system and application files included within the download that may include information to assist in the investigation and, any of which, may be relevant to the case.
Android Partitions
Boot Partition – The Boot partition enables the phone to boot and consists of the kernel and ramdisk.
System Partition – The System partition contains the Android interface and binaries as well as all of the pre-installed applications.
Recovery Partition – The Recovery partition contains a minimal failsafe boot image and allows the device to boot if the main boot partition fails. It includes the recovery console through which updates and other system functions can take place.
Data Partition – The Data partition contains most user data and is the location of the application data and communication information, such as call records and messages. This is where the majority of forensic evidence will be located and is wiped when a factory reset is performed.
Cache Partition – The Cache partition contains frequently accessed application data as well as recovery logs and downloaded update packages.
Misc Partition – The Misc partition contains system settings in form of carrier, USB and hardware settings.
Android – Standard Database Locations
The Android operating system contains a number of standard databases that can contain significant information, including calls, messages, contacts and Internet browsing history.
Stored Contacts – Contacts stored to the phone are located within an Sqlite database at the path \data\data\com.android.providers.contacts\databases\contacts2.db.
SMS and MMS Messages – Any sent and received SMS and MMS messages are stored within the database named mmssms.db that is located at the path \data\data\com.android.providers.telephone\databases.
User Accounts – The users accounts, including usernames and the provider are stored within the file named accounts.db at the path \data\system\users\.
User Dictionary – The user_dict.db database is located within the path \data\user\com.android.providers.userdictionary\databases\ contains frequently used words and user defined words for the predictive text facility.
In addition, the dynamic dictionary file named dynamic.lm located at the path \data\com.sec.android.inputmethod\Swiftkey\user\ contains new and learned words entered or accepted by the user.
This can contain unique words, including usernames and the names of contacts.
Calendar – Any calendar entries can be found within the database named calendar.db located at the path \data\com.android.providers.calendar\databases\.
Network Usage – Can contain the cellular and WLAN usage and location activity and is located within the path \data\com.google.android.gms\databases.
Internet Browsing History – The path \data\data\com.android.browser\databases\ may contain various databases, including browser2.db, browser.db and webview.db that may provide Internet browsing history activity.
Android – Installed Applications – Localappstate.db
In order to identify which applications are installed on the device, the file at the path data\data\com.android.vending\databases\library.db. There are others that contain more limited information, however, this file consists of a database that includes the name of the application, the time of download and the user. It can include applications that have been removed or deleted as well as applications installed onto other devices.
Then the data\data directory can provide a source to determine which applications are currently installed on the device.
The directory \data\data\com.android.vending\databases\ contains a database file named localappstate.db that contains the name of the application, the user registered to it and the date/time of download.
Android – Usagestats
The directory \data\system\usagestats\ contains daily, monthly and annual application use activity records and can include the number of seconds of use for each installed application as well whether the application was moved to the background, foreground and change of settings (lastevent).
Android – Batterystats
The directory \system\ contains a file named batterystats-daily.xml and the directory \data\data\com.google.android.gms\shared_prefs\ contains a file named batterystats.xml. These files relate to a tool within Android that collects battery data, including which application was active during a specific period of time and the amount of battery that it had used over that time.

About Athena Forensics
For information on our digital forensic services or if you require any advice or assistance please contact a member of our team on 0330 123 4448 or via email on enquiries@athenaforensics.co.uk, further details are available on our contact us page.
Our client’s confidentiality is of the utmost importance. All correspondence is treated with discretion, from initial contact to the conclusion of any mobile phone or computer forensic investigation.
Our digital forensics experts are fully aware of the significance and importance of the information that they encounter and we have been accredited to ISO 9001 for 10 years.
Our forensic experts are all security cleared and we offer non-disclosure agreements if required. Our premises along with our security procedures have been inspected and approved by law enforcement agencies.
Athena Forensics do not disclose personal information to other companies or suppliers.
https://athenaforensics.co.uk/service/computer-forensic-experts/
https://athenaforensics.co.uk/service/mobile-phone-forensic-experts/