Glossary term
Chip-Off Forensics
Chip-off forensics is the technique of physically desoldering the memory chip (eMMC, eMCP, or NAND) from a device's logic board and reading the raw flash directly with a specialized programmer.
Chip-off is the last-resort acquisition technique. It is destructive to the source device, so it is reserved for cases where conventional acquisition methods have failed and the matter justifies destruction.
The process requires specialized equipment: microscope, hot-air rework station, BGA reballing tools, and manufacturer flash programmers. The chip is desoldered carefully to avoid heat damage to the silicon, the contact pads are reballed, and the chip is mounted in a programmer that reads the raw flash content.
The recovered image is then parsed with forensic tools (Cellebrite, Magnet AXIOM) to reconstruct the file system and extract user data.
Common chip-off scenarios include water-damaged phones where the board has corroded but the chip is intact, fire-damaged phones where the chassis is destroyed, devices that have been physically broken, and devices where the secure element is functional but the rest of the board is not.
We perform chip-off in-house at our Langley lab, which is rare among Canadian forensic boutiques. We give counsel a written feasibility opinion before authorizing destructive work.
