Programme Overview
Training Description
Police and other law enforcement personnel
Information security professionals
Defense and Security personnel
Incident response teams
Accident reconstruction investigators
e-Business Security professionals
Experienced digital forensic examiners
Legal professionals
Banking, Insurance, and other professionals
Government agencies
IT managers
Digital Forensics Service Providers
Session Objectives
- Select the most effective forensic tools, techniques, and procedures to effectively analyze smartphone data Reconstruct events surrounding a crime using information from smartphones, including timeline development and link analysis (e.g., who communicated with whom, where, and when) Understand how smartphone file systems store data, how they differ, and how the evidence will be stored on each device Interpret file systems on smartphones and locate information that is not generally accessible to users Identify how the evidence got onto the mobile device - we'll teach you how to know if the user created the data, which will help you avoid the critical mistake of reporting false evidence obtained from tools Incorporate manual decoding techniques to recover unparsed data stored on smartphones
About the Course
This advanced smartphone forensic course provides examiners and investigators with advanced skills to detect, decode, decrypt, and correctly interpret evidence recovered from mobile devices. The course features 31 hands-on labs, a forensic challenge, and a bonus take-home case that allows students to analyze different datasets from smart devices and leverage the best forensic tools, methods, and custom scripts to learn how smartphone data hide and can be easily misinterpreted by forensic tools. Each lab is designed to teach you a lesson that can be applied to other smartphones. You will gain experience with the different data formats on multiple platforms and learn how the data are stored and encoded on each type of smart device. The labs will open your eyes to what you are missing by relying 100% on your forensic tools.
Curriculum & Topics
6 Topics | 5 Days
-
Subtopic 1.1: Introduction to Mobile Device Forensics: Reviewing the mobile forensic process (identification, preservation, acquisition, analysis, reporting).
-
Subtopic 1.2: Legal and Ethical Considerations: Focusing on chain of custody, warrant requirements, and data privacy laws.
-
Subtopic 2.1: Acquisition Techniques: Detailed look at logical, file system, and advanced physical/chip-off extractions.
-
Subtopic 2.2: Bypassing Security: Methods for overcoming screen locks, PINs, and full-disk encryption.
-
Subtopic 3.1: Android File System Analysis: Understanding critical filesystems (e.g., ext4, f2fs) and key artifact locations.
-
Subtopic 3.2: Native and Third-Party App Data: Deep diving into data stored in SQLite databases, XML files, and log files.
-
Subtopic 4.1: iOS File System & Backups: Detailed analysis of the HFS+ / APFS file systems and parsing encrypted iTunes and iCloud backups.
-
Subtopic 4.2: System and User Artifacts: Examination of KnowledgeC, Health, Location services, and user activity traces.
-
Subtopic 5.1: Malware Detection & Analysis: Identifying traces of mobile spyware, rooting/jailbreaking, and malicious apps.
-
Subtopic 5.2: Countering Anti-Forensics: Techniques to expose data hidden by secure containers, burner apps, and data wiping.
-
Subtopic 6.1: SQLite Database Forensics: Manual parsing and recovery of deleted records from SQLite free pages.
-
Subtopic 6.2: Python Scripting for Forensics: Writing custom scripts to automate parsing of unsupported applications and complex data sets.