Mobile Forensics

This intensive 3-day course equips cybersecurity professionals with the foundational and practical skills required to master mobile forensics on modern smartphone platforms. Through guided labs and structured analysis exercises, participants will learn how data extracted from mobile devices reveals critical evidence in live investigations, app-based malware infections, and advanced mobile threat activity.

The training begins with core concepts such as mobile OS architecture (Android and iOS), file systems, sandboxing, and data storage mechanisms, then progresses into real-world investigations using logical, file system, and physical acquisitions. Students will explore how modern mobile threats leverage stealthy techniques such as sideloaded malicious apps, encrypted messaging, and obfuscated persistence mechanisms.

Participants will gain hands-on experience with industry-standard tools and frameworks for mobile data acquisition, timeline reconstruction, and forensic artifact analysis. Special emphasis is placed on app behavior analysis, encrypted communication tracing, and detecting signs of compromised or jailbroken/rooted environments that bypass traditional detection methods.

By the end of the course, students will confidently extract and analyze mobile artifacts, identify indicators of compromise (IOCs), and reconstruct attacker behavior using data recovered from smartphones and tablets. This course bridges low-level mobile forensics with real-world incident response, making it essential for DFIR professionals, mobile threat hunters, and security teams focused on modern mobile device investigations.

Course curriculum

    1. Introduction to Mobile Forensics

    2. Definitions and Types of Extractions

    3. Android and iOS Evolution

    4. Modern Acquisition Challenges

    5. Imaging Strategies

    6. Tools for Acquisition

    7. Image Handling and Validation

    8. Android Artifacts Locations

    9. iOS Artifacts

    1. Setting up the environment

    2. Manual Data Extraction using ADB

    3. Device Screenshots with adb2rec

    4. Extracting Information with Android Triage

    1. Basic Mobile Forensic Triage

    2. Analyzing Databases

    3. WhatsApp Parser

    4. Analyzing The User Folder

    5. Analyzing Metadata on Media Files

    6. Analysis using ALEAPP and MobSF

    7. Analysis using Autopsy and XAMN Viewer

About this course

  • $299.00
  • 20 lessons
  • 4.5 hours of video content

Requirements

While not mandatory, it is recommended that participants have the following tools installed to fully engage with the hands-on exercises:

  • Tsurugi OS VM
  • Windows Flare VM

These tools will enhance your ability to work effectively with the course materials and practical exercises.