• Home
  • /
  • Training
  • /
  • DF125 – Mobile Device Examinations with EnCase

DF125 - Mobile Device Examinations with EnCase

Course duration: 2 days

CPE Credits: 16

Delivery method: Group-Live

NASBA defined level: Basic

Prerequisites: Basic computer skills. Advance preparation is not required for this course.

Full List of Courses Available

Course Overview

This hands-on course provides practical demonstrations and real-life simulations to help understand the methodology of using EnCase Forensic and EnCase Mobile Investigator in mobile device examinations involving criminal, corporate, and civil investigations. This course will provide instruction related to the acquisition of mobile devices using EnCase Forensic followed by the examination via the use of EnCase Mobile Investigator (as well as EnCase Forensic).

The course will detail performing acquisitions from both a handset and a device backup followed by examination of devices running the mobile operating systems Android and Apple iOS.During class the automated examination functionality of EnCase Mobile Investigator / EnCase Forensic will be used as well as manual examination and via EnScript programs of file types, including SQLite databases and Apple property lists.

Students attending this course will learn the following:

  • The history of Android and Apple iOS mobile operating systems
  • How to prepare for and conduct an acquisition of an Android device
  • How to conduct an acquisition of an Android Samsung S5/S6 device via the android bootloader
  • How to conduct an acquisition of an Apple iOS device
  • How to conduct an acquisition of Apple iOS backup (including an encrypted backup)
  • How to examine the Android system, user, application, and Internet artifacts
  • How to examine the Apple iOS system, user, application, and Internet artifacts
  • How to conduct an examination of still and moving image file formats
  • Understanding the structure of file types and data structures, including (but not limited) to support mobile device applications and system artifacts:
    • SQLite databases
    • Apple property lists (pLists)
    • EXIF

Audience

This course is intended for digital forensic investigators, including law enforcement, government, military, corporate, IT security, and litigation support professionals who are seeking to analyze smartphones and mobile devices for evidence for criminal and corporate investigations.

Learn more about our training courses

We are excited about your interest in our courses and eager to provide you with all the details you need.

Send us a message via the contact form and we will get back to you as soon as possible.

Send us your enquiries