ONLINE MDF: Mobile Device Forensics

***MOBILE DEVICE FORENSICS: ONLINE COURSE AND CERTIFICATION****

The IACIS Online Mobile Device Forensics Training Program is a 36-hour course of instruction being offered online. Upon completion, students have the opportunity to take the online Mobile Device Certification exam at no additional charge.

The program is designed to provide students with intermediate to advanced skills to analyze and interpret data during cell phone investigations.  This course goes behind the popular tools currently in use to reveal the sources of cell phone data used to store evidence.  At the completion of the course students will be confident in knowing they can gather and explain all data they have located during their examinations.  Students should have some experience in conducting cell phone examinations.

** UPDATE** This vendor neutral course has been completely redesigned to include more hands-on Android and iOS student practicals based on the most current operating systems.  

Topics include but are not limited to:

  • Acquiring file system and physical images from phones, to include handling and procedures for locked devices
  • Students will learn how to acquire cell phone data, and the different types of techniques to obtain the most relevant data.
  • There is some usage of command line to conduct the practicals. The commands are explained in detail; however, some students may find previous command line experience helpful.
  • Students will learn through hands-on exercises how the file systems are laid out in both iOS and Android, allowing them to find the data they are looking for quickly and be able to interpret it. This knowledge will carry over to new releases of the operating systems ensuring students can continue to stay current.
  • Validating data obtained from forensic tools, including data that tools miss.
  • Students will learn advanced third-party application analysis to interpret, recognize and decode artifacts stored by these applications.
  • Flash Memory, NAND Ram Architecture and learn how cell phones store their data at the physical level.
  • Obtaining and processing iOS backup files, including manual decoding, parsing and cracking of encrypted backup file images.
  • Viewing and interpreting iOS files such as plists to obtain valuable evidence.
  • Students will learn to use ADB and manually extract data from an Android device for those times when a commercial tool is unable to.
  • Students will learn about using python scripts and how to use them to enhance the data they can obtain during their examinations including manual application use of the queries.
  • Understand how SQLite databases function and how the data is stored, including how to use simple queries to manually parse the data.

PREREQUISITE: Basic Computer Forensic Examiner [BCFE] course AND completion of the Certified Forensic Computer Examiner [CFCE] certification are highly recommended, but not required.

CERTIFICATION: Completion of the online MDF course entitles each member to one attempt at the ICMDE Certification process.  The attempt must be completed within the time frame of your online cycle.  Each online class cycle is three months, a fourth month is allowed for testing.

WHEN:

Offered quarterly. If available, the offering will be posted HERE.

REGISTRATION:

Existing IACIS members simply log in with your credentials and go to the products page to purchase and register for the course.

For non-IACIS members, the membership fee is waived with the purchase of the training course; however, to register for the course you must complete a membership application at the time of purchase.

Membership for existing members who pay for the course will be waived for 2020. Non-IACIS members will receive membership from 10/1/19-12/31/2020.

Apply for membership and purchase the course on the PRODUCTS PAGE

COST: $995 US Dollars

  • Cancellation of this class may occur if there are insufficient students registered. In the event of a cancellation, personnel will typically be notified by email within 48 hours of the registration closure date. IACIS is not responsible for any individual expenses incurred as a result of a cancellation. The limit of IACIS financial liability is a full refund of the course fee.

****Payment MUST BE RECEIVED at least 45 days prior to the first day of class. Any payment arrangements other than payment through the website or payment via invoice must be approved by the IACIS Treasurer prior to admittance into the course. Please contact the treasurer for questions and approval (treasurer@iacis.com).  Cancellations within 45 days from the start of class to 30 days from the start of class will be subject to a $150 cancellation fee. There will be no refunds within 30 days from the start of class.****

Software needed by students for the class:

TWRP 3.0

ODIN 3.10.7

ADB-1.4.2

Netcat-win 32-1.12

Hashcat 4.0.1

Strawberry Perl 5.26.2.1

Plist Editor Pro

Elmcomsoft Phone Breaker

Python – 2.7.9 or 2.7.11 or 3.5.1

SIM card data

Zimmerman Hasher

Time Lord

SQLite Studio

7zip

SQ Lite Browser

Sanderson SQLite Studio,Binary Plist Decoder, Date Decoder

Minimal ADB fastboot DB Browser3.10.1

Plist Explorer