Last Day to Save $400 on SANS Minneapolis 2015

FOR585: Advanced Smartphone Forensics

It is almost impossible today to conduct a digital forensic investigation that does not include a smartphone or mobile device. Smartphones are replacing the need for a personal computer, and almost everyone owns at least one. The smartphone may be the only source of digital evidence tracing an individual's movements and motives, and thus can provide the who, what, when, where, why, and how behind a case. FOR585: Advanced Smartphone Forensics teaches real-life, hands-on skills that help digital forensic examiners, law enforcement officers, and information security professionals handle investigations involving even the most complex smartphones currently available.

The course focuses on smartphones as sources of evidence, providing students with the skills needed to handle mobile devices in a forensically sound manner, manipulate locked devices, understand the different technologies, discover malware, and analyze the results for use in digital investigations by diving deeper into the file systems of each smartphone. Students will be able to obtain actionable intelligence and recover and analyze data that commercial tools often miss for use in internal investigations, criminal and civil litigation, and security breach cases. Students will walk away with knowledge they can immediately put to use on their next smartphone investigation.

FOR585: Advanced Smartphone Forensics you will learn:

  • Smartphone Capabilities: Determine the who, what, when, where, why, and how of a case. Who used a smartphone? What did the user do on a smartphone? Where was the smartphone located at key times? What online activities did the user conduct using a smartphone, and when?
  • How to Recover Deleted Data: Use manual decoding techniques to recover deleted data stored on smartphones and mobile devices.
  • How to Detect Data Stored in Third-Party Applications: Who did the user communicate with using a smartphone and why are these activities sometimes hidden?
  • How to Detect Malware: Detect smartphones compromised by malware using forensics methods.
  • How to Bypass Locks: Bypass, crack, and/or decode lock codes manually recovered from smartphones, including cracking iOS backup files that were encrypted with iTunes.

The hands-on exercises in this course cover the best commercial and open-source tools available to conduct smartphone and mobile device forensics, and provide detailed instructions on how to manually decode data that tools sometimes overlook. The course will prepare you to recover and reconstruct events relating to illegal or unauthorized activities, determine if a smartphone has been compromised with malware or spyware, and provide your organization with the capability to use evidence from smartphones.

This intensive six-day course will take your mobile device forensics knowledge and abilities to the next level. Smartphone technologies are new and constantly changing, most forensics professionals are unfamiliar with the data formats. It is time for the good guys to get smarter and for the bad guys to know that their texts and apps can and will be used against them!

Course Topics

  • Forensic Analysis of Smartphones and Their Components
  • Devices and Components:
    • Android
    • iOS
    • BlackBerry
    • Windows phone/Mobile
    • Nokia (Symbian)
    • Chinese knock-offs
    • SIM cards
    • SD cards
  • Deep-Dive Forensics Examination of Smartphone File Systems and Data Structures
    • Recovering deleted information from smartphones
    • Examining SQLite databases in-depth
    • Finding traces of user activities on smartphones
    • Recovering data from third-party applications
    • Tracing user online activities on smartphones (e.g., messaging and social networking)
    • Examining event logs
    • Manual decoding to recover missing data or verify results
  • Identification of Malware and Spyware on Smartphones
    • Determining if malware or spyware exist
    • Handling the isolation of the malware
    • Determining what has been compromised
  • In-Depth Usage and Capabilities of the Best Smartphone Forensics Tools
    • Data carving
    • Conducting physical and logical keyword searches
    • Conducting timeline generation and link analysis using information from smartphones
    • Reporting
    • Plotting geolocation information from smartphones and smartphone components
  • Handling Locked Devices
    • Extracting evidence from locked smartphones
    • Decrypting backups of smartphones
    • Manually cracking lockdown files for smartphones
    • Accessing locked SIM cards
  • Incident Response Considerations on Smartphones
    • How your actions can alter the device
    • Determining whether a memory capture can be conducted on the smartphone
    • How to prevent remote access on the device

Course Syllabus
Course Contents
  FOR585.1: Smartphone Overview and Malware Forensics
Overview

Focus: Although smartphone forensics concepts are similar to those of digital forensics, smartphone file system structures differ and require specialized decoding skills to correctly interpret the data acquired from the device. On this first course day, students will apply what they know to smartphone forensics handling, device capabilities, acquisition methods, and data encoding concepts of smartphone components. Students will also become familiar with the forensics tools required to complete comprehensive examinations of smartphone data structures. Malware affects a plethora of smartphone devices. This section will examine various types of malware, how it exists on smartphones, and how to identify it. Up to five labs will be conducted on this first day alone!

All examiners today have to address the existence of malware on smartphones. Often the only questions relating to an investigation may be whether a given smartphone was compromised, how, and what can be done to fix it. It is important for examiners to understand malware and how to identify its existence on the smartphone.

Smartphones will be introduced and defined to set our expectations for what we can recover using digital forensics methodologies. We review the properties of Flash memory in mobile devices and demonstrate the pros and cons from a forensics perspective. We provide approaches for dealing with common challenges such as encryption, passwords, and damaged devices. Students will learn how to process and decode data on mobile devices from a forensics perspective, then learn tactics to recover information that even forensics tools may not always be able to retrieve.

The SIFT Workstation has been specifically loaded with a set of smartphone forensics tools that will be your primary toolkit and working environment for the week.

Exercises
  • SIFT Workstation - Laboratory setup.
  • Hands-on demonstrations and familiarization with Smartphone forensics tools.
  • Two malware labs - Malware analysis, and unpacking and analyzing .apk malware files
  • JTAG password cracking lab - Load and crack an Android password from a JTAG image.
  • Introduction to data decoding - Manually decoding data records.

CPE/CMU Credits: 6

Topics

The SIFT Workstation

Malware and Spyware Forensics

  • Different Types of Common Malware
  • Common Locations on Smartphones
  • How to Determine a Compromise
  • How to Recover from a Compromise
    • What Was Affected?
    • How to Isolate?

Introduction to Smartphones

  • Smartphone Components and Identifiers
  • Assessing Capabilities of Evidential Devices
  • Common File Systems
  • Forensics Impact of Flash Memory
  • Data Storage Broken Down and Defined

Smartphone Handling

  • Preserving Smartphone Evidence
  • Preventing Data Destruction

Forensics Acquisition Concepts of Smartphones

  • Logical Acquisition
  • File System Acquisition
  • Physical Acquisition
  • Advanced Methods Acquisition

Smartphone Forensics Tool Overview

  • Physical and Logical Keyword Searching
  • Data Carving
  • Exporting and Bookmarking Data
  • Malware Scanning
  • Reporting

JTAG Forensics

  • What is JTAG?
  • How to Analyze Data Acquired Using JTAG Methods

Smartphone Components

  • SIM Card Handling and Examination
  • SD Card Handling and Examination
  • Manual Decoding of Recovered Data

Bonus Materials

  • Malware/Spyware Cheat Sheet
  • APK Decompiling Cheat Sheet
  • Mobile Device Repair
  • Acquisition of Smartphones
  • Acquisition of SIM Cards
  • Relevant White Papers and Guides
 
  FOR585.2: Android Forensics
Overview

Focus: Android devices are among the most widely used smartphones in the world, which means they will surely be part of an investigation that will come across your desk. Android devices contain substantial amounts of data that can be decoded and interpreted into useful information. However, without honing the appropriate skills for bypassing locked Androids and correctly interpreting the data stored on them, you will be unprepared for the rapidly evolving world of smartphone forensics.

Digital forensics examiners must understand the file system structures of Android devices and how they store data in order to extract and interpret the information they contain. On this course day we will delve into the file system layout on Android devices and discuss common areas containing files of evidentiary value. Traces of user activities on Android devices are covered, as is recovery of deleted data residing in SQLite records and raw data files.

During hands-on exercises, you will use smartphone forensics tools to extract, decode, and analyze a wide variety of information from Android devices.

Exercises
  • Manually cracking a lockcode on an Android device by accessing the file containing the passcode.
  • Manually decoding and extracting information from Android file systems and logical acquisitions.
  • Introduction to manually parsing third-party applications and deep-dive decoding and recovery of user activities on Android devices.

CPE/CMU Credits: 6

Topics

Android Forensics Overview

  • Android Architecture and Components
  • NAND Flash Memory in Android Devices
  • Android File System Overview

Handling Locked Android Devices

  • Security Options on Android
  • Obtaining Unlock Information
  • Demonstration of Bypassing Android Security
  • Practical Tips for Accessing Locked Android Devices

Android File System Structures

  • Defining Data Structure Layout
    • Physical
    • File System
    • Logical
  • Data Storage Formats
  • Parsing and Carving Data
  • Physical and Logical Keyword Searches

Android Evidentiary Locations

  • Primary Evidentiary Locations
  • Unique File Recovery
  • Parsing SQLite Database Files
  • Manual Decoding of Android Data

Traces of User Activity on Android Devices

  • How Android Applications Store Data
  • Deep Dive into Data Structures on Android Smartphones
    • SMS/MMS
    • Calls, Contacts, and Calendar
    • E-mail and Web Browsing
    • Location Information
  • Salvaging Deleted SQLite Records
  • Salvaging Deleted Data from Raw Images on Android Devices

Bonus Materials

  • Android Cheat Sheet
  • Android Acquisition Methods
  • Relevant White Papers and Guides
 
  FOR585.3: iOS Forensics
Overview

Focus: Apple iOS devices are used worldwide. iOS devices contain substantial amounts of data (including deleted records) that can be decoded and interpreted into useful information. Proper handling and parsing skills are needed for bypassing locked iOS devices and correctly interpreting the data. Without iOS instruction, you will be unprepared to deal with the iOS device that will likely be a major component in a forensics investigation.

Digital forensics examiners must understand the file system structures and data layouts of Apple iOS devices in order to extract and interpret the information they contain. To learn how to do this, we delve into the file system layout on iOS devices and discuss common areas containing files of evidentiary value. Encryption, decryption, file parsing, and traces of user activities are covered in detail.

During hands-on exercises, students will use smartphone forensics tools to extract and analyze a wide variety of information from iOS devices. Students will also be required to manually decode data that were deleted or are unrecoverable using smartphone forensics tools.

Exercises
  • Manually decoding and extracting information from iOS file system and logical acquisitions.
  • Introduction to manually parsing third-party applications and deep-dive decoding and recovery of user activities on iOS devices.

CPE/CMU Credits: 6

Topics

iOS Forensics Overview and Acquisition

  • iOS Architecture and Components
  • NAND Flash Memory in iOS Devices
  • iOS File Systems
  • iOS Versions
  • iOS Encryption

iOS File System Structures

  • Defining Data Structure Layout
    • Physical
    • File System
    • Logical
  • Data Storage Formats
  • Parsing and Carving Data
  • Physical and Logical Keyword Searches

iOS Evidentiary Locations

  • Primary Evidentiary Locations
  • Unique File Recovery
  • Parsing SQLite Database Files
  • Manual Decoding of Android Data

Handling Locked iOS Devices

  • Security Options on iOS
  • Current Acquisition Issues
  • Demonstration of Bypassing iOS Security
  • Practical Tips for Accessing Locked iOS Devices

Traces of User Activity on iOS Devices

  • How iOS Applications Store Data
  • Deep Dive into Data Structures on iOS Devices
    • SMS/MMS
    • Calls, Contacts, and Calendar
    • E-mail and Web Browsing
    • Location Information
  • Salvaging Deleted SQLite Records
  • Salvaging Deleted Data from Raw Images

Bonus Materials

  • iOS Cheat Sheet
  • iOS Acquisition Methods
  • Relevant White Papers and Guides
 
  FOR585.4: Backup File and BlackBerry Forensics
Overview

Focus: BlackBerry smartphones are designed to protect user privacy, but techniques taught in this section will enable the investigator to go beyond what the tools decode and manually recover data residing in database files of BlackBerry device file systems. Backup smartphone images are commonly found on external media and the cloud, and may be the only forensics acquisition method for newer iOS devices that are locked. Learning how to access and parse data from encrypted backup files may be the only lead to smartphone data relating to your investigation.

Forensic examiners must understand the concept of interpreting and analyzing the information on smartphones, as well as the limitations of existing methods for extracting data from these devices. This course day covers how to handle encryption issues, BlackBerry Enterprise Server data, and locked devices. Manual decoding of BlackBerry data will provide access to a vast amount of data that forensics tools seem to miss.

Both BlackBerry and iOS backup files are commonly a part of digital forensic investigations. This section provides students with a deep understanding of backup file contents, manual decoding, and parsing and cracking of encrypted backup file images.

During hands-on exercises, students will use smartphone forensics tools to extract and analyze a wide variety of information from BlackBerry devices and iOS and BlackBerry backup files. Students will be required to manually decode data that were encrypted or deleted, or that are unrecoverable using smartphone forensics tools.

Exercises
  • Advanced backup file forensics exercise involving an iOS backup file that requires manual decoding and carving to recover data missed by smartphone forensics tools.
  • Advanced backup file forensics exercise involving a BlackBerry backup file that requires manual decoding and carving to recover data missed by smartphone forensics tools.
  • Manually decoding and extracting information from a BlackBerry file system and physical data dump.

CPE/CMU Credits: 6

Topics

Backup File Forensics Overview

  • Why This Is Relevant
  • Common File Formats For Smartphone Backups
    • iOS
    • BlackBerry
    • Android
    • Nokia

Creating and Parsing Backup Files

  • Examiner-created Backup Files
  • User-created Backup Files
  • Verifying Backup File Data
  • Using Smartphone Forensics Tools for Parsing
    • Pros and Cons

Evidentiary Locations on Backup Files (Focus on iOS and BlackBerry Backup Files)

  • What Is Missed by Smartphone Forensics Tools
  • Examining Event Logs
  • Examining Database and PList Files
  • Manual Decoding of Evidentiary Data

Locked Backup Files

  • Decrypting Locked iOS Backup Files
  • Decrypting Locked BlackBerry Backup Files

BlackBerry Forensics Overview

  • BlackBerry Architecture and Components
  • Malware on BlackBerry Smartphones

BlackBerry Forensic Acquisition and Best Practices

  • Practical Guidelines for Acquiring BlackBerry Smartphones
  • File System Acquisition
  • Physical Acquisition Approaches
  • Challenges of BlackBerry Forensic Acquisition

BlackBerry File System and Evidentiary Locations

  • File System Forensics on BlackBerry Smartphones
  • Primary Evidentiary Locations
  • Parsing Device Specific Files
  • BlackBerry 10

BlackBerry Forensic Analysis

  • Recovering Data from Physical Acquisitions
  • Unique File Recovery
  • Keyword Searching
  • Manual Decoding of BlackBerry Data
  • BlackBerry 10 OS

Bonus Materials

  • BlackBerry Cheat Sheets
  • BlackBerry Acquisition Methods
  • Backup File Acquisition Methods
  • Relevant White Papers and Guides
 
  FOR585.5: Third-Party Application and Other Smartphone Device Forensics
Overview

Focus: Given the prevalence of other types of smartphones around the world, it is critical for examiners to develop a foundation of understanding about data storage on multiple devices. Nokia smartphones running the Symbian operating system may no longer be manufactured, but they still exist in the wild. You must acquire skills for handling and parsing data from uncommon smartphone devices. This course day will prepare you to deal with "misfit" smartphone devices and provide you with advanced methods for decoding data stored in third-party applications across all smartphones.

This course day will cover other smartphone devices such as Nokia (Symbian), Chinese knock-offs, and Windows phones. These devices retain information about user activities that can be relevant in a digital investigation, including e-mail, web browsing, user-created files, and registry entries. We will cover techniques for parsing common data structures on these smartphone devices and recovering deleted items.

During hands-on exercises, you will use smartphone forensic tools to extract and analyze a wide variety of information from a Chinese knock-off phone. Students will be required to manually decode data that were deleted or are unrecoverable using smartphone forensic tools. The third-party application hands-on exercise will be a compilation of everything you have learned up until now in the course and will require the manual decoding of third-party application data from multiple smartphones.

Exercises
  • Advanced third-party application exercise requiring students to use skills learned during the first four days of the course to manually decode communications stored in third-party application files across multiple smartphones.
  • Knock-off phone exercise requiring manual decoding of a knock-off handset physically acquired using the Cellebrite CHINEX.
  • A Nokia lab requiring manual parsing and identification of devices based upon file system dumps from multiple devices. This lab challenges students to put together several concepts learned during the week.

CPE/CMU Credits: 6

Topics

Third-Party Applications on Smartphones Overview

  • Common Applications Across Smartphones

Third-Party Application Locations on Smartphones

  • How to Locate
  • Data Format

Decoding Third-Party Application Data on Smartphones

  • Manual Recovery
  • Decoding Methods

Knock-off Phone Forensics

  • Knock-off Phone Overview
  • Forensic Analysis
  • Evidentiary Locations
  • Manual Decoding of Knock-off File System Data

Nokia (Symbian) Forensics

  • Symbian Features Overview
  • Evidentiary Locations

Windows Phone/Mobile Forensics

  • Overview of Windows Phone/Mobile
  • Evidentiary Locations
 
  FOR585.6: Smartphone Forensic Capstone Exercise
Overview

Focus: This final course day will test all that you have learned during the course. Working in small groups, students will examine three smartphone devices and solve a scenario relating to a real-world smartphone forensic investigation. Each group will independently analyze the three smartphones, manually decode data, answer specific questions, form an investigation hypothesis, develop a report, and present findings.

By requiring student groups to present their findings to the class, this capstone exercise will test your understanding of the techniques taught during the week. The findings should be technical and include manual recovery steps and the thought process behind the investigative steps. An executive summary of findings is also expected.

Exercises

Each group will be asked to answer the key questions listed below during the capstone exercise, just as they would during a real-world digital investigation:

Identification and Scoping

  • What is the criminal operation?
  • What devices are involved?
  • Which individuals are involved?

Forensic Examination

  • What were the key communications between individuals?
  • What methods were used to secure the communication?
  • Were any of the mobile devices compromised by malware?

Forensic Reconstruction

  • What is the motive?
  • In addition, students will be required to generate a forensics report.

CPE/CMU Credits: 6

 
Additional Information
 
  Laptop Required

!!IMPORTANT - BRING YOUR OWN SYSTEM CONFIGURED USING THESE INSTRUCTIONS!!

Each student participating in this course needs a properly configured 64-bit system. Before coming to class, carefully read and follow these instructions exactly.

As your core operating system, you can use any 64-bit version of Windows, MAC OSX, or Linux that can also install and run VMware virtualization products.

It is critical that your CPU and operating system support 64 bits so that our 64-bit guest virtual machine will run on your laptop. VMware provides a free tool for Windows and Linux that will detect whether your host supports 64-bit guest virtual machines. For further troubleshooting, this Microsoft Support article provides instructions for Windows users to learn more about the CPU and OS capabilities. For Macs, please use this support page from Apple to determine 64-bit capability.

Please download and install VMware Workstation 10.0, VMware Fusion 6.0, or VMware Player 6.0 on your system prior to beginning the class. (Note: This is required to prevent issues with USB 3.0 ports.) If you do not own a licensed copy of VMware Workstation or Fusion, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial on its website.

Mandatory Hardware Requirements

  • CPU: A 64-bit Intel® x64 2.0+ GHz processor or higher-based system is mandatory for this course. (Important - Please read: a 64 bit system processor is mandatory.)
  • Wireless 802.11 B, G, N, or AC networking capability (required for labs and licensing).
  • Bring an adapter or otherwise ensure that your laptop supports an Internet cable for connection, as the class will be hardwired.
  • USB 3.0 Port(s) - highly recommended
  • 8 gigabytes of RAM minimum (more RAM is recommended due to virtual machine requirements).
  • 100 gigabytes of free space on your system hard drive.
  • Students should have the capability to have Local Administrator Access within their host operating system.

Mandatory Software Requirements

  • Host operating system: Any version of Windows, MAC OSX, or Linux operating system that also can install and run VMware virtualization products.
  • Install VMware Workstation, VMware Player or VMware Fusion.
  • Download and install 7Zip for Windows or Mac.

Install the following on your host Windows machine (if MAC/Linux host, install inside Windows VM):

  1. MS Office 2010 (Demo version for 60-day free trial - You need Excel 2007 or higher for this class - No exceptions).
  2. VMware Workstation 10, VMware Fusion 6.0. or VMware Player 6.0 (higher versions are okay).
  3. Download and install 7Zip.

IN SUMMARY, BEFORE YOU BEGIN THIS COUSRE YOU SHOULD:

  1. Bring the proper system hardware (64bit/8 GB RAM) and operating system configuration.
  2. Install VMware (Workstation, Player, or Fusion), MS Office, and 7Zip.

If you have additional questions about the laptop specifications, please contact laptop_prep@sans.org.

 
  Who Should Attend

FOR585 is designed for students who are both new to and experienced with mobile device forensics. The course provides the core knowledge and hands-on skills that a digital forensics investigator needs to process smartphones and other mobile devices. The course is a must for:

  • Experienced digital forensics examiners who want to extend their knowledge and experience to forensics analysis of mobile devices, especially smartphones.
  • Media exploitation analysts who need to master Tactical Exploitation or Document and Media Exploitation operations on smartphones and mobile devices by learning how individuals used their smartphones, who they communicated with, and what files they accessed.
  • Information security professionals who respond to data breach incidents and intrusions.
  • Incident response teams tasked with identifying the role that smartphones played in a breach.
  • Law enforcement officers, federal agents or detectives who want to master smartphone forensics and expand their investigative skills beyond traditional host-based digital forensics.
  • IT auditors who want to learn how smartphones can expose sensitive information.
  • Graduates of SANS SEC575, FOR408, FOR508, or FOR518 who want to take their skills to the next level.
 
  Prerequisites

While FOR408 is not a prerequisite for this course, a basic understanding of digital forensics file structures will help the student grasp topics that are more advanced. FOR585 covers advanced topics that should enhance all skill sets of those interested in digital forensics.

 
  Other Courses People Have Taken

Other Courses People Have Taken

FOR585 is an ideal course for graduates of SANS SEC575, FOR408, FOR508, and FOR518 who want to take their skills to the next level. Most of these courses can be taken in any order.

 
  What You Will Receive
  • Smartphone Analyysis Windows SIFT Workstation
    • A SIFT Windows virtual machine (Smartphone Version) is used with all hands-on exercises. The virtual machine is used to teach students how to examine and investigate information on smartphones. The SIFT virtual machine design for this course contains free and open-source tools, easily matching any modern forensics tool suite.
    • Windows 8.1 Standard License.
  • Smartphone Analysis Tool Licenses
    • Oxygen Forensics Demo License.
    • Microsystemation XRY Demo License.
    • Cellebrite Physical Analyzer Demo License.
    • Magnet Forensics IEF Mobile Demo License.
    • Andriller Demo License.
    • Open-source tools.
  • 32 GB Course USB
    • 32 GB USB 3.0 - loaded with smartphone case images, Windows SIFT workstation (smartphone version), tools, and documentation
  • SANS Smartphone Forensics Case Exercise Workbook
    • Exercise book is over 250 pages long with detailed step by step instructions and examples to help you become a master smartphone analyts
 
  You Will Be Able To
  • Extract and use information from smartphones and mobile devices and their components, including Android, iOS, BlackBerry, Windows Phone, Nokia (Symbian), Chinese knock-offs, SIM cards, and SD cards.
  • Understand how to detect hidden malware and spyware on smartphones and extract information related to security breaches, cyber espionage, and advanced threats involving smartphones.
  • Prevent loss or destruction of valuable data on smartphones by learning proper handling of these devices.
  • Use a variety of acquisition methods for smartphones with an understanding of the advantages and limitations of each acquisition approach.
  • Interpret file systems on smartphones and locate information that is not generally accessible to users.
  • Recover artifacts of user activities from third-party applications on smartphones.
  • Recover location-based and GPS information from smartphones.
  • Perform advanced forensic examinations of data structures on smartphones by diving deeper into underlying data structures that many tools do not interpret.
  • Analyze SQLite databases and raw data dumps from smartphones to recover deleted information.
  • Perform advanced data-carving techniques on smartphones to validate results and extract missing or deleted data.
  • Reconstruct events surrounding a crime using information from smartphones, including timeline development and link analysis (e.g., who communicated with whom, and locations at particular times).
  • Decrypt locked backup files and bypass smartphone locks.
  • Apply the knowledge you acquire during the course to conduct a full-day smartphone capstone event on the final day involving multiple devices and modeled after real-world smartphone investigations.
 
  Hands-on Training

This course features 17 hands-on labs and a final forensics challenge to ensure that students not only learn the material, but can also execute techniques to manually recover data. The labs cover the following topics:

  • Malware and Spyware - Two labs are designed to teach students how to manually decompact and statically analyze malware recovered from an Android device. The processes used here reach beyond the commercial forensics kits and methods.
  • JTAG Password Cracking - This lab shows students how to load images acquired using JTAG methods and how to crack the lockcode on the device.
  • Android Analysis - Two labs are designed to teach students how to manually carve for deleted data, validate tool results, and parse third-party application files for user-created data not commonly parsed by commercial forensics tools. Open-source methods are utilized and highlighted where possible. An additional lab teaches students how to manually crack lockcodes from Android devices.
  • iOS Analysis - Two labs are designed to teach students how to manually carve for deleted data, validate tool results, and parse third-party application files for user-created data not commonly parsed by commercial forensics tools.
  • Backup File Analysis - Two labs are designed to teach students how to parse data from iOS and BlackBerry backup files. These labs will drive students to parse data from database files, records, plist, and third-party application data.
  • BlackBerry Analysis - This all-encompassing lab provides several images to enable students to obtain the full picture of what is captured during various acquisition methods, how data are manually carved and parsed, and how BlackBerry proprietary formats can affect their investigations.
  • Third-party Application Analysis and Knock-off Phone Analysis - These labs challenge students to examine third-party applications pulled from multiple smartphone devices, and to handle knock-off devices that are not commonly parsed by commercial tools.
  • Smartphone Forensics Capstone - The final challenge tests what students have learned in the course. It features multiple smartphone devices used in various locations involving communication, third-party applications, Internet history, cloud and network activity, shared data, and more. This capstone exercise encourages students to dig deep and showcase what they learned in FOR585 so that they can immediately apply it to their work when returning to their jobs.
 
  Press & Reviews

"This is the most advanced mobile device training that I know of and is greatly needed. It is currently the only course being taught at this level!" - Scott McNamee, DoS/CACI

"As an experienced user of the tools, I found FOR585 very instructional on how and why these tools give the results they do during an examination." - SA Charles Cox, FBI Computer Analysis and Response Team

"FOR585 is the best out there." - Andy Nind, British Army

"This course is worth it, even for a novice like myself." - S. Gentry, Adobe

"This course was very high-quality training that provided exactly what was advertised!....Great BlackBerry lab. I have never dug this deep in a BlackBerry before." - C. McCollom, Clark County Sheriff's Office

This was an awesome class! Amazing amount of material and the capstone tied it all together." - D. Mayer, Broomsfield Police Department

"I finally know what I have been missing! I did not know I was ignorant." - Mark G., Department of Justice

"If I could afford it I would take this course every year. I am sure I would learn new things as the course evolves to new technology." - Jim Stapleton, student

"I have been working with phones since 2009, and [instructor] Heather [Mahalik] very casually showed me how much I don't know. Excellent!" - Harbin Combee, MPDC

"Advanced smartphone forensics (FOR585) provides students with the tools and strategies required to forensically examine the most widely used computers in the world." - Brad Wardman, PayPal

"The best part about Advanced Smartphone Forensics is it provides real world technologies for forensically investigating devices without the typical point and click approaches." - Andy Gil, ECO

"FOR585 provides forensics investigators with the mentality and set of tools required to forensically examine most types of devices." - Steve Bone, MOD

"Single best course I have taken. Course material laid out in a very logical way that made learning content very easy." - Bart Sims, Devon Energy

"Good, real-world experience. Clearly, Cindy has been there, done that." - Chris Mallow, University of Oklahoma

"Cindy is very knowledgeable and presents concepts in a way that is easy to understad." - Grant Melton, Indianapolis Police

"Every day there are so many great bits of real-world knowledge. It isn't just academic. Mind blowing experience." - Bart Dudek

"Kudos for integration of interpretive dance into file system structure. Awesome." - Bart Dudek

 

Author Statement

"Digital forensic investigations almost always involve a smartphone or mobile device. Often, the smartphone is the only form of digital evidence relating to the investigation and is the most personal device a person owns! Let's be honest: how many people share their smartphones like they do computers? Not many. Knowing how to recover all of the data residing on the smartphone is now an expectation in our field, and examiners must understand the fundamentals of smartphone handling, data recovery, accessing locked devices, and manually recovering data hiding in the background on the device. FOR585: Advanced Smartphone Forensics provides this required knowledge to beginners in mobile device forensics and to mobile device experts. This course has something to offer everyone!" - Heather Mahalik

"One thing is clear no matter whether you work in law enforcement or the private sector: the importance of evidence obtained from smartphones and other mobile devices has become crucial to all kinds of investigations. Solid foundational knowledge, skills, and techniques in mobile device forensics are no longer optional. Developed by passionate practitioners with a high level of experience in the field, FOR585: Advanced Smartphone Forensics provides the elements you need to succeed in your investigations and thrive in the rapidly changing mobile device forensics environment." - Cindy Murphy

"Eighty-five percent of the world's population today has a mobile phone. In the United States alone, almost half of these devices are smartphones. The tools and techniques for acquiring and analyzing these devices are changing every day. As the handsets become more sophisticated in the storage and obfuscation of personal user data, the tools and practitioners are in a race to uncover data related to investigations. The concepts covered in FOR585: Advanced Smartphone Forensics will not only highlight some of the best tools available for acquiring and analyzing the smart devices on the market today, they will also provide examiners with best practices and techniques for delving deeper into smart devices as new applications and challenges arise. FOR585 keeps students ahead of the curve!" - Domenica Crognale

Additional Resources

Take your learning beyond the classroom. Explore our site network for additional resources related to this course's subject matter.

*CPE/CMU credits not offered for the SelfStudy delivery method

Type
Topic
Course
/ Location
/ Instructor
Date
Register

Community SANS
Mobile Devices Dec 7, 2015 -
Dec 12, 2015
 

*Course contents may vary depending upon location, see specific event description for details.