SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThe Six Steps:
The authors frame mobile forensics as a discipline that sits between science and art: automated extraction tools can only go so far, and it is manual verification, cross-tool comparison, and disciplined documentation that make a forensic finding defensible in court, sometimes years after the original investigation. Not every case requires all six steps; the paper recommends scaling the depth of validation to the stakes of the investigation, reserving the full sequence, including deep-dive artifact validation and cloud data extraction, for major crimes cases where the evidence may be contested. The paper was authored collaboratively across law enforcement, forensic tool vendors (Cellebrite, Magnet Forensics, MSAB, Oxygen Forensics, ElcomSoft, Paraben, Belkasoft, Grayshift), and independent forensic researchers and instructors, reflecting practices drawn from casework across multiple jurisdictions and legal systems.
Determine all possible extraction methods for your search authority, process the data in more than one tool, conduct deep dive forensics, validate findings, report and share results, and commit to ongoing education.
Different tools can parse different data types from the same application, and comparing results across tools helps validate essential evidence and catch discrepancies before they affect a case.
Keeping a device powered on and network-isolated increases the chances of accessing it, though examiners should be aware some devices can be remotely wiped if they reconnect to a network.
By checking whether timestamps are shown in device local time or UTC, cross-checking for daylight saving time and time zone changes, and confirming whether the timestamp originates from the handset or the mobile network.
Not every case needs all six steps; simpler cases, like confirming recent communications on an in-custody suspect's phone, may not require deep-dive forensics or full cross-tool validation, while major crimes investigations warrant the complete process.


Heather brings 24+ years of experience supporting government agencies, defense contractors, law enforcement, and Fortune 500 companies. Her extensive case experience spans fraud investigations, crimes against children, counterterrorism, and more.
Learn more

Mattia Epifani pioneered methodologies for extracting critical evidence from encrypted mobile ecosystems, including iOS and Apple Watch. His groundbreaking work has become foundational for law enforcement and forensic analysts worldwide.
Learn more

Ms. Hyde is an experienced forensic examiner in both the government and commercial sectors as a contractor providing forensics services to the Department of Defense, Intelligence Community, and private sector.
Learn more

Ian Whiffin boasts an impressive 17-year career in policing, divided between the UK and Canada. His journey in Digital Forensics began in 2013 when he joined the Calgary Police Service as a police examiner. Over the last decade, Ian has worked on thousands of devices, tackling a wide variety of cases. His hands-on experience has often led him to develop innovative research and custom-coded solutions, which he generously shares on his website, doubleblak.com.
Learn more














