Smartphone Forensic Analysis
Smartphone forensic analysis fails most often at the last step, when an examiner reports what a tool displayed rather than what the data proves. This course teaches acquisition, decoding and validation across iOS and Android.
Over ten weeks you extract devices, take apart application databases by hand, resolve conflicting timestamps, and produce evidence documented well enough to survive challenge in a legal process.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Digital Evidence Acquisition and Rapid Triage
- Class size
- Capped at 12 learners

What you will be able to do
- Select an acquisition method suited to a device, its version and your authority
- Explain what each acquisition method captures and what it silently misses
- Decode SQLite databases by hand, including write ahead log content
- Recover deleted records that tool reports do not surface
- Interpret iOS usage evidence such as KnowledgeC and biome data
- Analyse Android application storage, sync artifacts and notification history
- Validate tool output against ground truth before reporting it
- Write an examination report suitable for disclosure to counsel
Course outline
6 modules
- Device isolation and power management at seizure
- Legal authority, consent and the scope of an examination
- Passcodes, biometrics and lawful access limits
- Documenting device state before anything is touched
- Choosing an acquisition strategy per device
What you need before you start
- Evidence handling experience or the acquisition course
- Comfort reading structured data such as JSON and database tables
- A machine able to run the supplied analysis virtual machine
- Test devices are useful for validation work but not required
Who this course is for
- Forensic examiners taking on mobile casework
- Police and private investigators handling seized devices
- Corporate investigators examining company issued phones
- eDiscovery specialists dealing with mobile collections
- Analysts who must defend mobile findings under scrutiny
Where this leads
Prepares you for
CHFI
Awarded by EC-Council
Mobile device examination forms part of the Computer Hacking Forensic Investigator syllabus, and this course goes well beyond it. EC-Council administers the exam and awards the CHFI credential to candidates who pass; we provide only the training behind it.
Questions about this course
More in digital forensics and incident response
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



