Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Advanced

Smartphone Forensic Analysis

Smartphone forensic analysis fails most often at the last step, when an examiner reports what a tool displayed rather than what the data proves. This course teaches acquisition, decoding and validation across iOS and Android.

Over ten weeks you extract devices, take apart application databases by hand, resolve conflicting timestamps, and produce evidence documented well enough to survive challenge in a legal process.

Duration
10 weeks
Format
Live online, instructor-led
Prerequisites
Digital Evidence Acquisition and Rapid Triage
Class size
Capped at 12 learners
Smartphone Forensic Analysis

What you will be able to do

  • Select an acquisition method suited to a device, its version and your authority
  • Explain what each acquisition method captures and what it silently misses
  • Decode SQLite databases by hand, including write ahead log content
  • Recover deleted records that tool reports do not surface
  • Interpret iOS usage evidence such as KnowledgeC and biome data
  • Analyse Android application storage, sync artifacts and notification history
  • Validate tool output against ground truth before reporting it
  • Write an examination report suitable for disclosure to counsel

Course outline

6 modules

  • Device isolation and power management at seizure
  • Legal authority, consent and the scope of an examination
  • Passcodes, biometrics and lawful access limits
  • Documenting device state before anything is touched
  • Choosing an acquisition strategy per device

What you need before you start

  • Evidence handling experience or the acquisition course
  • Comfort reading structured data such as JSON and database tables
  • A machine able to run the supplied analysis virtual machine
  • Test devices are useful for validation work but not required

Who this course is for

  • Forensic examiners taking on mobile casework
  • Police and private investigators handling seized devices
  • Corporate investigators examining company issued phones
  • eDiscovery specialists dealing with mobile collections
  • Analysts who must defend mobile findings under scrutiny

Where this leads

Prepares you for

CHFI

Awarded by EC-Council

Mobile device examination forms part of the Computer Hacking Forensic Investigator syllabus, and this course goes well beyond it. EC-Council administers the exam and awards the CHFI credential to candidates who pass; we provide only the training behind it.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.