This hands-on intermediate course is designed for practitioners with foundational mobile forensic experience who want to advance their analysis and validation skills on Android and iOS devices.
The course covers advanced OS internals, security models, encryption, and artifact storage across both platforms. Participants work with full file system extractions, backups, and raw datasets to identify, parse, and validate key artifacts, with emphasis on understanding data structures and changes across OS versions.
Analysis is performed using a combination of industry-standard tools and open-source tools such as ALEAPP and iLEAPP and others. A core focus is validating tool output, identifying parsing limitations, and performing manual verification.
Practical exercises include SQLite database analysis, plist and application data parsing, artifact correlation across sources, and recovery of deleted or partially available data. Participants will also explore cloud-related evidence, including iCloud and Google account artifacts and synchronization behaviour.
The course concludes with in-depth examination of modern iOS full file system artifacts, including Health, Screen Time, analytics, usage logs, and secure storage (Keychain), along with reporting and defensibility of findings.