MOBILE · Advanced Android and iOS mobile forensics training

Mobile Forensics Deep Dive

Hands-on intermediate course in advanced Android and iOS analysis: OS internals, encryption, manual SQLite and plist parsing, cloud artefacts and validating what your tools report.

Dates
22–26 Feb 2027
Duration
5 days, 08:00–17:00
Level
Intermediate
Seats
Limited number of seats
Advanced Android and iOS mobile forensics training – Mobile Forensics Deep Dive

Course overview

This hands-on intermediate course is designed for practitioners with foundational mobile forensic experience who want to advance their analysis and validation skills on Android and iOS devices.

The course covers advanced OS internals, security models, encryption, and artifact storage across both platforms. Participants work with full file system extractions, backups, and raw datasets to identify, parse, and validate key artifacts, with emphasis on understanding data structures and changes across OS versions.

Analysis is performed using a combination of industry-standard tools and open-source tools such as ALEAPP and iLEAPP and others. A core focus is validating tool output, identifying parsing limitations, and performing manual verification.

Practical exercises include SQLite database analysis, plist and application data parsing, artifact correlation across sources, and recovery of deleted or partially available data. Participants will also explore cloud-related evidence, including iCloud and Google account artifacts and synchronization behaviour.

The course concludes with in-depth examination of modern iOS full file system artifacts, including Health, Screen Time, analytics, usage logs, and secure storage (Keychain), along with reporting and defensibility of findings.

Who should attend

Practitioners with foundational mobile forensic experience who want to advance their analysis and validation skills on Android and iOS devices.

Course objectives

  • Perform and understand advanced Android and iOS extraction techniques conceptually and practically (where legally applicable)
  • Explain Android security features (FBE, Project Treble, Verified Boot) and iOS security (Secure Enclave, Lockdown Mode, USB Restricted Mode)
  • Work directly with binary dumps, partitions, and file system structures
  • Manually parse and validate SQLite databases, WAL, SHM, journal files
  • Recover deleted SQLite records and interpret freelist pages
  • Decode and analyze plist files (XML and binary)
  • Analyse full iOS file system artifacts including:
    • Health data
    • Location history
    • Screen Time
    • Communication logs
    • Usage analytics
  • Analyse Android system logs, account data, and app artifacts
  • Conduct structured third-party app analysis
  • Understand cloud artifacts and GDPR-based acquisition
  • Evaluate damaged devices and hardware recovery feasibility
  • Produce defensible, technically validated forensic reports

Prerequisites

  • Completion of Basic Mobile Forensics (or equivalent knowledge)
  • Experience working with mobile extractions
  • Understanding of Android and iOS file systems
  • Basic command line familiarity (ADB, terminal navigation)
  • Basic knowledge of SQLite

Tools and techniques

  • ALEAPP
  • iLEAPP
  • industry-standard mobile forensic tools
  • SQLite tools
  • ADB

Certificate

Official e-DiFTA certificate

Every participant who passes the course receives an official e-DiFTA certificate confirming successful completion of the class and recognising the training hours completed.

Instructor

Saša Deković

Saša Deković

Consultant, INsig2

Saša works at INsig2 as a consultant in the digital forensics department, where he is primarily responsible for forensic training and client education, and for support during demanding and complex investigations. Saša was involved in equipping and…

Full profile →

Frequently asked questions

Which tools are used in the course?

A combination of industry-standard tools and open-source tools such as ALEAPP and iLEAPP. A core focus is validating tool output and verifying results manually.

Who can attend this course?

Attendance is intended exclusively for law enforcement personnel, military personnel engaged in digital forensic activities and private-sector investigators.

What is included in the €2,500 fee?

Five days of hands-on training (08:00–17:00), an official certificate of successful completion recognising the training hours, a buffet lunch and morning and afternoon coffee breaks every day.

How are seats allocated?

Seats are limited and allocated on a “first paid – first confirmed” basis. Your registration is confirmed once payment is received; the payment deadline is 25 December 2026.

Do I receive a certificate?

Yes. Every participant who passes the course receives an official e-DiFTA certificate confirming successful completion of the class and recognising the training hours completed.

Is VAT charged?

Invoices are issued from France. Private individuals and organisations in France pay French VAT (20%). Organisations outside France are invoiced without French VAT when they provide a valid VAT number, TIN or EIN. Full VAT rules.

Related courses

All 8 courses →
€2,500MOBILE · 22–26 Feb 2027
Register →