Course overview
This intensive 2-month training program is designed to equip participants with comprehensive skills in mobile device forensics and the identification of Indicators of Compromise (IoCs). The course covers foundational mobile architecture, acquisition techniques, Investigation methodologies, artifact analysis, and advanced threat detection methods. Learners will explore forensic methodologies for Android, iOS, smartwatches, and encrypted apps, along with hands-on experience using tools like FTK, Tableau TX1, iMazing, iConsole, Activity Monitor, and Oxygen Forensic Detective. Topics include network and email forensics, malware behaviour, cloud investigations, and mobile threat landscapes. The program culminates with a capstone case and a mock courtroom presentation to simulate real-world investigation and reporting.
Programme Details
- Duration: 2 Months.
- Mode: Offline (Hands-on Lab training).
- Batch Size: Limited to 5 students for individualised mastery.
- Location: A-525, Anthurium Tower, Noida Sector 73.
Topics Covered
- Introduction to Mobile Platforms (Android & iOS) and Device Architecture
- Mobile Forensics Fundamentals, Evidence Handling & Hashing Techniques
- Laws related to mobile forensic
- Mobile Chipsets, Boot Process, File Access & OS Security Features
- Data Acquisition Techniques: Logical, File System & Physical Extraction
- Hands-on Extraction on oxygen Detective.
- Hands on FTK and its use in Mobile forensic
- Forensic Analysis using Oxygen Forensic Detective (OFD)
- Rooting, Jailbreaking, Device Modes (ADB, DFU, Recovery, EDL)
- Smartwatch Forensics and Artifact Extraction
- Geolocation Forensics: GPS, EXIF Data, KML Plotting with QGIS
- Indicators of Compromise (IoCs): Types, Detection & Forensic Relevance
- Mobile Threat Landscape, Attacks, IMSI/TMSI Analysis & Rogue Towers
- Mobile Phone field test methods
- Threat Hunting using FTK, VirusTotal, and YARA
- Objective based mobile phone investigation.
- Whatsapp, FaceTime, Telegram and other calling apps and call history extraction and reconstruction.
- IOC Correlation & Reporting Best Practices
- Data packet analysis
- Network Forensics: C2 Traffic, DNS Tunnelling, Proxy/VPN Artifacts
- Encrypted Traffic, Beaconing & Anomaly Detection
- Email Forensics: Protocols, Header Analysis, System & Application Logs
- Advanced Detection Techniques: Malware, Lateral Movement, Privilege Escalation
- Use of iMazing, iConsole, IDS/IPS & Thermal Imaging in Forensics
- Cloud Artifact Investigation (Google/iCloud), Token-Based Access
- Capstone Project: End-to-End Investigation, Report Submission & Mock Courtroom Presentation
Hands-On training list
- Learn to disassemble mobile devices and identify key internal components.
- Practice securing electronic evidence using Faraday bags.
- Perform cryptographic hashing (MD5, SHA1, SHA256) to ensure data integrity.
- Acquire data from SD cards and USB drives using Tableau TX1 forensic imager.
- Verify image integrity using hash comparison.
- Practice data wiping procedures and understand their forensic implications.
- Conduct logical and physical acquisition using Oxygen forensic detective.
- Participate in a live demo of Oxygen Forensic Detective (OFD) and explore supported data types.
- Gain hands-on experience with rooting (Android) and jailbreaking (iOS) devices.
- Work with device modes such as ADB, DFU, Recovery, and EDL for data access.
- Extract application data (WhatsApp, Telegram, SMS, contacts) using Oxygen Forensic Detective and Other forensic tools.
- Extract GPS/EXIF geolocation metadata and visualize it using Google Earth and QGIS.
- Identify file hashes, persistence mechanisms, and suspicious files using FTK and Autopsy.
- Use VirusTotal and YARA rules to validate malware indicators.
- Practice correlating indicators across tools and documenting findings using standardized formats.
- Analyze network traffic for indicators of C2 communication, DNS tunneling, and VPN/proxy artifacts.
- Data packet analysis.
- Conduct system-level and application-level analysis to uncover signs of compromise.
- Detect advanced signs of compromise such as lateral movement and privilege escalation on mobile devices.
- Use tools like iMazing, Activity Monitor, and iConsole for in-depth iOS analysis.
- Explore the use of IDS/IPS in mobile environments.
- Perform thermal diagnostics using Thermal Imaging Cameras.
- Extract and investigate cloud artifacts using token-based access for Google and iCloud accounts.
- Complete a real-world case simulation with a test device/image containing hidden evidence.
- Acquire, validate, and analyze data using TX1, Oxygen Forensic Detective, FTK, and Autopsy.
- Identify Indicators of Compromise and document findings in a comprehensive forensic report.
- Legal framework in mobile forensic domain in india.
- Present the case in a mock courtroom setting, demonstrating chain of custody, analysis methodology, and reporting standards.
What will you learn?
- Understand Android & iOS architectures, mobile chipsets, boot processes, and OS-level security features
- Learn data acquisition techniques – logical, file system, and physical – using tools like Tableau TX1 and FTK Imager, oxygen forensic.
- Perform forensic analysis with Oxygen Forensic Detective, including rooting, jailbreaking, and recovery from multiple device modes (ADB, DFU, EDL)
- Work on smartwatch forensics, geolocation data analysis, and KML plotting with QGIS
- Identify and analyze IoCs such as file hashes, domains, IPs, and C2 communication
- Conduct threat hunting using tools like FTK, Autopsy, VirusTotal, and YARA
- Dive into network forensics, including DNS tunneling, proxy/VPN detection, SSL/TLS traffic analysis, and anomaly detection
- Explore email forensic techniques, application/system log analysis, and mobile malware behaviour
- IOS mobile device forensic investigation process
- Gain exposure to emerging forensic technologies such as iMazing, iConsole, IDS/IPS, and thermal imaging
- Complete a capstone investigation project with evidence acquisition, analysis, reporting, and a mock courtroom presentation
