messages.db location.db health.db photos.db SQLite: messages id timestamp text 1 1704067200 [BLOB] 2 1704153600 [BLOB] 3 null [DEL] RECOVERED protobuf · plist · NSKeyedArchiver DECODED Date: 01 Jan 2024 From: +4477009... Body: Meet at 7... Status: DELETED
INTERMEDIATE 4.5 Days EG or On-Site

App Data ForensicsMobile App Forensics Training Course

Understand what apps leave behind — and how to find it

COURSE DETAILS

Duration: 4.5 Days (Classroom Based)
Level: Intermediate
Max Class Size: 12 Delegates (2 Trainers)
Certification: Reboot App Data Forensics Certificate
Equipment: All tools, lab devices and practice environments provided
Location: Hosted at our Reboot training facility at the Electronics Group, Leeds, UK
Pre-requisites: Basic digital forensic knowledge and familiarity with mobile device examination
COURSE FEE £2,000 + VAT per delegate

WHY APP DATA FORENSICS?

Applications (apps) are at the centre of almost every modern investigation. Full file-system extractions provide a wealth of potential evidence and intelligence, but as new apps appear your vendor tools may struggle to keep pace with decoding significant data. Many apps leave behind a rich trail of data — but only if you know where to look and how to interpret what you find.

App Data Forensics goes beneath the surface of those applications which are significant to your investigation, breaking down exactly how the app stores its data, what artefacts are created by user activity, and how those artefacts can be located, interpreted and presented as evidence. Delegates will work directly with SQLite databases, property lists, cache files and other data storage mechanisms.

By understanding the internal architecture of the apps your subjects use, you will be better equipped to identify evidence that vendor tools may not decode, challenge incomplete extraction reports, manually validate vendor tool output and deliver thorough and defensible findings.

WHO WILL BENEFIT

This course is designed for digital forensic practitioners who may be required to perform data investigation and analysis, and want to move beyond automated tool output to a deeper, artefact-level understanding of evidentially significant apps encountered in investigations.

  • •Digital forensic examiners & analysts
  • •Law enforcement forensic units
  • •Corporate investigation and eDiscovery teams
  • •Laboratory managers seeking deeper app analysis capability

WHAT WE TEACH ON THIS COURSE

App Data Forensics provides in-depth, hands-on training in app-level forensic analysis for both iOS and Android platforms. Working with real app data, students will learn to identify, decode and interpret the most significant artefacts and be able to present their findings to 3rd parties in a clear and intelligible format. Topics covered include:

•App-level forensic analysis across multiple platforms, including macOS, iOS, Windows and Android.
•SQLite database analysis: the SQLite engine process including associated files, database structure, building queries, identifying and using table joins, deleted and partial record recovery and generating reports.
•iOS and Android app data storage architecture
•Property list (plist) parsing and interpretation on iOS
•App cache, thumbnails and media store analysis
•Identifying artefacts not decoded by automated extraction tools
•Court-ready documentation of app-level findings

PRE-COURSE REQUIREMENTS

Delegates should have a working knowledge of digital forensic principles and have conducted device examinations using standard extraction tools such as Cellebrite UFED, MSAB XRY or Magnet AXIOM. No prior app development knowledge or scripting experience is required. An understanding of iOS and Android file system structures is beneficial but not essential.

UPCOMING DATES

App Data Forensics
INTERMEDIATE
TBC — 2027
The Electronics Group, Faraday House, Leeds LS16 6QE
REGISTER INTEREST

Dates are being finalised. Contact us to register interest or discuss scheduling or on-site delivery.

Ready to book or have questions about this course?

RELATED COURSES