Skip to content
Module 16 hrs3 topics

Mobile and network forensics foundations

The scope of mobile and network forensics and where they fit.

Start module
  1. Mobile and Network Forensics: Scope and DisciplineDefines what mobile and network forensics investigates and how the two disciplines complement each other within digital investigations. Establishes the evidence types, legal frameworks, and investigator roles common to both fields.13 min
  2. Digital Evidence in Mobile and Network ContextsExamines the nature of volatile and persistent digital evidence found on mobile devices and across network infrastructure. Covers chain-of-custody requirements and how evidence integrity is maintained from seizure through analysis.13 min
  3. Legal and Jurisdictional Frameworks for Mobile and Network EvidenceSurveys the international legal landscape governing interception, data seizure, and cross-border evidence requests relevant to mobile and network investigations. Compares key statutes and mutual legal assistance treaty (MLAT) mechanisms across major jurisdictions.13 min
Module 26 hrs3 topics

Mobile device architecture and data

How phones store data: file systems, memory, and where evidence lives.

Start module
  1. Mobile Device Hardware ArchitectureDescribes the physical components of smartphones and tablets including SoC design, memory chips (NAND/eMMC/UFS), and baseband processors. Explains how hardware design affects what data can be recovered and how.13 min
  2. Mobile Operating Systems and File SystemsCompares iOS and Android OS architectures, their sandboxing models, and the file systems they use such as APFS, ext4, and F2FS. Details partition layouts and the directory structures where user data and system artifacts reside.13 min
  3. Data Persistence and Evidence Locations on Mobile DevicesMaps where evidence commonly lives on mobile devices including SQLite databases, plist files, keychain entries, and cached media. Explains how wear-leveling and garbage collection in flash storage affect deleted-data recovery prospects.13 min
Module 36 hrs3 topics

Mobile acquisition methods

Logical, file-system and physical acquisition, JTAG and chip-off.

Start module
  1. Logical and File-System AcquisitionCovers logical acquisition through vendor APIs and file-system extraction techniques that retrieve accessible files without unlocking low-level storage. Compares the scope and limitations of each method and the tools most commonly used.13 min
  2. Physical Acquisition TechniquesExplains full-disk physical acquisition including EDL mode, bootloader exploits, and direct memory reads that produce a bit-for-bit image of device storage. Discusses when physical acquisition is warranted and how encryption affects feasibility.13 min
  3. JTAG and Chip-Off AcquisitionDescribes hardware-level extraction methods: JTAG, which accesses memory through test access ports, and chip-off, which physically removes and reads storage chips. Covers the specialist equipment, risks of damage, and scenarios where these methods are the only option.13 min
Module 46 hrs3 topics

Analysing mobile artifacts

Messages, app data, call logs, location history and deleted-data recovery.

Start module
  1. Call Logs, SMS, and Messaging App ArtifactsDetails how call records, SMS and MMS messages, and data from messaging applications such as WhatsApp, Signal, and iMessage are stored and structured. Explains how to parse and interpret these databases to reconstruct communication timelines.13 min
  2. Location History and Geolocation ArtifactsExamines the sources of location evidence on mobile devices including GPS logs, Wi-Fi probe histories, cell-tower records, and application location caches. Covers how to correlate multiple sources to establish device presence at a place and time.13 min
  3. Deleted Data Recovery on Mobile DevicesSurveys techniques for recovering deleted records from SQLite free pages, unallocated NAND blocks, and cached thumbnail stores. Addresses the impact of operating-system version, encryption, and trim on recovery success rates.13 min
Module 56 hrs3 topics

SIM, cloud and backup forensics

SIM data, cloud accounts, and device backups as evidence sources.

Start module
  1. SIM Card ForensicsExplains the data stored on SIM and USIM cards including IMSI, contact entries, SMS records, and location update history (LOCI). Covers forensic readers, relevant file-system standards, and what SIM data proves in a network context.13 min
  2. Cloud Account ForensicsDescribes how to obtain and analyse cloud-service data from providers such as Apple iCloud, Google, and Microsoft under lawful process. Covers the evidence types available, preservation letters, and legal process differences between jurisdictions.13 min
  3. Device Backup ForensicsDetails the structure of iOS iTunes and iCloud backups and Android backup formats and how to extract forensic value from them without device access. Explains encryption, manifest databases, and how backups often contain data not present on the live device.13 min
Module 66 hrs3 topics

Network forensics foundations

The OSI model, protocols and network evidence sources for investigators.

Start module
  1. The OSI Model and Protocols for Network InvestigatorsProvides investigators with a working understanding of the OSI reference model and how protocols at each layer generate forensic artifacts. Focuses on TCP/IP, DNS, HTTP/S, and common application-layer protocols as evidence sources.13 min
  2. Network Evidence Sources and Their Forensic ValueSurveys the types of evidence available in a networked environment including router logs, DHCP leases, NetFlow records, RADIUS logs, and intrusion detection alerts. Explains the relative reliability and coverage of each source type.13 min
  3. Reconstructing a Network Timeline from Multiple SourcesExplains the methodology of correlating timestamps, IP addresses, and session identifiers across heterogeneous log sources to build a coherent event timeline. Covers clock-skew normalisation and the challenges of NAT and shared addresses.13 min
Module 76 hrs3 topics

Packet capture and traffic analysis

Capturing and interpreting network traffic to reconstruct events.

Start module
  1. Packet Capture Tools and MethodsCovers the tools and techniques used to capture network traffic including Wireshark, tcpdump, and commercial network taps, along with span ports and inline capture. Explains capture placement strategy and how to ensure completeness and integrity of packet collections.13 min
  2. Traffic Analysis and Protocol DissectionDescribes how to interpret packet captures to reconstruct sessions, identify transferred files, and detect anomalous behaviour. Covers display filters, stream reassembly, and carving artefacts such as images, documents, and credentials from PCAP files.13 min
  3. Encrypted Traffic AnalysisExplains what investigators can determine from TLS and other encrypted sessions without decryption, including server name indication (SNI), certificate metadata, traffic-volume patterns, and timing analysis. Discusses lawful decryption scenarios and SSL inspection in controlled environments.13 min
Module 86 hrs3 topics

Log analysis and network artifacts

Server, firewall and application logs, and correlating them.

Start module
  1. Server and Application Log AnalysisDetails how to extract investigative value from web server, email, database, and application logs including common formats, parsing techniques, and indicators of compromise. Covers anti-forensic log-clearing and what residual traces may remain.13 min
  2. Firewall and Intrusion Detection Log AnalysisExplains how to interpret firewall connection logs, IDS/IPS alerts, and proxy records to reconstruct attacker activity and data exfiltration paths. Covers rule interpretation, alert triage, and distinguishing true positives from noise.13 min
  3. Log Correlation and SIEM in Forensic InvestigationsDescribes how security information and event management (SIEM) platforms aggregate and correlate log data and how investigators use them during incident response and post-event forensic review. Addresses evidence preservation from SIEM systems and the limitations of log retention policies.13 min
Module 96 hrs3 topics

Wireless, IoT and emerging devices

Wi-Fi, Bluetooth, wearables and IoT as evidence.

Start module
  1. Wi-Fi ForensicsCovers the forensic artifacts generated by Wi-Fi networks including access-point association logs, probe request histories stored on devices, and packet-level evidence from 802.11 frames. Explains how Wi-Fi data places a device or person at a location.13 min
  2. Bluetooth ForensicsExamines the evidence generated by Bluetooth and Bluetooth Low Energy connections including pairing records, device discovery logs, and data exchanged over RFCOMM and GATT profiles. Covers acquisition from mobile devices and dedicated Bluetooth sniffers.13 min
  3. IoT and Wearable Device ForensicsSurveys the forensic acquisition and analysis of smart-home devices, wearables, and embedded IoT sensors as evidence sources. Addresses the diversity of proprietary platforms, cloud-dependency, and the investigative value of sensor data such as heart rate logs, step counts, and smart-speaker recordings.13 min
Module 106 hrs3 topics

Tools, reporting and legal issues

Common toolchains, validation, reporting and admissibility.

Start module
  1. Mobile and Network Forensics ToolchainsSurveys the leading commercial and open-source tools used in mobile forensics (Cellebrite UFED, Oxygen Forensic Detective, MSAB XRY) and network forensics (Wireshark, NetworkMiner, Zeek). Compares capability coverage, validation requirements, and licensing considerations.13 min
  2. Tool Validation and Scientific ReliabilityExplains why forensic tools must be validated before use in casework, covering established validation frameworks such as NIST CFTT and Daubert/Frye standards for admissibility. Describes how examiners document tool versions, test results, and known limitations to withstand cross-examination.13 min
  3. Forensic Reporting and Expert Testimony in Mobile and Network CasesDescribes the structure and content requirements of a forensic examination report covering mobile and network evidence, including findings, methodology, and limitations. Covers how examiners present technical conclusions as expert witnesses and respond to challenges in adversarial legal proceedings.13 min

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.