Digital Forensic Investigators need to understand the inner working of mobile devices and how they store data in order to extract and interpret the information they contain. The second day of the course covers mobile device operation and data storage, and forensic examination of SIM cards. This day begins with a review of operating systems and file systems on common devices, including Windows Mobile and Blackberry. Devices will be provided in class for you to work with. We build on this foundational knowledge of the different ways that information is arranged and protected on mobile devices by closely examining logical storage objects they contain, including user created data (e.g., call logs, SMS/MMS/e-mail messages, calendars, address books) and system files (e.g., Registry). We delve into the storage structure of SIM/USIM cards as defined in GSM11.11 and TS51.011, dealing with PIN protection, and creating a safe
SIM for forensic examination purposes.
During hands-on exercises on day 2, you will use manufacturer and developer tools to gain a deeper understanding of mobile device internals. Furthermore, you will acquire and examine the contents of SIM cards to get practical, hands-on experience and better understand how they store data, how to decode the data, the types of information they contain, and how that information can be useful in an investigation.
| SECURITY 563 Upcoming Events | |||
| Event | Location | Dates | Delivery Method |
| SANS Security East 2010 | New Orleans, LA | Jan 10, 2010 - Jan 18, 2010 | Live Event |
| Community SANS San Antonio 2010 | San Antonio, TX | Jan 25, 2010 - Jan 29, 2010 | Community SANS |
| SANS Security West 2010 | San Diego, CA | May 07, 2010 - May 15, 2010 | Live Event |