SECURITY 563SECURITY 563


Course PDF

Significant amounts of potentially probative information are stored logically on mobile devices, including text messages, e-mails, call logs, calendar items, photos and videos. The third day of the course focuses on forensic acquisition and examination of logical data from mobile devices. No one tool can accomplish everything, and you need to be able to select the right tool for the job at hand.

This day begins with a hands-on evaluation of several toolkits for acquiring logical data from mobile devices to assess their strengths and weaknesses from a forensic perspective. We look at what goes on behind the scenes of various forensic acquisition tools for mobile devices to provide a better understanding of how they work. We also teach approaches to dealing with common challenges that arise in the field, and demonstrate approaches to bolstering weaknesses in a tool with solid forensic processes.

As day 3 progresses, we dig progressively deeper into digital evidence on mobile devices, analyzing call logs, SMS/MMS, photos, and associated metadata. In addition, we demonstrate how to utilize e-mail, Web browsing, and other Internet activities on mobile devices in an investigation. Practical, hands-on case scenarios give you an opportunity to work with multiple forensic examination tools and verify the completeness and accuracy of their results.




SECURITY 563 Upcoming Events
Event Location Dates Delivery Method
SANS Security East 2010New Orleans, LAJan 10, 2010 - Jan 18, 2010Live Event
Community SANS San Antonio 2010San Antonio, TXJan 25, 2010 - Jan 29, 2010Community SANS
SANS Security West 2010San Diego, CAMay 07, 2010 - May 15, 2010Live Event
"This is awsome! We're seeing details that most people don't even know exist" - John Wright, Info Tech, Inc.
"The class provided in-depth, real world, hands-on information" - Robert Dale Drollinger, General Dynamics
SANS Institute