Cellebrite Advanced Smartphone Analysis (CASA)

Nivel: experto.

Código: CASA.

Duración: 4 días.

Course description

This 4-day advanced analysis course takes a hands-on, in-depth look into the forensic recovery of application data found in today’s smartphones. This class is recommended for those familiar with UFED Physical Analyzer or who have completed the CCPA course. In this course, participants will learn how to decode information which is not decoded by forensic tools. They will also utilize third party software and Python scripts to analyze, verify and validate findings.

SQLite Database Structures

This module focuses on SQLite database structures and functionality. You will learn about write-ahead log and shared memory files, binary large objects handling, free page lists and free page handling, the vacuum function, and how table data is joined. You will use practical, hands-on exercises using UFED Physical Analyzer and verify their findings using other software tools and be able to:

iOS Overview and Analysis

In this module you will learn about the demographics of iOS. You will learn what happens during the extraction process of an iOS device using UFED technology. We will show you how applications are stored, accessed and various ways to decode information found in XML and binary plist files. You will also learn about date and time encoding schemes and using a number of hands-on practical exercises you will examine numerous files of interest. At the completion of this module, you will be able to:

iOS Device Access

In this module, you will learn about the challenges caused by the Data Protection API found in Apple iOS devices. You will learn about:

iOS and iCloud Backups

In this module we will learn about iOS backups found on computer systems, encrypted iOS extractions, and what kind of information can be contained within them. We will also discuss backup file encryption and decryption using open source tools, iCloud backups, and decoding. At the completion of this module, you will be able to:

Android Overview

In this module we will discuss the evolution of the Android operating system since its availability in 2007. You will also learn about the different file systems commonly used and how data is stored on Android devices and SD cards. We will discuss encryption, extractions and limitations. At the completion of this module, you will be able to:

Android System Artifacts

In this module you will learn about important Android system artifacts. You will learn about obtaining data that documents wireless networks, time zone settings, mounted file systems, SD Card usage, pattern lock codes, Bluetooth information, and operating system versions; this information may prove critical to the investigation. At the completion of this module, you will be able to:

Android User Artifacts

In this module you will learn about artifacts created by the user’s interaction with different applications on the Android device. Using hands-on practical exercises, you will examine: Google Maps data, unsupported applications, and artifacts which store data about user activity which aren’t parsed as part of any tool extraction. At the completion of this module you will be able to:

Note: Successful completion of the Cellebrite Advanced Smartphone Analysis (CASA) examination and practical skills test results in a Cellebrite Advanced Smartphone Analysis Certification credential.