Choose your language
Mobile forensics Course
More than 2 million students worldwide

Mobile forensics Course

Master the full mobile forensics workflow — from device seizure and data acquisition to artefact analysis and courtroom testimony. This course covers iOS, Android, cloud sources, and emerging technologies, giving you the technical depth and procedural discipline that real investigations demand. Whether you work in law enforcement, corporate security, or digital forensics consulting, this is the hands-on training that moves your career forward.

Dedika for businesses

What you will learn:

  • Acquire data from iOS and Android devices using logical, physical, JTAG, and chip-off methods.

  • Analyse file system artefacts, deleted records, and encrypted data stores on both major mobile platforms.

  • Preserve and document mobile evidence to satisfy chain of custody and admissibility requirements.

  • Reconstruct investigative timelines by correlating artefacts across apps, system logs, and cloud sources.

  • Detect anti-forensic activity, mobile malware, and data exfiltration indicators on compromised devices.

  • Structure and deliver professional forensic reports that meet legal and regulatory standards.

How you study in practice Mobile forensics Course

How you practise Mobile forensics Course

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your company and its specific needs.

Click here

Course content

8 Chapters • 39 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Mobile Forensics

  • Lesson 1 • The Mobile Forensic Process

    Outlines the end-to-end forensic workflow from identification through reporting. Establishes procedural discipline that all subsequent chapters reinforce.

  • Lesson 2 • Mobile Device Ecosystem Overview

    Surveys major mobile platforms, hardware architectures, and market trends. Provides context for understanding why platform differences affect forensic methodology.

  • Lesson 3 • Introduction to Mobile Forensics

    Defines mobile forensics, its scope, and its distinction from traditional digital forensics. Anchors the chapter by framing why mobile devices are critical evidence sources.

  • Lesson 4 • Legal and Ethical Framework

    Covers consent, authorisation, privacy obligations, and admissibility principles applicable to mobile evidence. Ensures examiners operate within lawful and ethical boundaries throughout the course.

Chapter 2See details

Mobile Device Architecture and Storage

  • Lesson 1 • Data Storage Locations and Artifacts

    Maps where user data, application data, and system logs reside on-device. Enables targeted acquisition and reduces time spent on irrelevant storage regions.

  • Lesson 2 • Encryption and Secure Storage

    Introduces full-disk and file-based encryption schemes protecting mobile data. Sets the stage for acquisition challenges addressed in later chapters.

  • Lesson 3 • Mobile File Systems

    Covers file systems used by iOS and Android, including journaling and encryption layers. Understanding file system structure is prerequisite to interpreting acquired images.

  • Lesson 4 • Data Persistence and Deletion

    Explains how data survives deletion, wear-leveling, and garbage collection in flash storage. Prepares students to recover residual data during analysis.

  • Lesson 5 • Hardware Components Deep Dive

    Examines processors, memory chips, baseband modules, and sensors relevant to forensic recovery. Connects hardware knowledge to understanding data residency locations.

Chapter 3See details

Evidence Handling and Device Preservation

  • Lesson 1 • Packaging, Transport, and Storage

    Details proper packaging materials, labeling, and environmental controls for mobile evidence. Ensures physical integrity from scene to laboratory.

  • Lesson 2 • Scene Assessment and Device Identification

    Covers recognising mobile devices, accessories, and associated media at a scene. Proper identification prevents overlooking evidence and guides subsequent handling decisions.

  • Lesson 3 • Network Isolation Techniques

    Explains methods to prevent remote wipe, data sync, and network-based evidence alteration. Isolation is the most time-critical preservation step after device discovery.

  • Lesson 4 • Documentation and Chain of Custody

    Establishes rigorous documentation standards for every handling event. Accurate records are essential for courtroom admissibility and audit trails.

  • Lesson 5 • Device State Management

    Addresses decisions around powered-on vs. powered-off devices and screen-lock status. Correct state management preserves volatile data and avoids triggering security lockouts.

Chapter 4See details

Mobile Data Acquisition Methods

  • Lesson 1 • Acquisition Method Taxonomy

    Classifies acquisition methods by invasiveness, data yield, and required expertise. Provides a decision framework used throughout the chapter and the course.

  • Lesson 2 • JTAG and Chip-Off Acquisition

    Explains hardware-level extraction via JTAG interfaces and direct chip reading. These destructive or semi-destructive methods are last-resort options for damaged or locked devices.

  • Lesson 3 • Cloud and Remote Data Acquisition

    Addresses acquiring data from cloud backups, synced accounts, and carrier records. Extends the acquisition scope beyond the physical device.

  • Lesson 4 • Physical Acquisition Techniques

    Covers bootloader exploits, EDL mode, and forensic boot images for full physical dumps. Physical acquisition yields the most complete data set when encryption permits.

  • Lesson 5 • Logical and File System Acquisition

    Demonstrates backup-based and file system extraction techniques on iOS and Android. These methods are the least invasive and most commonly applied in practice.

Chapter 5See details

iOS Forensic Analysis

  • Lesson 1 • Location and Sensor Data

    Recovers GPS coordinates, Wi-Fi positioning, and motion sensor logs from iOS. Location evidence can corroborate or refute timeline claims in investigations.

  • Lesson 2 • Application and Browser Artifacts

    Analyses installed app data, browser history, and cached web content on iOS. App artifacts often contain user activity evidence not found in system databases.

  • Lesson 3 • iOS File System and Key Artifacts

    Maps the iOS directory structure and identifies high-value forensic artifacts. Knowing artifact locations accelerates analysis and reduces examiner error.

  • Lesson 4 • iOS Backup and iCloud Analysis

    Parses encrypted and unencrypted iTunes backups and iCloud data sets. Backup analysis often yields data unavailable from direct device acquisition.

  • Lesson 5 • Communications and Messaging Artifacts

    Extracts and interprets SMS, iMessage, call logs, and voicemail data from iOS. Communication artifacts are among the most probative evidence in mobile investigations.

Chapter 6See details

Android Forensic Analysis

  • Lesson 1 • Application Data and Browser Artifacts

    Analyses APK structures, app databases, and browser artifacts on Android. App data diversity across Android versions demands adaptive analysis techniques.

  • Lesson 2 • Communications and Messaging on Android

    Recovers SMS, MMS, call logs, and third-party messaging data from Android devices. Covers both native and manufacturer-specific messaging implementations.

  • Lesson 3 • Android File System and Key Artifacts

    Navigates Android partition layout and locates high-value forensic data stores. Manufacturer and version variations require flexible artifact location strategies.

  • Lesson 4 • Google Account and Cloud Artifacts

    Recovers Google account-synced data, Drive content, and Play Store records. Cloud-synced artifacts extend evidence beyond the physical device.

  • Lesson 5 • Location and Sensor Artifacts

    Extracts GPS history, Google location data, and sensor logs from Android. Correlating location artifacts with timestamps builds investigative timelines.

Chapter 7See details

Advanced Artifact Analysis and Timeline Reconstruction

  • Lesson 1 • Cross-Platform Artifact Correlation

    Correlates evidence across iOS, Android, and cloud sources within a single investigation. Multi-platform cases require unified analytical frameworks to avoid evidence gaps.

  • Lesson 2 • Deleted and Hidden Data Recovery

    Applies carving, SQLite recovery, and unallocated space analysis to recover deleted data. Recovered deleted artifacts frequently provide decisive investigative evidence.

  • Lesson 3 • Metadata Extraction and Interpretation

    Extracts timestamps, geotags, and file metadata from media and documents. Metadata provides objective anchors for timeline construction.

  • Lesson 4 • Anti-Forensic Detection and Countermeasures

    Identifies evidence of data wiping, encryption, and app-based concealment techniques. Recognising anti-forensic activity is essential for complete and accurate reporting.

  • Lesson 5 • Timeline Creation and Correlation

    Builds unified timelines by correlating artifacts from multiple data sources. Cross-source correlation reveals patterns invisible in single-source analysis.

Chapter 8See details

Reporting, Testimony, and Case Presentation

  • Lesson 1 • Case Review and Quality Assurance

    Implements peer review, verification, and audit processes before report submission. Quality assurance prevents errors that could undermine case outcomes.

  • Lesson 2 • Evidence Presentation and Visualisation

    Creates charts, timelines, and visual exhibits that communicate complex artifact data. Effective visualisation improves comprehension and persuasiveness in legal proceedings.

  • Lesson 3 • Forensic Report Structure and Standards

    Defines the components of a professional forensic report and quality standards. A well-structured report is the primary deliverable of every mobile forensic examination.

  • Lesson 4 • Writing for Technical and Legal Audiences

    Adapts report language and detail level for investigators, attorneys, and judges. Audience-appropriate writing prevents misinterpretation of forensic findings.

  • Lesson 5 • Expert Witness Testimony Preparation

    Prepares examiners for deposition and courtroom testimony on mobile forensic findings. Credible testimony requires mastery of both content and courtroom communication skills.

Certification

Your valid completion certificate

This course is for you:

  • Law enforcement officer: needs structured mobile evidence skills for criminal cases.

  • Corporate security analyst: investigates insider threats and data leaks on company devices.

  • IT professional: transitioning into a dedicated digital forensics career path.

  • Private investigator: handles civil and fraud cases where phone data is central.

  • Cybersecurity student: building a specialisation that stands out to forensic employers.

  • Incident responder: needs mobile-specific techniques to complete compromise investigations.

What our students say

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top qualifications

FAQ

Who is Dedika?

Is the certificate valid in South Africa?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course