
Welcome to BEC 301
This course will provide you with the knowledge and preparation to use the Belkasoft X forensic software to analyze mobile device digital evidence acquired from cell phones and tablets. This course is meant for beginners, but also contains information and scenario-based exercises suitable for advanced users looking for a refresher in the realm of mobile forensics.
You will be challenged with several hands-on activities, but on-demand does not mean you are alone. Our instructors are available for questions and clarification on concepts discussed in this course. Reach out to them as needed!
- Pete McGovern – pete@codeblueforensics.com
- Joe Church – jchurch@digitalshield.net
Suggested Hardware Configuration
Belkasoft Evidence Center is very powerful and can be resource intensive depending on how the platform us being used for analysis. It is highly recommended that you take this course using a system with the following minimum specifications:
- Windows 10
- 8 GB RAM
- 500GB Hard drive (with at least 50GB of free space)
- 3MBPS broadband Internet
- 32GB USB 3.0 external hard drive
Student Desktop
Some minor setup of the course data will need to be performed on your system before proceeding with the course. Please follow the instructions below before starting Module 01.
- Download the student folder files from the Dropbox link below https://www.dropbox.com/sh/67rh51xj0tum1ff/AACSn5CcNIdryhHctOJapmPLa?dl=0
- Copy the file “BEC X 301 Student Folder.zip” to your desktop
- Install 7-zip on your forensic workstation
- Right-click the file from step #2 and select 7zip > “Extract Here”
Introduction
Mobile Device Technology Overview
Mobile Device Acquisitions
Lessons
Module 3 – Mobile Device Acquisitions Activity – Logical acquisition of an iPhone using the AFC method Activity – Logical acquisition of an iPhone using the iTunes Backup method Activity – Logical acquisition of an Android phone using the ADB Backup method Activity – Logical acquisition of an Android phone using the MTP/PTP method Activity – Manual acquisition of an Android phone using the Screen Capturer method Quiz – Module 3Understanding Apple iOS Artifacts
Lessons
Module 4 – Understanding Apple iOS Artifacts Activity – User/Data Directory Activity – Address Book Activity – Call History Activity – SMS/MMS/iMessages Activity – Calendar Activity – iOS Notes Activity – Safari Bookmark and Cache Activity – Thumbnail Cache Activity – 3rd Party Apps Quiz – Module 4Understanding Android Artifacts
Mobile Device Examinations
Mobile Device Analysis Techniques
Lessons
Module 7 – Mobile Device Analysis Techniques Activity – Search Techniques using Keywords Activity – Search Techniques using Keyword Lists Activity – Search Techniques using Regular Expressions Activity – Search Techniques using Pre-defined Searches Activity – Filtering Activity – Bookmarking Activity – Reporting Activity – Evidence Reader Report Quiz – Module 7bec 301 – final exam
Lessons
BEC 301 – Final ExamCertification
Lessons
Bec 301 Certification