AX302

Magnet AXIOM Advanced iOS Examinations

What You’ll Learn

This course is an intermediate-level two-day training course, designed for participants who are familiar with the principles of digital forensics and who are seeking to expand their knowledge base into deep iOS file system examinations.

In this course, students will learn about key artifacts available only to the file system level extractions and not available in traditional backup style acquisition methods. These artifacts include activity tracking points such as PowerLog and KnowledgeC as well as several sources of location data from the device. Students will learn about Apple’s security measures that are in place and discuss how they can impact acquiring different levels of file system extractions.

Several methods will be discussed to understand the pros and cons of using each of these methodologies appropriately. Magnet AXIOM will also be leveraged to learn how the iOS filesystem is structured, how to locate key data, and how artifacts are structured. In addition, students will learn about artifacts specific to the iOS full file system and its multiple levels of data protection. Third-party artifact analysis of several advanced, secure artifacts will be covered, including how the device keychain ties into these artifacts. A methodology will be discussed on how to conduct deep-level iOS examinations and how to understand specific operating system artifacts in context to show device interactions over time. Students will learn how to put someone behind a device physically interacting with it, and even sometimes where that device has been.

Because AX302 is an intermediate-level course, it is strongly recommended that students first complete Magnet AXIOM Examinations (AX200). AX200 will provide a thorough understanding of AXIOM that will help students focus on the cloud aspect of investigations in AX302.

Course Introduction

  • Cover the basic prerequisites for Magnet AXIOM 

Understanding iOS and Apple’s Security

  • Discussion-focused coverage of the iOS operating system’s security functions and structure.
  • Learn about device protection class keys, understanding the handset lock codes and their function, as well as other functions of the operating system.

Device Image Types & Filesystem Acquisitions

  • Compare the different methods in the industry currently to extract filesystem images of iOS devices.
  • Compare the different levels of filesystem images that can be acquired before and after the entering of the user’s handset lock code. Learn how to explore key artifacts within these different extraction types.

Importing Data in Magnet AXIOM

  • Understand the multiple ways to ingest information and develop a proper workflow for ingesting information from filesystem extractions.
  • Learn about several AXIOM functions such as Dynamic App Finder, Search for Custom Files by Type, and how to target secure messaging applications.

Exploring Artifacts in Magnet AXIOM

  • Explore multiple artifacts, including deep diving into artifacts that are core to the iOS file system – core artifacts will be explored in depth including techniques for recovering deleted information from these databases.
  • Advanced file system artifacts such as PowerLog and KnowledgeC will be covered to talk about application usage times and data amounts. These and other artifacts will be explored to show examiners how to track when targets are interacting physically with a device in a specified timeframe.
  • Exclusive file system artifacts such as location history, third party applications, and more will also be explored. 

Try The Training Annual Pass (TAP)

TAP lets you pay once, but train continuously. For $5,795 USD (less than the cost of two courses), you can attend any class at any time throughout the following 12 months.


Upcoming Classes


CLASS TYPE

LOCATION

DATES
Virtual Instructor-Led (EST)OnlineJune 9-10
Virtual Instructor-Led (CST)OnlineJuly 7-8
Virtual Instructor-Led (CST)OnlineJuly 9-10

Frequently Asked Questions

What do I need to bring?

Computer needs will be determined by class, but otherwise, it’s a classroom like any other, so bring in something to take notes on, water, lunch, etc.

How many students are in a classroom?

It can vary wildly depending on location and topic. Check out our registration page to find out how many seats are available per class.

Can I get custom training for my organization?

Yes! Simply contact us and let us know the details of who would be receiving the training and what topic you would like addressed. We’ll follow up with more details.

What materials will I receive in the course?

You will receive an course manual which you can keep and refer to long after the course has been completed.

Are all courses available with TAP?

Yes. If you’ve purchased a TAP, you can take any course, any time, no matter if it’s in-person, online, or online self-paced.