This event has ended!

View current events hosted by Jonathan Zdziarski

Advanced iPhone Forensics L-1: Chicago, IL

Tuesday, May 4, 2010 at 8:00 AM - Wednesday, May 5, 2010 at 5:00 PM (CT)

Chicago, IL

Ticket Information

Ticket Type Sales End Price Fee Quantity
Standard Admission   more info Ended $3,500.00 $9.95
Active Duty Law Enforcement Personnel   more info Ended $2,500.00 $9.95

Event Details

 


Advanced iPhone Forensics Workshop L-1


Recovering Evidence, Personal Data, and Corporate Assets

The iPhone has become America's #1 mobile device, and is increasingly being used in business, personal activities, and also crime. iPhones store an enormous amount of information useful to corporate security professionals and law enforcement agents. Enterprises must adequately manage sensitive data which may put their company at risk. Law enforcement agencies and freelance forensic examiners must process the iPhone for evidence linking its owner to crimes. 

Join us as Jonathan Zdziarski, iPhone forensics expert and author of many iPhone books including iPhone Forensics andiPhone SDK Application Development, leads your organization's security professionals through the delicate process of recovering and processing evidence stored on the iPhone. This two-day workshop will guide you, hands on, through forensic examination of iPhone, iPhone 3G, and iPhone 3G[s] devices covering iPhoneOS v1.x, v2.x, up to the latest v3.1.3 software. iPad forensics will also be demonstrated. Attendees will receive a special iPhone forensic guide and access to automated tools used in the field by hundreds of law enforcement agencies. All of the tools and demo content will also be provided so attendees can learn and explore hands-on. Join us and follow along hands-on to learn:

  • What kind of evidence is stored on the device
  • How to prepare an environment for iPhone forensics
  • Circumventing passcode protection and encrypted backups to gain access to the device
  • Building a custom recovery toolkit for the iPhone
  • Interrupting the iPhone's "secure wipe" process
  • Data recovery of an iPhone user disk partition, preserving and recovering the entire raw user disk partition. Recovery over USB cable and Wi-Fi will be demonstrated.
  • Recovering deleted voicemail, images, email, and other personal data using data carving techniques
  • Recovering geotagged metadata from camera photos (GPS coordinates taken at the time the photo was taken)
  • Electronic discovery of Google map lookups, keyboard typing cache, and other data stored on the live file system
  • Extracting contact information and other data from the iPhone's database
  • Collecting desktop trace and establishing trusted relationships to owners' desktops
  • Different recovery strategies based on case needs
Using the tools and know-how provided in this workshop, you'll work hands-on to recover stored and deleted information from the iPhone including:
  • Keyboard caches containing usernames, passwords, search terms, and historical fragments of typed communication.
  • Screenshots preserved from the last state of an application, taken whenever the home button is pressed or an application is exited.
  • Deleted images from the suspect's photo library, camera roll, and browsing cache.
  • Deleted address book entries, contacts, calendar events, and other personal data.
  • Exhaustive call history, beyond that displayed.
  • Map tile images from the iPhone's Google Maps application, lookups and longitude/latitude coordinates of previous map searches, and coordinates of the last GPS fix.
  • Browser cache and deleted browser objects, which identify the web sites a user has visited.
  • Cached and deleted email messages, SMS messages, and other communication with corresponding time stamps.
  • Deleted voicemail recordings stored on the device.
  • Pairing records establishing trusted relationships between the device and one or more desktop computers.
In addition, Jonathan will walk you through many common corporate and crime scene scenarios and describe the kind of data that will prove most useful in your investigation. A Q/A session will conclude the conference as time permits. Classroom assistants will be available to help during all classes. 

This is a Mac-only course. Be sure to bring a Mac notebook and an iPhone if you would like to learn hands-on. Do not bring live evidence or any data that cannot be at risk from classroom mistakes. To keep everything on track, the following classroom specifications will be used:
  • Mac OS X Leopard v10.5.7 or Snow Leopard (v10.6.x)
  • iTunes 8.1.1
  • [Optional] An iPhone, iPhone 3G, or iPhone 3G[s] running firmware v1.0.2 - 3.1.3
  • [Optional] An iPad running firmware v3.2

Don't miss the opportunity to have your personnel trained by the leading expert in iPhone forensic examination. Register today, as space is limited.

Important Billing Information

If you do not have a PayPal account or would like to have your credit card billed directly, please contact us directly at jonathan@zdziarski.com.

Refund Policy

Due to the expenses involved in organizing this workshop, cancelations within 14 days of the event date are non-refundable. We will work with you, however, to place you in a different workshop that may better fit your schedule. 

 

 

When & Where



Chicago Police Training Academy
1300 West Jackson Boulevard
Chicago, IL 60607

Tuesday, May 4, 2010 at 8:00 AM - Wednesday, May 5, 2010 at 5:00 PM (CT)


  Add to my calendar

Hosted By

Jonathan Zdziarski



Jonathan Zdziarski is considered, worldwide, to be the foremost expert in iOS related digital forensics. Better known as the hacker "NerveGas" in the iPhone development community, his research into the iPhone helped lead the effort to port the first open source applications, and his book, iPhone Open Application Development, taught developers how to write applications for the popular device long before Apple introduced its own SDK. Prior to the release of his book, iPhone Forensics, Jonathan wrote and supported an iPhone forensics manual distributed exclusively to law enforcement. Jonathan frequently consults law enforcement agencies on high profile cases and assists federal, state, and local agencies in their investigations.