Cellebrite Apple Intermediate Forensics (CAIF)
This three-day training will include a deeper look at analysing macOS and iOS devices. In the course, participants work on a case using the Cellebrite Inspector software.
Who is this training for?
This training is designed for digital investigators with a basic knowledge of macOS and iOS devices who want to expand their knowledge and reach a higher level of proficiency. It is recommended to take the Cellebrite Apple Forensics Fundamentals training first before starting this course.
What do you learn during the training?
- Analysing mounted volumes, device connections and network connections in macOS.
- Interpret encountered log files on macOS and iOS devices to analyse Apple Mail. including its structure, e-mail messages and related files.
- Identifying evidence around the use of Terminal.
- Recognising the GUID Partition Table and understanding its structure.
- Understanding the Hierarchical File System (HFS+).
- Distinguishing and interpreting APFS disk structures from different macOS versions.
- Creating, investigating and analysing an APFS disk.
- Recognising and understanding the differences between link files, APFS clones and APFS farm links in macOS.
- Creating and analysing Time Machine backups and APFS Snapshots.