// Analysis

Explore Mobile Device Forensics

Before you image anything, Nugget wants to know: locked or unlocked, and since when.

Mobile forensics rewards patience with device state and punishes assumptions about it. Most of what goes wrong in casework happens before the imaging tool even opens — someone treats a warrant for the handset as a warrant for the iCloud account behind it, or trusts a physical extraction on a locked iPhone that turns out to be mostly ciphertext. Nugget works through those decision points with you: what's your legal authority for this store, what state is this device really in, what can that acquisition method actually yield given the encryption underneath.

A session usually starts with a scaffold, not a blank question. Nugget lays out a device timeline or sketches how Data Protection classes map to BFU and AFU states, then asks you to reason across it — what changes the moment this phone gets its first unlock, why does that matter for what you can recover. From there it moves into the artifacts themselves: SQLite files, WAL frames, plists, the raw data behind whatever a vendor tool's report claims it found.

This isn't a replacement for your coursework or your lab's SOP — it's a place to rehearse the judgment calls those don't have time to slow down for: epoch conversions, freelist reasoning, scope boundaries, the difference between a polished timeline and the database it was built from.

// What a session feels like

You bring the questions. Nugget asks the next one.

  • Nugget sketches an iOS Data Protection diagram on the whiteboard — passcode, Secure Enclave, key classes — and asks you to mark what's actually available to an examiner the moment a BFU phone lands in evidence.
  • In the terminal, you open a raw SQLite database Nugget has staged and are asked to find a deleted message the parsed report never mentioned — Nugget steers you toward the freelist and WAL instead of the polished UI.
  • Nugget hands you three timestamps from the same case — one Unix seconds, one Cocoa epoch, one WebKit microseconds — and asks you to build a timeline before trusting any tool's pre-converted column.

Start exploring Mobile Device Forensics tonight — a 30-day trial, cancel anytime.

Start your 30-day trial