Advanced Applied Database Forensics (Live on-site – Pittsburgh, PA – July 2025)
5-day Advanced Course – Live Remote
Course Overview
Learn to use various applications and utilities to successfully identify, process, understand and exploit numerous database structures found on iOS, Android, Windows, and Apple systems.
Students will gain knowledge of how relational databases function in the storage of records and fields of information to support a front-end application. SQLite will be covered in detail where the attendee will learn how to recover deleted information from Free Pages and unallocated space within the primary and journal files using scripting techniques. Additional databases will then be examined including ESE, LevelDB’s and Binary Plists.
Students will examine data from a host of systems including Mac, Windows, Android, iPhone.
We will use a variety of open-source and leading forensic applications to examine key artifacts through multiple hands-on labs and student exercises. Throughout the weeklong course topics will include:
- Relational Database Fundamentals
- Examination of the SQLite Databases at the physical level
- Examination of SQLite B-tree Pages
- The exploitation of Overflow Pages, Freelist Pages, and Rollback Journals
- Analysis of Write-Ahead Logs (WAL) and Database Schemas
- Extensive exercises in using SQLite Query Language
- Extensive scripting of chromium based browser SQLite databases
- Deep Dive into LevelDBs and extraction of meaningful data
- Introduction to Apple Plist and forensic analysis
The course will follow adult learning principles through training aids such as presentations, diagrams, and practical instructor lead examples. Each artifact covered will be presented in either one or two 50-minute sessions followed by review questions. Students will be given the opportunity throughout the course to ask questions and discuss objectives covered in more detail. Throughout each day students will have practical exercises to work on to reinforce the topics.
Students will examine data from a host of systems including Mac, Windows, Android, iPhone.
We will use a variety of open-source and leading forensic applications to examine key artifacts through multiple hands-on labs and student practicals.
What you will receive:
Printed course manual · Student USB · Access to the Spyder Forensics Academy · Course certificate – Optional self-packed test post course completion