Your learning

Complete Digital Forensics Session D – Mobile Analysis

After Session C, analyse the educational mobile image, build a timeline, bookmark evidence, and append structured findings to your case file.

Last reviewed: 28 August 2026

Before you begin

  • Your institution has enabled Domain Laboratories.
  • You have an active Academic Enrolment on the Course Offering.
  • Teaching staff have attached and enabled the Digital Forensics Laboratory.
  • You have completed Sessions A–C for the same laboratory (Evidence Integrity, Browser Evidence, and Mobile Acquisition).

Open Session D

  1. Open My Learning and enter the Course Offering Learning Experience.
  2. Open Laboratories and launch Digital Forensics Laboratory.
  3. On the Digital Forensics hub, confirm Session C shows Completed.
  4. Select Start Session D (or Continue Session D / Resume Analysis).

Analyse the mobile image

  1. Review the Device Summary for the educational image produced after Session C. Use Copy for SHA-256, IMEI, or artefact references when you need them in findings.
  2. Move through workspace views such as Messages, Calls, Contacts, Media, Browser, Downloads, and Location.
  3. Mark artefacts reviewed, bookmark important items, and add investigator notes. After each action (or on reload), you return to the view and step you need next.
  4. Complete guided investigation tasks by selecting artefact references that support each conclusion.
  5. Use the Timeline view to add chronological events tied to evidence timestamps.
  6. Record structured Findings with evidence references, confidence, reasoning, and recommendations.
  7. Optionally download the Mobile Analysis Summary, Evidence Findings Report, or Timeline PDFs.
  8. Select Mark summary ready, then Complete Session D to return to Learning Experience.

Notes

  • Analysis contributions append to the same case file from Sessions A–C. Earlier evidence is not overwritten.
  • The dataset is educational only — AppliedMode does not parse real phone images, SQLite databases from devices, or commercial forensic tools.
  • Session Completion PDF records Session D contribution only — it is not a final investigation report.
  • After Session D is completed, Session E – Investigation Planning unlocks on the same Digital Forensics hub.