GK200 Graykey Examinations

GK200 is an intermediate-level, four-day training course designed for participants who are familiar with the principles of digital forensics and are looking to extend their capability into iOS, Android, and vehicle examinations using Magnet Graykey. Students must be part of a law enforcement agency and must be cleared in advance to attend this course.

Description

GK200 is an intermediate-level, four-day training course designed for participants who are familiar with the principles of digital forensics and are looking to extend their capability into iOS, Android, and vehicle examinations using Magnet Graykey. Students must be part of a law enforcement agency and must be cleared in advance to attend this course.

Across four days of instruction and hands-on exercises, students will build a practical workflow for handling iOS and Android devices in the field and in the lab, and learn to operate Graykey end-to-end to extract data from locked and secured mobile devices. The course also introduces Magnet Autokey, Magnet’s vehicle acquisition solution, which extends the Graykey workflow to supported modern vehicles and is currently available to US law enforcement as an add-on to Graykey Premier licenses.

Magnet Axiom is used throughout the course to explore how mobile file systems are structured and how to locate the data that matters most. Students will study the artefacts specific to Graykey’s extraction outputs and the different levels of data protection implemented on modern mobile devices. From Keychain and Keystore analysis to the advanced methodologies needed to uncover operating system artefacts, students leave the course able to deal effectively and efficiently with data from mobile devices — regardless of extraction level or device state.

Students must be part of a law enforcement agency and MUST own a Magnet Graykey. 

What to expect

Hear directly from Justin Almanza, a Forensics Trainer at Magnet Forensics, about Magnet Forensics training courses specifically designed to help you in your mobile investigations, including Core Mobile Acquisition & Analysis (AX150), Axiom Advanced Mobile Forensics (AX300), and Graykey Examinations (GK200).

Course prerequisites

Because GK200 is an intermediate-level course, it is recommended that students first complete Magnet Axiom Examinations (AX200).

Course modules

Module 1: Course Introduction
Review of the course outline, personal introductions, and the week-long case scenario that will be used throughout the training event. Students finish the module with a clear understanding of the structure of the course.

Module 2: Graykey Overview
An introduction to the Graykey device itself — covering hardware, licensing, capture and extraction settings, enhanced capabilities, and device preferences. This module also covers the full range of Graykey’s operational features, including Mobile Excursion, Crypto Triage, logical+, category-based extractions, and Magnet Graykey Fastrak.

Module 3: iOS Fundamentals
Discussion-focused coverage of the iOS operating system’s structure and security. Students will review the APFS file system, core Apple security hardware and firmware, device keys, the Secure Enclave, data protection classes, handset lock codes, and USB Restricted Mode.

Module 4: iOS Acquisitions Using Graykey
Hands-on work covering the full iOS extraction workflow: evidence preservation, known- and unknown-passcode workflows, BFU, AFU, full filesystem and Logical+ extractions, and brute-forcing passcodes using the Axiom Wordlist Generator and Hashcat. This module also introduces Magnet Autokey, Magnet’s vehicle acquisition tool, including supported infotainment systems, vehicle artifacts, the vehicle acquisition workflow, and current Autokey availability.

Module 5: Android Fundamentals
Discussion-focused coverage of the Android operating system’s structure and security. Students will explore the Generic Kernel Image, Android file system and partitions, core Android security features, full-disk and file-based encryption, Android passcodes, and vendor-specific security features such as Samsung Secure Folder.

Module 6: Android Anti-Forensics
An awareness module focused on anti-forensic operating systems and applications, with particular attention to GrapheneOS — its privacy and security features, supported devices, data-wipe behaviors, and the handling and seizure considerations these devices introduce.

Module 7: Android Acquisitions Using Graykey
Hands-on work covering the full Android extraction workflow: evidence preservation, known- and unknown-passcode workflows, BFU Android devices, Download/Upload/Fastboot modes, and brute-forcing techniques (including multi-user brute-force).

Module 8: Graykey Outputs and Magnet Axiom
An overview of the different outputs produced by Graykey (BFU, AFU, full filesystem, selective, Logical+, process memory, keychain/keystore, password list, passcode history, progress report) and how to load these into Magnet Axiom Process and Examine for analysis.

Module 9: Analyzing iOS Extraction Types
A practical deep-dive into the artifacts available at each iOS extraction level — BFU, AFU, full filesystem, and Logical+ — using Axiom Examine. Students will locate and interpret artifacts such as Accounts, Apple Notes, Apple Mail, Significant Locations, Apple Maps, KnowledgeC, and cached locations.

Module 10: Analyzing Android Extraction Types
A practical deep-dive into the artifacts available at each Android extraction level (BFU and Full File System), with emphasis on mainstream data protection features such as Secure Folder, Dual Messenger, and Google Private Space.

Additional information

Who should attend: Participants who are unfamiliar with the principles of digital forensics
Advanced preparation: None
Program level: Advanced-level
Field of study: Computer software & applications
Delivery method: Group live

Refunds and cancellations: Training Course(s) can be rescheduled to a later date or cancelled by either Magnet Forensics or you without charge or penalty if written notice is received twenty-one (21) days or more prior to the date of the Training Course. No rescheduling shall be permitted on less than twenty-one (21) days written notice, which shall constitute a cancellation without a refund. Your written rescheduling or cancellation notice must be emailed to training@magnetforensics.com or contact 202.984.3417. If Magnet Forensics cancels a Training Course due to insufficient attendance, you will have the option to register in a different scheduled Training Course or receive a full refund. Please do not book travel until you have confirmed that the Training Course will be running.

Magnet Forensics is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website:www.nasbaregistry.org.

Similar courses

AX250 is an advanced level course designed for students who are familiar with the principles of digital forensics and use Magnet Axiom in Windows investigations. You can purchase training classes directly online using a credit card or if payment by purchase order is required, please request a quotation from sales@magnetforensics.com.

More Information

This course is an expert-level four-day training course, designed for participants who are familiar with the principles of digital forensics and who are seeking to improve their mobile device investigations. You can purchase training classes directly online using a credit card or if payment by purchase order is required, please request a quotation from sales@magnetforensics.com.

More Information

Magnet Axiom Examinations (AX200) is ideal for those who require intermediate-level training with a digital investigation platform that covers cases involving smartphones, tablets, computers, and cloud data in a single collaborative interface. This course is the perfect entry point for examiners who are new to Axiom. You can purchase training classes directly online using a credit card or if payment by purchase order is required, please request a quotation from sales@magnetforensics.com.

More Information

This course is an intermediate-level four-day training course, designed for participants who are somewhat familiar with the principles of digital forensics and who are seeking to expand their knowledge base into cloud-based and social media forensics. You can purchase training classes directly online using a credit card or if payment by purchase order is required, please request a quotation from sales@magnetforensics.com.

More Information

AX350 is an expert-level four-day training course, designed for participants who understand digital forensics fundamentals, basic Axiom usage, and are seeking to expand their forensic investigative skills targeting Mac computers. You can purchase training classes directly online using a credit card or if payment by purchase order is required, please request a quotation from sales@magnetforensics.com.

More Information

Forensic Fundamentals (AX100) is a beginner-level course, designed for participants who are unfamiliar with the principles of digital forensics. You can purchase training classes directly online using a credit card or if payment by purchase order is required, please request a quotation from sales@magnetforensics.com.

More Information

Digital Video Investigations with Magnet Witness (DV200) is a beginner-level course, designed for participants who are not yet familiar with the concepts of the recovery and analysis of digital video files from commercially available digital video recorders.

More Information

Magnet Axiom to Cyber Transitions is ideal for those who are looking to continue their education and transition into the unique features of Axiom Cyber after taking the Axiom Examinations (AX200) course.

More Information

Magnet Axiom Examination (AX200 Microlearning) is ideal for those who are relatively new to forensics and want to learn how to utilize Axiom to get the most out of the forensic platform. Axiom is a platform that covers cases involving mobile device, computer, and cloud data in a single collaborative interface. Students will learn the workflows of how to interrogate and investigate devices containing digital media.

More Information

Core Mobile Acquisition and Analysis (AX150) is a beginner level course, designed for participants who are unfamiliar with the principles of mobile forensics. The course focuses on iOS and Android devices from the point of collection to the point of analysis whilst exploring Magnet Axiom and Magnet tools such as Magnet Acquire, the Magnet Custom Artifact Generator (MCAG) and Magnet Axiom Dynamic App Finder.

More Information

Core Mobile Acquisition and Analysis (AX150 Microlearning) is a beginner level course, designed for participants who are unfamiliar with the principles of mobile forensics. The course focuses on iOS and Android devices from the point of collection to the point of analysis whilst exploring Magnet Axiom and Magnet tools such as Magnet Acquire, the Magnet Custom Artifact Generator (MCAG) and Magnet Axiom Dynamic App Finder.

More Information

Magnet Axiom Advanced Mobile Forensics (AX300 Microlearning) details the use of Magnet Axiom’s advanced mobile analysis capabilities. Students will learn advanced analysis techniques and leverage Magnet Axiom Examine to become proficient in investigating advanced aspects of full file system extractions of both iOS and Android devices.

More Information

The Magnet Griffeye Examinations Course is a 3-day training course designed for students who have attended the Magnet Griffeye Lite online course or have already attained proficiency in Magnet Griffeye Advanced. The course is designed to equip you with the necessary skills and tools to handle media files effectively during a criminal investigation, thereby maximizing the productivity of the tool.

More Information

Magnet Verakey Examinations (VK200) is an intermediate-level four-day training course, designed for participants who are familiar with the principles of digital forensics and who are seeking to improve their mobile device investigations.

More Information

Magnet Axiom’s Portable Case is a lightweight version of the full capabilities found in Axiom—designed for easy access and analysis of forensic findings. It shares the ability to investigate the case data from digital devices and produce reports with non-technical stakeholders, such as investigators and attorneys.

More Information

Magnet Griffeye Lite is a limited, free version of Griffeye offered to law enforcement officials to navigate digital media more efficiently. In this free tutorial, available in numerous 20-minute-or-less modules, attendees will see how they can make the most out of their use of Griffeye Lite, including how to use the software, applying searching and filtering techniques, as well as creating reports and exporting.

More Information

This two-day instructor-led course provides students with the knowledge and skills necessary to perform structural comparative analysis on digital image and video files and to articulate expert results in both a report and court of law. Students will learn how to manually decode multimedia files at the binary level, performing authentication examinations using file metadata and structure. We will be working within Magnet Verify.

More Information

DV300 is an advanced course designed for investigators, examiners, and analysts who are already operating at a moderate level of audio/video complexity. This course focuses heavily on what practitioners should know instead of step-by-step training on how to conduct an investigation.

More Information

This course is a two-day, expert-level training program designed to equip digital forensic examiners with advanced skills for navigating complex mobile data. Emphasizing unsupported third-party applications, advanced data structures, and custom artifact creation, this course will provide essential tools for analyzing mobile device data with confidence.

More Information

This course is designed for individuals who have completed the Magnet Griffeye Lite course. It will provide the skills and tools needed to process cases, manage media files, and utilize the collaborative features of the tool, allowing multiple examiners to work together on a single case and enhancing the overall productivity of the tool.

More Information

Magnet Axiom Digital Evidence Reporting: A Prosecutor’s Toolkit (AP100) is an introductory-level, three-day training course designed for criminal prosecutors. It provides a strengthened understanding of digital forensics and how it applies to prosecutorial duties.

More Information

The AX250 Axiom Advanced Computer Forensics microlearning course offers a comprehensive exploration of Windows operating system artifacts and their forensic relevance.

More Information