GK200 Graykey Examinations
GK200 is an intermediate-level, four-day training course designed for participants who are familiar with the principles of digital forensics and are looking to extend their capability into iOS, Android, and vehicle examinations using Magnet Graykey. Students must be part of a law enforcement agency and must be cleared in advance to attend this course.
Description
GK200 is an intermediate-level, four-day training course designed for participants who are familiar with the principles of digital forensics and are looking to extend their capability into iOS, Android, and vehicle examinations using Magnet Graykey. Students must be part of a law enforcement agency and must be cleared in advance to attend this course.
Across four days of instruction and hands-on exercises, students will build a practical workflow for handling iOS and Android devices in the field and in the lab, and learn to operate Graykey end-to-end to extract data from locked and secured mobile devices. The course also introduces Magnet Autokey, Magnet’s vehicle acquisition solution, which extends the Graykey workflow to supported modern vehicles and is currently available to US law enforcement as an add-on to Graykey Premier licenses.
Magnet Axiom is used throughout the course to explore how mobile file systems are structured and how to locate the data that matters most. Students will study the artefacts specific to Graykey’s extraction outputs and the different levels of data protection implemented on modern mobile devices. From Keychain and Keystore analysis to the advanced methodologies needed to uncover operating system artefacts, students leave the course able to deal effectively and efficiently with data from mobile devices — regardless of extraction level or device state.
Students must be part of a law enforcement agency and MUST own a Magnet Graykey.
What to expect
Hear directly from Justin Almanza, a Forensics Trainer at Magnet Forensics, about Magnet Forensics training courses specifically designed to help you in your mobile investigations, including Core Mobile Acquisition & Analysis (AX150), Axiom Advanced Mobile Forensics (AX300), and Graykey Examinations (GK200).
Course prerequisites
Because GK200 is an intermediate-level course, it is recommended that students first complete Magnet Axiom Examinations (AX200).
Course modules
Module 1: Course Introduction
Review of the course outline, personal introductions, and the week-long case scenario that will be used throughout the training event. Students finish the module with a clear understanding of the structure of the course.
Module 2: Graykey Overview
An introduction to the Graykey device itself — covering hardware, licensing, capture and extraction settings, enhanced capabilities, and device preferences. This module also covers the full range of Graykey’s operational features, including Mobile Excursion, Crypto Triage, logical+, category-based extractions, and Magnet Graykey Fastrak.
Module 3: iOS Fundamentals
Discussion-focused coverage of the iOS operating system’s structure and security. Students will review the APFS file system, core Apple security hardware and firmware, device keys, the Secure Enclave, data protection classes, handset lock codes, and USB Restricted Mode.
Module 4: iOS Acquisitions Using Graykey
Hands-on work covering the full iOS extraction workflow: evidence preservation, known- and unknown-passcode workflows, BFU, AFU, full filesystem and Logical+ extractions, and brute-forcing passcodes using the Axiom Wordlist Generator and Hashcat. This module also introduces Magnet Autokey, Magnet’s vehicle acquisition tool, including supported infotainment systems, vehicle artifacts, the vehicle acquisition workflow, and current Autokey availability.
Module 5: Android Fundamentals
Discussion-focused coverage of the Android operating system’s structure and security. Students will explore the Generic Kernel Image, Android file system and partitions, core Android security features, full-disk and file-based encryption, Android passcodes, and vendor-specific security features such as Samsung Secure Folder.
Module 6: Android Anti-Forensics
An awareness module focused on anti-forensic operating systems and applications, with particular attention to GrapheneOS — its privacy and security features, supported devices, data-wipe behaviors, and the handling and seizure considerations these devices introduce.
Module 7: Android Acquisitions Using Graykey
Hands-on work covering the full Android extraction workflow: evidence preservation, known- and unknown-passcode workflows, BFU Android devices, Download/Upload/Fastboot modes, and brute-forcing techniques (including multi-user brute-force).
Module 8: Graykey Outputs and Magnet Axiom
An overview of the different outputs produced by Graykey (BFU, AFU, full filesystem, selective, Logical+, process memory, keychain/keystore, password list, passcode history, progress report) and how to load these into Magnet Axiom Process and Examine for analysis.
Module 9: Analyzing iOS Extraction Types
A practical deep-dive into the artifacts available at each iOS extraction level — BFU, AFU, full filesystem, and Logical+ — using Axiom Examine. Students will locate and interpret artifacts such as Accounts, Apple Notes, Apple Mail, Significant Locations, Apple Maps, KnowledgeC, and cached locations.
Module 10: Analyzing Android Extraction Types
A practical deep-dive into the artifacts available at each Android extraction level (BFU and Full File System), with emphasis on mainstream data protection features such as Secure Folder, Dual Messenger, and Google Private Space.
Additional information
Who should attend: Participants who are unfamiliar with the principles of digital forensics
Advanced preparation: None
Program level: Advanced-level
Field of study: Computer software & applications
Delivery method: Group live
Refunds and cancellations: Training Course(s) can be rescheduled to a later date or cancelled by either Magnet Forensics or you without charge or penalty if written notice is received twenty-one (21) days or more prior to the date of the Training Course. No rescheduling shall be permitted on less than twenty-one (21) days written notice, which shall constitute a cancellation without a refund. Your written rescheduling or cancellation notice must be emailed to training@magnetforensics.com or contact 202.984.3417. If Magnet Forensics cancels a Training Course due to insufficient attendance, you will have the option to register in a different scheduled Training Course or receive a full refund. Please do not book travel until you have confirmed that the Training Course will be running.
Magnet Forensics is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website:www.nasbaregistry.org.