Icon Menu
Icon Search

GK200 Magnet GrayKey Examinations

This course is an intermediate-level four-day training course, designed for participants who are familiar with the principles of digital forensics and who are seeking to expand their knowledge base into deep iOS examinations and the use of the Magnet GRAYKEY device.Students must be part of a law enforcement agency and MUST be a Grayshift Customer.  All attendance is cleared by Grayshift in order to attend this course.  Students will get hands-on use of the GRAYKEY device and learn how to fully operate it — including how to establish a proper workflow for handing iOS devices in the field to the lab and how to acquire a full file system image of iOS devices.Magnet AXIOM will also be leveraged to learn how the iOS filesystem is structured, how to locate key data, and how artifacts are structured. In addition, students will learn about artifacts specific to the iOS full file system and its multiple levels of data protection. Third-party artifact analysis of several advanced, secure artifacts will be covered, including how the device keychain ties into these artifacts. A methodology will be discussed on how to conduct deep-level iOS examinations and how to understand specific operating system artifacts in context to show device interactions over time. Students will learn how to put someone behind a device physically interacting with it, and even sometimes where that device has been.

Course Prerequisites

Because GK200 is an intermediate-level course, it is strongly recommended that students first complete Magnet AXIOM Examinations (AX200). AX200 will provide a thorough understanding of AXIOM that will help students focus on the mobile aspect of investigations in GK200.

Course Modules


  • Cover the basic prerequisites for both the AXIOM software and GRAYKEY unit.


  • Discussion-focused coverage of the iOS operating system’s security functions and structure.

  • Learn about device protection class keys, understanding the handset lock codes and their function, as well as other functions of the operating system.


  • Covering all the options and settings of the GRAYKEY unit in order to successfully and efficiently operate the device to extract information from iOS devices.

  • Information about the latest versions of iOS will be discussed.

  • Learn how to gain access to information previously unavailable by most forensic techniques.

  • See how to extract information from devices that are still passcode-locked as well as techniques to deal with the bypassing of the passcodes standing in their way.


  • Compare the different types of extractions that can be generated with the GRAYKEY units, what examiners can expect to find in each type, and how this information can help further investigations in multiple ways.

  • Learn how to explore key artifacts available in these different image types, exclusive to the GRAYKEY style of data extraction, and how to build methodologies to attempt more efficient passcode cracking.


  • Understand the multiple ways to ingest information and develop a proper workflow for ingesting information from GRAYKEY extractions.

  • Learn about several AXIOM functions such as Dynamic App Finder, Search for Custom Files by Type, and how to target secure messaging applications.


  • Explore multiple artifacts, including deep diving into artifacts that are core to the iOS file system — core artifacts will be explored in depth including techniques for recovering deleted information from these databases.

  • Advanced file system artifacts such as PowerLog and KnowledgeC will be covered to talk about application usage times and data amounts. These and other artifacts will be explored to show examiners how to track when targets are interacting physically with a device in a specified timeframe.

  • Exclusive file system artifacts such as location history, third party applications, and more will also be explored.

Additional Information

Who Should Attend: Participants who are unfamiliar with the principles of digital forensics
Advanced Preparation: None
Program Level: Advanced-level
Field of Study: Computer Software & Applications
Delivery Method: Group LiveRefunds and Cancellations: Training Course(s) can be rescheduled to a later date or cancelled by either Magnet Forensics or you without charge or penalty if written notice is received twenty-one (21) days or more prior to the date of the Training Course. No rescheduling shall be permitted on less than twenty-one (21) days written notice, which shall constitute a cancellation without a refund. Your written rescheduling or cancellation notice must be emailed to [email protected] or contact 226-499-8962. If Magnet Forensics cancels a Training Course due to insufficient attendance, you will have the option to register in a different scheduled Training Course or receive a full refund. Please do not book travel until you have confirmed that the Training Course will be running.Magnet Forensics is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website:www.nasbaregistry.org.

Interested in Private Training or Hosting a Training Class?

Magnet Forensics Training


Duration - 4 Days

Dates & Locations

  • 10.09.24 - Location TBC

Enquire about this training course