We build the case, write the evidence, and load it onto real devices. Your people work an investigation that behaves like the ones crossing their desk.
You know the options. Published images have walkthroughs on the internet by now. A real case with the names swapped brings problems nobody wants. And a dataset with a dozen obviously incriminating artifacts gets solved before the coffee is cold.
None of that is the job. The job is finding two messages that matter in ninety that do not, when one of the two was deleted three weeks ago.
Most of it is nothing. Hundreds of ordinary messages, a full contact list, a fitness app. Signal only means something against that.
Deleted is actually deleted. It sits in the database the way real deleted messages do. If the tool cannot pull it, neither can the student.
The apps are real apps. They run, they hold their own records, and a logical extraction will not touch them. Somebody has to notice that and say so.
It does not sit on one device. A registry key on the laptop says a USB was plugged in eleven times. The stick is in the car. Neither one tells you much alone.
Anyone who has tried to build one of these knows the loading is the easy part. This is the rest of it.
Who answers to whom. Who is careful and who is sloppy. What they call things when they do not want to say them out loud. Get that wrong and an experienced investigator stops believing the whole thing inside ten minutes.
Each step from one device to the next has to be findable, but only by doing the work. Too obvious and nobody learns anything. Impossible and they just get frustrated and stop.
Real people text about dinner and forget to reply and argue about nothing. Without hundreds of messages like that, there is no haystack, and finding the needle proves nothing.
Deleted messages have to sit where deleted messages actually sit. Apps have to run and write their own logs. If Cellebrite cannot pull it, it might as well not be there.
Every point on the rubric traces to something that exists on a specific device. Nobody loses marks on a question the evidence cannot answer.
A phone off the arrest. A laptop from the office. A USB in the glovebox. A drone in the shed. The story runs through all four and nothing is labeled.
Work it yourself on the right. Each device holds one thing that opens the next. That is how the exercise grades, and it is how the real one goes.
Open the artifacts. One of them tells you where to go next.
Training usually starts at the workstation. By then somebody has already seized the device, handled it, and booked it in — and what they did decides what is left to find. One kit covers all of it, because the same devices work at every stage.
What gets bagged and what gets left on the seat. The phone is obvious. The USB in the door pocket is not. More evidence is lost in these ten minutes than anywhere else in the case.
Knowing what to ask the lab for, and knowing what to do with the report when it comes back instead of filing it and hoping.
Imaging the device, pulling deleted material properly, and recognizing when a logical extraction has missed something — then being able to explain why to someone who is not technical.
Putting four devices together into one story, working out which account is lying, and seeing the thing that no single device shows.
Someone who can design a criminal network that holds together. Someone who can write both sides of a conversation so the two people actually sound different. A developer to build apps that run and keep their own records. An examiner to check the whole thing survives an extraction. And someone to turn it into grading that holds up when a student challenges a mark.
We do it in one process instead of five. Content is written to a fixed spec, then checked by code rather than by opinion — is the chain complete, do the devices agree with each other, does the timeline hold, does every rubric point trace to something real. Then a person reviews it and signs it off before it ships. Nothing goes out that neither of us has read.
That is why it costs what it costs, and why you get it in weeks instead of building it yourself over a semester.
Case design — who is involved, how they are organized, and why the boss is careful when the runner is not.
The trail — every lead findable, and only by doing the work.
Writing the evidence — conversations, deleted messages, documents, call history, contacts.
Building the apps — working software that keeps its own records and logs.
Checking it — automated validation first, then a person.
Grading — a hundred-point rubric where every point traces to real evidence.
Loaded, checked, and ready to image. Your tools read them exactly as they would a device off a real seizure, because that is what they are.
Instructor guide with the answer key, a packet for the students, roleplayer scripts if you want to run interviews, and injects for running it live.
A hundred-point rubric where every point traces back to something real on a specific device. No question the evidence cannot answer.
Tell us that, who needs to get better at working it, and what your lab already runs. We will come back with what a kit for it would look like. No obligation, and we will say so if we are not the right fit.
Start a conversation