The controlling source

Every volume and chapter in the mobile phone evidence Manual.

The EchoTrace Manual is the single controlling source behind all 47 Academy courses. It moves from evidence theory and the confidence framework through the technical behaviour of the handset, the cellular network, the cloud accounts, and the apps, into timeline and location analysis, and closes with a maintained reference layer every stream draws on during live work.

Parts
4
Volumes
11
Chapters
158
Evidence scope
1device class — the phone, its network, cloud, and apps

HOW EACH VOLUME IS BUILT

Reference material and reasoning in the same chapter.

The substantive technical volumes follow a consistent internal pattern, so a learner always knows where the artifact catalogue ends and the interpretation begins. Most volumes also carry an experimental-findings chapter that records observed platform behaviour together with its uncertainty.

  1. 01Purpose and terminology

    What the mobile source is, why the system creates it, and the terms used precisely.

  2. 02Sources and acquisition

    Where the artifact appears, and how it is obtained or accessed on a phone.

  3. 03Interpretation and validation

    What the record supports, what it cannot, and how the meaning is confirmed.

  4. 04Limitations and common errors

    Uncertainty, attribution limits, and the mistakes practitioners most often make.

Every volume is written backwards

That pattern comes from backward design. We do not start with a topic and hope a skill emerges from it; we start with the capability a practitioner has to demonstrate under review, then work back to the material that gets them there. The outcome is defined first, the evidence that can prove it is chosen second, and the teaching is written last.

In the Manual that shows up chapter by chapter. Each chapter states the practical outcome it serves, uses realistic but controlled evidence rather than a new dataset every time, and explains the concept in plain language before asking anyone to apply it. Practice then uses that same evidence, so learners reason about the material instead of decoding a fresh scenario. Assessment comes later and uses changed values or a different case, which is what separates a learner who understands the method from one who remembers an answer. See the five steps behind every course

WHAT WE TEACH

The courses we offer, part by part.

This is the taught curriculum in full: 4 parts holding 11 volumes and 158 chapters, and every one of the 47 Academy courses is built from it. Each part below opens with what it establishes, then lists its volumes and the chapters inside them. See the 47 courses these volumes teach

Part 1: Technical Foundations

1 volume

Establishes the distinctions every later volume depends on: phone versus number versus account versus person, recorded event versus interpretation, and confidence stated as part of the finding.

Volume 1

Foundations

Provenance, confidence, and bounded claims

Sets out the EchoTrace philosophy, evidence theory, the confidence framework, and timeline methodology as they apply to mobile evidence. Investigations are treated as an effort to establish which technical explanations survive the evidence, not to confirm a theory.

WHAT YOU PRODUCESource-to-claim trace with stated limitations

5 chapters

  1. The EchoTrace Philosophy
  2. Evidence Theory
  3. Confidence Framework
  4. Timeline Methodology
  5. Investigation Workflow

Part 2: Mobile Evidence Sources and Ecosystems

7 volumes

Builds the technical literacy to read each phone-linked source on its own terms — what the system creates it for, what it records, and what it cannot establish about a person.

Volume 2

Telecommunications Engineering

How networks generate phone records

Cellular fundamentals, LTE and 5G architecture, IMS, VoLTE and Wi-Fi calling, radio propagation, towers and sectors, and carrier core networks. The emphasis is why a serving cell describes network association rather than a position, and why handsets signal constantly without any user action.

WHAT YOU PRODUCENetwork-behaviour notes that bound every location claim

8 chapters

  1. Cellular Fundamentals
  2. LTE Architecture
  3. 5G Architecture
  4. IP Multimedia Subsystem (IMS)
  5. Voice over LTE and Voice over Wi-Fi
  6. Radio Propagation
  7. Towers and Sectors
  8. Carrier Core Networks
Volume 3

Carrier Evidence

Reading the records the carrier keeps

Call detail records, SMS records, data sessions, attach and detach events, paging, tracking area updates, billing records, switch logs, and IP address allocation — then how to interpret them together without overstating content, subscriber, or user.

WHAT YOU PRODUCENormalized carrier event ledger with documented limits

10 chapters

  1. Call Detail Records
  2. SMS Records
  3. Data Sessions
  4. Attach and Detach Events
  5. Paging
  6. Tracking Area Updates
  7. Billing Records
  8. Switch Logs
  9. IP Address Allocation
  10. Interpreting Carrier Evidence
Volume 4

Apple Ecosystem

Account, device, and iCloud artifacts

The Apple Account as an identity layer, then iCloud, Find My and the Find My network, backup, Photos, Keychain, Safari, Health, and Wallet. Includes an artifact catalogue and experimental findings that record observed behaviour together with its uncertainty.

WHAT YOU PRODUCEApple artifact map separating capture, sync, and access

12 chapters

  1. Apple Account
  2. iCloud
  3. Find My
  4. Find My Network
  5. iCloud Backup
  6. Photos
  7. Keychain
  8. Safari
  9. Health
  10. Wallet
  11. Apple Artifacts
  12. Experimental Findings
Volume 5

Google Ecosystem

The widest phone-linked evidence surface

The longest volume in the Manual. Google accounts and Takeout, location services, Maps Timeline, the Android ecosystem, Play Services, backup and restore, Find My Device, Chrome, Gmail, Drive, Photos, Web and App Activity, and more — closing with a workflow and the errors investigators most often make with Google data.

WHAT YOU PRODUCEGoogle evidence workflow with per-source confidence notes

23 chapters

  1. Google Account Fundamentals
  2. Google Takeout
  3. Google Cloud Services
  4. Google Location Services
  5. Google Maps and Timeline
  6. Android Ecosystem
  7. Google Play Services
  8. Android Backup and Restore
  9. Find My Device
  10. Chrome Ecosystem
  11. Gmail
  12. Google Drive
  13. Google Photos
  14. Google Search and Web & App Activity
  15. YouTube
  16. Google Play
  17. Google Contacts, Calendar, Keep, and Tasks
  18. Google Fit and Activity Data
  19. Third-Party Application Access
  20. Google Artifacts
  21. Experimental Findings
  22. Google Investigation Workflow
  23. Common Investigative Errors
Volume 6

Microsoft Ecosystem

Mobile identity, authentication, and sync

Microsoft account fundamentals, cloud services, OneDrive, Outlook, Teams, Edge, activity data, Authenticator, Entra ID, and SharePoint — used to separate mobile activity from desktop, web, and automated activity, and to test mobile attribution and authentication evidence.

WHAT YOU PRODUCEMobile authentication and sign-in reconstruction

15 chapters

  1. Microsoft Account Fundamentals
  2. Microsoft Cloud Services
  3. Windows Ecosystem
  4. OneDrive
  5. Outlook
  6. Microsoft Teams
  7. Microsoft Edge
  8. Windows Timeline and Activity
  9. Microsoft Authenticator
  10. Azure and Microsoft Entra ID
  11. SharePoint
  12. Microsoft Artifacts
  13. Experimental Findings
  14. Microsoft Investigation Workflow
  15. Common Investigative Errors
Volume 7

Third-Party Applications

Where most phone evidence now lives

Phones derive much of their evidentiary value from applications rather than the operating system. Covers app accounts and authentication, local data, cloud synchronization, and the messaging, social, location and transport, health, banking, media, and productivity categories — ending in a reference catalogue.

WHAT YOU PRODUCEApplication inventory with account and sync provenance

16 chapters

  1. Third-Party Application Ecosystem
  2. Application Accounts and Authentication
  3. Local Application Data
  4. Cloud Synchronization
  5. Messaging Applications
  6. Social Media
  7. Location and Transportation
  8. Health and Fitness
  9. Banking and Commerce
  10. Media and Entertainment
  11. Productivity and Collaboration
  12. Application Artifacts
  13. Experimental Findings
  14. Third-Party Application Investigation Workflow
  15. Common Investigative Errors
  16. Application Reference Catalogue
Volume 8

Mobile Device Forensics

Acquisition, artifacts, and validation

Twenty chapters on preservation, mobile architecture and security, acquisition methods, file systems, tooling, and the application, location, communication, media, log, and network artifacts they surface — held to the principle that tool output is validated before it is interpreted.

WHAT YOU PRODUCEAcquisition record and artifact validation log

20 chapters

  1. Mobile Device Forensics Fundamentals
  2. Evidence Preservation
  3. Mobile Device Architecture
  4. Forensic Acquisition Methods
  5. File Systems
  6. Device Security
  7. Mobile Forensic Tools
  8. Application Forensics
  9. Location Forensics
  10. Communication Forensics
  11. Media Forensics
  12. Device Logs
  13. Network Forensics
  14. Cloud Correlation
  15. Artifact Validation
  16. Mobile Device Artifacts
  17. Experimental Findings
  18. Mobile Forensics Workflow
  19. Common Investigative Errors
  20. Future Reference Library

Part 3: Mobile Analytical Methods

2 volumes

Turns separate phone-linked sources into a tested reconstruction — normalized in time, bounded in space, and expressed with the alternatives that remain open.

Volume 9

Timeline Reconstruction

The core analytical discipline

Normalize before correlating, distinguish event time from record, sync, and access time, corroborate independent sources, assign confidence, and keep testing competing sequences. Covers event, location, communication, device, and cloud timelines, timestamp interpretation, hypothesis testing, and visualization.

WHAT YOU PRODUCETraceable multi-source mobile timeline

17 chapters

  1. Timeline Reconstruction Fundamentals
  2. Evidence Normalization
  3. Multi-Source Correlation
  4. Confidence Assessment
  5. Event Reconstruction
  6. Location Reconstruction
  7. Communication Timelines
  8. Device Activity Timelines
  9. Cloud Timelines
  10. Timestamp Interpretation
  11. Hypothesis Testing
  12. Visualization
  13. Reporting
  14. Experimental Findings
  15. Timeline Reconstruction Workflow
  16. Common Investigative Errors
  17. Case Study Framework
Volume 10

Spatial Analysis

Location as bounded context, not certainty

Coordinate systems, mobile spatial sources, and uncertainty come first, then cellular spatial analysis, GPS, Wi-Fi and Bluetooth positioning, GIS, terrain and environmental effects, movement reconstruction, and visualization that communicates evidence rather than conclusions.

WHAT YOU PRODUCEMovement reconstruction with stated positional uncertainty

16 chapters

  1. Foundations of Spatial Analysis
  2. Coordinate Systems and Mapping
  3. Spatial Data Sources
  4. Spatial Confidence and Uncertainty
  5. Cellular Spatial Analysis
  6. GPS Analysis
  7. Wi-Fi and Bluetooth Positioning
  8. Geographic Information Systems for Investigations
  9. Terrain and Environmental Analysis
  10. Movement Reconstruction
  11. Visualization
  12. Spatial Correlation
  13. Experimental Findings
  14. Spatial Analysis Workflow
  15. Common Investigative Errors
  16. Future Reference Library

Part 4: Technical Tools and Reference

1 volume

Maintains the shared lookup layer every stream draws on during live analysis, under version control and periodic validation.

Volume 11

Reference Tables

Standardized lookups under version control

A maintained reference layer for telecommunications, mobile devices, cloud platforms, digital forensics, spatial work, and legal standards — designed for accuracy, traceability, and scheduled revalidation rather than one-off notes.

WHAT YOU PRODUCEValidated reference set with maintenance ownership

16 chapters

  1. Purpose and Philosophy of Reference Tables
  2. Design Standards for Reference Tables
  3. Core Reference Libraries
  4. Validation and Maintenance
  5. Telecommunications Tables
  6. Mobile Device Tables
  7. Cloud Platform Tables
  8. Digital Forensics Tables
  9. Geographic and Spatial Tables
  10. Investigative Reference Tables
  11. Legal and Standards Tables
  12. EchoTrace Reference Library
  13. Experimental Findings
  14. Reference Library Management
  15. Common Reference Errors
  16. Future Master Reference Library

WHAT THE CURRICULUM BUILDS

Capability that outlasts a single tool or platform version.

Progress is measured by what a learner can defend under review, not by chapters marked complete. Every course maps to named competencies from the 88-competency framework.

  • Read each source on its own terms

    Understand what handset artifacts, cellular network records, cloud accounts, and app data actually document — and precisely where each one stops.

  • Reconstruct rather than confirm

    Normalize evidence, correlate independent sources, and test the competing technical explanations before stating a finding.

  • State confidence and limits

    Express what the evidence supports, what it cannot establish, and why — as part of the finding rather than a caveat bolted on afterwards.

  • Standardize the unit, not just the analyst

    Work from one maintained reference layer so quality survives staff turnover, tool changes, and platform updates.

NEXT STEP

See how the 11 volumes map onto your caseload.

Send us your seat count and the evidence you actually work with. We will return a written subscription quote, a recommended learning pathway through the streams, and the documentation your procurement and information-security teams will ask for.

  • Streams matched to your roles and evidence sources
  • Sample course and mock investigation walkthrough
  • Seat bands and multi-unit rollout options