Hello Internet, Matt here with my first certification review. I am pretty new to this whole reviewing industry certifications, but I have quite a bit to say about this certification. There are many good things about it and only (maybe) a couple of things that I would like to mention. I’d like to start out by saying that this cert is an entry-mid level cert, so it should be on your list of forensics certs to take when you’re within your first five years in industry.
The format of this post will be very simple. I’ll begin with my reasoning for taking it, the format of the exam and courseware, the benefits and drawbacks of this exam, and my overall ideas of whether you should take it or not (and when you should take it).
Why did I take the ICMDE cert?
First of all, I realize that I broke one of the cardinal rules of informational articles: putting an acronym without explaining the expansion first. If you’re mad at me, here is the full name of this certification: the International Association of Computer Investigative Specialists: IACIS Certified Mobile Device Examiner. Whooo, that’s a mouthful, I know. But we’re done with that mouthful. Using the acronym is much easier than saying the full name.
Now I took it because I feel like it’s necessary to stand out in the industry. It shows that I care about mobile forensics (the area that I most like) and have the proper fundamentals for being a good professional on this subject. I’d like to also have as many doors open to me. Case in point, I might be an expert witness some day and this is one certification that the court might like for me to have.
I also decided to attempt this exam because it has a practical component. I believe practical tests are the most important to showing that one has learned skills. Traditional multiple choice tests are one way of showing proficiency, but to really prove mastery of the basics, one must show that they can actually do the basics. This is also one of the reasons why I would recommend it to someone looking for a certification.
The Format
I just got done mentioning the practical component. That comes at the end. That comes after the learning phase and the first test.
The learning phase includes an exam preparation course. They make you sign an NDA before taking this course which certifies that you won’t share details about the course you got. Those resources include the manual, the course or any of the practical materials and the exams.
There is a comprehensive syllabus on the IACIS website that outlines the core competencies of the ICMDE. These core competencies include knowing your way around the basic artifacts of an iOS and Android file system, knowing the terminology behind mobile forensic, how to understand databases.s, knowing the proper investigative processes and also knowing basic SQL and how to read and analyze a database.
The format of the testing phase of the certification is different from the traditional certification format. The ICMDE has two exams that are required to obtain it, rather than one. The two exams consist of a written and a practical one. Both exams are forty-eight hours (two days) long, so you have plenty of time to do work and the test if you need to do that.
Since you have forty-eight hours to complete the test, the necessary eighty percent required to pass is more easily achievable because you can spend a lot of time doing a first dry run and then check multiple times if you are really scared of not passing.
In my case, I (someone who is already familiar with some of the material) took around three and a half hours to complete my first run of the written exam. I then took another three hours to check it before I submitted it for a passing grade. I lost track of how much time I took with my first try of the practical but it was more like the total time I took with the written exam combined with a few extra hours of testing and checking.
Overall, this is a fairly rigorous process. If you decide to take it and you’re new, you will learn alot and strengthen many connections between device image and data. If you’re experienced, you might also learn a couple of new things like I did (like how to decrypt Signal on Android or how to take encoded data from iOS’ photos.db).
Benefits and Drawbacks
Tool agnostic
My favorite part of this certification is that I could use Linux for it. Being able to use Linux also meant that I could use things like ALEAPP, iLEAPP, Autopsy, and other open-source software to help me analyze the various images.
While I like vendor-specific certifications (and I might take a Magnet Forensics certification next) I do not like being expected to only use one toolset and not be expected to verify results with other common tools. The stipulation that I can use anything meant that I can get as deep as I wanted.
Timing
The timing of the certification period was both good and bad for me in my specific case. On the good side, I had three months to finish the course and close to six to finish the two exams, but I didn’t like that it took so long to start up. I paid in May and started about two months later. This was just too slow and late for me. I’ve been used to seeing certifications that start their processes as soon as you buy them; you buy, you start the class and take the test once you’ve studied enough and get your result either immediately or after a few days. The timing of this course was strange because it was the same thing as a college course where you have a certain date when classes start.
This is not the biggest of deals, but it is something to be aware of.
The Information
Before I get too far into this, I have to say that I took the class online. This means I didn’t get the full class experience like some other colleagues that go to IACIS whenever they can. I may have missed some content, but got most of it. At least I assume so.
When it comes to the information, itself, it’s some of the basics of mobile forensics. It is the stuff you’d learn easily on the job. That made this course somewhat of a breeze to complete and made the written test easier to understand. I am super sure that most people who take this will complete the written exam on the first try. The practical exam might be slightly more difficult, but it’s doable.
The videos (if you’re online) will probably be set up in the following format:
SQLite → iOS → Android.
Again, the info is not too hard to memorize or just write down. That is another benefit of doing this completely online: you have full access to ALL the resources you want. You can write down all of the info you’re likely to forget and take that with you into the exams, like I did.
NDA
One big downside of this exam whether you take it in person or online is the NDA you’ll sign. That’s probably the worst thing about it. The NDA you sign says that you won’t give any of the very specific information about test to anyone else. This information includes the manual and the more specific course contents as well as exam questions. I understand very well why they do this. Cheating is terrible.
One problem I have is that one who says that they know how to do something they didn’t know how to do before taking the exam can only say that they know how to do it and not mention that they learned it from ICMDE. That also makes it harder for potential takers of ICMDE to know specific information they will be receiving from the course outside of somewhat vague core competencies.
You wouldn’t know if anything from this blog after last month was from ICMDE or not…
Encryption
I may be going too deeply into the material of the exam, but you may get applications in your practical images that are not trivial to analyze. As mentioned before, Signal is an example of one of these encrypted apps. Breaking the encryption on certain apps is more trivial than others. If you are a potential candidate, you’ll discover which ones are easier than the others and which ones can’t be done by hand.
This is both good and bad because you’ll gain experience with decrypting encrypted apps. It is important to do these by hand because that’s just another way to verify that you are getting the correct results. The only downside to this is that you might be out of luck for some if you need to heavily reference documentation. Some apps might also not be possible to decrypt by hand because they are somehow too encrypted to the point where you need the commercial software to do the job.
In iOS images, you may be asked for things like AirTags or other devices information that are paired with iPhones. Your mileage may vary with what you get, but you might be able to use open-source software like ArtEx and others to gather data from AirTags and other encrypted things. In the same way, Android has some system artifacts that are encoded. You can use abx2xml to decode Android Binary XML format and I’m sure there are others that can deal with other encoded formats.
The Exams
Quick note: Since I’m on an NDA, I will not talk about my exams and will generalize what I think things will be like for you.
So, when you finish the course, either online or in person, you’ll be automatically enrolled in a course for the exams. Your first exam will be a multiple choice/true+false/written exam. It will consist of questions based on the concepts you learned in the course. It’s simple and cut and dry; you’ll probably get it on your first try. If you don’t get it the first time, you’ll have a second try. You also have a second exam of completely practical nature which gives you a dataset and a story to follow. Each question in this exam asks about a certain piece of data in any of the images within the dataset.
Both are automatically graded, but are said to be checked by human reviewers. If you pass both, you’ll be a success and you will sign a document agreeing that you worked on the exam by yourself. Once you do that, you’ll get a badge and they’ll also send you a paper certificate of achievement. With this step your process, you are done!
If you don’t pass either stage of the exams, you will have a second opportunity. After that, you have to pay for further opportunities.
My Take on the Test
In my opinion (I bet that’s the main thing you’re here for) this test is rigorous and is a good indicator of your skill (with one caveat). You have the first test to prove that you understand the core, under-the-hood concepts of digital forensics. Once they know that you can successfully say “Hey, I can understand what we do and why we do it in a forensic sense!” you can move onto practically applying it. If you can successfully prove that you can apply the concepts you learned and interpret the things you see in an image correctly, you are deserving of the certification.
Now for the caveat. I don’t know what tools you have. If you have good tools and know how to use them, you might be able to finish the practicals in short order. If not, you might have a bit of trouble with the questions that the exam asks for. For instance, a question may ask for something that’s deleted or not easily viewable. In the case that this happens with a limited toolset, you may be forced to research a bit on how to possibly get it. Also there’s encryption: a mess for those who are not afforded major luxuries like Magnet or Cellebrite. I was forced to use four different tools as well as manual methods on my practicals because each method was not getting the things I needed and I wanted to cross-verify.
That caveat can be a blessing in disguise for a couple of reasons. First off, you can get a free trial of a software that you haven’t been exposed to. In my case, I got to have a look at ArtEx, an open-source tool that I haven’t been exposed to before. It didn’t give me all of what I expected but it answered one question, so I’m happy. The second positive takeaway is that not having the fancy tools forces you to learn some methods that people who are used to big commercial suites conveniently gloss over. One example of this for me was decrypting Signal’s Android databases.
Also, if you have questions about the test or have feedback on a question that might be written incorrectly or may be asking for missing evidence, you may have to wait long to receive a response. Jung Son, the coordinator of the ICMDE is based in NZ, so, most of my readers may be in the previous day (he is exactly 19 hours ahead of me, time-wise) and he also has a high position at his day job. All of that means that you might have to bite the bullet and figure things out on your own and not get an answer on serious test questions.
The test is all basic material (at least for me) and I think it’s a great beginner forensic course and certification. You will have some great practical experience when you successfully complete this exam. It is also a big plus for the employers that you want to get jobs from. You will have a great thing on your profile and a great talking point in your interviews.
Conclusion
In conclusion, my experience with the IACIS ICMDE certification has been a good one and one that taught me about some forensic processes that I didn’t know about before and conveyed knowledge about technical concepts that I hadn’t seen or mastered yet. It was a fun process to go through and I would highly recommend it to people who want to learn more about digital forensics and want to have something tangible to show recruiters.
This certification is $1000 well spent if you are in forensics or just interested in getting into the field. Consider taking it if you have the time and money available. I say time because each of the exams provide a 2-day window to complete, submit and score them. However, two days should be more than enough time if you know what you’re doing and can efficiently parse through mobile images.
Now go forth and look to IACIS for a great and well-respected industry certification if you are in the market for one!



Thanks for sharing this Matthew, I always find it fascinating the discussion about certs (and how valuable they are). Gaining a cert definitely sets a standard, which is great. But as I often say to my students, gaining a certification is only part of overall competency...ongoing mentorship and personal experience are both vital to self development.