What should I consider with a smart or embedded device?¶
Smart and embedded devices can be surprisingly useful evidence sources.
A doorbell may record motion and video. A smart speaker may hold account and device relationships. A tracker may show movement. A vehicle system may record connections, journeys or paired phones. A camera, alarm, sensor or controller may show exactly when something happened.
The key is to recognise that the physical device is often only one part of a wider connected system. The useful evidence may be split between the device, a hub or router, a companion phone, and a cloud service.
Start with the line of enquiry¶
Before worrying about extraction methods, ask what the device could help you establish.
A smart device might help answer questions such as:
- Was somebody or something present at a particular time?
- Did a door open, alarm trigger or sensor activate?
- Was video, audio or an image captured?
- Which account controlled the device?
- Which phone or tablet was paired with it?
- Which network was it using?
- Did it connect to another device?
- Was a setting changed or an event acknowledged?
- Could the provider hold a longer event history than the device itself?
That can turn an ordinary-looking household or workplace gadget into a useful line of enquiry.
Think of the whole connected setup¶
Take a smart doorbell as a simple example.
The doorbell itself may record button presses, motion events or local media. The home router may show that it was connected. The owner's phone may hold the companion app and account details. The provider may hold event history, stored video, device identifiers and sharing information.
That wider picture is often where the real value sits.
Removing the physical device without identifying the account, app or cloud service can leave the investigation with only one piece of the evidence.
The device itself may give the DFU very little¶
This is worth being clear about. Some smart and embedded devices are poor physical examination targets.
They may have very little local storage, use proprietary hardware, encrypt what they do store, or keep only enough information to operate before sending the useful data elsewhere. A perfectly relevant smart device can therefore reach a digital-forensics unit and produce very little on its own.
That does not make the device useless to the investigation.
Its make, model, serial number, account relationship, network details and provider can still tell you where the better evidence is likely to be. In many cases the important job is identifying the ecosystem rather than expecting the box on the wall to contain a rich local history.
The provider may hold the evidence you actually want¶
With many connected devices, the useful historical data sits mainly with the service provider.
That might include:
- event history;
- stored video, audio or images;
- account and device registrations;
- timestamps;
- sharing or household-member information;
- subscription details;
- linked devices;
- security or access events; and
- records showing when the device last communicated with the service.
So when you identify a smart device, identify the provider and account early as well. If the information matters, preservation or disclosure from the provider may be much more productive than relying on a later physical examination of the device.
Remember that it may still be watching you¶
A live smart device can also be an operational issue.
Cameras, video doorbells, microphones, motion sensors and similar devices may continue recording while officers or investigators are at the scene. Some can send notifications, stream live video or audio, or alert an account holder that somebody is nearby.
That matters during searches, arrests and other operational activity. Do not assume a small domestic gadget is passive just because nobody appears to be using it.
If that creates a genuine operational risk, deal with it deliberately and record what was done. The right response depends on the device and the situation; simply ripping out power or resetting it may lose evidence without solving the wider problem.
Record what you can see before changing anything¶
Take a few minutes to understand the device in place.
Record:
- where it is and what it appears to be doing;
- make, model and serial number where visible;
- display, lights, warnings and status indicators;
- power source and connected cables;
- removable storage;
- nearby hubs, controllers or base stations;
- obvious network connections;
- any phone or tablet being used to control it; and
- whether it appears to be recording, moving, alarming or controlling another system.
Context can be important.
A camera mounted over a driveway tells you something different from the same camera sitting unplugged in a drawer. A tracker attached to a vehicle immediately suggests a different set of questions from one found loose in a bag.
Look for the other parts of the system¶
Smart devices often depend on other equipment or accounts.
Useful questions include:
- Which account controls it?
- Which app is used with it?
- Is there a hub or base station?
- Does it use a memory card or local recorder?
- Which network is it connected to?
- Does it send data to a cloud service?
- Can several people control it?
- Is it linked to another phone, vehicle or household device?
Nearby routers, phones, tablets and hubs may be just as important as the smart device itself.
Be careful not to destroy the useful state¶
Once you know why the device matters, preservation becomes easier to think about.
Pressing buttons, removing power, resetting the device or opening the companion app can change its state. A reset may remove pairing or configuration. Power loss may clear volatile data. Opening an app may synchronise new information or generate fresh events.
That does not mean “never touch it”. It means make the action deliberate.
If you need to intervene, know what you are trying to achieve and record what you changed.
For unfamiliar, proprietary or technically complex equipment, specialist help may save you from losing a useful evidence source.
Remember safety and operational impact¶
Some embedded devices do more than collect data.
They may control:
- alarms and access systems;
- heating or utilities;
- machinery;
- medical equipment;
- vehicles;
- industrial processes; or
- security systems.
In those cases, safety and service continuity come first.
If the device is part of something operationally important, do not isolate or power it down just because it looks like a small electronic exhibit. Get the relevant owner or specialist involved and record the decision.
When should a specialist make the power decision? covers that situation, while device isolation explains how connectivity can be controlled without automatically removing power.
A useful first-response outcome¶
By the time you move on, you should ideally know:
- what the device is;
- why it may matter;
- what events or records it may hold;
- which account, app, hub or provider belongs to it;
- which other devices may contain related evidence;
- what state it was in when found; and
- whether any action is needed now to protect evidence, safety or ongoing services.
The main point is not to be intimidated by unfamiliar smart devices, but do not overestimate the value of the hardware itself either.
Treat them as connected evidence sources. They can give you useful timelines, relationships, media, movement and account information. Sometimes the device will hold useful data locally; sometimes the DFU will get very little from it and the provider will be the much better route.
Work out which situation you are dealing with before deciding what to seize, preserve or request.