Mobile Extractions¶
60 investigator questions.
Use the list below or search the complete library.
- Can the device clock be wrong?
- Could an application database or forensic parser be incomplete or wrong?
- Could an artefact have been created automatically?
- Could another person have used the handset?
- Could cloud-linked data have come from another device?
- Could the handset have been remotely accessed or controlled?
- Does a contact entry prove the person knew that contact?
- Does a message in the report prove it was sent or received?
- Does an account name prove who used the application?
- Does data on the phone prove the user knew it was there?
- Does possession of the phone prove authorship of its messages?
- Does the absence of a message, call or application prove it wasn’t there?
- Does the report contain everything that was on the phone?
- How do I find out what data was actually extracted?
- How do I preserve a useful result from a reader report?
- How do I record where an artefact came from?
- How should I build a timeline from several applications?
- How should I deal with duplicated results?
- How should I deal with missing or impossible-looking times?
- How should I search a mobile extraction report?
- How should I search for dates, amounts and reference numbers?
- How should I search for email addresses?
- How should I search for telephone numbers?
- How should I search for URLs, domains and IP addresses?
- Is a screenshot from the report enough?
- Is the timestamp stored in UTC or local time?
- I’ve been given a mobile phone extraction or reader report. What can I do with it?
- What alternative names, usernames and identifiers should I search?
- What can Bluetooth records show?
- What can browser-history records show?
- What can cached or thumbnail images show?
- What can call-history records show?
- What can location records show?
- What can notifications reveal?
- What can photographs and their metadata show?
- What can search-history records show?
- What can Wi-Fi records show?
- What corroboration should I look for before attributing mobile evidence?
- What does a timestamp prove about when a person acted?
- What does an application artefact actually show?
- What does deleted mean in a mobile extraction?
- What does it mean when data is marked parsed or decoded?
- What does recovered mean in a mobile extraction?
- What exactly is a mobile phone extraction report?
- What happens when the device timezone changes?
- What is the difference between an extraction, a reader report and an analyst’s summary?
- What is the difference between created, modified, accessed and received time?
- What is the difference between draft, queued, sent, delivered and read?
- What is the difference between logical, file-system and physical extraction?
- What should a supervisor ask before relying on mobile-extraction evidence?
- What should I ask the digital-forensics unit before relying on the report?
- What should I check before I start reviewing the report?
- What should I do when mobile evidence conflicts with another account?
- When should I return to the digital-forensics unit or specialist?
- Which timestamp in a mobile report should I use?
- Why can one artefact show several different times?
- Why is searching only for the suspect’s name unreliable?
- Why might an application timestamp differ from the phone timestamp?
- Why might one conversation appear in several places?
- Why might two reports from the same device contain different information?