I have been given a mobile extraction
Establish what was acquired, what the reader report displays and what may be missing before searching for names or treating parsed material as a complete account of the device.
Start with what needs doing now
Use this route to check the report's scope, preserve useful results and interpret artefacts, timestamps and attribution with appropriate limits.
Move from the supplied report to identifiers, searches, source artefacts, corroboration and a defensible suspect.
Reference MEX-060OrientateBefore reviewing the reportConfirm the device, extraction type, date, tool, scope, timezone and known limitations before interpreting results.
Reference MEX-051Preserve the resultHow do I retain a useful finding?Keep the artefact, surrounding context, identifiers and route back to the extraction rather than relying on a detached screenshot.
Reference MEX-014Understand the evidence and the offender method
Use this route to understand how extraction data becomes a reader report and see a separate offender's deleted material survive in other forms.
Understand the difference between acquired device data, parsed artefacts, a reader report and an analyst's interpretation.
Reference MEX-061Separate offender exampleDodgy Dave deletes the wildlife-trade chat and keeps the thumbnailsSee deleted communications leave related thumbnails, caches, accounts, transfers and provider evidence.
Reference MEX-062Go directly to the issue you need to resolve
Recognise inaccessible, unparsed, overwritten, excluded and remote material.
Reference MEX-012DeletionWhat does deleted actually mean?Distinguish a deleted record, a recovered artefact and residual data.
Reference MEX-040TimeWhich timestamp should I use?Identify what each time represents before constructing a sequence.
Reference MEX-054AttributionWhat should corroborate mobile evidence?Test the artefact against accounts, devices, communications and real-world events.
Reference MEX-037Browse every Mobile extractions guidance page
The complete reference library remains available when you need a narrower question.- Can the device clock be wrong?
- Could an application database or forensic parser be incomplete or wrong?
- Could an artefact have been created automatically?
- Could another person have used the handset?
- Could cloud-linked data have come from another device?
- Could the handset have been remotely accessed or controlled?
- Does a contact entry prove the person knew that contact?
- Does a message in the report prove it was sent or received?
- Does an account name prove who used the application?
- Does data on the phone prove the user knew it was there?
- Does possession of the phone prove authorship of its messages?
- Does the absence of a message, call or application prove it wasn’t there?
- Does the report contain everything that was on the phone?
- How do I find out what data was actually extracted?
- How do I preserve a useful result from a reader report?
- How do I record where an artefact came from?
- How should I build a timeline from several applications?
- How should I deal with duplicated results?
- How should I deal with missing or impossible-looking times?
- How should I search a mobile extraction report?
- How should I search for dates, amounts and reference numbers?
- How should I search for email addresses?
- How should I search for telephone numbers?
- How should I search for URLs, domains and IP addresses?
- Is a screenshot from the report enough?
- Is the timestamp stored in UTC or local time?
- I’ve been given a mobile phone extraction or reader report. What can I do with it?
- What alternative names, usernames and identifiers should I search?
- What can Bluetooth records show?
- What can browser-history records show?
- What can cached or thumbnail images show?
- What can call-history records show?
- What can location records show?
- What can notifications reveal?
- What can photographs and their metadata show?
- What can search-history records show?
- What can Wi-Fi records show?
- What corroboration should I look for before attributing mobile evidence?
- What does a timestamp prove about when a person acted?
- What does an application artefact actually show?
- What does deleted mean in a mobile extraction?
- What does it mean when data is marked parsed or decoded?
- What does recovered mean in a mobile extraction?
- What exactly is a mobile phone extraction report?
- What happens when the device timezone changes?
- What is the difference between an extraction, a reader report and an analyst’s summary?
- What is the difference between created, modified, accessed and received time?
- What is the difference between draft, queued, sent, delivered and read?
- What is the difference between logical, file-system and physical extraction?
- What should a supervisor ask before relying on mobile-extraction evidence?
- What should I ask the digital-forensics unit before relying on the report?
- What should I check before I start reviewing the report?
- What should I do when mobile evidence conflicts with another account?
- When should I return to the digital-forensics unit or specialist?
- Which timestamp in a mobile report should I use?
- Why can one artefact show several different times?
- Why is searching only for the suspect’s name unreliable?
- Why might an application timestamp differ from the phone timestamp?
- Why might one conversation appear in several places?
- Why might two reports from the same device contain different information?
- Work through a mobile extraction
- What is a mobile extraction report?
- Dodgy Dave deletes the wildlife-trade chat and keeps the thumbnails