Does the report contain everything that was on the phone?¶
Usually not, and the missing material may have been inaccessible, unparsed, overwritten, stored elsewhere or excluded from the report.
Script¶
A mobile report rarely contains everything that was ever on the phone.
It may not even contain everything that was stored on the device at the moment of acquisition.
There are several separate reasons.
First, the acquisition method may not reach every area.
A logical extraction normally depends on interfaces and permissions provided by the operating system or application.
A file-system or physical method may provide broader access but still encounter encryption, hardware security, damaged storage or unsupported partitions.
The device may have been locked or only partly unlocked.
Second, data may sit somewhere else.
Modern applications synchronise with cloud services.
Photographs, messages, files and account activity may be stored mainly on a provider’s servers.
The device may contain only a cache, thumbnail, token or recent subset.
Data visible in an application may have been fetched from the cloud and not preserved locally in a form the forensic tool can acquire.
The reverse is also possible.
A report may contain cloud-synchronised material created on another phone, tablet or computer using the same account.
Third, the data may have been acquired but not interpreted.
Forensic software has to understand thousands of operating-system and application formats.
An updated application may change its database.
The files may be present while the tool doesn’t recognise or parse them.
A second tool or later software version may produce additional results from the same extraction.
Fourth, data may have been deleted, overwritten or removed by normal device processes.
Flash storage uses garbage collection and wear levelling.
Deleted remnants may be recoverable in some circumstances and gone in others.
There is no guarantee that an older item remains available.
Fifth, the report itself may be restricted.
The examiner may create a package containing only selected dates, artefact categories, bookmarks or legally authorised material.
A portable case may deliberately contain a subset so investigators aren’t overwhelmed or exposed to irrelevant information.
A PDF or spreadsheet is usually narrower again.
Sixth, the viewer may hide data through settings or filters.
Deleted items, source details, media or particular categories may be excluded from the current view even though they are in the package.
So when somebody asks, “Is this everything?”, break the question down.
Did the acquisition obtain all accessible data under that method?
Did processing recognise all relevant formats?
Did the report include all processed results within scope?
And is the viewer currently displaying them?
The honest answer may be:
“This is the complete reader package created from the successful logical extraction, but the examiner reports that one encrypted application couldn’t be decoded.”
Or:
“This report contains selected artefacts from the full extraction for the authorised date range.”
Those are useful and defensible descriptions.
The common mistake is to judge completeness by size.
A 200-gigabyte package can still miss one important application.
Another is to treat any limitation as making the whole extraction worthless.
A report may be incomplete in one area while providing reliable evidence in another.
Ask what matters to the investigation.
If the missing item is central, return to the digital-forensics unit with a precise question.
Was the relevant application installed?
Were its source files acquired?
Were they parsed?
Was the report filtered?
Could a cloud, backup or provider source hold the missing data?
Completeness is not a yes-or-no property of the report.
It is an explanation of what was accessible, processed and included.
Key takeaway
Completeness has to be assessed across acquisition, decoding and report scope. A report can be very large and still be incomplete.
Related questions¶
- How do I find out what data was actually extracted?
- Does the absence of a message, call or application prove it wasn’t there?
- What should I ask the digital-forensics unit before relying on the report?
Source notes¶
- NIST SP 800-101 Rev. 1: Guidelines on Mobile Device Forensics
- SWGDE Best Practices for Mobile Device Evidence Collection, Preservation, Handling and Acquisition
- SWGDE Best Practices for Mobile Device Forensic Analysis
- Cellebrite: Reader overview and limitations
- Magnet Forensics: Creating and sharing a Portable Case