How do I preserve a useful result from a reader report?¶
title: How do I preserve a useful result from a reader report? subtitle: Bookmark it, retain its context and export it in a form that preserves source and provenance rather than only appearance. slug: how-do-i-preserve-a-useful-result-from-a-reader-report series: mobile-extraction-and-reader-reports section: searching-and-preserving-results card_type: question_card content_type: core-operational risk_level: normal pathway_order: 23 section_order: 10 status: draft owner: IF Digital last_updated: '2026-07-25' version: '0.1' review_gate: pending review_mode: ai-assisted review_timebox_mins: 30 qa_gate: pending qa_count: 0 pipeline_ref: PIPELINE_PRG_001 pipeline_version: '1.1' public_safe: true video_ready: true word_count: 522 estimated_read_time_seconds: 216 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - mobile evidence - preservation - bookmark - export - provenance sources: - title: 'Cellebrite Reader: UFDR Report Viewer for Investigators' url: https://cellebrite.com/en/products/cellebrite-inseyets/reader/ - title: 'Magnet Forensics: Portable Case for evidence review' url: https://www.magnetforensics.com/blog/the-power-of-portable-case-unleashing-evidence-discovery-for-all-investigators/ - title: 'Magnet Forensics: Creating and sharing a Portable Case' url: https://www.magnetforensics.com/resources/case-collaboration-with-magnet-ief-how-to-create-a-portable-case/ - title: SWGDE Best Practices for Mobile Device Forensic Analysis url: https://www.swgde.org/documents/published-complete-listing/20-f-005-swgde-best-practices-for-mobile-device-forensic-analysis/
How do I preserve a useful result from a reader report?¶
Bookmark it, retain its context and export it in a form that preserves source and provenance rather than only appearance.
Script¶
You find a result in the reader report that may be important.
Don't rely on remembering where it was or taking one cropped screenshot.
Preserve it in layers.
First, bookmark or tag the artefact inside the review tool where that function is available.
Use a clear label connected to the investigative issue.
Add a short comment explaining why it matters.
Cellebrite Reader and Magnet Portable Case are designed to support searching, tagging, bookmarks and collaborative review.
Those features create a useful working record, but they are not the only preservation step.
Record the artefact details.
Capture:
the device or exhibit;
extraction or evidence source;
application and account;
artefact type;
participants;
displayed time and timezone;
status or direction;
source path;
record or message identifier;
and the exact relevant content.
If the artefact has an attachment, preserve the relationship between the attachment and the communication.
Then preserve the context.
For a message, include enough of the surrounding conversation to explain what it answers or prompts.
For a call, include nearby calls where they form a sequence.
For browser activity, preserve the relevant history, URL and associated download or search record.
An isolated hit can be misleading.
Now export through the reader tool where appropriate.
Choose a format that retains the fields needed to understand and trace the item.
A PDF may be readable.
A spreadsheet may support review.
A native or focused review package may retain richer source detail.
The right format depends on the purpose.
Don't treat every export as equivalent.
Record the export settings, selected items, date, tool version and person who created it.
Keep the original reader package unchanged.
Save annotations and bookmarks through the supported case workflow rather than altering source data.
If several people are reviewing the material, agree how tags, comments and exports will be named.
Portable-case products may preserve shared bookmarks, tags and comments, which can be valuable for collaboration.
They may also contain only a subset selected by the examiner.
Don't lose sight of the full extraction held by the digital-forensics unit.
Where the result is central, disputed or technically complex, ask the examiner to validate and preserve it against the source.
The examiner may produce a focused export, source database extract, hash, screenshot or statement explaining the parser and underlying record.
This is particularly important for recovered, deleted, location or status artefacts whose meaning is not obvious from the reader view.
The common mistake is:
“I bookmarked it, so it is preserved.”
A bookmark helps you find the item in that package.
It does not replace the package, source extraction or evidential export.
Another mistake is to export only the visible text and lose the source path, participants or timestamp basis.
A good preserved result lets another person answer:
What was found?
Where was it found?
What source produced it?
What context surrounded it?
How was this copy created?
And who can return to the extraction if it needs validation?
Preserve the reader package, bookmark the artefact, record the provenance and create a focused export for the intended use.
The finding should remain traceable all the way back to the acquired source.
Key takeaway
Preserve the result, the surrounding context and the route back to the extraction.
Related questions¶
- Is a screenshot from the report enough?
- How do I record where an artefact came from?
- How should I deal with duplicated results?
Source notes¶
- Cellebrite Reader: UFDR Report Viewer for Investigators
- Magnet Forensics: Portable Case for evidence review
- Magnet Forensics: Creating and sharing a Portable Case
- SWGDE Best Practices for Mobile Device Forensic Analysis