How do I record where an artefact came from?¶
title: How do I record where an artefact came from? subtitle: Record the device, acquisition, evidence source, application, artefact type, source path and record identifier. slug: how-do-i-record-where-an-artefact-came-from series: mobile-extraction-and-reader-reports section: searching-and-preserving-results card_type: question_card content_type: core-operational risk_level: normal pathway_order: 25 section_order: 12 status: draft owner: IF Digital last_updated: '2026-07-25' version: '0.1' review_gate: pending review_mode: ai-assisted review_timebox_mins: 30 qa_gate: pending qa_count: 0 pipeline_ref: PIPELINE_PRG_001 pipeline_version: '1.1' public_safe: true video_ready: true word_count: 522 estimated_read_time_seconds: 216 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - mobile evidence - provenance - source path - artefact - recording findings sources: - title: SWGDE Best Practices for Mobile Device Forensic Analysis url: https://www.swgde.org/documents/published-complete-listing/20-f-005-swgde-best-practices-for-mobile-device-forensic-analysis/ - title: 'NIST SP 800-101 Rev. 1: Guidelines on Mobile Device Forensics' url: https://csrc.nist.gov/pubs/sp/800/101/r1/final - title: 'Cellebrite Reader: UFDR Report Viewer for Investigators' url: https://cellebrite.com/en/products/cellebrite-inseyets/reader/ - title: 'Magnet Forensics: Portable Case for evidence review' url: https://www.magnetforensics.com/blog/the-power-of-portable-case-unleashing-evidence-discovery-for-all-investigators/
How do I record where an artefact came from?¶
Record the device, acquisition, evidence source, application, artefact type, source path and record identifier.
Script¶
A mobile artefact is much easier to challenge, validate and explain when its origin is recorded properly.
Don't record only:
“WhatsApp message found on phone.”
That leaves several unanswered questions.
Which phone?
Which extraction?
Which WhatsApp account?
Which database or source?
Which record?
Was it active, recovered or from a backup?
Start with the evidence source.
Record the case reference and device or exhibit identifier.
Identify the acquisition or package you reviewed.
If the case contains several extractions, note which one produced the artefact.
Record whether the source was the handset, SIM, memory card, backup, cloud acquisition or another combined source.
Then record the report context.
Include the report or portable-case name, creation date where available, tool and version, and any relevant filter or timezone setting.
This helps another reviewer reproduce what you saw.
Now record the artefact itself.
Useful fields commonly include:
application or service;
account identifier;
artefact category;
participants;
direction or status;
displayed date and time;
timezone;
message, event or record ID;
conversation ID;
source file or database path;
table or field where exposed;
and whether the item was parsed, recovered or classified as deleted.
Not every report will show every field.
Record what is available and identify what would need examiner support.
Keep the distinction between the friendly artefact and the technical source.
The report may display:
“Outgoing WhatsApp message from Steve to Dave.”
The underlying source may be a row in a database within a specific application container.
Both descriptions matter.
The friendly view explains the result.
The source path allows validation.
If the artefact includes media, preserve the file name, hash where available, source path and relationship to the message or application.
Identical files can appear in several locations.
The context may distinguish an attachment, cached copy, thumbnail or separately saved file.
If the result was discovered through search, record the search term and filters that produced it.
If it was found through a timeline, map, conversation view or examiner bookmark, record that route as well.
This makes the review process reproducible.
Use a consistent finding reference.
For example:
MOB-02 / WhatsApp / message ID 84721 / 14 July 2026 18:42 BST / source database path.
The exact local format can vary.
The principle is consistency.
The common mistake is to copy the message text into a report and discard the technical detail as unnecessary.
That detail becomes important if the timestamp, account, deletion status or parser interpretation is later disputed.
Another mistake is to paste a long source path without explaining the artefact in ordinary language.
The investigator and examiner need both layers.
A good finding note answers:
What is it?
Which device or source did it come from?
Where did the tool find it?
How did the tool classify it?
Which identifiers link it to the surrounding records?
What was the viewer setting?
And where is the preserved export or bookmark?
The chain should run from your conclusion back to the artefact, from the artefact to the source file, and from the source file to the acquisition.
If that chain is recorded, a specialist can validate the result and another investigator can understand it without starting again.
Key takeaway
A useful finding should remain traceable from your note or export back through the report to the source data and acquisition.
Related questions¶
- How do I preserve a useful result from a reader report?
- How should I search a mobile extraction report?
- What does it mean when data is marked parsed or decoded?
Source notes¶
- SWGDE Best Practices for Mobile Device Forensic Analysis
- NIST SP 800-101 Rev. 1: Guidelines on Mobile Device Forensics
- Cellebrite Reader: UFDR Report Viewer for Investigators
- Magnet Forensics: Portable Case for evidence review