Skip to content
MEX-031 Mobile Extractions

What can call-history records show?


title: What can call-history records show? subtitle: They may record call-related events, participants, direction, duration and status—not necessarily who spoke or what was said. slug: what-can-call-history-records-show series: mobile-extraction-and-reader-reports section: interpreting-common-artefacts card_type: question_card content_type: core-operational risk_level: normal pathway_order: 31 section_order: 6 status: draft owner: IF Digital last_updated: '2026-07-25' version: '0.1' review_gate: pending review_mode: ai-assisted review_timebox_mins: 30 qa_gate: pending qa_count: 0 pipeline_ref: PIPELINE_PRG_001 pipeline_version: '1.1' public_safe: true video_ready: true word_count: 494 estimated_read_time_seconds: 204 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - mobile evidence - call history - telephone - application calls - communications sources: - title: SWGDE Best Practices for Mobile Device Forensic Analysis url: https://www.swgde.org/documents/published-complete-listing/20-f-005-swgde-best-practices-for-mobile-device-forensic-analysis/ - title: 'NIST SP 800-101 Rev. 1: Guidelines on Mobile Device Forensics' url: https://csrc.nist.gov/pubs/sp/800/101/r1/final - title: 'NIST Computer Forensics Tool Testing: Mobile Devices' url: https://www.nist.gov/itl/csd/secure-systems-and-applications/computer-forensics-tool-testing-program-cftt/cftt-7


What can call-history records show?

They may record call-related events, participants, direction, duration and status—not necessarily who spoke or what was said.

Script

Call-history records can show that a device, account or application recorded a call-related event.

They may include:

the other number or account;

incoming or outgoing direction;

start or end time;

duration;

missed, rejected or answered status;

SIM or account used;

and whether the call used the ordinary telephone service or an internet application.

Those fields can be very useful.

They don't automatically prove who held the device, who spoke or what was said.

Start with the source.

Is the record from the native telephone call log, a messaging application, a cloud account, a notification, a provider record or another participant’s device?

A WhatsApp or Signal call may not appear in the ordinary mobile-network call log.

A provider call-detail record may not include an internet application call.

A combined reader report may present both under a friendly “Calls” category.

Keep the application and source visible.

Direction also needs care.

An outgoing record may show that the local device or account initiated the call attempt.

It does not prove that the other party answered.

An incoming missed call shows that the application or device recorded an incoming attempt.

It does not prove the user noticed it.

An answered status may be stronger, but it still does not identify who actually spoke.

Duration can help.

A zero-second or very short event may represent a failed or unanswered attempt, depending on the system.

A longer duration may support that a connection existed.

It does not reveal the content of the conversation.

Compare local and provider records where possible.

The device may store a user-friendly time and duration.

The network provider may record signalling or billing data.

An application provider or the other participant’s device may preserve another view.

Small differences can arise because the systems record different stages.

Also consider deletion and synchronisation.

A call may be removed from the visible log but remain in a database, backup or notification.

A cloud-synchronised call history may appear on more than one device.

The record may belong to the account history rather than proving that this handset handled the call.

Check for device-specific evidence where that matters.

The common mistake is:

“The phone called this number for ten minutes, so the suspect spoke to that person.”

The record may support a ten-minute connection associated with the device or account.

The people on each end still need attribution.

Another mistake is:

“There is no call in the phone log, so no call happened.”

The communication may have occurred through an application, another device or a record that was not acquired or retained.

A careful conclusion might say:

“The native call database records an outgoing answered call from SIM 1 to this number, beginning at this time and lasting 612 seconds.”

Then explain what links the SIM, handset and other number to the relevant people.

Call history is strong evidence of communication events.

It is weaker evidence of human identity and no evidence of spoken content unless another source records it.

Key takeaway

Treat a call record as evidence of a recorded communication event. Use account, network and contextual evidence for the people and conversation behind it.

Source notes


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.