Skip to content
MEX-038 Mobile Extractions

What does a timestamp prove about when a person acted?


title: What does a timestamp prove about when a person acted? subtitle: It records a system event associated with data; human action is an inference that may require account, device and contextual evidence. slug: what-does-a-timestamp-prove-about-when-a-person-acted series: mobile-extraction-and-reader-reports section: timestamps-and-timelines card_type: question_card content_type: core-operational risk_level: high-risk pathway_order: 48 section_order: 8 status: draft owner: IF Digital last_updated: '2026-07-25' version: '0.1' review_gate: pending review_mode: ai-assisted review_timebox_mins: 60 qa_gate: pending qa_count: 0 pipeline_ref: PIPELINE_PRG_001 pipeline_version: '1.1' public_safe: true video_ready: true word_count: 468 estimated_read_time_seconds: 194 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - mobile evidence - timestamp - human action - attribution - evidential limits sources: - title: SWGDE Best Practices for Mobile Device Forensic Analysis url: https://www.swgde.org/documents/published-complete-listing/20-f-005-swgde-best-practices-for-mobile-device-forensic-analysis/ - title: 'NIST SP 800-101 Rev. 1: Guidelines on Mobile Device Forensics' url: https://csrc.nist.gov/pubs/sp/800/101/r1/final


What does a timestamp prove about when a person acted?

It records a system event associated with data; human action is an inference that may require account, device and contextual evidence.

Script

A timestamp records that a system associated a time value with an event or item.

It does not automatically prove that a particular person acted at that exact moment.

Start with the technical event.

The timestamp may record:

message creation;

server submission;

delivery;

application access;

file modification;

location measurement;

photograph capture;

notification posting;

or synchronisation.

The system event may be closely connected to a human action.

A locally composed message may reflect typing and sending.

A camera capture record may reflect pressing the shutter.

A browser typed-URL record may reflect direct entry.

But alternative processes can create similar records.

An application can generate a message automatically.

A cloud service can synchronise a file from another device.

A background process can access or modify data.

A shared account can be used by somebody else.

A device can be remotely controlled.

A timestamp can be inherited during backup or copying.

The person attribution therefore requires another chain.

Which account or device created the event?

Who controlled it?

Was the action manual or automated?

Could another authorised user or linked device have caused it?

Does the surrounding activity support the proposed person and purpose?

Precision also matters.

A timestamp displayed to the second may not mean that the underlying system measured the event to the second.

The source may store whole seconds, milliseconds, minutes or a rounded value.

Some applications batch events and assign the same time.

Recovered records may lose precision.

Don't imply greater accuracy than the source supports.

Clock accuracy matters too.

If the device clock was wrong, the timestamp may preserve the wrong time faithfully.

If the value came from a provider server, it may be more stable but represent a different processing stage.

Use a range where appropriate.

A sequence may support that activity occurred between two externally timed events even when the exact device time is uncertain.

Corroboration can strengthen human attribution.

A device unlock, application-use record, typed content, local attachment, CCTV, payment or witness evidence may connect the event to the person.

Several records derived from the same database are not independent corroboration.

The common mistake is:

“The message timestamp is 21:14, so the suspect typed the message at 21:14.”

The source may record server submission, and the message may have been scheduled or sent from another linked device.

Another mistake is to say timestamps prove nothing.

A well-understood source, accurate clock and strong control evidence can support a precise sequence.

A careful conclusion might say:

“At 21:14:06 UTC, the service recorded submission of this message from the account. Local device records show the application active on the seized handset immediately beforehand.”

Then explain the evidence linking the handset to the person.

A timestamp anchors a technical event.

The person and action require a supported attribution, not an automatic leap.

Key takeaway

State the recorded event first. Attribute it to a person only when control and causation are supported.

Source notes


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.