What is the difference between an extraction, a reader report and an analyst’s summary?¶
title: What is the difference between an extraction, a reader report and an analyst’s summary? subtitle: They sit at different stages between the device and the investigative conclusion. slug: what-is-the-difference-between-an-extraction-a-reader-report-and-an-analysts-summary series: mobile-extraction-and-reader-reports section: understanding-what-you-have card_type: question_card pathway_order: 3 section_order: 2 status: draft owner: IF Digital last_updated: '2026-07-25' version: '0.1' review_gate: pending review_mode: ai-assisted review_timebox_mins: 30 qa_gate: pending qa_count: 0 pipeline_ref: PIPELINE_PRG_001 pipeline_version: '1.1' public_safe: true video_ready: true word_count: 538 estimated_read_time_seconds: 223 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - mobile evidence - extraction - reader report - analyst summary - source sources: - title: 'NIST SP 800-101 Rev. 1: Guidelines on Mobile Device Forensics' url: https://csrc.nist.gov/pubs/sp/800/101/r1/final - title: 'Cellebrite Reader: UFDR Report Viewer for Investigators' url: https://cellebrite.com/en/products/cellebrite-inseyets/reader/ - title: 'Cellebrite: Reader overview and limitations' url: https://cellebrite.com/en/series/tip-tuesday/cellebrite-reader-overview/ - title: 'Magnet Forensics: Creating and sharing a Portable Case' url: https://www.magnetforensics.com/blog/deep-dive-portable-case-part-one/
What is the difference between an extraction, a reader report and an analyst’s summary?¶
They sit at different stages between the device and the investigative conclusion.
Script¶
The terms extraction, reader report and analyst’s summary are often used as though they describe the same thing.
They don’t.
They represent different stages between the device and the conclusion.
The extraction is the acquired dataset.
It is the material obtained from the phone, memory card, backup, application container or another authorised source using a particular acquisition method.
Depending on the method, it may contain selected logical data, a file-system view, a broader memory image or several related acquisition files.
The extraction usually needs forensic software to interpret it.
It may contain files and databases that aren’t immediately meaningful to a non-specialist.
The reader report or portable review package comes later.
An examiner processes the extraction and creates a package that another person can open using review software.
This package normally presents parsed artefacts in recognisable categories such as messages, calls, contacts, media and internet activity.
It may also allow searching, filtering, tagging, timeline review and focused exports.
But it may contain all parsed artefacts or only a subset selected by the examiner.
The analyst’s summary is different again.
It is a human-produced account of what the examiner or analyst considers relevant.
It may explain the device and acquisition, the methods used, key findings, limitations, validation steps and conclusions.
It may refer to artefacts included elsewhere, but it isn’t normally the complete dataset.
Think of it like this.
The extraction is the acquired source material.
The reader report is a review environment created from processed source material.
The analyst’s summary is a person’s explanation of selected findings from that material.
Each has a different purpose.
The extraction is needed for deeper examination, reprocessing and validation.
The reader package lets investigators review large volumes of data without carrying out the acquisition.
The summary communicates findings and professional interpretation.
Problems arise when one is mistaken for another.
An investigator may be told that “the extraction has been sent” when they have actually received a filtered UFDR, portable case or PDF.
They may search it, find nothing and conclude that the original extraction contained nothing.
That conclusion isn’t safe until the report scope is known.
The opposite problem occurs when an analyst’s summary is treated as the only material worth reviewing.
The analyst may not know every name, nickname, location, reference or factual detail that matters to the investigation.
The investigator may be better placed to recognise significance within the reader package.
Start by asking:
What files have I received?
Which one is the extraction?
Which one is the review package?
Was the package filtered?
Is there a separate examiner or analyst report?
Can important artefacts be traced back to a source file or database?
Who holds the full extraction if further work is needed?
The common mistake is:
“I searched the report, so I searched the whole phone.”
You searched the material made available through that report.
Another is:
“The examiner didn’t mention it in the summary, so it wasn’t on the device.”
The summary reflects the task, scope and findings selected for reporting.
Use all three layers properly.
Review the summary for methodology and limitations.
Use the reader package to apply investigative knowledge.
And return to the extraction through the digital-forensics unit when validation or further processing is needed.
Key takeaway
The extraction is the acquired dataset, the reader report is a review package, and the analyst’s summary is a selected explanation of findings.
Related questions¶
- What exactly is a mobile phone extraction report?
- What should I check before I start reviewing the report?
- How do I find out what data was actually extracted?
Source notes¶
- NIST SP 800-101 Rev. 1: Guidelines on Mobile Device Forensics
- Cellebrite Reader: UFDR Report Viewer for Investigators
- Cellebrite: Reader overview and limitations
- Magnet Forensics: Creating and sharing a Portable Case