Skip to content
MEX-050 Mobile Extractions

What should I ask the digital-forensics unit before relying on the report?


title: What should I ask the digital-forensics unit before relying on the report? subtitle: Ask focused questions about source, scope, processing and validation rather than requesting an unexplained ‘full download’. slug: what-should-i-ask-the-digital-forensics-unit-before-relying-on-the-report series: mobile-extraction-and-reader-reports section: understanding-what-you-have card_type: question_card pathway_order: 13 section_order: 12 status: draft owner: IF Digital last_updated: '2026-07-25' version: '0.1' review_gate: pending review_mode: ai-assisted review_timebox_mins: 30 qa_gate: pending qa_count: 0 pipeline_ref: PIPELINE_PRG_001 pipeline_version: '1.1' public_safe: true video_ready: true word_count: 607 estimated_read_time_seconds: 251 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - mobile evidence - digital forensics unit - examiner questions - validation - supervision sources: - title: 'NIST SP 800-101 Rev. 1: Guidelines on Mobile Device Forensics' url: https://csrc.nist.gov/pubs/sp/800/101/r1/final - title: SWGDE Best Practices for Mobile Device Forensic Analysis url: https://www.swgde.org/documents/published-complete-listing/20-f-005-swgde-best-practices-for-mobile-device-forensic-analysis/ - title: 'Cellebrite: Reader overview and limitations' url: https://cellebrite.com/en/series/tip-tuesday/cellebrite-reader-overview/ - title: 'Cellebrite: Creating reports for Reader' url: https://cellebrite.com/en/series/tip-tuesday/different-methods-for-creating-reports-in-cellebrite-reader/


What should I ask the digital-forensics unit before relying on the report?

Ask focused questions about source, scope, processing and validation rather than requesting an unexplained ‘full download’.

Script

You don’t need to send every mobile-report question back to the digital-forensics unit.

You should go back when the answer depends on acquisition detail, source validation, missing data or a conclusion the reader report can’t safely support.

Make the question specific.

“Is this a full download?” is unlikely to produce a useful answer.

Instead ask what you need to establish.

Start with the source.

Which device, SIM, memory card, backup or cloud source produced this report?

Were several sources combined?

Could the artefact have originated from another synchronised device or account?

Then ask about acquisition.

What method was used?

Was the device unlocked?

Did the acquisition complete successfully?

Were any partitions, containers or applications inaccessible?

Were there failed attempts or an earlier extraction?

Does another acquisition exist?

Now ask about processing.

Which forensic tool and version processed the data?

Was the relevant application version supported?

Were additional parsers, scripts or tools used?

Are source files present even though no high-level artefacts appear?

Was the extraction reprocessed after software updates?

Then ask about the package you received.

Does it contain all parsed artefacts within scope?

Was it filtered by date, category, bookmark or legal authority?

Were media or large files excluded?

Are recovered or deleted items included?

Does the viewer show the source file and path for important results?

If one artefact matters, identify it exactly.

Provide the report name, artefact type, displayed time, participants, content and source path where available.

Then ask:

What source record produced this display?

Which fields were parsed?

Was the record active, recovered or classified as deleted?

Was the result validated?

Can it be checked against the source database, another tool, the device or a related record?

If the artefact is missing, ask a structured question.

Was the application installed?

Were its data files acquired?

Were they decrypted?

Did the tool support that application version?

Was the relevant period included?

Could the data sit in a cloud account or backup?

Is further processing proportionate and possible?

Also ask about time.

Which timezone does the report display?

What was the device time and offset from a reference clock?

Is the displayed value stored by the application, calculated by the tool or converted by the viewer?

Later cards will deal with timestamp interpretation in depth, but the examiner may need to explain the source.

Be clear about the proposed conclusion.

If you want to say that the user deleted a message, ask whether the source supports deliberate user deletion.

If you want to say the person sent it, ask what links the artefact to the account, device state and user.

If you want to rely on absence, ask what the extraction and parser were capable of finding.

The common mistake is to send the unit a broad request to “check the phone for anything useful”.

The investigator usually understands the people, language, events and case context better than the examiner.

Use that knowledge to define the question.

Another mistake is to treat the examiner as responsible for every investigative inference.

The digital-forensics unit can explain the acquisition, source, processing and limitations.

The investigator still has to connect the artefact to the wider evidence and person.

A useful request might say:

“The reader report shows this recovered message at this time. We need to establish whether it was an active sent message, what database record produced it, whether the deleted classification is supported, and whether another tool or participant record corroborates it.”

That gives the examiner something precise to answer.

Go back to the digital-forensics unit when the technical source matters.

And take them a proposition, not just a large report and a request for certainty.

Key takeaway

The digital-forensics unit can give a much better answer when you identify the artefact, proposition and limitation that matter.

Source notes


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.