What should I check before I start reviewing the report?¶
title: What should I check before I start reviewing the report? subtitle: Confirm the device, source, scope, dates, settings and report limitations before searching. slug: what-should-i-check-before-i-start-reviewing-the-report series: mobile-extraction-and-reader-reports section: understanding-what-you-have card_type: question_card pathway_order: 4 section_order: 3 status: draft owner: IF Digital last_updated: '2026-07-25' version: '0.1' review_gate: pending review_mode: ai-assisted review_timebox_mins: 30 qa_gate: pending qa_count: 0 pipeline_ref: PIPELINE_PRG_001 pipeline_version: '1.1' public_safe: true video_ready: true word_count: 558 estimated_read_time_seconds: 231 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - mobile evidence - reader report - pre-review checks - scope - settings sources: - title: 'Cellebrite: Configuring and reviewing a Reader report' url: https://cellebrite.com/en/ask-the-expert/cellebrite-reader-familiarizing-yourself-with-the-platform/ - title: 'Cellebrite: Creating reports for Reader' url: https://cellebrite.com/en/series/tip-tuesday/different-methods-for-creating-reports-in-cellebrite-reader/ - title: 'Magnet Forensics: Creating and sharing a Portable Case' url: https://www.magnetforensics.com/blog/deep-dive-portable-case-part-one/ - title: SWGDE Best Practices for Mobile Device Forensic Analysis url: https://www.swgde.org/documents/published-complete-listing/20-f-005-swgde-best-practices-for-mobile-device-forensic-analysis/
What should I check before I start reviewing the report?¶
Confirm the device, source, scope, dates, settings and report limitations before searching.
Script¶
Before searching a mobile report, check that you understand what you have opened.
This sounds obvious.
In a large investigation, it is surprisingly easy to review the wrong device, an earlier extraction, a limited report or a package created for another purpose.
Start with the case and device identifiers.
Confirm the case reference, exhibit or property number, device description and any recorded identifiers such as the make, model, serial number, IMEI or assigned exhibit label.
If several similar phones were seized, a filename such as “Samsung report” isn’t enough.
Then check the evidence source.
Does the package relate to the handset’s internal storage, a SIM or identity module, a memory card, a local backup, a cloud acquisition, or a combination of sources?
Cloud and backup material can contain data that wasn’t resident on the phone at the time of seizure.
Material found in a linked account may also originate from another device.
Now check the dates.
When was the device seized?
When was the acquisition performed?
Was there more than one acquisition?
When was the data processed?
When was your report created?
A report generated months later using updated software may contain different parsed results from an earlier report based on the same acquisition.
Check the acquisition type and result.
Was it described as logical, advanced logical, file system, full file system, physical, backup, cloud or something else?
Was the device unlocked?
Did the examiner report any failed, partial or interrupted acquisition?
Were encrypted areas or unsupported applications identified?
Don’t decide what those labels mean from the name alone. Record them and look for the examiner’s explanation.
Then check the report scope.
Was it limited to a date range?
Were only selected artefact categories included?
Was it created from bookmarked items?
Was irrelevant or legally out-of-scope material excluded?
Does the report include all available extractions for the device, or only one?
Reader and portable-case products are designed to let examiners share some or all processed artefacts. A large package can still be filtered.
Check the viewing settings as well.
Are deleted or recovered items hidden?
Are source indications displayed?
Are timezones set correctly?
Are translations enabled?
Are media files present but filtered from the current view?
Cellebrite’s own Reader guidance warns that settings can affect whether expected data is visible.
Now identify the tool and version.
Which acquisition tool was used?
Which analysis tool and parser version processed the data?
Has the package been opened in a compatible or newer reader version?
You don’t need to memorise version histories, but the information may matter if a relevant application wasn’t supported at the time.
Finally, read the examiner’s notes and limitations before searching.
Look for scope restrictions, failed extraction stages, unsupported apps, known timestamp issues, missing passwords, damaged data, manual checks and recommendations for further work.
The common mistake is to begin with a keyword and only later discover that the report covers the wrong date range.
Another is to assume that the absence of a category means the device didn’t contain that data.
A useful pre-review note should state which device and source you are reviewing, which acquisition and report version, the report scope, the time display setting and any known limitation.
That small record makes your later findings easier to explain and reproduce.
Before asking what the report says, make sure you know which report it is.
Key takeaway
Five minutes checking the report context can prevent hours of searching the wrong device, wrong period or incomplete package.
Related questions¶
- How do I find out what data was actually extracted?
- Why might two reports from the same device contain different information?
- What should I ask the digital-forensics unit before relying on the report?
Source notes¶
- Cellebrite: Configuring and reviewing a Reader report
- Cellebrite: Creating reports for Reader
- Magnet Forensics: Creating and sharing a Portable Case
- SWGDE Best Practices for Mobile Device Forensic Analysis