How do I find out what data was actually extracted?¶
Start with the extraction or acquisition summary, not the menu in the reader.
The reader tells you what has been presented for review. The acquisition records tell you what sources were actually obtained and what happened when the forensic tools processed them.
Keep three things separate¶
A useful way to think about it is:
| Question | Where the answer usually comes from |
|---|---|
| What was acquired? | Acquisition summary / examiner notes |
| What was successfully interpreted? | Processing logs / tool output |
| What was included in my report? | Report scope / reader settings |
Those three lists may not be identical.
What should the acquisition information tell you?¶
Look for:
- exhibit and device identifier;
- handset make/model;
- acquisition date and time;
- method used;
- device lock or access state;
- whether the acquisition was complete, partial or failed;
- SIM, memory card, backup or cloud sources dealt with separately;
- tool and version;
- errors or inaccessible areas; and
- output or extraction identifier.
A simplified summary might read:
That immediately tells you far more than the list of categories in the reader.
The data may exist even if the reader has no neat category for it¶
Forensic tools try to turn raw files and databases into recognisable things such as Messages, Calls, Contacts and Locations.
Sometimes source files are acquired but the tool cannot fully interpret them — for example after an app update or where data is encrypted or unsupported.
So if something important appears to be missing, ask whether the source file exists even though the reader did not turn it into a normal artefact.
The supplied report may be narrower again¶
An examiner may legitimately create a report limited by:
- date;
- application;
- category;
- authority;
- bookmark selection;
- media type; or
- another case-specific scope.
The reader itself may also have active filters.
This is why the report does not necessarily contain everything that was on the phone.
When to ask the DFU¶
If the distinction matters, do not send a vague request saying “is there anything else?”
Ask something specific:
“Was WhatsApp data from the relevant period successfully acquired and parsed, and is all of that parsed data included in this report?”
That is much easier for the DFU to answer.
What should I ask the digital-forensics unit? gives more examples of how to frame that question.
The practical point is: work out what was acquired, what was understood, and what was presented. Do not treat those as the same inventory.