Skip to content
Skip to main content
Mobile Extractions Operational Explainer

How do I find out what data was actually extracted?

Start with the extraction or acquisition summary, not the menu in the reader.

The reader tells you what has been presented for review. The acquisition records tell you what sources were actually obtained and what happened when the forensic tools processed them.

Keep three things separate

A useful way to think about it is:

Question Where the answer usually comes from
What was acquired? Acquisition summary / examiner notes
What was successfully interpreted? Processing logs / tool output
What was included in my report? Report scope / reader settings

Those three lists may not be identical.

What should the acquisition information tell you?

Look for:

  • exhibit and device identifier;
  • handset make/model;
  • acquisition date and time;
  • method used;
  • device lock or access state;
  • whether the acquisition was complete, partial or failed;
  • SIM, memory card, backup or cloud sources dealt with separately;
  • tool and version;
  • errors or inaccessible areas; and
  • output or extraction identifier.

A simplified summary might read:

Example acquisition summary
Exhibit: SA/12 · iPhone 15Acquisition: Full file system · completed 2026-09-14 11:22 UTCWhatsApp database: acquired and parsedSignal data: acquired · partial parsingCloud backup: not acquired

That immediately tells you far more than the list of categories in the reader.

The data may exist even if the reader has no neat category for it

Forensic tools try to turn raw files and databases into recognisable things such as Messages, Calls, Contacts and Locations.

Sometimes source files are acquired but the tool cannot fully interpret them — for example after an app update or where data is encrypted or unsupported.

So if something important appears to be missing, ask whether the source file exists even though the reader did not turn it into a normal artefact.

The supplied report may be narrower again

An examiner may legitimately create a report limited by:

  • date;
  • application;
  • category;
  • authority;
  • bookmark selection;
  • media type; or
  • another case-specific scope.

The reader itself may also have active filters.

This is why the report does not necessarily contain everything that was on the phone.

When to ask the DFU

If the distinction matters, do not send a vague request saying “is there anything else?”

Ask something specific:

“Was WhatsApp data from the relevant period successfully acquired and parsed, and is all of that parsed data included in this report?”

That is much easier for the DFU to answer.

What should I ask the digital-forensics unit? gives more examples of how to frame that question.

The practical point is: work out what was acquired, what was understood, and what was presented. Do not treat those as the same inventory.

Reference: MEX-013Mobile Extractions