Skip to content
Skip to main content
Mobile Extractions Foundation Explainer

What is a mobile extraction report?

A mobile extraction is data acquired from a device using a recorded method. A reader report is software's organised presentation of some of that data. It can make millions of technical records searchable and understandable, but the categories on screen are not the source device and do not explain every limitation or interpretation on their own.

In one sentence
The device held data; an acquisition collected what its method could reach; processing interpreted some of it; and the reader package presents a selected view. Each layer answers a different question.

How the phone becomes a report

Source device
Acquisition method
Extracted files
Processing and parsing
Reader package
Investigator view

Data can be inaccessible, unparsed, filtered or excluded at different points. A limitation at one layer does not automatically make every result at another layer unreliable.

The source device is the physical handset and its state. The acquisition is the process used to collect accessible data. A logical, file-system or physical extraction describes the acquisition route and scope; it is not a simple ranking from bad to good.

Processing software examines acquired files and databases. It may decode application structures, identify artefacts and present them under headings such as messages, media, locations and accounts. The reader package then exposes selected results, sometimes with bookmarks, filters or a restricted date range.

There are three different inventories

Finding out what was actually extracted requires three separate questions:

  1. What data did the acquisition obtain?
  2. What data did the software successfully parse or decode?
  3. What data did the examiner include in the package supplied to the investigator?
Simplified extraction summary
AcquiredFile-system extraction X-744application files, system data, media and account stores
Processed27 application familiesone encrypted application not decoded
SuppliedReader package R-744Aauthorised date range and examiner bookmarks
These are three related inventories, not three descriptions of the same thing

A missing application category may mean the app was not installed, its files were not acquired, the data could not be decoded or the results were excluded from this report. Absence from the report does not prove absence from the phone.

A parsed artefact is a software interpretation with a source

Example parsed result
extraction=X-744source=/data/user/0/relaychat/databases/messages.dbrecord_id=MSG-11908stored_time=2026-06-18T22:12:41Zparser_state=deleted
Established the named extraction and parser produced this result from the specified sourceStill open the precise meaning of the fields, the completeness of the record and the human activity behind it

The source path and record identifier make the result traceable. Recording where an artefact came from allows an examiner to revisit it, compare tools or explain why the report shows it.

Parsed or decoded does not mean invented. It means the software interpreted a technical structure. Most useful mobile review depends on that work. Where a result is central, surprising or ambiguous, source data and specialist explanation can test the interpretation.

“Deleted”, “recovered” and “not present” are not synonyms

A deleted label may reflect a status field, a recovered database row or the parser's interpretation of a source condition. Recovered may mean data was reconstructed or surfaced from a source not normally displayed. Neither label automatically proves that a particular user deliberately removed an item.

The reverse assumption is equally unsafe. A report failing to show a message does not prove nobody sent it. The item may never have reached this device, may have been stored remotely, may have been overwritten, may remain unparsed or may fall outside the package scope.

EstablishedThe report presents the specified artefact and source fields produced through the recorded extraction and processing workflow.
Still openWhether the dataset is complete, how an ambiguous state arose, and what the artefact proves about a person's knowledge or conduct.

Reader time is not automatically event time

One artefact can carry created, modified, received, server, device and database times. The reader may convert them for display. Several different times can appear on one artefact, and the device timezone can change.

22:12:41 UTCProvider records the message event.
23:12:44 localDevice database stores the received row.
22:13:01 UTCOperating system records a notification.

Those may describe different stages of one communication, not conflicting accounts. Building a cross-application timeline means preserving the original field, timezone and event meaning before normalising values for comparison.

Presence on the handset is not the final human conclusion

Cloud synchronisation, shared devices, received content, caches and automatic processes can all place material on a phone. Data on a phone does not automatically prove knowledge, and possession does not prove authorship of its messages.

That does not make the extraction weak. It tells the investigator what to do next. Account sessions, recipient devices, provider records, contemporaneous possession, witness evidence and conduct can turn a properly sourced artefact into a strong attribution case. Corroboration before attributing mobile evidence should be positive and specific, not a ritual caveat.

A defensible description keeps the layers visible

“Reader package R-744A displays message MSG-11908, parsed from the identified database within extraction X-744” explains what the report establishes.

“The phone proves Lena deleted the message” collapses source, interpretation, deletion and personal attribution into one sentence. Further evidence may eventually support that conclusion, but the report label alone does not.

Operational takeaway
Use the reader for access, search and explanation while retaining the evidence route behind it. Distinguish acquired, parsed and supplied data; preserve source references; and test important conclusions against independent records and human context.
Reference: MEX-061Mobile Extractions