Mobile Device Forensics
Law & Forensics recovers and analyzes evidence from smartphones, tablets, and wearables for litigation, corporate investigations, and incident response. Our examiners handle any device regardless of operating system or level of encryption, using industry-standard forensic tooling.
Mobile Device Forensics capabilities
Mobile Device Data Extraction
We recover critical information from smartphones, tablets, and wearables across operating systems and encryption levels using advanced acquisition tools such as Cellebrite UFED, Oxygen Forensic Suite, and XRY for a thorough, defensible extraction.
Mobile Device Malware Analysis
Our team identifies and dissects malicious software on mobile devices using tools such as IDA Pro, OllyDbg, and Ghidra, explaining the malware's behavior and origin and delivering actionable remediation recommendations.
Mobile Device Incident Response
We provide rapid response to urgent mobile device incidents, leveraging EnCase, FTK, and Magnet AXIOM to analyze breaches, identify the source of unauthorized access, and help clients mitigate risk and minimize damage.
Mobile Device Forensics — matters we are engaged for
A departing employee's phone was personal, not issued
The device holds the evidence and the company does not own it. What can be examined turns on the policy in force, the consent obtained, and the jurisdiction — and getting that sequence wrong can taint the evidence and create exposure of its own.
The messages that matter were set to disappear
Signal, WhatsApp disappearing messages and similar channels leave less than people assume but more than nothing. Notification artifacts, backups and the other end of the conversation frequently survive after the thread itself is gone.
Extraction depth is contested
What can be pulled from a phone depends on the model, the OS version and the vendor's current security posture — not on the tool's marketing. Stating plainly what was and was not accessible is what keeps the report credible under cross-examination.
A device is returned late, or reset first
A factory reset before handover is itself a finding. Reset timestamps, account re-provisioning records and backup history establish when it happened, which is often the fact the matter actually turns on.
Mobile Device Forensics — frequently asked questions
Which mobile devices can you examine?
We handle smartphones, tablets, and wearables across operating systems, including devices protected by encryption, using advanced forensic acquisition tools.
What tools do your examiners use?
For extraction we use Cellebrite UFED, Oxygen Forensic Suite, and XRY; for malware analysis we use IDA Pro, OllyDbg, and Ghidra; and for incident response we use EnCase, FTK, and Magnet AXIOM.
Can you recover data from an encrypted device?
Yes. Our examiners are experienced in working with encrypted devices and have recovered critical evidence from encrypted mobile devices to support litigation and corporate investigations.
Do you support urgent incident response?
Yes. Our mobile device incident response services provide rapid analysis of breaches and unauthorized access, identifying the source and delivering actionable recommendations to contain and remediate the incident.
Can you analyze mobile malware?
Yes. We identify and analyze malicious software on mobile devices, determine how it behaves and spreads, and recommend security measures to prevent further compromise.
Mobile Device Forensics — questions, terms and comparisons
Questions answered
Case law
Terms defined
Digital Forensics experts who testify to this work
Full expert panel →
J-Michael Roberts
Senior Director
Digital Forensics · Incident Response · Malware Reverse Engineering

Daniel B. Garrie
Founder
Digital Forensics · Expert Witness Testimony · Incident Response

Roland Cloutier
Expert Consultant
Incident Response · Expert Witness Testimony
Our experts serve as court-appointed special masters, forensic neutrals, and arbitrators — 40 appointments are listed by matter and citation.
Mobile Device Forensics case results
Electric Utility / Power Generation
Forensic Attribution Halts a Departing Engineer's Theft of Grid Design Data at an Electric Utility
Logistics & Freight
Insider Theft of Proprietary Routing and Pricing Models Traced and Proven at a National Logistics Carrier
Public Research University
Forensic Attribution of Faculty Research-IP Theft at a Public Research University

