Skip to content

Mobile Device Forensics

Law & Forensics recovers and analyzes evidence from smartphones, tablets, and wearables for litigation, corporate investigations, and incident response. Our examiners handle any device regardless of operating system or level of encryption, using industry-standard forensic tooling.

Mobile Device Forensics capabilities

  • Mobile Device Data Extraction

    We recover critical information from smartphones, tablets, and wearables across operating systems and encryption levels using advanced acquisition tools such as Cellebrite UFED, Oxygen Forensic Suite, and XRY for a thorough, defensible extraction.

  • Mobile Device Malware Analysis

    Our team identifies and dissects malicious software on mobile devices using tools such as IDA Pro, OllyDbg, and Ghidra, explaining the malware's behavior and origin and delivering actionable remediation recommendations.

  • Mobile Device Incident Response

    We provide rapid response to urgent mobile device incidents, leveraging EnCase, FTK, and Magnet AXIOM to analyze breaches, identify the source of unauthorized access, and help clients mitigate risk and minimize damage.

Mobile Device Forensics — matters we are engaged for

  • A departing employee's phone was personal, not issued

    The device holds the evidence and the company does not own it. What can be examined turns on the policy in force, the consent obtained, and the jurisdiction — and getting that sequence wrong can taint the evidence and create exposure of its own.

  • The messages that matter were set to disappear

    Signal, WhatsApp disappearing messages and similar channels leave less than people assume but more than nothing. Notification artifacts, backups and the other end of the conversation frequently survive after the thread itself is gone.

  • Extraction depth is contested

    What can be pulled from a phone depends on the model, the OS version and the vendor's current security posture — not on the tool's marketing. Stating plainly what was and was not accessible is what keeps the report credible under cross-examination.

  • A device is returned late, or reset first

    A factory reset before handover is itself a finding. Reset timestamps, account re-provisioning records and backup history establish when it happened, which is often the fact the matter actually turns on.

Mobile Device Forensics — frequently asked questions

Which mobile devices can you examine?

We handle smartphones, tablets, and wearables across operating systems, including devices protected by encryption, using advanced forensic acquisition tools.

What tools do your examiners use?

For extraction we use Cellebrite UFED, Oxygen Forensic Suite, and XRY; for malware analysis we use IDA Pro, OllyDbg, and Ghidra; and for incident response we use EnCase, FTK, and Magnet AXIOM.

Can you recover data from an encrypted device?

Yes. Our examiners are experienced in working with encrypted devices and have recovered critical evidence from encrypted mobile devices to support litigation and corporate investigations.

Do you support urgent incident response?

Yes. Our mobile device incident response services provide rapid analysis of breaches and unauthorized access, identifying the source and delivering actionable recommendations to contain and remediate the incident.

Can you analyze mobile malware?

Yes. We identify and analyze malicious software on mobile devices, determine how it behaves and spreads, and recommend security measures to prevent further compromise.

More Digital Forensics questions answered →

Digital Forensics experts who testify to this work

Full expert panel →
  • J-Michael Roberts, Senior Director, Law & Forensics

    J-Michael Roberts

    Senior Director

    Digital Forensics · Incident Response · Malware Reverse Engineering

  • Digital Forensics · Expert Witness Testimony · Incident Response

  • Roland Cloutier, Expert Consultant, Law & Forensics

    Roland Cloutier

    Expert Consultant

    Incident Response · Expert Witness Testimony

Our experts serve as court-appointed special masters, forensic neutrals, and arbitrators — 40 appointments are listed by matter and citation.

Ready to discuss your matter?

Submit a case