Mobile device forensics is the forensically sound recovery, examination and reporting of data from smartphones and tablets: messages, call logs, location history, app data and deleted records. Because storage is encrypted and soldered in, what can be extracted depends on the device, its operating-system version and the acquisition method, so a defensible examination states which extraction was performed.
Why phones are harder than computers
A laptop drive can be removed, attached to a write blocker and imaged sector by sector. A phone's storage is soldered to the board and encrypted with keys held in dedicated hardware, so acquisition happens through whatever interface the device exposes — and each operating-system release narrows those interfaces. Capability is a moving target: a technique that worked on a model last year may not work on the same model after an update. Commercial extraction tools exist for exactly this reason, but no tool reaches everything on every device.
The four extraction types and what each yields
"We extracted the phone" covers outcomes that differ enormously. NIST's Guidelines on Mobile Device Forensics (SP 800-101 Rev. 1) classifies acquisition methods on a five-level scale — manual, logical, hex dumping/JTAG, chip-off and micro read — that becomes more technical, invasive and destructive as it climbs, and it warns that once a higher level is used, lower ones may no longer be possible. In practice, current examinations describe four outcomes:
- Logical. The data the device's own backup or synchronisation interface hands over: contacts, call logs, SMS, photos and whatever app data the vendor chooses to expose. Reliable and widely available; excludes deleted content and most protected app containers.
- File system. A copy of the accessible file system, including application databases. Because messaging apps store messages in SQLite databases that keep deleted rows until the database is compacted, this often recovers material a logical extraction misses.
- Full file system. Everything the running operating system can read, including protected containers, keychain-class secrets and the system logs that record app usage, lock and unlock events and cached location fixes. This is why it now matters: on current devices the artifacts that decide cases — third-party messaging, health and location caches, usage logs — live in areas a logical extraction never sees, and full-file-system is the practical ceiling for most modern phones.
- Physical. A bit-for-bit copy of the flash storage. Rare on current encrypted devices; chip-off recovers ciphertext without the keys to read it, so a "physical" extraction of a modern phone is usually a full-file-system extraction by another name.
An examiner should state which was obtained, on which tool and version, and why. "We got everything off the phone" cannot be true of most modern devices, and it invites a cross-examination that will not go well.
The artifacts that decide cases
- Message databases. iMessage and SMS on iOS live in a single SQLite database; Android keeps SMS and MMS in the telephony provider's database. Both retain timestamps, read status, attachments and — until overwritten — deleted rows.
- Ephemeral messaging apps. Whether content survives depends on the app's storage design and the user's settings. Local databases, notification caches and the other party's device are the usual sources; "it auto-deleted" is a fact to test, not to accept.
- Location and health data. Cached cell and Wi-Fi fixes, significant-location records, photo EXIF coordinates, and step and workout data corroborate or contradict an account of where someone was. Cell-site records, by contrast, come from the carrier rather than the phone and are a separate discipline with its own limits. See can phone location history be used as evidence.
- Usage and system logs. Which app was in the foreground when, screen lock and unlock events, power and charging state. These are what turn "the message existed" into "the user opened it at that minute".
- Deleted-record recovery has limits. Rows deleted from a database can persist in free pages or the write-ahead log until the database is compacted; content in unallocated flash is subject to wear-levelling and garbage collection, so recovery there is, in SWGDE's words, still possible but may seem random. An honest report says what was recovered, from where, and what could not be. See can deleted text messages be recovered.
Consent, warrants and the two Supreme Court cases
Authority to examine comes before technique. In criminal matters, Riley v. California requires a warrant to search the digital contents of a phone seized on arrest, and Carpenter v. United States requires one for historical cell-site location records held by the carrier. In civil matters the basis is consent, an employer's device policy, or a court order — and a personal device is usually examined under a protocol in which a forensic neutral images it, applies agreed search terms and produces only responsive material. See can we examine an employee's personal phone. SWGDE's collection guidance puts the same point first: confirm legal authority before touching the device.
Handling before the examiner arrives
- Do not unlock and browse. Opening apps marks messages read, fires deletion timers and changes application state.
- Isolate it from networks. A device that receives a remote-wipe command loses everything. NIST describes three methods, each with a drawback: airplane mode requires interacting with the device; powering off can trigger authentication that closes extraction options; a shielded container drains the battery and is not always effective.
- Preserve the passcode. Without it, extraction options narrow sharply.
- Do not update the operating system. An update can close the interface the extraction depended on.
- Preserve the cloud account too. Synced data and backups may predate the events in dispute and may hold material the device has since deleted.
What a defensible mobile examination report contains
NIST's reporting chapter and SWGDE's analysis guidance converge on the same contents:
- Identity of the examiner and the requesting party; dates of receipt and of the report.
- Each item examined, with make, model, serial number or IMEI, and its condition on receipt.
- Chain of custody from seizure to examination.
- The tool and version used, the extraction type obtained, and the hash value of the extraction so it can be verified.
- The steps taken, in enough detail that another examiner could repeat them.
- Findings keyed to specific artifacts and file paths, distinguishing live data from recovered-deleted data.
- Validation — results confirmed with a second tool or manual review where the finding matters.
- Limitations: what was not extracted, what could not be recovered, and what the data cannot show.
See what a digital forensics report contains.
When a mobile forensics expert witness is needed
A mobile forensics expert is needed whenever a phone's contents will be contested rather than stipulated: when a screenshot's authenticity or timing is disputed, when deleted messages or location history bear on a claim, when a party says a device was lost or wiped, or when the other side's examiner has drawn conclusions the artifacts cannot support. The testimony must survive Daubert, which means the examination has to have been done and documented as described above — a witness cannot fix at trial what the extraction did not record. See how to challenge the other side's forensic expert.
Law & Forensics provides digital forensics expert witness services for matters where mobile device forensics is at issue.
From our work
Primary sources
Dealing with mobile device forensics in a live matter?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
