Mobile device forensics is the recovery and analysis of data from phones and tablets. Unlike computer forensics it cannot rely on removing storage and imaging it directly: what can be extracted depends on the device model, the operating system version, and the security state at the moment of acquisition.
Why phones are harder than computers
A laptop's drive can be removed, write-blocked and imaged. A phone's storage is soldered to the board and encrypted by a key held in dedicated hardware. There is no equivalent of attaching it to a write blocker and reading sectors.
Acquisition therefore happens through whatever interface the device exposes, and the vendor spends considerable effort narrowing those interfaces with each release. The result is that capability is a moving target: a technique that worked on a model last year may not work on the same model after an update.
What "we extracted the phone" can mean
The phrase covers outcomes that differ enormously, and the distinction matters when assessing what an extraction can and cannot show:
Logical — the data the device's own backup or sync interface will hand over. Reliable and widely available; limited to what the vendor exposes, and generally excludes deleted content.
File system — a fuller copy of the accessible file system, including application databases. Because messaging apps typically store messages in databases that retain deleted rows until compacted, this often recovers material a logical extraction misses.
Physical — a complete copy of the storage. Rare on current devices and dependent on specific vulnerabilities being available for that model and version.
An examiner should state which was obtained. "We got everything off the phone" is a claim that cannot be true for most modern devices, and it invites a cross-examination that will not go well.
The associated cloud account is often the better target
Because phones sync, a substantial portion of the relevant data frequently exists in the associated cloud account — where it may be obtainable with far less friction, and may include material the device itself has since deleted. Backups of the device stored in the cloud can also predate the events in dispute, which occasionally makes them the most valuable evidence available.
Any scoping conversation about a phone should include its cloud account, and any preservation instruction should cover both.
Handling before the examiner arrives
- Do not unlock and browse. Opening messaging apps marks messages read, triggers deletion timers on ephemeral content, and changes application state.
- Keep it powered and charged, or, where the situation calls for it, isolate it from networks. A device that receives a remote-wipe command loses everything.
- Preserve the passcode. Without it, extraction options narrow dramatically and may close entirely.
- Do not update the operating system. An update can close the exact interface an extraction depended on.
The privacy constraint is real
A phone holds a person's entire life, most of which is irrelevant to any dispute. That is precisely why courts have been receptive to protocols where a forensic neutral images the device, applies agreed search parameters, and produces only responsive material. Where a personal device is at issue, proposing that arrangement early is usually faster than litigating over whether the device can be examined at all.
From our work
Dealing with mobile device forensics in a live matter?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
