Technical field guide
The sections below preserve the service-specific depth behind Mobile & Endpoint eDiscovery Collections, edited for the current national practice and its documented engagement model. Methods are selected for the source, authorization, system state and assigned specialty. No single tool or artifact establishes a conclusion, and legal, regulatory or certification decisions remain with the responsible authority.
What This Solves
A significant share of business communication now happens on phones. Text messages, Signal threads, WhatsApp conversations, and calendar data from a custodian's iPhone may be the most important evidence in the matter. So may the browser history on their work laptop, or the files copied to a USB drive the night before a resignation. None of that data survives a standard IT backup, and none of it will survive a factory reset either.
Mobile and endpoint collections require speed, the right tools, and a methodology that will not be challenged at deposition. Collecting a phone using iTunes sync, or imaging a laptop by dragging files to an external drive, does not constitute forensic collection. It loses metadata, may alter timestamps, and produces no chain-of-custody record. Collection methods are selected and documented for repeatability and technical review, whether the device is in your client's hands, an employee's home, or in the custody of a third party.
For matters requiring full forensic device examination (not just eDiscovery collection), GDF's mobile device forensics team and computer forensics team handle deep analysis including deleted data recovery, encryption bypass where permitted, and full artifact examination.
NIST Mobile Forensics Standards
NIST Special Publication 800-101, "Guidelines on Mobile Device Forensics," defines mobile forensics as "the science of recovering digital evidence from a mobile device under forensically sound conditions using accepted methods." GDF's mobile collection practices follow the NIST SP 800-101 framework, which structures the discipline around five stages: preservation, acquisition, examination, analysis, and reporting.
The NIST framework recognizes three primary acquisition types, each appropriate for different situations. Logical acquisition extracts data through standard application programming interfaces, producing call logs, contacts, messages, and app data. Filesystem acquisition provides deeper access by extracting the device's file system directly, capturing additional data including some deleted artifacts. Physical acquisition creates a bit-for-bit image of the device's storage, the most complete method when the device and circumstances permit it. GDF selects and documents the acquisition method based on device type, operating system version, encryption status, and the specific data needed for the matter.
Devices and Platforms Covered
Mobile and endpoint forensics requires different tooling and techniques for each platform, operating system version, and device state. GDF's collection team is equipped for the full range of devices encountered in litigation:
- iOS (iPhone and iPad): Logical, advanced logical, and filesystem-level acquisitions using industry-standard tools. GDF handles current and legacy iOS versions, including devices with passcode or biometric lock, with appropriate legal authority.
- Android: Acquisition from Samsung, Google Pixel, LG, and other manufacturers. Android's fragmentation across OS versions and manufacturer customizations requires tool selection and methodology documentation on a per-device basis.
- Windows laptops and desktops: Forensic imaging using write-blocked hardware, producing verified bit-for-bit images in E01 or AFF4 format. Includes both on-site imaging and remote collection for endpoints not accessible in person.
- macOS devices: Forensic imaging with T2 and Apple Silicon security considerations addressed. GDF's analysts understand macOS artifact locations including APFS snapshots, Unified Logs, and the SQLite databases used by Apple applications.
- Tablets and specialized devices: iPad, Surface Pro, Kindle, and other tablet platforms used in business environments.
- Wearables and IoT endpoints: Apple Watch, fitness trackers, and connected devices when their location, activity, or communication data is relevant to the matter.
Remote and Agent-Based Endpoint Collection
Many litigation matters involve custodians in multiple cities or states. Flying a forensic analyst to each location is time-consuming and expensive. For endpoint collections where physical imaging is not required, GDF uses agent-based remote collection tools that extract targeted data sets from Windows and macOS devices over a secure connection, with a full audit trail of what was collected, from which device, and when.
Remote collection does not mean uncontrolled collection. GDF scopes remote collections to specific custodians, date ranges, file types, and directories. The process runs in the background without disrupting the user, and the collection agent is removed after the acquisition is complete. Every remote collection produces a log file that documents the collection parameters, items collected, and hash values for the output package.
For high-stakes matters or when the collection may be challenged, on-site forensic imaging remains the strongest methodology. GDF's responders can deploy to most U.S. locations within 24 hours.
Evidence Integrity and Defensibility
The most common attacks on mobile and endpoint collections target three things: write contamination (was the original altered during collection?), authentication (how do you know the image is an exact copy?), and continuity (can you account for where the evidence was at every moment after collection?). GDF's process addresses all three directly.
Write-blocking hardware ensures zero writes occur to the original device during imaging. Hash verification at acquisition time and again at analysis time confirms the image matches the original, bit for bit. Chain-of-custody documentation should account for each material custody transfer from collection through delivery. When expert support is in scope, the assigned examiner can address the documented method, integrity checks and custody record.