Digital evidence
Mobile Device Forensics
Preserve and interpret the record people carry with them: messages, application data, locations, media, account activity and the gaps that matter.
The engagement
A phone is several evidence sources
A phone is not a single evidence source. It is a changing collection of device records, synchronized cloud data, application databases, media, credentials and timestamps. The useful answer rarely comes from one screenshot or one extraction report.
GDF scopes the legal or factual question first, preserves the available sources, validates acquisition results and explains what the artifacts establish and what they do not. The work is documented for counsel, another examiner and, when necessary, the court.
Scope
iPhone and iPad examination
Logical, file-system and other supported acquisitions, with device state and collection limits recorded.
Android examination
Preservation and analysis across varied manufacturers, operating systems, encryption states and application stores.
Messaging and collaboration apps
Structured review of SMS, iMessage and supported third-party application records, attachments and account context.
Location and movement artifacts
Assessment of device, application, image and network records that may support a location inference or limit its reliability.
Deleted and residual data
Recovery attempts and database-level review with a clear distinction between active, deleted, cached and reconstructed records.
Cloud and account correlation
Comparison of handset artifacts with available backups, provider exports and linked account activity.
Methodology
How the examination works
-
Triage
Stabilize the device and identify time-sensitive data, access constraints and connected accounts.
-
Preserve
Acquire the best available source without turning routine handling into an undocumented change.
-
Correlate
Test device artifacts against applications, accounts, media and other evidence sources.
-
Explain
Report observed facts separately from interpretation, including competing explanations and gaps.
Evidence commonly examined
Evidence reviewed
- Physical devices and removable media
- Device backups and provider exports
- Application databases and caches
- Images, video and embedded metadata
- Mobile-device-management records
- Account, network and location logs
What you can expect
What you receive
- Acquisition and chain-of-custody record
- Searchable artifact exports and timelines
- Technical findings with limitations
- Declarations, exhibits and testimony support
Frequently asked
Common questions
Can you recover deleted text messages?
Sometimes. Recovery depends on the device, operating system, application, encryption state, elapsed time and subsequent use. We preserve first, then state the result and its limits without promising recovery.
Can a phone prove where a person was?
A device can contain location-related artifacts, but their precision and meaning vary. We assess the source, timestamp, collection method and corroborating records before offering an inference.
Should the phone be turned off?
Do not experiment with the device. Isolation and power decisions depend on its state, encryption and the risk of remote change. Call before taking action when evidence is at risk.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189