Digital evidence

Mobile Device Forensics

Preserve and interpret the record people carry with them: messages, application data, locations, media, account activity and the gaps that matter.

Bagged hard drive beside a forensic write blocker.

The engagement

A phone is several evidence sources

A phone is not a single evidence source. It is a changing collection of device records, synchronized cloud data, application databases, media, credentials and timestamps. The useful answer rarely comes from one screenshot or one extraction report.

GDF scopes the legal or factual question first, preserves the available sources, validates acquisition results and explains what the artifacts establish and what they do not. The work is documented for counsel, another examiner and, when necessary, the court.

Scope

  • iPhone and iPad examination

    Logical, file-system and other supported acquisitions, with device state and collection limits recorded.

  • Android examination

    Preservation and analysis across varied manufacturers, operating systems, encryption states and application stores.

  • Messaging and collaboration apps

    Structured review of SMS, iMessage and supported third-party application records, attachments and account context.

  • Location and movement artifacts

    Assessment of device, application, image and network records that may support a location inference or limit its reliability.

  • Deleted and residual data

    Recovery attempts and database-level review with a clear distinction between active, deleted, cached and reconstructed records.

  • Cloud and account correlation

    Comparison of handset artifacts with available backups, provider exports and linked account activity.

Methodology

How the examination works

  1. Triage

    Stabilize the device and identify time-sensitive data, access constraints and connected accounts.

  2. Preserve

    Acquire the best available source without turning routine handling into an undocumented change.

  3. Correlate

    Test device artifacts against applications, accounts, media and other evidence sources.

  4. Explain

    Report observed facts separately from interpretation, including competing explanations and gaps.

Evidence commonly examined

Evidence reviewed

  • Physical devices and removable media
  • Device backups and provider exports
  • Application databases and caches
  • Images, video and embedded metadata
  • Mobile-device-management records
  • Account, network and location logs

What you can expect

What you receive

  • Acquisition and chain-of-custody record
  • Searchable artifact exports and timelines
  • Technical findings with limitations
  • Declarations, exhibits and testimony support

Frequently asked

Common questions

Can you recover deleted text messages?

Sometimes. Recovery depends on the device, operating system, application, encryption state, elapsed time and subsequent use. We preserve first, then state the result and its limits without promising recovery.

Can a phone prove where a person was?

A device can contain location-related artifacts, but their precision and meaning vary. We assess the source, timestamp, collection method and corroborating records before offering an inference.

Should the phone be turned off?

Do not experiment with the device. Isolation and power decisions depend on its state, encryption and the risk of remote change. Call before taking action when evidence is at risk.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.