What mobile phone forensics actually is
Mobile forensics is the disciplined extraction, preservation and analysis of data from smartphones and tablets so that what comes out of the device can be relied on in court. It is not data recovery, and it is not what a repair shop does. The difference is procedural: every step is recorded, every copy is hashed, and the original device is left in the state it was found.
A modern examination reaches messages and call logs, contacts, photographs and video, browsing history, location traces, application databases, health and sensor data, and a large volume of system artefacts that ordinary users never see.
Extraction methods, in plain terms
| Method | What it does | When it is used |
|---|---|---|
| Logical | Copies visible user data through the phone's own interfaces | Live records, quick preliminary reviews |
| File system | Copies the accessible file system, including some system data | Fuller picture without full physical access |
| Physical | Bit for bit image of storage, including deleted material | Serious cases where deleted content matters |
| Chip off | Reads the memory chip directly after careful removal | Damaged or otherwise unreadable devices |
Why the method matters for solicitors
The choice of method sets the ceiling on what your report can say. A logical extraction can confirm the presence of a message; it usually cannot confirm the absence of one. A physical or file system extraction can, because it reaches the databases and journals that record deletions. If you are considering the value of digital evidence to a case, ask the examiner what depth of extraction the device supports before you commit to a strategy.
How the process runs
- 01Scoping. Agreeing what the court actually needs answered, and what the extraction must reach to answer it.
- 02Preservation. Isolating the device from the network, documenting its state, and taking a forensic image.
- 03Verification. Cryptographic hashes at every stage, so any later change to the copy is provable.
- 04Analysis. Reconstructing conversations, timelines, locations and app activity from the image, never from the live device.
- 05Reporting. A CPR Part 35 compliant report that a non technical reader can follow, and that will hold up under cross examination.
What we need from the instructing party
- The specific questions in issue, framed for the tribunal.
- The device, ideally powered off, with any PIN or passcode noted separately.
- The relevant date range and the accounts or numbers of interest.
- The court deadline and whether a preliminary opinion is needed first.
Do not let anyone have a quick look at the device. Every unlock, scroll and screenshot alters the very records the examination will rely on.
Frequently asked questions
Often yes, depending on the device, the operating system version and how long ago the deletion took place. The earlier the device is preserved, the more there is to recover.
No. A properly conducted examination leaves the handset in the state it was received. All work is done on the forensic image.
A focused examination on a single device usually takes days rather than weeks, once the device and instructions are with us. Urgent work can be prioritised.
