Introduction
Mobile phones have become one of the most important sources of digital evidence in modern investigations.
Smartphones routinely contain communications, photographs, internet activity, location information, application data, financial records, health information, and cloud-based content.
As a result, police agencies frequently seize and examine mobile devices during criminal investigations.
A forensic examination is not simply a process of “looking through a phone.” It is a structured scientific process designed to preserve evidence, maintain integrity, and produce findings that may be presented in court.
1. Seizure of the Device
The examination process begins when investigators seize a mobile device.
Important considerations include:
- Photographing the device in situ.
- Recording the device condition.
- Documenting date, time, and location of seizure.
- Recording whether the device is powered on or off.
- Identifying connected accessories such as chargers, SIM cards, smart watches, or memory cards.
Investigators may place devices into:
- Faraday bags.
- Airplane mode.
- Shielded containers.
This prevents:
- Remote wiping.
- Remote locking.
- Synchronization with cloud services.
- Network communication.
2. Chain of Custody
Every transfer of the device is documented.
The chain of custody records:
- Who seized the phone.
- When it was transferred.
- Who examined it.
- When it was returned or stored.
Maintaining continuity ensures evidence integrity and admissibility.
3. Initial Examination
Examiners record:
- Manufacturer.
- Model.
- Serial number.
- IMEI number.
- SIM card identifiers.
- Storage capacity.
- Device condition.
Typical examples include:
- Android devices.
- iOS devices.
4. Isolation from Networks
Modern smartphones continuously communicate with:
- Mobile networks.
- Wi-Fi networks.
- Cloud services.
- Messaging platforms.
Isolation methods include:
- Airplane mode.
- Faraday bags.
- SIM removal.
- RF-shielded rooms.
This helps preserve the evidence state.
5. Device Unlocking
One of the greatest challenges is obtaining access.
Methods include:
User Cooperation
The owner voluntarily provides:
- PIN.
- Password.
- Passcode.
- Biometrics.
Forensic Exploitation
Specialized forensic tools may exploit vulnerabilities to bypass security.
Legal Powers
Some jurisdictions allow courts to compel disclosure of credentials.
Password Attacks
Investigators may attempt:
- Brute-force attacks.
- Dictionary attacks.
- Password recovery techniques.
6. Acquisition Methods
Several acquisition techniques exist.
Manual Examination
An examiner physically operates the device and photographs screens.
Advantages:
- Simple.
- Useful for locked devices.
Limitations:
- Time consuming.
- Limited evidence.
Logical Extraction
Data is obtained through operating system interfaces.
Recovered data may include:
- Contacts.
- Messages.
- Call logs.
- Photographs.
- Application data.
File System Extraction
Provides access to:
- System files.
- Application databases.
- Logs.
- Configuration files.
This often yields substantially more evidence.
Physical Extraction
A bit-for-bit copy of flash memory.
Potentially recovers:
- Deleted data.
- Unallocated space.
- Hidden information.
Modern encryption increasingly limits physical extraction capabilities.
7. Forensic Tools
Common forensic platforms include:
- Cellebrite UFED
- Magnet AXIOM
- MSAB XRY
- Oxygen Forensic Detective
These tools support:
- Data extraction.
- Parsing application data.
- Timeline analysis.
- Cloud acquisition.
- Reporting.
8. Types of Evidence Recovered
Communications
- SMS messages.
- MMS.
- Emails.
- Chat applications.
Call Data
- Incoming calls.
- Outgoing calls.
- Missed calls.
- Voicemail records.
Photographs and Videos
Images often contain metadata including:
- Date and time.
- GPS coordinates.
- Camera information.
Internet Activity
- Browser history.
- Search history.
- Cookies.
- Downloads.
Application Data
Applications may contain:
- Conversations.
- Documents.
- Usage history.
- Login information.
Location Data
Sources include:
- GPS.
- Wi-Fi databases.
- Cell tower information.
- Application location records.
9. Deleted Data Recovery
Deleted information may sometimes be recovered.
Factors affecting recovery include:
- Device model.
- Operating system.
- Encryption.
- Time elapsed.
- Device usage.
Modern smartphones use encryption that can make deleted data recovery extremely difficult.
10. Cloud Evidence
Many smartphones synchronize with cloud services.
Potential sources include:
- Backups.
- Photographs.
- Messages.
- Documents.
- Device settings.
Cloud data may be acquired using legal authority or user credentials.
11. Timeline Reconstruction
Investigators frequently build timelines showing:
- Device usage.
- Calls.
- Messages.
- Internet activity.
- Application use.
- Location events.
Multiple artefacts are correlated to determine:
- What happened.
- When it happened.
- Who may have been involved.
12. Reporting
The forensic examiner produces a report containing:
- Scope of examination.
- Methods used.
- Tools employed.
- Findings.
- Limitations.
- Supporting evidence.
Reports should remain objective and avoid speculation.
13. Court Presentation
The examiner may provide evidence in court.
Topics frequently addressed include:
- Examination methodology.
- Validation of tools.
- Integrity of evidence.
- Chain of custody.
- Interpretation of artefacts.
Courts generally place considerable importance on:
- Repeatability.
- Scientific methodology.
- Documentation.
Common Mobile Forensic Artefacts
Artefact Examples
Calls Incoming, outgoing, missed calls
Messages SMS, MMS, chat databases
Contacts Address books
Photos EXIF metadata
Location GPS records
Applications Usage databases
Internet Browser history
System Logs Device events
Cloud Data Backup records
Notifications Application alerts
Limitations of Mobile Phone Examinations
Examiners may encounter:
- Strong encryption.
- Unsupported devices.
- Damaged hardware.
- Secure messaging applications.
- Limited access permissions.
- Deleted or overwritten data.
- Cloud-only content.
A forensic examination cannot always recover everything that once existed on a device.
Conclusion
Police mobile phone examinations involve far more than simply viewing the contents of a device. Examiners use validated forensic methods to preserve evidence, acquire data, analyze artefacts, and present findings in an objective manner.
Modern examinations may reveal communications, location information, internet activity, application usage, and cloud data. However, encryption, security features, and evolving operating systems increasingly influence what can be recovered and interpreted.
About Athena Forensics
For information on our computer forensic expert services or if you require any advice or assistance please contact a member of our team on 0330 123 4448 or via email on enquiries@athenaforensics.co.uk, further details are available on our contact us page.
Our client’s confidentiality is of the utmost importance. All correspondence is treated with discretion, from initial contact to conclusion of the matter.
We are fully aware of the significance and importance of the information that they encounter and we have been accredited to ISO 9001 for 14 years.
Our premises along with our security procedures have been inspected and approved by law enforcement agencies and we do not disclose personal information to other companies or suppliers.
Our team are all security cleared and we offer non-disclosure agreements if required.
Our premises along with our security procedures have been inspected and approved by law enforcement agencies.
Athena Forensics do not disclose personal information to other companies or suppliers.