Skip to main content
Smartphone on an antistatic mat, connected by cable to an extraction device and a laptopAI-generated

Service

Smartphone forensics

Mobile devices hold communication, location data, media files and app databases. Which of it can be extracted depends on the model, the operating system version and the state of the device.

What is examined

  • Messages, call logs and contacts, including deleted remnants in databases
  • App databases, caches and account data
  • Media files with their embedded metadata
  • Location and sensor data, backups and paired devices

How the examination is carried out

  1. 1.Selection of the extraction method appropriate to model, firmware and lock state
  2. 2.Logical, file system or physical extraction, with hashes recorded
  3. 3.Analysis of the extraction, including database records marked as deleted
  4. 4.Manual verification of automatically parsed results

Technical limits

These limits are stated before the instruction, not afterwards.

  • Modern devices are fully encrypted; without the passcode, access is often impossible.
  • The extraction depth depends on model and firmware and cannot be promised in advance.
  • Messages deleted long ago may have been removed from the database entirely.
  • Content stored only in the cloud is not part of a device extraction.

FREQUENTLY ASKED QUESTIONS

Smartphone forensics: frequently asked questions

Equipment used

Systems used in this examination

Next step

Discuss your case

Describe the situation briefly. We will say what can realistically be established, and what cannot.

+49 221 99981 490ContactBook an appointment