Mobile Investigations

Everyone Has a Phone

Today nearly every digital forensic investigation deals with evidence from cell phones and tablets, and we refer to this branch of digital investigations as "mobile forensics". Fortunately there are a number of vendors providing software and hardware tools specifically targeting the needs of mobile forensics.

Diagram mobile forensics

Software for Mobile Investigations

Blackbag block 300x200

BlackLight ● Mobilyze
● Macquisition

BlackBag Technologies

Forensics for Mac & Windows
Contact us
Oxygen forensics block 300x200

Oxygen Forensics Detective

Oxygen Forensics

Mobile and cloud forensics
Contact us
Cellebrite block 300x200

UFED

Cellebrite

Cell Phone Forensics
Contact us
Magnet black block 300x200

Axiom

Magnet Forensics

Computer and Cell Phone Forensics
Contact us

Mobile Device Acquisition

Capturing evidence from cell phones and tablets is one of the biggest hurdles in mobile forensics. Unlike a computer, it's not typically feasible or practical to create a forensic image of the mobile device's internal storage. Instead, it's generally necessary to use a specialized tool like Cellebrite's UFED to acquire data from the mobile device.

Cellebrite ufed touch

Analysis

Mobile devices have "apps" (mobile applications) and each one can generate data and artifacts that may be relevant in an investigation. Tools like those from Cellebrite and Oxygen Forensics give the investigator the ability to browse and understand data generated by a range of mobile applications.

Using Cellebrite's UFED product to view hex data is similar to the way you might work using Guidance Software's EnCase product for desktop forensic analysis.

Cellebrite ufed hex

 

Many cell phone apps store data in SQLite databases. Cellebrite's UFED product provides a convenient tool for examining these databases.

Cellebrite ufed sqlite

Decryption

Sometimes the mobile investigation is working from a backup image of the mobile device instead of data captured from the mobile device itself. Often these backups are encrypted, so decrypting them is an essential first step in the investigation. Tools like Oxygen Forensics Detective and Magnet's Axiom provide built-in support for decryption. In both cases the underlying decryption technology is provided by Passware, another leading forensics software vendor.

Oxygen encrypted backups

Jumpstart the Software Learning Curve with Digital Intelligence Training

Acquiring tools is step one. Using them effectively while sifting through complex regulatory challenges often requires a step learning curve. Let Digital Intelligence help. We offer technology, product, and process training to build the skills need to work efficiently in a changing digital landscape.

We define and conduct training based on your experience, knowledge level, and professional goals. At our training location or yours. Contact us to learn more.

Enhance Your In-House Capabilities with Digital Intelligence Forensic Services

Looking for an alternative to the traditional "buy, learn, and use" model of software ownership? Digital Intelligence Forensic Services offers price competitive options. Our skilled, certified, and in-house services staff have decades of digital forensic and eDiscovery case work experience. Contact us to learn more about our capabilities, creative service options, and collaborative approach to working for you.

Technical Support You Can Count On

When you purchase from Digital Intelligence, you’re getting the best forensic products money can buy. But the value doesn’t stop there. You get lifetime technical support and access to a professional, dedicated support team. We measure our success not just by the number of systems we sell but also by the level of support we provide. Whether it’s a question about your FRED, UltraBlock, Imager or software – or a question about a forensic problem you face – we have your back. Call, email, or text. We are here for you.

Ready to buy? Shop online in our new store!