Home // BLOG // COMPUTER FORENSICS

Mobile device forensics: what can be extracted and proven

Extraction levels, deleted messages, confrontation with screenshots, and the limits honesty requires declaring.

Computer Forensics · July 15, 2026 · 8 min read

Forensic extraction of mobile devices on the laboratory bench

The cell phone has become the central archive of people's lives, and consequently the central exhibit in almost every dispute. Conversations, photos, locations, transactions, calendars: what used to be scattered across documents, witnesses, and statements is now concentrated in a device that fits in a pocket. The question that reaches the laboratory, in endless variations, is always the same: what can be extracted, and what of it counts as evidence?

The serious answer begins by separating forensic extraction from simply looking through the device. Opening the phone and photographing the screen produces a record with no verifiable integrity, which the STJ (Brazil's Superior Court of Justice) has already held inadmissible when done without method. Forensic extraction is a different operation: specialized tools acquire the device's data in a structured way, with a hash that authenticates the dataset and a report that documents the procedure. It is a type of analysis whose complexity the laboratory knows deeply: Adriano Vallim served as a Cellebrite Certified Instructor for Latin America, training the teams that operate this kind of tool.

The three levels of extraction

Not every extraction reaches the same depth, and an honest report states which level was possible. Logical extraction collects what the system agrees to hand over: contacts, messages, media, call logs. File system extraction reaches the apps' internal databases, home to structures the screen never shows. Physical extraction, when the device model allows it, copies the memory at binary level and opens the most valuable door: recovery of deleted data. What can be achieved varies with manufacturer, model, system version, and the device's condition; promising results before examining is a mark of amateurism.

The deleted data that remains

A deleted message does not always disappear. Apps like WhatsApp store their conversations in databases that do not release space immediately: deleted records remain in free areas of the database and in auxiliary files until they are overwritten. Examining these structures recovers, in a share of cases, messages the user believed eliminated, and technically demonstrates that a deletion occurred, when, and in what context. The same goes for photos, videos, and browsing records. The window, however, closes with use: each day of an active device overwrites a little of what could have been recovered. Hence the standing guidance: at the first suspicion, airplane mode and forensic examination, in that order.

"The phone examined with method tells the complete story: what exists, what was deleted, and what someone tried to make it look like. The difference lies in who asks and how."

What the examination demonstrates beyond content

The evidentiary value of an extraction goes beyond reading conversations. Metadata demonstrates when each message was sent, received, and read, from which account and on which device the database resided. Comparing the extraction against a screenshot presented by the opposing party exposes montages: a conversation that does not exist in the database, altered order, a swapped interlocutor. Location records, connected networks, and usage artifacts reconstruct movements and routines. In labor disputes, the examination demonstrates actual working hours; in fraud, the path of the scheme; in family cases, the authenticity (or not) of the dialogue on which the accusation rests.

The most requested examination: the screenshot confrontation

No demand grows as fast as this one: a printed conversation was filed in the record and the party swears it did not happen that way. The examination confronts the screenshot with the database extracted from the device, and the verdict tends to be binary. Either every message in the screenshot exists in the database, with matching sender, content, and timestamp, and the screenshot comes out strengthened; or the confrontation exposes the montage: a message that does not exist in the database, a reassembled sequence, a date incompatible with the app's installation, a contact renamed to swap the conversation's interlocutor. Image editors and fake conversation generators produce visually perfect screenshots in minutes, and that is exactly why the STJ has been treating a screen capture unaccompanied by examination as fragile evidence. The screenshot accuses; the extraction demonstrates.

Android and iPhone: what changes in practice

On Android, the diversity of manufacturers and versions creates extraction windows that vary device by device: models recently on the market can resist for months, while older devices usually allow deep extractions. On the iPhone, the closed ecosystem standardizes behavior: full extractions depend on the combination of model and system version, and the encrypted backup, when the password is known, yields a rich dataset that includes app databases. In both worlds, one constant: the sooner the device is preserved, the wider the technical window.

Limits that honesty requires declaring

There are technical and legal boundaries that no marketing changes. A third party's device is not examined without the owner's authorization or a court order: forensic work is strictly lawful, and requests outside that limit are refused. An unknown password is no trivial obstacle: the possibilities depend on model and version, and there are scenarios where access is not feasible. Content that lives only in the provider's cloud requires a judicial request through the proper channel, with attention to the retention periods of the Brazilian Internet Framework (Marco Civil da Internet): application records are kept for 6 months, connection records for 1 year. Once the period lapses, there is nothing left to request.

Custody of the device

All the value of the extraction collapses if the device's journey is not documented. The laboratory's protocol applies to the mobile device the same discipline as to any trace:

  • Receipt photographed and described, with a numbered seal;
  • Immediate network isolation: airplane mode and, when the case requires, signal-blocking packaging;
  • Documented extraction, with tool and version declared and a hash of the extracted dataset;
  • Examination performed on the extraction, never on the device in use;
  • Storage in a vault room with controlled access until return or the case's conclusion.

The cell phone is today the best-informed witness in most disputes. But a witness is only heard if it arrives at the hearing intact. Between suspicion and proof there is a technical path that admits no improvisation: preserve early, extract with method, examine with honesty about what is possible and what is not. That is the path that turns the device in the pocket into the exhibit that decides the case.

VALLIM

Adriano Vallim

Forensic expert specializing in digital crimes, working across computer forensics, handwriting and document examination, and forensic phonetics. He combines technical, academic and institutional credentials that place him among the most complete references in the field in Brazil. See the full background →

Read next

The technical evidence your case requires. The authority courts respect.

Initial feasibility consultation at no cost. Reply within 24h on business days.
Request an Examination