Home // FORENSIC UNITS // DIGITAL EVIDENCE

Forensic Extraction from Mobile Phones and Devices

Extraction and analysis of Android and iOS smartphones and tablets: messages, apps, location, media and deleted content, acquired with a method that preserves evidential value and protects every party.

The problem

A mobile phone is the central archive of anyone's life

Conversations, photos, movements, transactions, contacts: no other object concentrates as many traces as a smartphone. That is why it decides criminal, employment and family cases, as well as corporate investigations.

Yet the very device that holds the evidence destroys it just as easily: every unlock alters records, every sync overwrites data, and a single remote command can wipe everything. How the phone is accessed decides whether its content becomes evidence or a liability.

The Brazilian Superior Court of Justice (STJ) has been demanding method: in HC 943,895/PR (5th Panel, 2025), access to the phone before the forensic examination rendered the evidence unusable; in AgRg in HC 828,054/RN (5th Panel, 2024), screenshots taken directly on the device, with no extraction tool and no hash values, resulted in inadmissible evidence.

Forensic extraction exists precisely for this: to acquire the content of the device in a documented, verifiable and repeatable way, under ABNT NBR ISO/IEC 27037 and CPP, arts. 158-A to 158-F (Brazilian Code of Criminal Procedure).

From device to evidence: forensic extraction
Types of extraction

Three depths of acquisition, one and the same procedure

Logical

Logical extraction

Acquisition of live data through the system's own interfaces: contacts, calls, messages, media and accessible app data. It is the fastest and least invasive route; as a rule, it does not reach deleted content.

File system

File system extraction

Access to the partitions and to the device's internal file structure, including app databases and their internal records: this is where deleted messages still present in the databases, settings and usage artefacts typically appear.

Physical

Physical extraction

A bit-for-bit copy of the device memory, including unallocated areas: the greatest possible depth and the best chance of recovering deleted content. Feasibility depends on the make, model, operating system version and state of encryption.

The choice of method is not a preference: it is dictated by the device, by the operating system version and by the purpose of the examination. The report records which extraction was performed, with which tool and version, and what each choice does and does not reach, so that the method can be checked by either party.

The reach

What the examination usually reveals

The actual reach depends on the device and on the feasible method, but the typical repertoire includes:

Messages

Conversations and apps

WhatsApp, Telegram, Instagram, SMS and others: messages, groups, exchanged media and the apps' internal records, read directly from the device's databases.

Deleted

Deleted content

Deleted messages, photos and videos that remain in unallocated areas or in residual database records. Even partial recoveries are often enough to demonstrate that the content once existed.

Media

Photos and videos with metadata

Date, time, source device and, where enabled, the GPS coordinates written into the file (EXIF): a photo stops being merely an image and becomes a dated, located event.

Location

Movement history

GPS records, known Wi-Fi networks and data from apps that record position: geolocation triage is often the first filter applied in a case with multiple devices.

Usage

Device usage records

Calls, contacts, calendar, browsing history, installation and removal of apps: the artefacts that reconstruct the user's digital routine.

Attribution

Who actually used the device

Registered accounts, e-mail addresses, usage patterns and setup dates: the examination verifies whether the device handed over really is the one belonging to the person under investigation, including where someone attempts to present another phone as their own.

From extraction to conclusion

Timeline and link chart

Extracted data is raw; it is the analysis that turns it into an answer. Two constructs underpin most conclusions:

TimelineChronological ordering of messages, calls, media, movements and system events: what happened, in what order, and what was going on before the fact in question
LinksCorrelation between devices and accounts: with whom messages were exchanged, when and over which channel, forming the chart of relationships that guides the investigation
CoincidencesIn forensic analysis, a coincidence is a hypothesis to be tested, not a conclusion: every convergence of time, place or contact is tested against alternative explanations
CyclesForensic work proceeds in cycles: rapid triage of the essentials, deeper analysis by theme, and enrichment as the investigation raises new questions
Difficult cases

Locked, broken or passcode-less devices

Where the passcode is supplied by the owner or by whoever holds legitimate authority, extraction is the natural route. Without the passcode, the feasibility of access depends on the make, model, operating system version and condition of the device, and is assessed case by case, with no promise in advance: there are feasible scenarios, and there are scenarios in which the encryption prevails. The assessment states which scenario applies before any engagement.

A broken device is not a lost device: a dead screen, a damaged connector or a faulty board often conceal intact memory. In such cases, the recovery laboratory repairs the device until forensic extraction becomes possible, with every intervention documented. This subject has its own page: Forensic Data Recovery →

Preservation

What to do, and not to do, with the device before the examination

Most of the evidence lost on mobile phones is lost before the examination. The rules that preserve evidential value:

The guarantee the method provides

Sealed media protects even the person under investigation

At the end of the extraction, the data is written to destination media finalised as read-only, with the hash calculated at closing and a numbered seal applied. From that point on, any insertion, alteration or removal of content becomes technically detectable: the hash would no longer match.

This design protects both ends of the case. Whoever brings the accusation receives evidence that withstands any allegation of tampering; whoever is under investigation receives the assurance that nothing can be added to their device after collection. A properly conducted forensic examination is not the instrument of one party: it is the neutral ground on which the data speaks for itself.

Who this examination is for

Six typical profiles of demand

Criminal

Criminal defence lawyers

Production of evidence for the defence or the prosecution and technical review of official extractions: the experience of someone who trained the operators of the tool used by law enforcement also serves to check what was done on the case file.

Employment

Employment lawyers

Dismissal for cause, harassment, unfair competition and misuse of equipment: messages and records from the corporate or personal device, collected within legal limits.

Family

Family lawyers

Divorce, custody and parental alienation: conversations and media preserved with method, always starting from legitimate access to the device examined.

Companies

Companies and in-house legal departments

Internal investigations, sensitive dismissals, suspected breaches or fraud: the corporate device examined under a procedure that holds up if the matter reaches the courts.

Individuals

Victims of scams and digital crime

Fraud, threats, account takeover: preservation of the victim's own device as evidence, before updates and everyday use erase the traces.

Party expert

Party-appointed expert work in an official examination

Attendance at a court-ordered extraction, drafting of questions to the expert and an opinion on someone else's report: the party's technical eye inside the proceedings.

Frequently asked questions on this examination
What can be extracted from a mobile phone?
It depends on the model, the operating system and the feasible method, but the typical repertoire includes messages and media from apps, location history, photos with metadata, call records, usage data and, in many scenarios, deleted content. The feasibility assessment indicates what your case allows before any engagement.
Do deleted messages and photos come back?
Often yes, but not always: recovery depends on the space not having been overwritten, on the type of extraction that is feasible and on the protections built into the system. Partial recoveries are common and frequently sufficient to demonstrate that the content once existed. The report lists what was recovered and what was not.
Locked phone, no passcode: is the examination possible?
With the passcode of the owner or of whoever holds legitimate authority, yes. Without it, feasibility depends on the make, model, operating system version and condition of the device, and is assessed case by case, with no promise in advance. The assessment states the scenario before any charge is made for the examination.
How long does the examination take?
The acquisition itself usually takes between 2 and 8 hours, depending on the capacity of the device and the volume of data. The long stage is the analysis, proportional to the amount of information and the scope: from days to weeks, with prioritised initial triage where a procedural deadline applies.
Does extraction alter or damage the device?
The procedure is designed to preserve: the examination works on the acquired data, the device is returned, and whatever was done to it is recorded in the chain of custody. On damaged devices requiring prior repair, every physical intervention is photographed and documented.
Can someone else's phone be examined (a spouse, an employee)?
Only with proven legitimacy: the owner's consent, corporate equipment within the company's acceptable use policy, or a court order. A stated ethical refusal: no unauthorised access, no cracking of third-party passwords, no covert monitoring. That filter protects the client, the case and the evidence.

See also

WhatsApp and Conversation Examination →   Forensic Data Recovery →   Computer Forensics →   Expert Reports and Opinions →

Nationwide service

Collection anywhere in Brazil, on site or remote

The base is São Paulo; the reach is nationwide. Depending on the case, collection takes place at the laboratory, on site (an office, a company, a notary's office or a courthouse) or through an assisted remote procedure, under the same procedure of hashing and documented chain of custody.

Urgent matters

Emergency preservation

A device at risk of remote wiping, an imminent procedural deadline or evidence about to expire: urgent preservation cases receive priority triage through the business WhatsApp line, including outside the standard response flow.

The phone in your case still holds the evidence

The sooner the device is preserved, the further the examination can reach. The feasibility assessment defines the method, the expected reach and the budget before any work begins. Until then: flight mode, and nobody touches it.

Request an assessment
Representative cases

The level of work you are engaging

Before deciding, it is worth seeing what has already come through this laboratory: cases described without identifying the parties, in the format of challenge, method and result.

See all representative cases →

The technical evidence your case requires. The authority courts respect.

Initial feasibility consultation at no cost. Reply within 24h on business days.
Request an Examination