Forensic examination of iPhone and Android smartphones
Acquisition, preservation and analysis of a phone's content — apps, messages, photos, metadata — to reconstruct a timeline and document it in a report.
In short. A forensic examination of a smartphone means copying its content with a method that does not alter it, verifying that copy with a cryptographic hash, then searching it for relevant items and dating them: messages, files, locations, apps. What can be extracted depends on the model, the operating system, the device's condition and encryption.
Is your phone hacked or being spied on? This page covers smartphone forensics in general. If you suspect spyware, read my phone has been hacked or I think I am being watched instead.
Acquisition and preservation
The phone is copied first. Depending on the model, the operating system version and the access available, several levels of extraction are possible, from the most superficial to the most complete. The level achieved and its limits are recorded in the report.
The copy receives a SHA-256 hash and the analysis works on that copy. The phone is returned to you in the state in which you handed it over. For a device you own, the passcode allows a more complete extraction; we never examine a third party's device without a legal basis.
What the analysis can cover
Apps
Installed, deleted or hidden apps, permissions granted, configuration profiles and remote management.
Messages and calls
SMS, iMessage and messaging apps, call logs, attachments, with their timestamps.
Photos and videos
Files and their metadata: capture date, device, and location where it was recorded.
Metadata and timeline
System timestamps, usage history, connections and locations, brought together to reconstruct the order of events.
Deleted data
Deleted messages, photos or contacts can sometimes be recovered. This depends on the system, encryption and time elapsed: it is never guaranteed, and the report says so.
Before you hand the phone over
- Do not reset or restore it.
- Do not install a system update.
- Do not delete any app or message.
- Leave it switched on if possible, and call us before doing anything else.
These precautions, and those for other media, are set out in our digital evidence guide.
The examination report
The report sets out the acquisition method, the hashes, the items found with their source and timestamp, and the limits of the analysis. It is written to be understood by you, your lawyer and, where relevant, a court, which alone assesses the evidential weight of the material. See also IT forensic expertise.
How it unfolds
How a smartphone examination works
-
1
First conversation
You describe the situation and what you want to establish; we say whether an examination makes sense.
-
2
Handover
At our office in Lasne or by appointment, with a handover record.
-
3
Copy and analysis
Extraction, SHA-256 hash, then analysis on the copy. Your phone is returned to you.
-
4
Report
Signed report and a verbal explanation of the findings.
Frequently asked questions
Can deleted messages be recovered?
Sometimes. It depends on the model, the operating system version, encryption, the app used and the time since deletion. We make no promise before examining the device.
iPhone or Android: is there a difference?
Yes. The two systems store and protect data differently, which affects the extraction methods available and their reach. We state case by case what is feasible.
Will I get my phone back?
Yes, after copying. The analysis works on the copy; the device is returned in the state in which you handed it over.
A smartphone to have examined?
First conversation free and confidential. We will tell you what can be extracted from your device, and what cannot.