602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

Digital Forensics

Mobile & Tablet Forensics

Full file system extraction, deleted message recovery and pattern-of-life analysis from phones and tablets — documented for court.

OxygenPrimary Engine
CellebriteUFED
MagnetVeraKey
Chain of CustodyEvery Engagement
Court-ReadyBy Design

Deleted is rarely gone

A modern handset holds more evidence than any other device a person carries: messages across a dozen apps, location history, call records, app data, deleted media still resident in unallocated space. The question is almost never whether the data existed. It is whether it was acquired correctly.

Acquisition follows a documented chain from the moment the device is received, and every finding is cross-validated on a second tool before it enters a report. Screen lock bypass is performed only where authorization exists.

What we deliver

Deleted Messages & Chats

Recovery of deleted messages and encrypted chat logs across mainstream and third-party applications.

Full File System Extraction

Magnet VeraKey full file system acquisition where the device and authorization permit it.

Location & Pattern of Life

Location metadata and movement analysis assembled into a chronological timeline.

Malware & Stalkerware

YARA-based detection of malware, stalkerware and command-and-control activity on the device.

Phones hold more and give up less

A modern phone is the richest single evidence source most people carry and the hardest to acquire from. It holds messages across a dozen applications, location history, photographs with embedded metadata, health and movement data, payment records, call and contact history, application usage down to the minute, connected devices, and the cloud accounts that mirror all of it. It is also encrypted by default, updated constantly, and designed by very capable engineers specifically to resist extraction.

Both halves of that matter to a client’s expectations. Yes, the phone probably contains the answer. No, nobody can guarantee they will get it out, and the honest variable is not the examiner’s skill — it is the make, model, operating system version, security patch level, and above all the lock state of the device when it reaches us.

What determines whether extraction succeeds

Whether it is locked, and whether you have the passcode. This is the dominant factor by a wide margin. An unlocked device, or a locked device with a known passcode and lawful authority to use it, opens the widest range of options. A locked device with an unknown passcode may yield very little.

Version and patch level. Extraction capability is a moving target. Methods available for one version disappear in the next. A device left on an older version is often more accessible than a current one, which is why devices should be preserved in the state they arrive in and not updated.

Whether it is on and connected. A phone that stays online can be remotely wiped or locked. A device seized or surrendered should be isolated from the network immediately — airplane mode is not sufficient on its own; a Faraday bag or equivalent isolation is.

What kind of extraction is achievable. A logical extraction retrieves what the device will hand over through normal interfaces — messages, contacts, call logs, media. A file-system or full extraction reaches application databases, deleted records within them and system artefacts, and is materially more revealing. Which is possible depends on all of the above.

What is usually recoverable, and what is not

Usually recoverable. Messages across the platform’s own applications and many third-party ones, call and contact history, photographs and video with their embedded metadata including timestamps and, often, location, browser history and searches, application usage, device connection history, and location records the device retains itself.

Often recoverable. Deleted messages, because many applications keep their data in databases where deleted rows persist until the space is reused. Deleted photographs from a recycle area. Cached content from applications that have since been removed. Notes and drafts that were never sent.

Frequently not recoverable. Content from end-to-end encrypted applications configured to expire, where the record simply no longer exists on the device. Data from a phone that has been factory reset — the reset generally destroys the encryption key, which makes the remaining data unreadable rather than merely deleted. And anything from a locked device where no viable method exists for that model and version.

Where the device itself is a dead end, the account behind it often is not. Much of what a phone holds is mirrored to a cloud account, and that route runs through cloud extraction with the account holder’s authorisation or legal process.

Authority — the question we ask before the phone

Whose device is it, and who can lawfully authorise its examination? This gets settled before anything is connected, because getting it wrong is worse than getting nothing.

A company-owned device issued to an employee is usually examinable by the employer, subject to policy and to whatever personal material sits alongside the business data. A personally owned device used for work is a different and more constrained question. A spouse’s device is not authorised by marriage. A device belonging to another adult cannot be examined on the say-so of someone who happens to have possession of it. And a device in a criminal matter belongs in the hands of law enforcement, with the appropriate legal process.

We will ask for documented authority and we will decline where it does not exist. Investigative work in Arizona is licensed under A.R.S. Title 32, Chapter 24; Honeybadger holds Private Investigations Agency licence 1759795. Examining a device without authority is a crime and produces evidence that cannot be used — the worst of both outcomes.

How the examination is run

Documented receipt and condition, including lock state and battery. Network isolation. Extraction by the least invasive method that reaches the required data, with the method and tooling recorded. Hash verification of the extraction. Analysis against a defined question rather than a general trawl — phones contain enormous volumes of irrelevant personal material, and a proportionate examination is both cheaper and far more defensible.

Reporting presents findings with the artefacts that support them, in a form a non-technical reader can follow: conversation threads in context rather than raw database rows, timelines that align records from different applications, and a clear statement of what was not recoverable and why.

Where a matter is contested, a scoped protocol agreed between the parties in advance — search terms, date ranges, custodians, what gets produced and what stays with the examiner — avoids the fight about proportionality and is worth proposing early.

How it is priced

Extraction is quoted per device and varies with model, version and lock state — locked devices requiring advanced methods cost more and carry no guarantee, which we say before taking the work rather than after. Analysis is quoted hourly against scope. Cloud extraction and testimony are quoted separately.

Included: documented receipt and isolation, extraction, hash verification, chain of custody, and a written report. Quoted separately: locked-device attempts beyond the standard, additional devices, associated cloud accounts, expedited turnaround, and testimony.

Frequently asked questions

Can you get into a locked iPhone or Android?

Sometimes, depending on the model, the operating system version and the patch level — and never with a guarantee. Anyone who guarantees it is not describing this field. With the passcode and lawful authority, the picture is very different, which is why that question comes first.

Can you recover deleted text messages?

Often, yes. Many messaging applications store data in databases where deleted records persist until the space is reused. Messages set to expire in end-to-end encrypted applications are usually genuinely gone. The sooner the phone stops being used, the better the odds.

They factory reset the phone. Is anything left?

Usually very little of the content, because the reset generally destroys the encryption key and renders the remaining data unreadable. The reset itself is a documented event with a time, and the associated cloud account often survives it — which is frequently the better route.

Can I examine my spouse’s or employee’s phone?

Only with proper authority. Marriage does not confer it. A company-owned device is usually examinable subject to policy; a personal device used for work is more constrained. We ask for documented authority and decline without it, because an unauthorised examination is a crime and the result is unusable anyway.

What should I do with the phone right now?

Isolate it from the network so it cannot be remotely wiped — a Faraday bag or equivalent, not just airplane mode. Do not update it, do not unlock and browse it, do not charge it into a computer. Note who has had it and when, and leave it as it is.

Can you look at the phone without reading everything on it?

Yes, and in contested matters you should insist on it. A scoped protocol — search terms, date ranges, what is produced and what stays with the examiner — is more proportionate, more defensible and usually cheaper than a full review.

Who this is for

  • Law firms
  • Corporate counsel
  • HR & compliance
  • Insurers
  • Private clients
  • Family law matters
  • Criminal defense

Screen lock bypass is performed for authorized parties only. We will require written confirmation of authority before acquisition begins.

Scope your requirement

Tell us the device count, the data volume and the deadline you are working against. Chain of custody documentation is included with every engagement.