Zum Inhalt springen
Follow the Data, Not the Phone

For anyone who has worked in mobile forensics long enough, there was a time when getting hold of the smartphone felt like the end goal. The device was the jackpot — the place where everything lived and everything could be found.

That mental model no longer holds. And understanding why it doesn’t is one of the most practically important shifts a legal team can make when building a mobile evidence strategy.

In the third installment of the Bezüglich der Beweislage Spalte in Heutiger geschäftsführender Gesellschafter, CEO & Gründer von iDS Dan Respekt and iDS Director Bobby Williams — a forensic data testifying expert — map the evolving landscape of mobile forensics and introduce a framework that changes how investigators should think about where evidence actually lives.

The Four Axes of Mobile Data

The centrepiece of the article is a concept that reframes mobile forensics entirely: smartphones don’t have one data landscape — they have four.

There is data that resides fully on the device and can be acquired directly. There is data that exists only partially on the device — for example, only the last two weeks of email. There is data that is evidenced on the device but doesn’t actually reside there, such as browser history that references content stored elsewhere. And there is data that was never on the device at all, such as phone carrier Customer Detail Records held by the network.

Each axis may require a completely different collection approach. The implication is significant: no single tool or method captures everything, and investigators who only look at what’s directly on the device are almost certainly leaving relevant evidence behind.

The Snapchat Problem

Regard and Williams illustrate the multi-layered approach through a real-world example involving Snapchat — a platform specifically designed to be ephemeral. When a client needed specific Snapchat messages recovered, the iDS team deployed four simultaneous strategies: a physical image acquisition of the device using Cellebrite; a cloud-based collection via Oxygen Forensics using the user’s credentials; a direct extraction through Snapchat’s own “Download My Data” feature; and a search of the device’s photo library for any manually saved screenshots.

Beyond those four, the team also evaluated — and decided against — iTunes backups, connected device imaging, iCloud account backups, and app-specific iCloud syncing. The point isn’t just that multiple approaches exist. It’s that the decision about which to pursue requires deliberate case-by-case thinking, not a templated playbook.

Everything Is Subject to Change

Perhaps the most sobering note in the article is this: the data that can be acquired, and from where it can be acquired, can change on any given day. Operating system updates, application changes, user configuration, and the ongoing cat-and-mouse between forensic tool developers and device manufacturers mean that what worked last month may not work today.

That volatility demands the kind of investigative curiosity and technical adaptability that distinguishes a genuine forensic expert from someone simply running a standard process.

At iDS, this is precisely how our Digitale Forensik und Untersuchungen teams approach every mobile engagement — starting with case needs, building a bespoke plan, and following the data wherever it leads.

Um mit einem iDS-Experten in Kontakt zu treten, besuchen Sie idsinc.com.

iDS bietet beratende Datenlösungen für Unternehmen und Anwaltskanzleien auf der ganzen Welt und verschafft ihnen damit einen entscheidenden Vorteil – sowohl vor Gericht als auch außerhalb. Die Fachexperten und Datenstrategen von iDS sind darauf spezialisiert, Lösungen für komplexe Datenprobleme zu finden und sicherzustellen, dass Daten als Vermögenswert und nicht als Belastung genutzt werden können. Weitere Informationen finden Sie unter idsinc.com.


Haben Sie Schwierigkeiten mit einem in diesem Beitrag verwendeten Fachbegriff? Schauen Sie in unserem Glossar für Datenanalysten den Code zu knacken.