
You can contact our forensic team on 0221 64306610. Please tell us what your enquiry is about.
Mobile forensics – digital evidence preservation and analysis of smartphones
Smartphones and tablets are among the most information-rich pieces of evidence that may be encountered during an investigation. The key is not to extract as much data as possible from a device. Rather, it is crucial to secure the traces relevant to the evidence in a controlled manner, to evaluate them in context and to document them in a way that is transparent – including those points where a technical assessment is no longer valid.
LanCologne is a specialist consultancy with its own forensic laboratory in Cologne that examines mobile devices. As we also cover other areas of IT forensics and data recovery, mobile devices can, where necessary, be analysed in conjunction with other digital evidence, rather than being considered in isolation. Our technical expertise is underpinned by a TÜV Rheinland-certified qualification in mobile device and Windows forensics, which is publicly available in the Certipedia certificate database under certification number 0000067863.
Do you suspect your smartphone might be infected with spyware, stalkerware or malware? We carry out forensic examinations of iOS and Android devices to look for signs of compromise – using a documented procedure, verifiable findings and a clear assessment of what these findings do and do not indicate. On compromise testing

What mobile forensics can do – and what it cannot do
Mobile forensics involves the preservation, extraction, analysis and evaluation of digital information from smartphones, tablets and associated data sources. It answers technical questions: What data is present on the device? When was it created, modified or received? Can events be reconstructed? How significant are the traces found?
It does not answer any legal questions. Whether a finding is relevant to proceedings is decided by the court or the client – not the expert. Furthermore, she offers no guarantee: whether a particular piece of information can be recovered depends on the device model, operating system version, encryption, the condition of the device and its subsequent use following the incident in question.
Suspected spyware, stalkerware or malware
A significant proportion of mobile forensics enquiries begin with a suspicion: someone knows information they cannot possibly know. A device was temporarily out of the user’s control. A relationship breakdown is escalating. Or a work smartphone is behaving suspiciously following a phishing incident.
In such cases, we keep a forensic compromise assessment It is not a virus scan and does not use signatures; instead, it scans the device for traces that would be left behind by tampering or surveillance.
What is being investigated
- installed applications, their source and the permissions granted to them
- Configuration and profile settings, device management and certificates
- System and start-up artefacts, as well as mechanisms that enable them to remain on the device permanently
- Network and connection artefacts, including unusual target connections
- Diagnostic, crash and log data that may indicate unexpected process activity
- Accounts, linkings and synchronised access on connected devices
What a result tells us
We consistently distinguish between a technical Evidence, a Note, a unconfirmed suspicion and a lack of evidence. If no abnormalities are found, this does not mean that there is definitely nothing wrong – it means that no evidence could be identified using the available data and methods. We include this distinction in the report because it makes all the difference to the client’s subsequent decision.
Furthermore, attacks on mobile devices may be designed to leave as few permanent traces as possible. For this reason, too, the absence of any anomalies does not allow us to rule out the possibility with certainty – though it does provide a reliable indication of what has been checked and what has not been found.
Every stage of the investigation is documented: what was tested, using which method, with what result, and where the conclusions end. We describe the procedure in detail on the page Mobile Threat & Malware Check.
The examination procedure
Scope of the case and the question of evidence
The starting point is the question to be answered – not the device. The question to be answered determines which data sources are relevant, which backup method is suitable and what the appropriate scope of the investigation should be. A vague question leads to a vague result.
Preservation of evidence and condition of equipment
A smartphone is a dynamic system. It receives messages, synchronises accounts, logs events and cleans up databases – even when nobody is using it. Every minute that a device continues to run after the event in question can alter relevant traces.
For this reason, the device’s receipt, condition and identification are documented, and unnecessary alterations are avoided. Where the circumstances require it, we carry out the forensic examination on site, rather than transporting the device.
Extraction
Data is extracted from the secured device in a format suitable for analysis. The methods available depend on the device and its version. In the case of protected or locked devices, it may be possible to unlock or decrypt them, depending on the model, operating system version and condition. No general commitment can be inferred from this; we assess each case individually.
Analysis and Correlation
This is where the real value of the findings lies. Individual artefacts are examined in context: a database is cross-checked against system logs, a timestamp against an independent source, and a location-based artefact against the context in which it was created. Contradictions between sources are not a hindrance here, but often constitute the actual finding.
Assessment and documentation
The result is a classification that distinguishes between technically verifiable facts, professionally sound conclusions, mere suggestions and unsubstantiated assumptions – and which specifies where the validity of the statement ends.
Types of fuse
The standard procedures differ in terms of scope and requirements:
- Logical backup – accesses data provided by the operating system via defined interfaces. Widely applicable, but limited to what the system provides.
- File system-based backup – captures file system structures and, as a result, often also includes database remnants, temporary storage and ancillary structures that a logical backup does not capture.
- Device-specific procedures – advanced access rights, the availability of which depends heavily on the model, operating system version and security level.
The term „physical backup“ is used inconsistently in practice. In the case of mobile devices, it does not generally produce an unaltered bitstream image, as is the case with a conventional hard disk. We therefore only use it where it is technically accurate – and not as a quality guarantee.

iOS and Android – different starting points
The possibilities vary considerably. Treating both platforms as if they were the same is misleading.
iPhone and iPad
Apple devices are highly standardised and, at the same time, protected by hardware-based encryption and strictly controlled system access. What is accessible depends largely on the model generation, iOS version and the device’s status. The data analysed includes, amongst other things, communication data, media files and their metadata, as well as system and usage artefacts. We cover details of the platform on the page for forensic examination of iPhones.
Android
Android is highly fragmented: manufacturers, chipsets, Android versions, security patch levels and encryption status vary considerably. On the one hand, this broadens the range of possible approaches; on the other hand, the findings are less predictable than with iOS. For further details: Android Forensics in Detail.
iPhone forensics
The model generation, iOS version and device status determine the available procedures.
Android forensics
The manufacturer, chipset, version and patch status result in very different starting points.
Compromise check
Scan for traces of spyware, stalkerware and malware – with a clear classification of the findings.
iCloud Forensics
Accounts, backups and synchronised content may contain information that is missing from the device.
Key artefact fields
Messaging and communication
Messages, attachments, contacts, group and time information, as well as the associated metadata, are among the most frequently examined data. It is important to distinguish between what an app displays on the screen and what is actually stored in its data structures. A screenshot of a chat does not constitute a forensic analysis. For more information, see Messenger forensics.
App databases, SQLite, WAL and SHM
Many applications store their data in SQLite databases. In addition to the actual database file, there are often ancillary structures – in particular, the write-ahead log (WAL) and the shared memory file (SHM). These may contain entries that are no longer visible in the main database. In the case of findings relevant to evidence, we examine these structures at the raw data level, rather than relying on the processed output of a tool. See the WAL and SHM analysis.
Deleted data
There is no guarantee of recovery. Modern devices encrypt data by default; flash memory is cleared in the background; databases clean themselves up. If the relevant keys have been discarded or the relevant areas overwritten, reconstruction is technically impossible.
However, secondary traces often remain: entries in secondary database structures, cache memory, thumbnails, notification histories, backups or synchronised copies on connected devices. Conversely, the fact that a piece of information can no longer be reconstructed does not prove that it never existed.
Location and movement data
Possible sources include photo metadata, map and navigation data, app and system artefacts, as well as network and cloud-related data. Caution is advised when evaluating this evidence: a location artefact indicates device activity, not the whereabouts of a specific person. The question of who was carrying the device at the time in question is not a technical one, but a question of evidence.
Timestamps and event reconstruction
Time stamps are one of the most common sources of error. Time zones and formats vary, and the same file may contain several time values, each with a different meaning: creation, modification, receipt, dispatch, synchronisation, database entry or display. A single value is therefore rarely sufficient on its own. Where possible, we cross-reference it with independent sources – such as Android device logs.

Analysis rather than a tool report
Forensic software can back up, extract, organise and provide clues. However, the automatically generated report produced by a tool does not in itself constitute an expert interpretation.
Tools make assumptions: they categorise entries, interpret time-based data and illustrate relationships that may not necessarily hold true in individual cases. We therefore assess the plausibility of findings relevant to the evidence at the artefact and raw data levels, insofar as this is necessary and technically feasible. For a broader context, see our IT forensic expert services.
Cloud accounts and connected devices
A device rarely stands alone. Accounts, backups, synchronised content and other devices belonging to the same user may contain relevant information – sometimes even if this is no longer present on the device under investigation. Such sources are only taken into account within the scope of the investigation mandate and the existing legal and technical authorisations.
Openness regarding results, documentation and chain of custody
Investigations are conducted without preconceptions. Relevant artefacts are analysed, regardless of whether they support or contradict a working hypothesis. Even when commissioned by a party, the technical investigation remains impartial. A negative result is a technically correct finding and is stated as such.
The following are documented: receipt, condition and identification of the device; handover procedures; processing steps; the chosen security method; tools and versions used; the analysis steps; and the limitations of the investigation. Integrity or hash values are generated where technically feasible – in the case of mobile devices, this is not possible in every procedure or at every level.
Types of output: documentation, report, expert opinion
The scope depends on the assignment, the issue in dispute and the intended use:
- Technical documentation – structured processing of the backed-up and extracted data, so that the client can continue working on it themselves.
- Forensic Investigation Report – a comprehensive evaluation including findings, interpretation, significance and stated limitations.
- IT Forensic Expert Report – an expert opinion addressing a specific question of evidence, prepared for use in legal proceedings.
We will discuss which method is appropriate before the examination begins.
Who we are conducting research for
The technical investigation is the same in all scenarios; it is the typical questions that differ.
Courts require a neutral, transparent answer to a specific question of evidence. Lawyers and criminal defence lawyers often have existing test results technically reviewed. law enforcement agencies commission the securing and analysis of evidence as a supplementary expert service. The company investigate internal incidents, potential data leaks or the reconstruction of specific processes. Insurance require technical clarification of claims and the verification of digital evidence. Private individuals contact us with questions about their own devices and also require a clear explanation of the results.
Technical limitations
The scope of the investigation is limited by the device model and operating system version, security updates and encryption, the device’s lock status and condition, any data deletions and database purges, continued use following the incident in question, synchronisation processes, as well as faults and physical damage.
A key factor here is whether a device has already been unlocked once since it was last switched on. Before the first unlock, large parts of the data are encrypted and technically inaccessible; after unlocking, more sections of the data are in an unencrypted state. This difference can determine which form of investigation is even possible – and it is a reason not to restart a device unnecessarily following a relevant incident.
It is therefore not possible to guarantee completeness or success. What can be achieved in a specific case can only be reliably assessed after examining the device and the nature of the problem. If there is a physical fault or if the focus is on data recovery, it may be necessary to Data recovery the more appropriate way.
Forensic technologies and tools
Established forensic tools, as well as supplementary in-house analysis steps, are used for data acquisition, extraction and analysis. The choice of tools depends on the device, the data source and the specific issue at hand – not the other way round.
Professional competence is not determined by software ownership, partner logos or manufacturer names, but by the methodical verification of results. Tool outputs are verified where findings are relevant to the evidence and are not accepted without verification.
Frequently asked questions about mobile forensics
How does a mobile forensics investigation work?
Clarify the research question, securely back up the device, extract data, analyse and correlate artefacts, and classify and document the findings. The scope of each step depends on the research question.
How long does an examination take?
That depends on the device, the volume of data, the backup method and the scope of the investigation. We can provide a reliable estimate once we have assessed the case – it would be irresponsible to quote a fixed timeframe.
Can deleted messages be recovered?
Sometimes. Whether a reconstruction is successful depends on encryption, memory management, the passage of time and subsequent use. Secondary traces often exist in ancillary structures of databases, caches or backups. There is no guarantee.
Can a locked device be examined?
Depending on the model, operating system version and condition of the device, it may be possible to unlock or decrypt it. We will check in advance whether this applies in your specific case.
How do the iPhone and Android differ?
iOS is highly standardised and tightly secured, whilst Android is very heterogeneous. Both factors have a direct impact on the security procedures available and the predictability of the findings.
Are hash values generated?
Yes, where technically feasible. With mobile devices, not every method produces an image for which a hash value has the same significance as it does for a traditional data storage medium. We document what has been generated and what it refers to.
What is the difference between a report and an expert opinion?
An investigation report documents findings and their interpretation. An expert report, furthermore, addresses a specific question of evidence in a form suitable for legal proceedings.
Is it possible to determine whether a device has been monitored?
System, app and network artefacts can provide clues. It is possible to find evidence, but not to rule anything out with certainty: if no anomalies are found, this means that no clues could be identified using the available data.
We have compiled answers to further questions at All questions and answers on mobile forensics.
Request a mobile forensic investigation
Tell us what the issue is and the condition of the device – we’ll let you know what is and isn’t technically possible.
To help us make an initial assessment, please provide the device model, operating system version, current status (switched on, locked, damaged), whether the device is accessible, and a brief description of the issue. We cannot guarantee in advance that data extraction or recovery will be successful.