MOBILE FORENSICS

Android system logs and Logcat

Android generates numerous logs whilst in operation. These can provide information about system events, app activities and technical processes. Logcat and other system logs are therefore among the key sources of data in an IT forensic investigation.

Logcat
logd
Main, system, radio and event logs
Kernel messages
Crash and error logs
Timestamp
Process and service information
Device and system events

TECHNICAL BACKGROUND

Technical Fundamentals

Android uses several protocol sources, each of which contains different information.

Areas of forensic relevance include, amongst others:

  • Logcat
  • logd
  • Main, system, radio and event logs
  • Kernel messages
  • Crash and error logs
  • Timestamp
  • Process and service information
  • Device and system events

Availability and features vary depending on the Android version, manufacturer and device configuration.

OUR APPROACH

This is how your examination will be carried out

A transparent process – from the initial enquiry to the handover of the report.

1
Available logs are backed up and analysed using recognised IT forensic tools. Timestamps, events and system information are correlated with other artefacts in order to objectively assess technical relationships. All stages of the investigation are fully documented.
2
LanCologne produces expert reports for private individuals, as well as for companies and solicitors. Our reports have already been used in court proceedings. In some cases, we have been directly commissioned to produce IT forensic reports. Upon request, we can provide anonymised or redacted sample reports or extracts.

TYPICAL QUESTIONS

When is this analysis required?

  • Which events were logged?
  • Is it possible to trace app launches or system errors?
  • What time-related information is available?
  • What protocols are actually available?
  • How reliable are the log data?

LIMITATIONS & CONCLUSION

What you should know

Log data is often retained for only a limited period and may be lost as a result of system restarts, overwriting or system clean-ups. Not every event is logged permanently.

Android system logs often provide valuable technical insights. However, their significance only becomes apparent when they are analysed in conjunction with other evidence and supported by comprehensive forensic documentation.

CUSTOMER REVIEWS

What our customers say

4.8 out of 5 stars on Trustpilot · 54 reviews

★★★★★

“The highest standards of professionalism, prompt service and excellent communication. They made the seemingly impossible a reality. This is what genuine customer service is all about – unrivalled in Germany!”

idalein

Verified review on Trustpilot

★★★★★

“Very helpful advice, excellent responsiveness and communication. My problem was completely resolved and the lost data was recovered. I’m very satisfied and, of course, relieved!”

Layla Pankratz

Verified review on Trustpilot

★★★★★

“My problem was sorted out professionally and quickly; everyone I spoke to was always friendly, and I can still get in touch if I have any questions – I’m very grateful for that!”

a woman from Cologne

Verified review on Trustpilot

Enquire now – free initial consultation

Would you like to have Android system logs or Logcat data professionally analysed? LanCologne can assist you with an objective IT forensic analysis and comprehensive expert documentation.

FREQUENTLY ASKED QUESTIONS

Frequently Asked Questions

Click on a question to see the answer.

What is Logcat?

The central Android logging system for outputting system and app events.

Are log data stored permanently?

Not always. Many entries are overwritten after a certain period of time.

Is Logcat data admissible in court?

Depending on the issue at hand, they can provide important technical advice.

Do manufacturers differ?

Yes. The scope and content of the minutes may vary.

Could an expert report be drawn up on this matter?

Yes. The results are documented and evaluated in a transparent manner.