false
OasisLMS
Login
Catalog
Forensic Examination of Mobile Device Data
Forensic Examination of Mobile Device Data
Forensic Examination of Mobile Device Data
Back to course
[Please upgrade your browser to play this video content]
Video Transcription
Video Summary
The transcript gives a high-level overview of how mobile device data is examined in litigation and forensic investigations. It explains that mobile evidence, like other electronically stored information, may be produced in native or presentation formats, but mobile devices often involve proprietary app data and special extraction methods. A major theme is timestamps and time zones, including daylight saving changes, which are critical for building accurate timelines.<br /><br />The speaker discusses several data sources: data stored directly on the phone, mobile carrier records and call detail records, cloud backups, app provider records, and account authentication logs. These sources can reveal call history, text messages, location information, device make and model, IP addresses, and account activity. The talk emphasizes that “phone data” is often not actually stored on the phone itself, but synchronized with services like Google, Apple, Uber, or other app providers.<br /><br />The presentation also covers device identification, preservation, full file system extractions, and the importance of asking the right questions to determine what evidence is relevant. It concludes with case studies showing how deleted texts, proprietary databases, selfies with metadata, and app records can be used to reconstruct events and test claims about location, access, or tampering.
Keywords
mobile device data
forensic investigations
litigation evidence
timestamps and time zones
carrier records
cloud backups
app provider records
device extraction
metadata and call detail records
×
Please select your language
1
English