Mobile Device Forensics

The phone in your
suspect's pocket
holds the case.

Phones carry more evidence than any other device in most investigations. Data Rescue Labs performs full-spectrum mobile forensics on iOS and Android — including the deep recovery work that most examiners cannot or will not attempt.

8,400+
Devices examined
iOS · Android
Both platforms
Secure Intake · Mobile Privileged
Two phones with cables - mobile device forensics
02 / Mobile Device Forensics
What we deliver

Six capabilities.
Every extraction method.

Whether your device is current, locked, water-damaged, or wiped — we have a proven workflow. Each capability below is available as a standalone engagement or as part of a full examination.

01
Extractions

Full file system (FFS), file-based and logical extractions of iPhones and Androids using court-validated extraction tooling. Lawful AFU (After First Unlock) and BFU (Before First Unlock) acquisition for locked devices, with every method documented for chain-of-custody integrity. Every extraction is hash-verified before analysis begins.

FFSAFUBFUSHA-256
02
Deleted Message Recovery

Recovery of deleted third-party messaging appsWhatsApp, Signal, Telegram and Messenger — including SQLCipher-encrypted databases and WAL/freelist carving that recovers data beyond standard tool output. We do not recover deleted SMS, iMessage or Snapchat — those pathways are not viable from current iOS/Android devices.

SQLiteWAL carvingSQLCipher
03
App-Specific Analysis

Deep analysis of dating apps, financial and crypto apps, ride-share, marketplace, ephemeral messaging and secure communication tools. We extract app artifacts that vendor tools ignore or misparse.

iOSAndroidCustom parsing
04
GPS & Location Reconstruction

Significant locations, frequent locations, route history and geofence-anchored activity. We correlate location data across apps, device logs and cloud artifacts to build a timeline that survives cross-examination.

Sig. LocationsGeofenceCloud corr.
05
BlackBerry Forensics

One of the few Canadian labs still performing BlackBerry chip-off acquisition. Legacy BB10 and earlier devices: NAND desolder, raw read, and reconstruction in our Faraday-shielded acquisition bay. Specialty service for historical custody, archived evidence and discovery matters where the only surviving device is a BlackBerry.

BB10 / LegacyNAND chip-offFaraday bay
06
Wearable & IoT Extractions

Extractions for Apple Watch, Wear OS, Fitbit, smart home devices and connected accessories. IoT devices often contain timestamped behavioral data — location, motion, biometrics — that phones alone cannot provide.

Apple WatchWear OSSmart home
Mobile Acquisition Workflow

How a phone reaches the courtroom.

Mobile-specific workflow — Faraday shielding from the moment the device arrives, every artifact hash-verified.

01
Faraday Receipt

Device placed in a Faraday bag at intake to prevent remote wipe. Photographed, logged, sealed under privilege.

02
FFS / BFU Extraction

licensed extraction tooling. Chip-off via NAND read when the device is locked or damaged.

03
App-Database Recovery

SQLCipher decryption, WAL frame carving, freelist recovery — the deleted-message work most vendor tools miss.

04
Mobile Evidence Report

Screenshot exhibits, app-by-app artifact tables, geofence timelines, metadata appendix — all bates-stampable.

05
Mobile Testimony

Translating BFU vs AFU, chip-off and recovered-message provenance into language a jury understands.

When you need this

Six situations that
bring clients to us.

S01
Deleted message recovery

A deleted text, photo, or message is central to a legal dispute and needs to be recovered or confirmed unrecoverable.

SQLite carving · WAL analysis · freelist recovery
S02
Employee data theft

A phone belongs to a departing employee suspected of data theft — app access logs, file transfers and cloud sync artifacts tell the story.

App artifact analysis · cloud sync · timeline
S03
Family law & infidelity

An infidelity, custody, or family-law matter requires admissible mobile evidence — location history, communications and timeline reconstruction.

Significant locations · iMessage · call logs
S04
Cryptocurrency theft

A cryptocurrency theft traces back to a compromised phone — private key exposure, clipboard hijacking, or SIM-swap artifacts recovered.

Wallet apps · SIM swap · clipboard history
S05
Locked or damaged device

A device is locked, damaged, or otherwise inaccessible by conventional means — BFU acquisition, chip-off, or ISP may still recover what's needed.

BFU · chip-off · ISP · Faraday acquisition
S06
Expert report rebuttal

An expert opposing-side report needs to be independently verified or challenged — we review methodology, tool validation and conclusions.

Methodology review · Daubert · tool validation
What we recover

Every artifact a phone leaves behind.

Eight evidence classes — recovered, parsed and presented as exhibits.

Messages
SMS · iMessage · WhatsApp
Photos & Video
EXIF · thumbnails · cached
Location History
Sig. Loc · GPS · cell tower
Call Logs
Incoming · outgoing · facetime
App Data
Plist · SQLite · keychain
Cloud Sync
iCloud · Google · backups
Browser History
URLs · downloads · search
Deleted Items
WAL · freelist · carved
Why Data Rescue Labs

Mobile is our
deepest specialty.

We routinely recover deleted Telegram, Signal and WhatsApp messages from full file system extractions — including SQLCipher-encrypted databases, WAL frames and freelist remnants — that vendor tools mark as unrecoverable.

If your case turns on what was deleted, this is the difference between a finding and a dead end. Every report is authored by a credentialed examiner, documented for Daubert scrutiny and reproducible by opposing experts.

Other labs
Data Rescue Labs
Vendor extraction output only — no deep parsing
FFS + BFU + chip-off — every method available
Locked devices returned as unexaminable
BFU acquisition attempted — most inaccessible devices examined
Encrypted databases reported as unrecoverable
SQLCipher parsed manually — WAL and freelist carving applied
Proprietary app databases marked unsupported
Custom scripts written per-app — court-validated outputs
Reports not structured for Daubert/Frye challenges
Mobile examiners admitted in BC, ON, NY, CA and federal courts
Mobile FAQ

Phone forensics, specifically.

The mobile questions we hear most often from counsel, HR and individuals across Canada.

Can deleted messages be recovered from a phone?

For third-party messaging apps — WhatsApp, Signal, Telegram and Messenger — often yes. These apps store messages in SQLite (sometimes SQLCipher-encrypted) databases. When a message is deleted, the row is usually only flagged — the data persists in the SQLite WAL (Write-Ahead Log) and freelist until the database vacuums. We carve those structures to recover deleted content.

Success rate is highest within days of deletion and drops as the device gets used. Heavy daily use speeds up the vacuum.

We do not currently offer deleted SMS, iMessage or Snapchat recovery — those vendor pathways are not viable from current iOS/Android devices.

What is BFU vs AFU extraction?

BFU (Before First Unlock): phone has been powered on but never unlocked since boot. Encryption keys are not yet derived — most user data is inaccessible.

AFU (After First Unlock): phone has been unlocked at least once since boot. Keys are in memory and full-file-system extraction is possible.

For seized devices we try to acquire AFU when possible. For locked iPhones, we use court-validated unlock tooling appropriate to the chipset.

Can you extract data from a locked iPhone in Canada?

With proper authorization, yes. We use licensed forensic tooling that exploits known vulnerabilities to bypass the lock without altering data. Success rates vary by chipset and iOS version — we tell you up front what we can and cannot recover before any work begins.

We do not jailbreak as a first step — jailbreaking modifies the device and weakens the chain of custody.

How long does WhatsApp / Signal / Telegram forensics take?

WhatsApp: deleted messages can often be recovered from the local SQLCipher database and from iCloud / Google Drive chat backups. Signal: limited recovery — sealed-sender and disappearing messages don't leave readable traces beyond their lifetime. Telegram: cloud-backed, so even "deleted" messages can sometimes be recovered from server-side artifacts if accessible.

Can a wiped Android phone be recovered?

Depends on the wipe method.

Factory reset: limited recovery — the cryptographic key is destroyed, making the data unreadable even though raw NAND blocks may persist. Full overwrite: nothing to recover.

Chip-off: in some cases, we can desolder the NAND, read it raw and recover unencrypted file fragments — but modern Android (10+) encrypts by default, so success is limited to older or unencrypted devices.

Is jailbreaking required for iPhone forensics?

No and we avoid it when possible. Jailbreaking modifies the device, weakens chain of custody and can corrupt user data. We prefer licensed forensic tooling (licensed forensic tooling) which exploits the device without modifying user-accessible storage.

Jailbreak-based extraction is a fallback for older devices when no licensed exploit is available.

Can you recover deleted photos from a phone's camera roll?

Yes — iOS keeps deleted photos in a "Recently Deleted" album for 30 days by default. Beyond that, deleted photos may persist in the Photos.sqlite WAL, in iCloud Photo Library recovery, in the camera roll's hidden cache, or in old iTunes / Finder backups. We check all sources.

Android: deleted photos can sometimes be recovered from internal storage, the trash folder, Google Photos cloud and emulated SD card slack space.