Public records • Neutral recollection, no legal or medical advice.
Commonwealth v. ClancyInvestigation Archive • 2026
Back to documents
Forensic Psychology Standardsforensic
Source: Plymouth Superior Court filing • Public record

SWGDE Best Practices for Mobile Evidence

1. [Introduction](#1-introduction)

Source file: download original file (310 KB)SWGDE Best Practices for Mobile Evidence (PDF)
Download & cite

SWGDE Best Practices for Mobile Evidence

Source: Scientific Working Group on Digital Evidence (SWGDE)

URL: https://www.swgde.org/documents/published-complete-listing/

Document Type: Best Practices

Current Version: Current


Table of Contents

1. Introduction

2. Mobile Evidence Overview

3. Acquisition Methods

4. Examination Procedures

5. Analysis and Reporting

6. Tool Validation

7. Quality Assurance

8. References


1. Introduction

1.1 Purpose

This document establishes best practices for the collection, preservation, acquisition, examination, analysis, and reporting of evidence from mobile devices. These practices are designed to ensure the integrity and reliability of mobile device evidence in legal proceedings.

1.2 Scope

These best practices apply to:

  • All types of mobile devices (smartphones, tablets, wearables)
  • All operating systems (iOS, Android, Windows, etc.)
  • All acquisition methods (logical, physical, chip-off, JTAG)
  • All examination and analysis procedures
  • All reporting formats
  • 1.3 Intended Audience

  • Digital forensic examiners
  • Law enforcement personnel
  • Legal professionals
  • Quality assurance managers
  • Forensic laboratory managers
  • 1.4 Definitions

  • Acquisition: The process of creating a forensic copy of data from a mobile device
  • Chain of Custody: Documentation of evidence handling from collection to disposition
  • Examination: The process of extracting and processing data from an acquired image
  • Analysis: The interpretation of extracted data to answer investigative questions
  • Validation: The process of verifying that tools and methods produce accurate results

  • 2. Mobile Evidence Overview

    2.1 Types of Mobile Evidence

    User-Generated Data

  • Text messages (SMS/MMS)
  • Email communications
  • Contact information
  • Call logs
  • Photos and videos
  • Social media posts and messages
  • Documents and files
  • Calendar entries
  • Notes and reminders
  • Device-Generated Data

  • Location data (GPS, cell tower, Wi-Fi)
  • Network connection logs
  • Application usage logs
  • System logs
  • Battery and charging history
  • Application-Specific Data

  • Messaging apps (WhatsApp, Signal, Telegram)
  • Social media apps (Facebook, Instagram, Twitter)
  • Banking and financial apps
  • Navigation and mapping apps
  • Gaming apps
  • Cloud storage apps
  • 2.2 Data Storage Locations

    Internal Storage

  • User partition
  • System partition
  • Cache partition
  • Recovery partition
  • External Storage

  • SD cards
  • MicroSD cards
  • External USB storage
  • Cloud Storage

  • Device manufacturer cloud services
  • Third-party cloud services
  • Email servers
  • Social media servers
  • 2.3 Data Volatility

    Volatile Data (Lost when device powers off)

  • RAM contents
  • Running processes
  • Network connections
  • Clipboard data
  • Login sessions
  • Persistent Data (Survives power off)

  • User files and data
  • Application data
  • System configuration
  • Deleted files (until overwritten)
  • Database records
  • 2.4 Encryption Considerations

    Types of Encryption

  • Full-Disk Encryption (FDE): Encrypts entire storage
  • File-Based Encryption (FBE): Encrypts individual files
  • Hardware Encryption: Encryption handled by dedicated chip
  • Software Encryption: Encryption handled by operating system
  • Encryption Impact on Acquisition

  • May prevent access to data
  • May require passcode/biometric for access
  • May affect tool compatibility
  • May require specialized techniques

  • 3. Acquisition Methods

    3.1 General Acquisition Principles

    Before Acquisition

    1. Document device condition and state

    2. Photograph device from multiple angles

    3. Record device identifiers (IMEI, serial number)

    4. Note battery level and charging status

    5. Identify lock status and authentication requirements

    6. Assess Faraday containment needs

    7. Verify tool compatibility

    During Acquisition

    1. Maintain chain of custody

    2. Document all steps taken

    3. Use write-blocking when appropriate

    4. Monitor acquisition progress

    5. Handle errors appropriately

    6. Verify data integrity

    After Acquisition

    1. Calculate and record hash values

    2. Secure original evidence

    3. Store forensic images properly

    4. Document acquisition results

    5. Complete chain of custody forms

    3.2 Logical Acquisition

    Definition

    Logical acquisition extracts data through the device's normal interfaces without creating a complete physical image of the storage.

    Methods

  • USB Connection: Direct cable connection to device
  • Wireless: Bluetooth or Wi-Fi connection (limited use)
  • Backup-Based: Creating device backups and extracting data
  • Cloud-Based: Accessing data through cloud services
  • Data Obtainable

  • Contacts and call logs
  • Text messages and multimedia messages
  • Photos and videos
  • Calendar entries
  • Notes and reminders
  • Application data (limited)
  • Device information
  • Limitations

  • Cannot access deleted data
  • Cannot access system files
  • May be blocked by encryption
  • Limited application sandbox access
  • Best Practices

    1. Document connection method and tools used

    2. Record all extracted data

    3. Verify data completeness

    4. Maintain device in forensic state throughout

    5. Document any errors or issues

    3.3 Physical Acquisition

    Definition

    Physical acquisition creates a bit-for-bit copy of the device's storage, including all data, deleted files, and unallocated space.

    Methods

  • Direct Access: Using forensic tools to read storage
  • Bootloader Exploitation: Using device vulnerabilities to access storage
  • Recovery Mode: Booting device into special mode for acquisition
  • DFU Mode: Device Firmware Update mode for iOS devices
  • Data Obtainable

  • All logical acquisition data
  • Deleted files and artifacts
  • System files and logs
  • Unallocated space data
  • Encryption keys (sometimes)
  • Application sandboxes
  • Hidden partitions
  • Considerations

  • May require device unlocking
  • Some devices require jailbreaking/rooting
  • Time-consuming for large storage devices
  • May void manufacturer warranty
  • May trigger anti-forensic mechanisms
  • Best Practices

    1. Use appropriate forensic mode for device

    2. Verify acquisition integrity with hash values

    3. Document any modifications to device

    4. Preserve original evidence

    5. Test acquisition completeness

    3.4 Chip-Off Acquisition

    Definition

    Chip-off acquisition involves physically removing the storage chip from the device and reading it directly using specialized hardware.

    When to Use

  • Device is damaged and cannot boot
  • Encryption cannot be bypassed
  • Other acquisition methods fail
  • Need access to raw storage data
  • Process

    1. Disassemble device to access storage chip

    2. Identify chip type and pinout

    3. Remove chip using hot air station

    4. Clean chip contacts

    5. Place chip in reader/adapter

    6. Read chip using forensic hardware

    7. Create forensic image

    Equipment Required

  • Hot air rework station
  • Chip reader/adapter
  • Microscope or magnification
  • ESD-safe workspace
  • Forensic hardware (e.g., PC-3000 Flash)
  • Risks and Considerations

  • Destructive process (device destroyed)
  • Requires specialized equipment and training
  • Risk of damaging the chip
  • May not work with all chip types
  • May require chip-specific adapters
  • Best Practices

    1. Document chip removal process

    2. Photograph chip and device board

    3. Record chip identifiers

    4. Verify chip reading integrity

    5. Preserve removed chip as evidence

    3.5 JTAG Acquisition

    Definition

    JTAG (Joint Test Action Group) is a hardware interface that allows direct access to the device's processor and memory through test points on the circuit board.

    When to Use

  • Device is damaged but board is intact
  • Need to bypass device locks
  • Other acquisition methods fail
  • Need direct memory access
  • Process

    1. Identify JTAG test points on device board

    2. Connect JTAG adapter to test points

    3. Use JTAG software to access memory

    4. Create forensic image

    5. Document connection points

    Equipment Required

  • JTAG adapter
  • Soldering equipment
  • JTAG software
  • Oscilloscope (for debugging)
  • Documentation of test points
  • Advantages

  • Bypasses device locks
  • Access to raw memory
  • Can work on damaged devices
  • Disadvantages

  • Requires technical expertise
  • May not be available on all devices
  • Requires specialized hardware
  • Time-consuming process
  • Best Practices

    1. Document JTAG connection points

    2. Photograph connection setup

    3. Record JTAG configuration

    4. Verify image integrity

    5. Document any issues encountered


    4. Examination Procedures

    4.1 General Examination Principles

    Before Examination

    1. Verify acquisition integrity

    2. Document examination environment

    3. Prepare examination workstation

    4. Verify tool functionality

    5. Document examination plan

    During Examination

    1. Work on forensic copy, not original

    2. Document all actions taken

    3. Use validated tools and methods

    4. Handle errors appropriately

    5. Preserve evidence integrity

    After Examination

    1. Document examination results

    2. Verify data completeness

    3. Secure examination materials

    4. Complete documentation

    5. Prepare for analysis

    4.2 Data Extraction Techniques

    File System Analysis

  • Mount forensic image
  • Navigate file system structure
  • Identify user data locations
  • Locate system files
  • Identify hidden files and directories
  • Database Parsing

  • Locate application databases
  • Extract database files
  • Parse database structures
  • Extract relevant records
  • Correlate data across databases
  • Artifact Recovery

  • Identify artifact locations
  • Recover deleted artifacts
  • Reconstruct fragmented data
  • Decode proprietary formats
  • Extract metadata
  • Deleted Data Recovery

  • Scan unallocated space
  • Identify file signatures
  • Reconstruct deleted files
  • Recover partially overwritten data
  • Document recovery limitations
  • 4.3 Common Examination Areas

    Communication Analysis

  • Text messages (SMS/MMS)
  • Email communications
  • Messaging app data (WhatsApp, Signal, etc.)
  • Call logs
  • Voicemail data
  • Location Analysis

  • GPS data
  • Cell tower records
  • Wi-Fi connection data
  • Geotagged photos
  • Location history
  • Photo/Video Analysis

  • Image metadata (EXIF)
  • Video metadata
  • Thumbnail images
  • Deleted media recovery
  • Facial recognition data
  • Internet Activity Analysis

  • Browsing history
  • Downloaded files
  • Search history
  • Bookmarks
  • Form data
  • Application Analysis

  • Installed applications
  • Application data
  • Application logs
  • Application permissions
  • Background processes
  • 4.4 Data Correlation

    Timeline Analysis

  • Create chronological timeline
  • Identify patterns and sequences
  • Correlate events across data sources
  • Identify gaps in timeline
  • Verify alibis or movements
  • Connection Analysis

  • Map communication patterns
  • Identify frequent contacts
  • Analyze social networks
  • Track device connections
  • Correlate with other evidence
  • Location Correlation

  • Map location history
  • Correlate with communication data
  • Identify movement patterns
  • Verify location claims
  • Correlate with other evidence

  • 5. Analysis and Reporting

    5.1 Analysis Principles

    Objectivity

  • Maintain impartial perspective
  • Avoid confirmation bias
  • Consider alternative explanations
  • Document assumptions
  • Acknowledge limitations
  • Completeness

  • Analyze all relevant data
  • Consider all possible interpretations
  • Document analysis methods
  • Verify findings
  • Peer review when appropriate
  • Accuracy

  • Use validated tools and methods
  • Verify calculations
  • Double-check conclusions
  • Document confidence levels
  • Acknowledge uncertainties
  • 5.2 Analysis Techniques

    Statistical Analysis

  • Frequency analysis
  • Pattern recognition
  • Trend identification
  • Anomaly detection
  • Correlation analysis
  • Contextual Analysis

  • Consider device owner's behavior
  • Account for normal usage patterns
  • Consider environmental factors
  • Account for application behavior
  • Consider technical limitations
  • Comparative Analysis

  • Compare with known baselines
  • Compare with other evidence sources
  • Compare with witness statements
  • Compare with other devices
  • Compare with known patterns
  • 5.3 Report Writing

    Report Components

    Executive Summary

  • Overview of examination
  • Key findings
  • Conclusions
  • Limitations
  • Methodology

  • Acquisition method used
  • Tools and versions
  • Examination procedures
  • Analysis techniques
  • Findings

  • Detailed examination results
  • Data extraction results
  • Analysis outcomes
  • Supporting evidence
  • Conclusions

  • Interpretation of findings
  • Answers to investigative questions
  • Limitations and caveats
  • Recommendations for further investigation
  • Supporting Documentation

  • Chain of custody
  • Tool validation records
  • Hash verification
  • Screenshots and visual evidence
  • Raw data (when appropriate)
  • Report Best Practices

    1. Clarity: Use clear, concise language

    2. Objectivity: Maintain neutral tone

    3. Completeness: Include all relevant information

    4. Accuracy: Verify all facts and figures

    5. Documentation: Support all conclusions

    6. Limitations: Acknowledge any constraints

    7. Standards: Follow established formats

    8. Review: Have report peer-reviewed

    5.4 Testimony Preparation

    Courtroom Preparation

  • Review report thoroughly
  • Prepare for cross-examination
  • Anticipate challenging questions
  • Practice testimony
  • Prepare visual aids
  • Testimony Best Practices

  • Answer questions directly
  • Use clear, non-technical language
  • Acknowledge limitations
  • Maintain professional demeanor
  • Stay within expertise

  • 6. Tool Validation

    6.1 Validation Principles

    Purpose of Validation

  • Verify tool accuracy
  • Ensure reliable results
  • Meet legal requirements
  • Maintain quality standards
  • Support testimony
  • Validation Scope

  • New tools before use
  • Tool updates and versions
  • New device types
  • New acquisition methods
  • New examination techniques
  • 6.2 Validation Procedures

    Testing Methodology

    1. Define test cases

    2. Create test data sets

    3. Execute tests

    4. Document results

    5. Analyze outcomes

    6. Validate accuracy

    Test Data Requirements

  • Known data sets
  • Multiple device types
  • Various operating systems
  • Different data types
  • Edge cases and anomalies
  • Validation Documentation

  • Test procedures
  • Test results
  • Accuracy calculations
  • Limitations identified
  • Approval documentation
  • 6.3 Tool Maintenance

    Update Procedures

  • Monitor tool releases
  • Test updates before deployment
  • Document update impacts
  • Update validation records
  • Train personnel on changes
  • Version Control

  • Track tool versions
  • Document version differences
  • Maintain compatibility records
  • Update procedures as needed

  • 7. Quality Assurance

    7.1 Quality Management System

    Quality Objectives

  • Ensure accurate results
  • Maintain consistency
  • Meet legal requirements
  • Satisfy customer needs
  • Continuously improve
  • Quality Processes

  • Document control
  • Personnel training
  • Tool validation
  • Case review
  • Corrective action
  • 7.2 Personnel Qualifications

    Training Requirements

  • Initial training on tools and methods
  • Continuing education
  • Specialized training for new techniques
  • Legal training for testimony
  • Safety training
  • Competency Assessment

  • Regular competency testing
  • Proficiency testing
  • Performance evaluation
  • Peer review
  • Continuing education verification
  • 7.3 Documentation Requirements

    Case Documentation

  • Case initiation records
  • Acquisition documentation
  • Examination records
  • Analysis documentation
  • Report documentation
  • Chain of custody records
  • Laboratory Documentation

  • Standard operating procedures
  • Tool validation records
  • Training records
  • Quality control records
  • Corrective action records
  • 7.4 Quality Control Measures

    Peer Review

  • Review of examination procedures
  • Review of analysis methods
  • Review of report writing
  • Review of testimony preparation
  • Review of quality processes
  • Proficiency Testing

  • Regular proficiency testing
  • Inter-laboratory comparisons
  • Blind testing programs
  • External quality assessments
  • Continuous improvement

  • 8. References

    8.1 SWGDE Documents

  • SWGDE Best Practices for Mobile Evidence
  • SWGDE Best Practices for Computer Forensics
  • SWGDE Best Practices for Digital Evidence Collection
  • SWGDE Recommendations for Validation Testing
  • SWGDE Glossary of Terms
  • 8.2 Industry Standards

  • ASTM E2825 - Standard Guide for Forensic Digital Image Processing
  • ISO/IEC 27037:2012 - Guidelines for identification, collection, acquisition and preservation of digital evidence
  • NIST SP 800-101r1 - Guidelines on Mobile Device Forensics
  • NIST SP 800-86 - Guide to Integrating Forensic Techniques into Incident Response
  • 8.3 Legal References

  • Federal Rules of Evidence
  • Daubert Standard
  • Frye Standard
  • State-specific evidence rules
  • Case law on digital evidence
  • 8.4 Academic Resources

  • Mobile forensic science journals
  • Digital forensic research papers
  • Conference proceedings
  • Textbooks and references
  • Online resources

  • Appendix A: Glossary

  • Acquisition: The process of creating a forensic copy of data
  • Chain of Custody: Documentation of evidence handling
  • Chip-Off: Physical removal and reading of storage chip
  • DFU Mode: Device Firmware Update mode (iOS)
  • Examination: Process of extracting and processing data
  • Faraday Bag: Shielding container for wireless devices
  • Hash Value: Mathematical value for verifying data integrity
  • JTAG: Joint Test Action Group (hardware interface)
  • Logical Acquisition: Data extraction through device interfaces
  • Physical Acquisition: Bit-for-bit copy of storage
  • Rooting: Gaining root access on Android devices
  • Validation: Process of verifying tool accuracy
  • Write Blocker: Device preventing data modification

  • Appendix B: Acquisition Checklist

    Pre-Acquisition

  • [ ] Document device condition
  • [ ] Photograph device
  • [ ] Record device identifiers
  • [ ] Note battery level
  • [ ] Identify lock status
  • [ ] Assess Faraday needs
  • [ ] Verify tool compatibility
  • [ ] Prepare documentation
  • Acquisition

  • [ ] Maintain chain of custody
  • [ ] Document all steps
  • [ ] Use write-blocking
  • [ ] Monitor progress
  • [ ] Handle errors
  • [ ] Verify integrity
  • Post-Acquisition

  • [ ] Calculate hash values
  • [ ] Secure original evidence
  • [ ] Store forensic images
  • [ ] Document results
  • [ ] Complete documentation

  • Appendix C: Examination Checklist

    Pre-Examination

  • [ ] Verify acquisition integrity
  • [ ] Document examination environment
  • [ ] Prepare workstation
  • [ ] Verify tool functionality
  • [ ] Document examination plan
  • Examination

  • [ ] Work on forensic copy
  • [ ] Document all actions
  • [ ] Use validated tools
  • [ ] Handle errors
  • [ ] Preserve evidence
  • Post-Examination

  • [ ] Document results
  • [ ] Verify completeness
  • [ ] Secure materials
  • [ ] Complete documentation
  • [ ] Prepare for analysis