Public records • Neutral recollection, no legal or medical advice.
Commonwealth v. ClancyInvestigation Archive • 2026
Back to documents
Forensic Psychology Standardsforensic
Source: Plymouth Superior Court filing • Public record

NIST SP 800-101r1: Guidelines on Mobile Device Forensics

1. [Introduction](#1-introduction)

Source file: download original file (1.3 MB)NIST SP 800-101r1, Mobile Forensics Guidelines (PDF)
Download & cite

NIST SP 800-101r1: Guidelines on Mobile Device Forensics

Source: National Institute of Standards and Technology (NIST)

URL: https://csrc.nist.gov/publications/detail/sp/800-101/rev-1/final

Document Type: Special Publication

Revision: 1 (r1)


Table of Contents

1. Introduction

2. Mobile Device Overview

3. Mobile Forensic Process

4. Mobile Device Data Acquisition

5. Mobile Forensic Tools

6. Mobile Device Operating Systems

7. References


1. Introduction

1.1 Purpose

This publication provides guidance on forensically examining mobile devices, including guidance on acquiring data from mobile devices, examining data, and reporting findings. It is intended to assist forensic practitioners, law enforcement, and digital investigators in conducting mobile device forensics examinations.

1.2 Scope

This document covers:

  • Mobile device fundamentals and architectures
  • Data acquisition techniques and procedures
  • Examination and analysis methodologies
  • Tool requirements and capabilities
  • Operating system-specific considerations
  • 1.3 Intended Audience

  • Digital forensic examiners
  • Law enforcement investigators
  • Incident response teams
  • IT security professionals
  • Legal professionals involved in digital evidence

  • 2. Mobile Device Overview

    2.1 Mobile Device Types

  • Smartphones: iPhone, Android devices, Windows Phone
  • Tablets: iPad, Android tablets, Windows tablets
  • Feature Phones: Basic phones with limited capabilities
  • Wearable Devices: Smartwatches, fitness trackers
  • IoT Devices: Connected devices with mobile capabilities
  • 2.2 Mobile Device Components

    Hardware Components

  • Processor: CPU and GPU for computing
  • Memory: RAM (volatile) and Flash storage (non-volatile)
  • Storage: Internal flash memory, external SD cards
  • Connectivity: Cellular, Wi-Fi, Bluetooth, NFC, GPS
  • Input/Output: Touchscreen, cameras, microphones, sensors
  • SIM Card: Subscriber Identity Module for cellular identification
  • Software Components

  • Operating System: iOS, Android, Windows Mobile, etc.
  • File System: How data is organized and stored
  • Applications: Native and third-party apps
  • User Data: Contacts, messages, photos, videos, etc.
  • 2.3 Data Types on Mobile Devices

    Volatile Data (Lost when device powers off)

  • Running processes
  • Network connections
  • Clipboard contents
  • Login sessions
  • Non-Volatile Data (Persistent storage)

  • User Data: Contacts, call logs, messages, photos, videos, documents
  • Application Data: App-specific data, databases, caches
  • System Data: Operating system files, configurations, logs
  • Network Data: Wi-Fi configurations, Bluetooth pairings
  • Location Data: GPS logs, cell tower information, Wi-Fi location data
  • 2.4 Data Storage Locations

    Internal Storage

  • Device memory (eMMC, UFS, NVMe)
  • SIM card
  • Embedded SE (Secure Element)
  • External Storage

  • SD cards
  • MicroSD cards
  • External USB storage
  • Cloud Storage

  • iCloud (Apple)
  • Google Drive (Android)
  • OneDrive (Windows)
  • Third-party cloud services

  • 3. Mobile Forensic Process

    3.1 Overview of the Forensic Process

    The mobile forensic process follows the standard digital forensic methodology:

    1. Identification: Identify potential evidence sources

    2. Preservation: Secure and protect evidence from alteration

    3. Collection: Acquire data from the device

    4. Examination: Process and extract relevant data

    5. Analysis: Interpret the extracted data

    6. Reporting: Document findings and conclusions

    3.2 Identification

    Evidence Identification Techniques

  • Visual inspection of the device
  • Check for visible damage or tampering
  • Document device make, model, and serial number
  • Photograph the device from multiple angles
  • Note any connected accessories (cases, chargers, etc.)
  • Pre-Acquisition Assessment

  • Determine device lock status (PIN, password, biometric)
  • Assess battery level and charging requirements
  • Identify potential Faraday container needs
  • Evaluate tool compatibility with device
  • 3.3 Preservation

    Physical Preservation

  • Use Faraday bags or containers to prevent remote access
  • Maintain chain of custody documentation
  • Document all handling of the device
  • Photograph evidence packaging
  • Logical Preservation

  • Document device state at time of seizure
  • Record network connections and status
  • Note any running applications
  • Capture device screenshots if possible
  • 3.4 Collection (Acquisition)

    Acquisition Levels

    1. Manual Examination: Physical interaction with device

    2. Logical Acquisition: Access through device interfaces

    3. Physical Acquisition: Bit-for-bit copy of storage

    4. Chip-Off Acquisition: Direct access to storage chip

    5. Micro Read: Examination of physical storage (advanced)

    Acquisition Methods

  • USB Connection: Direct cable connection
  • Wireless: Bluetooth, Wi-Fi (limited use)
  • JTAG: Joint Test Action Group (hardware interface)
  • Chip-Off: Physical removal and reading of storage chip
  • In-System: On-device acquisition tools
  • 3.5 Examination

    Data Extraction Techniques

  • File system analysis
  • Database parsing
  • Artifact recovery
  • Deleted data recovery
  • Encryption bypass (when possible)
  • Common Examination Procedures

    1. Mount acquired image

    2. Parse file system

    3. Extract databases

    4. Recover deleted artifacts

    5. Decode proprietary formats

    6. Search for keywords

    3.6 Analysis

    Analysis Techniques

  • Timeline analysis
  • Connection analysis
  • Location analysis
  • Communication analysis
  • Application analysis
  • Key Analysis Areas

  • Communication: Calls, texts, emails, messaging apps
  • Location: GPS data, cell tower records, Wi-Fi connections
  • Photos/Videos: Metadata, timestamps, locations
  • Internet Activity: Browsing history, downloads, searches
  • Social Media: Posts, messages, connections
  • Financial: Banking apps, payment data
  • 3.7 Reporting

    Report Components

  • Executive summary
  • Methodology description
  • Tools and techniques used
  • Findings and conclusions
  • Supporting documentation
  • Chain of custody
  • Report Best Practices

  • Use clear, concise language
  • Include screenshots and visual evidence
  • Document all procedures step-by-step
  • Maintain objectivity
  • Include limitations and caveats

  • 4. Mobile Device Data Acquisition

    4.1 Acquisition Methods Comparison

    MethodDescriptionProsCons
    **Manual**Physical interactionNo special toolsTime-consuming, may alter data
    **Logical**Interface-based accessFast, non-destructiveLimited data access
    **Physical**Bit-for-bit copyComplete dataRequires special tools
    **Chip-Off**Direct chip accessBypasses encryptionDestructive, requires expertise
    **JTAG**Hardware interfaceBypasses locksRequires technical knowledge

    4.2 Logical Acquisition

    What is Logical Acquisition?

    Logical acquisition extracts data through the device's normal interfaces (USB, Bluetooth, Wi-Fi). It provides access to user data without creating a complete physical image.

    Logical Acquisition Process

    1. Connect device via USB or wireless

    2. Authenticate with device (if required)

    3. Use forensic tool to extract data

    4. Export extracted data to examiner workstation

    5. Document all extracted data

    Data Obtainable Through Logical Acquisition

  • Contacts and call logs
  • Text messages and iMessages
  • Photos and videos
  • Calendar entries
  • Notes and reminders
  • Application data (limited)
  • Device information
  • Limitations

  • Cannot access deleted data
  • Cannot access system files
  • May be blocked by device encryption
  • Limited access to application sandboxed data
  • 4.3 Physical Acquisition

    What is Physical Acquisition?

    Physical acquisition creates a bit-for-bit copy of the device's storage, including all data, deleted files, and unallocated space.

    Physical Acquisition Process

    1. Put device in forensic mode (DFU, download mode, etc.)

    2. Connect to forensic workstation

    3. Use specialized tool to create image

    4. Verify image integrity (hash values)

    5. Store original evidence securely

    Data Obtainable Through Physical Acquisition

  • All logical acquisition data
  • Deleted files and artifacts
  • System files and logs
  • Unallocated space data
  • Encryption keys (sometimes)
  • Application sandboxes
  • Considerations

  • May require device unlocking
  • Some devices require jailbreaking/rooting
  • Time-consuming for large storage devices
  • May void manufacturer warranty
  • 4.4 Chip-Off Acquisition

    What is Chip-Off?

    Chip-off acquisition involves physically removing the storage chip from the device and reading it directly using specialized hardware.

    Chip-Off Process

    1. Disassemble device to access storage chip

    2. Remove chip using hot air station

    3. Clean chip contacts

    4. Place chip in reader/adapter

    5. Read chip using forensic hardware

    6. Create forensic image

    When to Use Chip-Off

  • Device is damaged and cannot boot
  • Encryption cannot be bypassed
  • Other acquisition methods fail
  • Need access to raw storage data
  • Risks and Considerations

  • Destructive process (device destroyed)
  • Requires specialized equipment and training
  • Risk of damaging the chip
  • May not work with all chip types
  • 4.5 JTAG Acquisition

    What is JTAG?

    JTAG (Joint Test Action Group) is a hardware interface that allows direct access to the device's processor and memory.

    JTAG Process

    1. Identify JTAG test points on device board

    2. Connect JTAG adapter to test points

    3. Use JTAG software to access memory

    4. Create forensic image

    5. Document connection points

    Advantages

  • Bypasses device locks
  • Access to raw memory
  • Can work on damaged devices
  • Disadvantages

  • Requires technical expertise
  • May not be available on all devices
  • Requires specialized hardware

  • 5. Mobile Forensic Tools

    5.1 Commercial Forensic Tools

    Cellebrite UFED

  • Manufacturer: Cellebrite
  • Capabilities: Logical, physical, chip-off acquisition
  • Supported Devices: Wide range of mobile devices
  • Features: Cloud extraction, password bypass, data analysis
  • GrayKey (Grayshift)

  • Manufacturer: Grayshift
  • Capabilities: Physical acquisition, password bypass
  • Supported Devices: Primarily iOS and Android
  • Features: Offline extraction, brute-force capabilities
  • MSAB XRY

  • Manufacturer: MSAB
  • Capabilities: Logical and physical acquisition
  • Supported Devices: Extensive device support
  • Features: Cloud extraction, encrypted device support
  • Magnet AXIOM

  • Manufacturer: Magnet Forensics
  • Capabilities: Acquisition and analysis
  • Supported Devices: Multiple platforms
  • Features: Cloud data, social media, artifact recovery
  • Oxygen Forensic Detective

  • Manufacturer: Oxygen Software
  • Capabilities: Logical and physical acquisition
  • Supported Devices: Wide range
  • Features: Cloud extraction, keylogger, data analysis
  • 5.2 Open Source Forensic Tools

    Autopsy

  • Type: Digital forensic platform
  • Capabilities: File system analysis, artifact recovery
  • Supported Platforms: Windows, Linux, macOS
  • Features: Timeline analysis, keyword search, hash lookup
  • Andriller

  • Type: Android forensic tool
  • Capabilities: Logical acquisition, data extraction
  • Supported Devices: Android devices
  • Features: Database parsing, artifact recovery
  • libimobiledevice

  • Type: iOS communication library
  • Capabilities: Device communication, data extraction
  • Supported Devices: iOS devices
  • Features: Backup creation, file access
  • stoned-step

  • Type: iOS forensics tool
  • Capabilities: DFU mode exploitation
  • Supported Devices: Older iOS devices
  • Features: Physical acquisition
  • 5.3 Tool Selection Criteria

    When selecting mobile forensic tools, consider:

    1. Device Compatibility: Does the tool support the target device?

    2. Acquisition Methods: What acquisition methods are available?

    3. Data Extraction: What data types can be extracted?

    4. Reporting: Does the tool generate court-admissible reports?

    5. Cost: What is the total cost of ownership?

    6. Training: What training is required?

    7. Support: Is vendor support available?

    8. Updates: How often is the tool updated?


    6. Mobile Device Operating Systems

    6.1 Apple iOS

    iOS Architecture

  • Kernel: XNU (hybrid kernel)
  • File System: APFS (Apple File System)
  • Security: Secure Enclave, Data Protection API
  • Encryption: AES-256 hardware encryption
  • iOS Forensic Considerations

  • Jailbreaking may be required for physical acquisition
  • Strong encryption protects data at rest
  • iCloud backups may be accessible with credentials
  • Passcode complexity affects acquisition difficulty
  • Key iOS Data Locations

  • /var/mobile/Containers/Data/Application/ - App data
  • /var/mobile/Library/ - User libraries
  • /var/db/ - System databases
  • /private/var/ - System files
  • Common iOS Artifacts

  • SMS/iMessage database (sms.db)
  • Call history (call_history.db)
  • Contacts (AddressBook.sqlitedb)
  • Photos metadata
  • Safari browsing history
  • App-specific data
  • 6.2 Google Android

    Android Architecture

  • Kernel: Linux kernel
  • File System: ext4, f2fs, EROFS
  • Security: SELinux, file-based encryption
  • Encryption: Full-disk or file-based encryption
  • Android Forensic Considerations

  • Rooting may be required for physical acquisition
  • Encryption varies by manufacturer and version
  • Google account credentials may provide cloud access
  • Manufacturer customizations affect acquisition
  • Key Android Data Locations

  • /data/data/ - App data directories
  • /data/system/ - System data
  • /sdcard/ - External storage
  • /data/misc/ - Miscellaneous data
  • Common Android Artifacts

  • SMS/MMS database
  • Call logs
  • Contacts database
  • Browser history
  • WiFi configurations
  • App-specific data
  • 6.3 Windows Mobile

    Windows Mobile Architecture

  • Kernel: Windows CE-based
  • File System: NTFS, FAT32
  • Security: Device encryption, PIN protection
  • Encryption: BitLocker (limited)
  • Windows Mobile Forensic Considerations

  • Limited market share
  • Less forensic tool support
  • Microsoft account may provide cloud access
  • Backup capabilities through Zune/Microsoft tools
  • 6.4 Feature Phones

    Feature Phone Considerations

  • Limited data storage
  • Proprietary operating systems
  • Limited forensic tool support
  • May require manufacturer-specific tools

  • 7. References

    7.1 NIST Publications

  • NIST SP 800-101r1: Guidelines on Mobile Device Forensics
  • NIST SP 800-86: Guide to Integrating Forensic Techniques into Incident Response
  • NIST SP 800-72: Guidelines on PDA Forensics
  • NIST SP 800-101: Guidelines on Mobile Device Forensics (Revision 0)
  • 7.2 Industry Standards

  • SWGDE Best Practices for Mobile Evidence
  • ASTM E2825 - Standard Guide for Forensic Digital Image Processing
  • ISO/IEC 27037:2012 - Guidelines for identification, collection, acquisition and preservation of digital evidence
  • 7.3 Academic Resources

  • Harris, R. (2006). "Arriving at an Agile Forensics Plan."
  • Breeuwsma, M. (2007). "Forensic Imaging of Embedded Systems Using JTAG Boundary-Scan."
  • Willassen, S. (2005). "Forensic Analysis of Mobile Phone Internal Memory."
  • 7.4 Web Resources

  • NIST Computer Security Resource Center: https://csrc.nist.gov
  • Mobile Forensic Science: https://www.mobileforensicscience.com
  • Forensic Focus: https://www.forensicfocus.com

  • Appendix A: Glossary

  • APFS: Apple File System
  • Chip-Off: Physical removal and reading of storage chip
  • DFU: Device Firmware Update (iOS recovery mode)
  • eMMC: Embedded Multi-Media Controller
  • Faraday Bag: Shielding container to block wireless signals
  • JTAG: Joint Test Action Group (hardware interface)
  • Logical Acquisition: Data extraction through device interfaces
  • Physical Acquisition: Bit-for-bit copy of storage
  • Rooting: Gaining root access on Android devices
  • Secure Enclave: Apple's security coprocessor
  • UFS: Universal Flash Storage

  • Appendix B: Acquisition Decision Tree

    Start
    │
    ├─ Is the device accessible?
    │  ├─ Yes → Can you unlock it?
    │  │        ├─ Yes → Use Logical or Physical Acquisition
    │  │        └─ No → Try password bypass tools
    │  │                └─ Success? → Use Logical or Physical Acquisition
    │  │                └─ Fail? → Consider Chip-Off or JTAG
    │  └─ No → Is the device physically damaged?
    │           ├─ Yes → Chip-Off or JTAG (if feasible)
    │           └─ No → Attempt recovery mode boot
    │                    └─ Success? → Use appropriate acquisition
    │                    └─ Fail? → Advanced techniques required