Mobile Forensics

Deep extraction and analysis of iOS and Android devices. Recover deleted messages, trace locations, and uncover evidence that traditional tools miss.

MJOLNIR SECURITY · DFIR SERVICES

MOBILE
FORENSICS

Every tap leaves a trace. We find them all.

🔓
0%
ANDROID
🔒
0%
iOS
MESSAGES
DELETED
LOCATIONS
DEVICES
MOBILE FORENSIC EXAMINATION LIFECYCLE
📱
DEVICE INTAKE
💾
ACQUISITION
🔓
DECODING & PARSING
🔬
EXAMINATION
🔗
CROSS-DEVICE ANALYSIS
📜
EXPERT REPORTING
DEVICE INTAKE Document device condition, serial number, IMEI, OS version. Photograph prior to acquisition. Network isolate.
Logical Extraction Coverage: 40%
App data · contacts · messages · call logs Any unlocked device
File System Extraction Coverage: 70%
Full file system including app sandboxes Jailbreak/root available
Physical Acquisition Coverage: 90%
Full partition image · unallocated space Exploit or unlock required
Chip-Off / JTAG Coverage: 98%
Direct chip access · bypasses encryption Damaged / locked devices
Cloud Acquisition Coverage: varies
iCloud · Google · Samsung · MDM extraction Credentials or consent
GrayKey / Cellebrite Coverage: 95%
Law enforcement grade · BFU/AFU unlock Supported iOS/Android build
💬 Communications
SMS · iMessage · RCS
WhatsApp · Signal · Telegram
Instagram DMs · Snapchat
Call logs · VoIP records
📍 Location History
GPS coordinates log
Significant locations (iOS)
Wi-Fi geolocation history
Cell tower triangulation
📷 Media & Files
Photo EXIF metadata
Video creation timestamps
Document access history
Cloud sync artefacts
📲 App Artefacts
Browser history · bookmarks
Banking app transaction logs
Email client local cache
Social media activity
⏱️ Device Activity
Screen-on/off events
App usage timeline
Notification history
Power cycle timestamps
🗑️ Deleted / Carved
SQLite deleted record carving
Photo vault remnants
Message deletion timestamps
Unallocated sector carving
iOS
iOS 14–18 · iPhone 11–16
Cellebrite UFED · GrayKey · AXIOM
Android
Android 10–14 · Samsung · Pixel
Cellebrite UFED · AXIOM · ADB
iPadOS
iPadOS 14–18 · all models
Same toolchain as iOS acquisition
Android MDM
Intune · JAMF · Knox enrolled
MDM API extraction · backup
Wearables
Apple Watch · Samsung Galaxy Watch
iOS/Android companion sync
RATATOSKR
BLE / RF proximity forensics
DELLING
Magnet AXIOM analysis layer
SIF
Remote mobile evidence portal
Cellebrite UFED
Industry-standard mobile acquisition
Magnet AXIOM
Cross-platform artefact parsing
GrayKey
Law enforcement iOS unlock device
Oxygen Forensics
Android / cloud acquisition suite
Axiom Cyber
Cloud + mobile unified analysis
○ IDLE
Awaiting device intake…
Forensic Examination Report
Full methodology · artefact inventory · analyst cert
Timeline Reconstruction
Unified cross-device chronology
Geolocation Report
Map overlay of device movement history
Communications Extract
Decoded messages · call log · media
Deleted Data Recovery
Carved artefacts with recovery methodology
Expert Witness Statement
Court-ready affidavit · testimony available
Criminal Investigations
Homicide · fraud · trafficking · terrorism
Civil Litigation
Employment · IP theft · contract disputes
Corporate HR
Misconduct · harassment · data theft
Insurance Fraud
Location validation · timeline dispute
Incident Response
Mobile component of enterprise breach

The Mobile Device as a Digital Witness

Mobile devices are the most personal computers people carry. They contain communications, location history, financial transactions, biometric data, photographs, and application records that can make or break an investigation. Whether the matter involves employee misconduct, intellectual property theft, fraud, harassment, or a criminal investigation, the smartphone often holds the most critical evidence.

Mjolnir Security operates a dedicated mobile forensics laboratory equipped with the latest extraction technologies from Cellebrite, GrayKey, MSAB, and Oxygen Forensics. Our examiners are trained to perform advanced extractions on the newest device models, including those with full-disk encryption, secure enclaves, and biometric locks. We handle everything from logical extractions for straightforward matters to chip-off and JTAG extractions for damaged devices.

Every examination follows forensic best practices with documented chain of custody, cryptographic hash verification, and detailed reporting that meets the evidentiary standards of Canadian and international courts.

iOS Forensics

Apple devices present unique forensic challenges due to hardware-backed encryption, the Secure Enclave Processor, and frequent operating system updates that change data storage structures. Our team maintains current capabilities across all iPhone and iPad generations:

Android Forensics

The Android ecosystem's fragmentation across manufacturers, chipsets, and OS versions requires specialized knowledge for each device family. Our examiners handle Samsung, Google Pixel, OnePlus, Huawei, and dozens of other manufacturers:

GPS & Location Analysis

Mobile devices continuously record location data through GPS, cell tower connections, Wi-Fi access point associations, and Bluetooth beacons. Our analysts reconstruct detailed location timelines that can place a device — and by extension its user — at specific locations at specific times. This analysis is invaluable for alibi verification, tracking stolen assets, or establishing patterns of behavior in harassment and stalking cases.

Deleted Data Recovery

When users delete messages, photos, or application data, the underlying data often persists in unallocated space, database write-ahead logs, or cached copies. Our recovery techniques go beyond standard tools to carve deleted artifacts from raw NAND flash images, reconstruct fragmented SQLite databases, and recover content from application-specific caches and temporary files.

Mobile Malware & Spyware Detection

We detect and analyze mobile surveillance tools including commercial spyware (NSO Pegasus, Cytrox Predator), stalkerware applications, and enterprise MDM abuse. Our analysis identifies unauthorized monitoring, data exfiltration channels, and the scope of compromised data.

📱

Advanced Extraction Lab

Equipped with Cellebrite Premium, GrayKey, MSAB XRY, and Oxygen Forensics Detective. We maintain capabilities for the latest device models and OS versions.

📍

Location Intelligence

Reconstruct precise location timelines from GPS, cell towers, Wi-Fi, and Bluetooth data. Visualize movement patterns on interactive maps for court presentations.

🔧

Damaged Device Recovery

Chip-off, JTAG, and ISP extraction techniques recover data from water-damaged, crushed, or intentionally destroyed devices when standard methods fail.

Need a Mobile Forensic Examination?

Whether it is a single device or hundreds of custodian phones, our lab is ready. Contact us to discuss your case and get a scoped engagement plan.