Deutsch

Digital Forensics

Mobile Forensics

A company phone holds messages, location history, credentials and documents — often more trade secrets than the associated computer. Which is why it is so frequently at the centre of an investigation.

A single mobile phone rests in a precise cradle on a dark examination surface, narrowly lit from below. The room around it stays dark.

The occasion

Typical reasons

  1. 01

    Suspected leakage of trade secrets when employees leave

  2. 02

    Loss or theft of a device with access to company data

  3. 03

    Suspected surveillance software on the devices of exposed individuals

  4. 04

    Reconstruction of communication as part of an internal investigation

  5. 05

    Examining a device as an entry point into the corporate network

The scope

What is technically possible

The scope depends heavily on device, operating system version and encryption. A logical acquisition through the device interfaces is almost always possible; a full physical acquisition only in certain constellations. We say before we start what is achievable in your specific case — and what is not. We do not make promises that depend on the device generation without checking first.

  1. 01

    Acquisition with proof of integrity through checksums

  2. 02

    Analysis of messages, call logs, calendars and contacts

  3. 03

    Installed applications, their permissions and their stored data

  4. 04

    Location data and network connections, as far as they were recorded

  5. 05

    Recovery of deleted content, as far as technically reachable

01

The frame

When the device is also used privately

Where devices are also used privately, an investigation operates under tight legal limits. We settle the scope in advance with your legal department, the data protection officer and the works council, and confine the analysis to the agreed area. Private content we come across along the way does not enter the report.

02

Admissibility

Evidentiary weight

For a result to hold up in court or in employment proceedings, the chain from device to report has to be documented without gaps: who had access when, which tools were used, which checksums prove integrity. We work to that standard from the outset — it cannot be established after the fact. For how this fits into the wider investigation, see Digital Forensics.

FAQ

Frequently asked questions

Can we simply examine an employee's company phone?

Not just like that. Even on a purely corporate device it depends on your acceptable use agreement, and as soon as private use is permitted the frame becomes considerably tighter. We settle this before acquisition with your legal department, the data protection officer and the works council. An analysis without that clearance is, in case of doubt, not usable — and creates a second problem alongside the first.

Can you recover deleted messages?

Sometimes. Whether it works depends on the device, the operating system version and how much has happened since the deletion. On modern encrypted devices the prospects are considerably poorer than they used to be. We try, but we do not promise it in advance.

What should we do with the device until you have it?

Do not switch it off, do not reset it, do not update it and do not let anyone browse around on it. Every one of those can overwrite traces. If the device is still connected and a remote wipe is a risk, talk to us before you take it off the network — the order matters here.

Will you see private messages in the process?

During technical acquisition that cannot always be separated; during analysis it can. We confine the analysis to the scope agreed in advance, and what is private does not appear in the report. The agreed scope is recorded in writing so it stays traceable later what was searched for.

How long does an investigation take?

Acquisition usually takes hours, analysis days depending on the question. A clearly bounded suspicion — the leakage of particular documents, say — is answered faster than an open search. So we scope the question beforehand.

Digital Forensics

More in this area

Malware Analysis

We take malware apart in an isolated environment and deliver concrete detection rules for your systems rather than a la…

View

Network Forensics

Network traffic reveals what has long been deleted on endpoints. We reconstruct entry, lateral movement and exfiltratio…

View

Cloud Forensics

There is no disk to image in the cloud. We secure logs, configuration states and identity data before the provider rete…

View

Behavioural Forensics

Tools change, habits persist. We analyse how an attacker operates and derive where they will start next time.

View

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.