Mobile, Endpoint, and Forensic Collections
Forensically sound acquisition from phones, laptops, desktops, and remote devices for litigation and regulatory matters. Physical, filesystem, and logical collection methods with chain-of-custody documentation that holds up in court.
What This Solves
A significant share of business communication now happens on phones. Text messages, Signal threads, WhatsApp conversations, and calendar data from a custodian's iPhone may be the most important evidence in the matter. So may the browser history on their work laptop, or the files copied to a USB drive the night before a resignation. None of that data survives a standard IT backup, and none of it will survive a factory reset either.
Mobile and endpoint collections require speed, the right tools, and a methodology that will not be challenged at deposition. Collecting a phone using iTunes sync, or imaging a laptop by dragging files to an external drive, does not constitute forensic collection. It loses metadata, may alter timestamps, and produces no chain-of-custody record. GDF performs collections that are admissible, reproducible, and defensible, whether the device is in your client's hands, an employee's home, or in the custody of a third party.
For matters requiring full forensic device examination (not just eDiscovery collection), GDF's mobile device forensics team and computer forensics team handle deep analysis including deleted data recovery, encryption bypass where permitted, and full artifact examination.
NIST Mobile Forensics Standards
NIST Special Publication 800-101, "Guidelines on Mobile Device Forensics," defines mobile forensics as "the science of recovering digital evidence from a mobile device under forensically sound conditions using accepted methods." GDF's mobile collection practices follow the NIST SP 800-101 framework, which structures the discipline around five stages: preservation, acquisition, examination, analysis, and reporting.
The NIST framework recognizes three primary acquisition types, each appropriate for different situations. Logical acquisition extracts data through standard application programming interfaces, producing call logs, contacts, messages, and app data. Filesystem acquisition provides deeper access by extracting the device's file system directly, capturing additional data including some deleted artifacts. Physical acquisition creates a bit-for-bit image of the device's storage, the most complete method when the device and circumstances permit it. GDF selects and documents the acquisition method based on device type, operating system version, encryption status, and the specific data needed for the matter.
Devices and Platforms Covered
Mobile and endpoint forensics requires different tooling and techniques for each platform, operating system version, and device state. GDF's collection team is equipped for the full range of devices encountered in litigation:
- iOS (iPhone and iPad): Logical, advanced logical, and filesystem-level acquisitions using industry-standard tools. GDF handles current and legacy iOS versions, including devices with passcode or biometric lock, with appropriate legal authority.
- Android: Acquisition from Samsung, Google Pixel, LG, and other manufacturers. Android's fragmentation across OS versions and manufacturer customizations requires tool selection and methodology documentation on a per-device basis.
- Windows laptops and desktops: Forensic imaging using write-blocked hardware, producing verified bit-for-bit images in E01 or AFF4 format. Includes both on-site imaging and remote collection for endpoints not accessible in person.
- macOS devices: Forensic imaging with T2 and Apple Silicon security considerations addressed. GDF's analysts understand macOS artifact locations including APFS snapshots, Unified Logs, and the SQLite databases used by Apple applications.
- Tablets and specialized devices: iPad, Surface Pro, Kindle, and other tablet platforms used in business environments.
- Wearables and IoT endpoints: Apple Watch, fitness trackers, and connected devices when their location, activity, or communication data is relevant to the matter.
Remote and Agent-Based Endpoint Collection
Many litigation matters involve custodians in multiple cities or states. Flying a forensic analyst to each location is time-consuming and expensive. For endpoint collections where physical imaging is not required, GDF uses agent-based remote collection tools that extract targeted data sets from Windows and macOS devices over a secure connection, with a full audit trail of what was collected, from which device, and when.
Remote collection does not mean uncontrolled collection. GDF scopes remote collections to specific custodians, date ranges, file types, and directories. The process runs in the background without disrupting the user, and the collection agent is removed after the acquisition is complete. Every remote collection produces a log file that documents the collection parameters, items collected, and hash values for the output package.
For high-stakes matters or when the collection may be challenged, on-site forensic imaging remains the strongest methodology. GDF's responders can deploy to most U.S. locations within 24 hours.
GDF's Collection Process
Preservation and Device Isolation
Before any acquisition begins, the device is isolated from networks to prevent remote wipe commands, data synchronization, or automatic updates from altering the evidence state. For mobile devices, this means airplane mode plus a Faraday bag or a signal-blocking case. For endpoints, it means network disconnection with documentation of the disconnection event. The initial device state is photographed and logged.
Acquisition Method Selection and Execution
GDF selects the appropriate acquisition method based on device type, OS version, encryption status, and matter requirements. Logical acquisition is used where it captures the required data. Filesystem or physical acquisition is used when deeper access is warranted. For endpoint imaging, hardware write blockers prevent any writes to the original device during imaging. The acquisition is executed and hash values (MD5 and SHA-256) are computed immediately on both the original and the acquired image to confirm an exact copy.
Validation and Integrity Verification
After acquisition, GDF verifies the image or extraction by recomputing hash values and confirming they match the values recorded at time of collection. This verification step is documented in writing and becomes part of the chain-of-custody record. For mobile extractions, GDF also validates that the output contains the expected data types and that application databases are intact and parseable.
Chain of Custody Documentation
GDF generates a chain-of-custody form at the time of collection, recording the device make, model, serial number, IMEI (for phones), collection date and time, analyst name, collection method, and hash values. Any transfer of custody is documented with the same specificity. These records are maintained for the duration of the matter and provided to counsel as part of the collection package.
Examination and Data Extraction
From the verified forensic image or mobile extraction, GDF processes the data using forensic analysis tools to extract targeted data types: emails, text messages, call logs, contacts, calendar entries, documents, browsing history, application data, geolocation records, and media files. For eDiscovery purposes, the extracted data is converted into standard formats for loading into a review platform. For forensic matters, GDF performs deeper artifact analysis and reporting.
Collection Report and Expert Documentation
GDF produces a written collection report documenting the devices collected, acquisition methods used, validation results, hash values, and a chain-of-custody log. This report is suitable for disclosure to opposing counsel, for use in meet-and-confer discussions, and as the basis for expert declaration or affidavit if the collection methodology is challenged.
Evidence Integrity and Defensibility
The most common attacks on mobile and endpoint collections target three things: write contamination (was the original altered during collection?), authentication (how do you know the image is an exact copy?), and continuity (can you account for where the evidence was at every moment after collection?). GDF's process addresses all three directly.
Write-blocking hardware ensures zero writes occur to the original device during imaging. Hash verification at acquisition time and again at analysis time confirms the image matches the original, bit for bit. Chain-of-custody documentation accounts for every custody transfer from collection through delivery. GDF's analysts are prepared to testify to each of these points under oath, and have done so in federal and state court proceedings.
What GDF Delivers
- Forensic image files (E01, AFF4) or verified mobile extraction packages
- MD5 and SHA-256 hash verification records
- Signed chain-of-custody documentation for each device
- Collection report documenting methodology, acquisition type, and validation
- Extracted data in review-ready format: load files, native files, or processed output
- Expert declaration or affidavit on collection methodology, if required
- Deposition and trial testimony on collection and analysis methodology
Last reviewed and updated: April 2026
Mobile Device Collections
- iOS: logical, filesystem, physical
- Android: all major manufacturers
- SMS, MMS, iMessage, WhatsApp, Signal
- App data, location history, call logs
Endpoint Imaging
- Windows forensic imaging (E01/AFF4)
- macOS (Intel, T2, Apple Silicon)
- Hardware write-blocker protocol
- On-site and remote collection options
NIST SP 800-101 Methodology
- Preservation and isolation first
- Documented acquisition method selection
- Hash-verified integrity confirmation
- Structured examination and reporting
Forensic Support Services
- Chain-of-custody documentation
- Expert declarations and affidavits
- Deposition and trial testimony
- Collection challenge support
Mobile or Endpoint Collection Needed?
All matters are strictly confidential. GDF can deploy on-site for urgent collections or begin remote endpoint collection within hours of engagement.
Related Services
Mobile Device Forensics
Deep forensic examination of mobile devices including deleted data recovery, encryption analysis, and artifact examination for litigation, employment, and criminal matters.
Learn MoreComputer Forensics
Court-admissible forensic analysis of laptops, desktops, and servers, including deleted file recovery, user activity reconstruction, and expert testimony.
Learn MoreCloud and SaaS Collections
Direct-source collection from Microsoft 365, Google Workspace, Slack, and other cloud platforms to complement device-level collections in complex matters.
Learn MoreEvidence on a Device. Let GDF Get It Right.
From a single custodian's iPhone to a fleet of corporate laptops, GDF's forensic collections protect evidence integrity and provide the documentation your attorney needs. Contact us to discuss your matter.