Acquiring Mobile Device Data (General Process Description)

With the forensic process, it is important to note that, with embedded systems such as smart devices, some data must be written to the device in order to communicate with it. Depending on the type of device, the data that is written will change. However, in order to follow the principles of forensics, the data that is written is documented and noted as part of the process. This process is repeatable with multiple devices and is considered forensically sound. In each section, the details of the process can be found. The methods used by the program are designed to write the minimal amount of data to the device to allow for a forensically stable data acquisition.

There are two methods of device detection: automatic detection and manual plug-in selection.

Guidance Software recommends acquiring via automatic detection. Use manual plug-in selection only in the event that the device is not detected or cannot be acquired via automatic detection.

Data acquisition usually consists of the following steps:

  1. Preparation Step: Prepare the device for working with the program. Guidance Software recommends the following:
  2. Selection Step: Go to Add Evidence > Acquire Mobile > Acquire from Device to start the Acquisition Wizard, which will guide you through the process of acquisition. The following items must be selected:
  3. Instructions Step: You can read special acquisition instructions if they are available for the selected device.
  4. Acquisition Step: The program acquires information from the device. In some cases, you might need to perform more actions with the device, such as pressing special buttons on it or entering special information. The process of acquiring the device features is displayed in the progress table.
  5. Final Step: Acquisition finishes, and you can disconnect your device from the computer.

There can be certain specifics about acquisition of different types of devices. For more information, see the description of data acquisition of the type of device you want to acquire.

Note: The program allows you to work with other data in the case during the acquisition. You can add, view, and process other evidence in the case while the device is being acquired.