Phone logic board with memory chip being read for forensic data extraction

Mobile Forensics Hardware: From Seizure to Extraction

A phone that has been seized is evidence from the moment it is picked up. What happens to it between then and the extraction decides how much of that evidence survives. We sell a lot of the hardware that sits along that path, so this is our run through of what each piece does and where it fits in a lab. Everything mentioned here is in our Mobile Forensics section.

1. Isolate the device first

A seized phone is still a working, connected device. Left alone it can pick up new messages, sync to the cloud, update its location history or take a remote wipe command, and any of those can overwrite the data you are after.

A Faraday bag or enclosure stops all of that by blocking the radio signals, so the phone stays as it was when it was seized. Bag it early. Keep it charged where that is appropriate, and only take it out of the shielding somewhere controlled. Our Faraday Bags range runs from phone and tablet sizes up to laptops, with car key pouches too, and includes Disklabs and our own FoneFunShop bags.

Disklabs PS1 Faraday phone shield bag
Disklabs PS1 Phone Shield

2. Getting the data off: JTAG, ISP, chip-off and memory types

Most examiners start with software extraction if the phone can be powered and accessed. If that fails, because the device is locked, damaged or simply not supported, it is time to look at hardware methods. There are three main ones and they get progressively more invasive.

JTAG

JTAG talks to the processor through test access points on the board, so memory can be read without fully booting the phone. You need a box with software support for that exact model, and you need to solder very fine wires onto very small pads. Have a look at our JTAG / ISP collection along with the JTAG jigs and adapters and JTAG accessories.

ISP (in-system programming)

With ISP you connect straight to the memory chip's data lines while the chip stays on the board. Nothing gets removed, so there is less chance of physical damage. The catch is that you have to find the right test points and keep the connections stable for the whole read.

Chip-off

Chip-off means taking the memory chip off the board and reading it in a programmer, using a socket or adapter that matches the chip's package. It is usually the last resort for a badly damaged device. It needs controlled heat and clean pad preparation, plus the right adapter for the job. The kit is in our Chip-Off tools, chip-off programmers, MOORC chip-off / ISP adapters and sockets and adapters collections.

UP-828P universal chip-off programmer
UP-828P Universal Programmer

eMMC and UFS

Most phones use eMMC or UFS storage. They have different interfaces and different packages, so your reader, socket and software all have to support whichever one is in front of you. Check the chip marking and package before you start. It saves time, and it saves chips.

3. Vehicle forensics and the UP-828

Car stereos and infotainment units can hold details of connected phones, contacts, call logs and navigation history. A lot of these units keep their data on standard memory chips, which can be read with chip-off. Our Vehicle Forensics UP-828 Chip-Off Kit puts a programmer together with a set of UP-828P adapters for this kind of work. We wrote about it in more detail in Chip-off for car stereos and IVI: where the UP-828P fits.

4. Inspection and magnification

You cannot repair or read what you cannot see. Before any heat goes near a board you want to check it for corrosion, old repairs, lifted pads and damaged tracks. In JTAG and ISP work a microscope is how you find the tiny test points and check your joints are clean, and after chip removal it is how you inspect and prep the pads and look the chip over.

Put a camera on the microscope and you can photograph each stage as well, which makes writing up the job a lot easier. Our Inspection & Magnification collection has trinocular and digital microscopes, cameras, lenses and lighting, plus thermal imaging cameras.

Relife RL-M5T trinocular microscope
Relife RL-M5T Trinocular HD Microscope

5. Repairing damaged devices to get at the evidence

Not every damaged phone needs chip-off. If the fault is a failed charging circuit, a shorted component or a broken connector, the phone can sometimes be repaired far enough to boot, and then a standard extraction is possible. That is often less invasive than pulling the memory chip. It still has to be done with the data in mind, though. Keep heat away from the storage, avoid swapping parts you do not need to, and write down every step.

Our Forensic Repair Training courses teach fault finding, diagnostics and micro-soldering at the bench, so examiners and lab staff can bring dead or damaged phones back to a working state for extraction.

6. Choosing kit

No single tool covers every job. Start with the devices you actually see. The mix of phones, tablets and vehicle units should decide which programmers, adapters and boxes you buy, and a lab that gets a lot of damaged handsets will lean more on repair, ISP and chip-off, which in turn means good magnification and rework gear.

Check memory support before buying adapters or sockets, because eMMC and UFS are not interchangeable. Training matters as much as hardware. These methods can put evidence at risk, so practise on boards that are not evidence first. And think about how you will document the work, because a microscope camera and a consistent procedure make reports far easier to write.

Our advice is to get isolation sorted first, then build up inspection and soldering, and add the specialist acquisition hardware as your casework calls for it. If you are not sure what suits your lab, give us a ring and we will talk it through.

Further reading

Zurück zum Blog