Phone examinations
Acquisitions of phones with Cellebrite UFED, MSAB XRY and MOBILedit. Recovery and review of messages, call logs, contacts, media and app data, including deleted content where the device allowed it.
Experience
Individual matters stay confidential. What follows describes the kind of work I carried out in a government digital forensics unit, not specific cases.
Acquisitions of phones with Cellebrite UFED, MSAB XRY and MOBILedit. Recovery and review of messages, call logs, contacts, media and app data, including deleted content where the device allowed it.
Forensic images of computer drives and external media with FTK Imager, verified by hash, then processed and reviewed in Magnet AXIOM.
Filtering large volumes of data by dates, file types and keywords, and correlating sources to give investigators clear leads.
Examining Android applications in a controlled emulator, observing their network traffic in Wireshark and reviewing their code when an app behaved differently than it looked.
Technical and analytical reports that explain what was found, how, and how certain it is, written for people who are not forensic specialists.
Documented handling of every exhibit and secure treatment of sensitive information, in a regulated government environment.