Independent review of the State's cell phone extraction — what the Cellebrite / UFED summary report doesn't show you.
When the prosecution images your client's phone, the report they hand over is a filtered view. We work only for the defense — re-examining the underlying extraction, recovering data where possible, and explaining what the State's summary left out. It's one focus of our broader digital forensics practice.
Law enforcement seizes the device, extracts it with a tool like Cellebrite, and produces a report built to support the prosecution's theory. It's accurate as far as it goes — but it's their selection of their findings.
An independent examiner asks a different question of the same data: what does the full record actually show? The extraction with three damaging texts often holds the surrounding conversation, the timing, the deleted context, and the metadata that change what they mean.
We're retained by the defense and report to the defense — never the prosecution. We tell you plainly when the data doesn't help your case; our job is an accurate, defensible answer, not a favorable one.
See how we present findings in our illustrative sample report, or learn more about digital forensic expert-witness work.
Depending on the device, OS version, and how the phone was handled, the following may be recoverable. Nothing here is guaranteed — we tell you what's realistic for your device before any work begins.
SMS, iMessage, RCS, and group threads — including deleted messages that may still persist in the database.
Chat and call records from app databases that the State's summary often skips entirely.
Call logs, voicemail, contacts, and the connections between numbers and identities.
Camera roll, downloaded media, and embedded metadata showing when and where a file was created.
On-device location history, Wi-Fi and cell associations, and app records that support — or contradict — a placement.
Browser history, search terms, account artifacts, and device-activity records that reconstruct what happened, and when.
Cellebrite UFED and Physical Analyzer are capable, widely used law-enforcement tools — but the report generated from an extraction is a curated subset, and the choices behind it matter.
A typical State disclosure is a PDF export — not the full extraction. Working from the
underlying extraction (the .ufd / image and its databases, not just the
printout), we see what the summary filtered out: adjacent conversations, untagged records,
native-form timestamps, and artifacts the template never surfaces.
Common gaps we look for: selective date ranges, filtered contacts or apps, content stripped of its original timestamp or time-zone, deleted material the report didn't flag, and tool interpretations presented as raw fact.
If the State produces only the report and not the extraction, that itself may be something for your motion practice — and we can help you articulate why the full extraction matters.
Not every seizure produces a complete image. Time pressure, a locked device, an unsupported model, or a shallower-tier extraction can all leave significant data uncollected.
A logical extraction — the most common, least invasive tier — pulls only what the phone's software will hand over, frequently missing deleted content, app databases, and large parts of the file system. If the State's evidence rests on one, a deeper independent examination may reach material they never collected.
A "partial extraction" noted in a report is a signal, not a dead end — it tells you the collection was incomplete, raising a fair question about what a more complete examination might change.
We assess what tier the State's extraction reached, what it typically captures, and whether a fuller examination is feasible and worthwhile for your case.
A screenshot of a text is one of the easiest pieces of "evidence" to fake — and one of the hardest for a jury to question. When the case turns on a disputed message, the source matters more than the picture.
A genuine message recovered from the device's own database carries metadata: timestamps, thread structure, sender/recipient identifiers, and a place in the conversation. A screenshot, re-typed quote, or edited image carries none of that — and the differences are detectable.
We compare the disputed item against the device data, examine the metadata and file artifacts of a screenshot or image, and report whether it matches what the device contains — and where it doesn't, explain why in plain terms.
We describe what the evidence does and does not support; we don't characterize findings beyond what the data shows, and the weight of any exhibit is for the court.
A phone that won't power on isn't automatically a phone with nothing to say. Depending on the damage and the device, recovery may still be possible.
Physical damage, liquid exposure, and storage failures range from trivially recoverable to not recoverable at all — rarely obvious which from the outside. We assess the device's condition and give a candid read on feasibility before any recovery attempt.
Locked and passcode-protected devices are a separate, evolving challenge — what's possible depends heavily on the model, OS version, and security hardware, and it changes over time. We'll tell you honestly whether access is realistic rather than promise a result we can't assure. We do not guarantee access to any locked device.
You don't need to be technical to cross-examine the State's examiner — but knowing the three tiers helps, because the tier used caps how much data the extraction can contain.
Findings only help if they hold up. Our process is built to survive cross-examination and to be understood by the people who decide the case.
We document chain of custody from the moment evidence reaches us, work from verified copies rather than originals, and record what we did and in what order — so the work is repeatable and reviewable.
Our methodology is built on established, peer-reviewable digital-forensic practice and is intended to meet the standards courts apply to expert evidence (Daubert and Frye, by jurisdiction). Where a technique is novel or contested, we say so plainly.
Reports come in two registers: a plain-English summary a judge, jury, and client can follow, and a technical appendix an opposing expert can test. See the format in our illustrative sample report.
We work routinely with public defenders and appointed counsel, and we know the work often has to clear a funding step first.
We have offices in Talent, Oregon, serving the Rogue Valley — Medford and the surrounding Jackson and Josephine County courts — and in Kahului, Hawaii, serving Maui.
Because much forensic work is performed on properly preserved copies, we also work with defense teams across the country. Devices can be shipped under documented chain of custody, and on-site acquisition arranged when needed.
Sometimes. When a message is deleted, the underlying data isn't always erased — traces can remain in the device's databases and may be recoverable. Whether they are depends on the device, the OS, and how much the phone has been used since.
We don't promise any specific message. We can assess your device and give you a realistic read on what's likely recoverable before you commit.
Yes. We're retained by criminal defense teams — including public defenders and appointed counsel — and we report to the defense, never the prosecution. Our methodology is the same regardless of who retains us.
It depends. Some work can be done from the State's report alone — reviewing what the summary included and excluded, or whether an offered exhibit matches the produced data.
But recovering deleted data or examining the device more deeply usually needs the physical device or full extraction. Tell us what you have and we'll tell you what's possible.
Both depend on the device, the tier, and what you need answered, so we scope each engagement individually rather than quote sight unseen. Where it fits, we start with a fixed-fee triage to test whether a full exam is worthwhile first.
Reach out for a free case consultation and a written scope estimate.
Tell us about the device and the State's evidence, and we'll give you a candid read on what's possible and a written scope estimate. We work only for the defense.
This page is general information about forensic services, not legal advice, and does not create an attorney–client or expert engagement. Recoverability of deleted or damaged data depends on the device and circumstances and is never guaranteed. We do not guarantee access to locked devices or any particular outcome. Cellebrite and UFED are products of their respective owners; Evntrace is independent and not affiliated with those vendors.