A carrier spreadsheet can reconstruct communications, associations, and movement. It can also mislead an investigation when the examiner treats network metadata as GPS, confuses a subscriber with a user, or trusts a mapping tool more than the underlying records.
A call detail record often arrives looking deceptively simple. There is a telephone number, a date, a time, a duration, and perhaps a cell site identifier. Load the records into an analysis platform, draw a few lines between numbers, place several sectors on a map, and a compelling story appears.
That is also where the danger begins.
CDR forensics is not the act of making a spreadsheet easier to read. It is the disciplined interpretation of records created by telecommunications systems for operational and charging purposes. Those systems were not designed to answer an investigator's questions. Their fields, timestamps, identifiers, and event logic must be understood before they can support a conclusion.
The examiner's job is to separate three things that are often blended together:
- What the carrier recorded
- What the network event allows us to infer
- What the evidence cannot establish
That separation is what turns carrier data into defensible evidence.
What a Call Detail Record Actually Is
The Scientific Working Group on Digital Evidence defines a CDR as a record maintained by a service provider that captures information typically needed to bill a subscriber or debit a prepaid balance. Common fields include the date, time, duration, source identifier, destination identifier, and amount of data transferred.
A CDR is metadata. It generally does not contain the spoken words of a call, the body of a text message, or the content of an internet session. It records that a network event occurred and describes selected attributes of that event.
The term CDR is also used too loosely. A carrier production may include several distinct datasets, each answering a different question.
Subscriber records
Subscriber records may establish the account holder, service dates, billing details, and assigned telephone number. They do not establish who possessed or used the device at a particular moment.
Voice records
Voice records may identify the originating and terminating numbers, event time, duration, direction, and disposition. They do not reveal the content of the conversation or identify the people who spoke.
SMS and MMS records
Messaging records may document that a messaging event occurred, its direction, the counterpart identifier, its time, and its status. They normally do not include message content unless that content was separately retained and lawfully obtained.
Data-session records
Data records may contain session times, transferred data volume, IP information, and sometimes serving-cell data. They generally do not identify the specific application activity or content responsible for the traffic.
Historical cell-site location information
Historical CSLI may identify the cell site and sector used for a recorded network event. It does not establish the handset's exact location, route, or street address.
Cell-site lists and carrier keys
A cell-site list and carrier key may provide tower coordinates, sector orientation, field definitions, and coding rules. They do not establish the actual coverage of every sector at every location and moment.
Specialized historical location data
Specialized records may provide an estimated distance, range, or calculated location with a stated uncertainty. They should not be presented as a precise coordinate unless the methodology, confidence information, and limitations support that conclusion.
This distinction matters because a call log, a billing record, historical cell-site location information, a tower dump, and a precision geolocation return are not interchangeable. Each has a different generation process, retention period, legal posture, and level of spatial precision.
One Subscriber Can Produce Many Identities
Telephone-number analysis alone is no longer enough. A modern investigation may involve several identifiers:
- MSISDN: the telephone number associated with the service
- IMSI: the subscriber identity associated with the SIM or eSIM profile
- IMEI: the identifier associated with the mobile equipment
- ICCID: the identifier of the physical SIM or eSIM profile
- IP addresses and ports: identifiers used during data sessions, often requiring separate attribution work
- Account, billing, or platform identifiers: records that may link a network subscription to a person or organization
Not every carrier production includes every identifier, and the meaning of a field must be confirmed using the provider's documentation.
Investigators should also expect identity changes. Numbers are ported. SIMs are replaced. Devices support multiple SIMs. eSIM profiles are activated and removed. A subscriber may lend a device, share an account, use a business line, or place a SIM into another handset. A mobile virtual network operator may hold the retail account record while the host carrier holds the relevant network data.
The correct attribution question is not simply, "Whose number is this?" It is:
Which account, subscription, SIM profile, device, and person can be associated with this event, during this specific period, and what independent evidence supports each link?
That wording prevents the examiner from collapsing account ownership, device possession, and human use into a single unsupported conclusion.
Acquisition Must Be Designed Around the Question
A generic request for "phone records" is rarely sufficient. Before seeking legal process, the investigator and examiner should define the propositions the records are expected to test.
If the question concerns communication, request the appropriate incoming and outgoing voice and messaging records. If it concerns location, request historical CSLI, the historical cell-site list covering the relevant period, carrier reference material, and any available specialized location data. If it concerns device or SIM changes, request the relevant identifier history. If the subscriber uses an MVNO, determine whether records are needed from both the retail provider and the underlying network operator.
The request should consider:
- The precise date range, including a justified buffer before and after the event
- All known numbers, IMSIs, IMEIs, ICCIDs, accounts, and aliases
- Subscriber and activation history
- Voice, SMS, MMS, and data-session records, as relevant
- Originating and terminating cell-site information, when available
- The cell-site list and sector configuration applicable to the historical period
- The carrier key, legend, data dictionary, and field definitions
- Time-zone and daylight-saving rules used in each dataset
- Switch, routing, disposition, feature, and call-forwarding fields
- Specialized historical location or engineering records, when relevant and available
- Business-record certifications or affidavits required for the anticipated proceeding
Preservation should happen early. Some specialized engineering and location records may have short retention periods. In the United States, 18 U.S.C. Section 2703(f) provides a mechanism for qualifying governmental entities to require preservation while the appropriate legal authority is obtained. The exact legal process depends on the data, jurisdiction, and circumstances, so investigators should coordinate with counsel or the prosecutor rather than rely on a standard template.
A Defensible Examination Workflow
1. Preserve the production as evidence
Retain the carrier's original files, folder structure, delivery correspondence, certifications, instructions, and metadata. Record when, how, and from whom the production was received. Calculate cryptographic hashes at intake and after any controlled transfer. Conduct analysis on verified working copies.
Do not treat the converted spreadsheet as the original evidence. A PDF converted to CSV, a renamed column, a reformatted timestamp, or a software import may change values, truncate identifiers, strip leading zeros, apply scientific notation, or silently alter date interpretation.
2. Read the carrier key before reading the records
Field names are not universal. "Start time" may represent call initiation, network seizure, answer, or another billing event. "Duration" may represent connected time, rounded billing time, or session length. An incoming record may describe direction from the target's perspective or the switch's perspective.
The carrier key is part of the evidence, not optional documentation. If a field remains ambiguous, document the ambiguity and seek clarification from the provider.
3. Build a lossless normalization layer
Preserve every source field and add normalized fields beside it. Do not overwrite the source values. A useful normalized schema may include:
- Source file and source row
- Provider and record type
- Original timestamp and stated time zone
- Normalized UTC timestamp
- Display timestamp in the relevant local time zone
- Originating and terminating identifiers
- Target-relative direction
- Event status or disposition
- Reported duration and derived end time
- IMSI, IMEI, ICCID, IP address, and port, when present
- Originating and terminating cell and sector identifiers
- Tower latitude, longitude, azimuth, and beamwidth
- Transformation notes and validation status
This structure preserves traceability. Every plotted point, link, and timeline entry should lead back to a carrier file and source row.
4. Normalize time without destroying time evidence
Time errors can move an event across a crime window, an alibi, or even a date boundary. Carriers may report UTC, the device's local time, the switch's local time, a centralized provider time zone, or mixed conventions across datasets.
Record the original value, the original time-zone basis, the conversion rule, and the normalized result. Test daylight-saving transitions. Check whether the switch served more than one time zone. Compare a sample of known events with handset records, voicemail notifications, or another independent source.
Never add the reported call duration to a timestamp until the provider's definition of that timestamp and duration is understood.
5. Resolve identities across time
Create an identifier history that shows when each number, IMSI, IMEI, and subscriber relationship was active. Look for device swaps, SIM swaps, porting, shared plans, temporary numbers, and gaps in service.
Attribution should be expressed in layers:
- The carrier associated the number with an account.
- The carrier associated the subscription or SIM with a device identifier during a period.
- Independent evidence associated the device with a person.
- A particular event is consistent with, or inconsistent with, that person's known activity.
The final step normally requires corroboration beyond the CDR.
6. Validate the cell-site data
Use the historical cell-site list that matches the event period. Confirm that the CDR's cell identifiers resolve correctly. Check the latitude and longitude, sector number, azimuth, beamwidth, and any technology-specific identifiers. Include neighboring sites when assessing the network environment.
Do not assume a current tower list accurately represents a historical network. Sites are added, removed, reconfigured, renamed, and reoriented.
7. Analyze in layers
Start with direct observations before moving to inference.
Event layer: What network events were recorded, and what is their timing, direction, duration, and disposition?
Identity layer: Which numbers, subscriptions, SIMs, devices, accounts, and people can be associated, and during which periods?
Relationship layer: Which identifiers communicated, how often, in what sequence, and around which relevant events?
Temporal layer: What activity occurred before, during, and after the investigative window?
Geographic layer: Which serving sites or sectors were recorded, and what approximate areas are consistent with those connections?
Corroboration layer: Which conclusions are supported or contradicted by handset artifacts, cloud data, video, access control, financial records, vehicle data, witness accounts, or other independent sources?
Separating these layers prevents a colorful map or dense link chart from being mistaken for proof.
8. Verify the work independently
Automated tools are excellent for ingesting large productions, resolving sites, generating timelines, and visualizing relationships. They are not substitutes for validation.
Manually verify a representative sample of records from the source through normalization to the final visualization. Recalculate key time conversions. Independently plot critical sites. Check counts and totals before and after processing. Have a qualified second examiner technically review the methods, records, and conclusions.
Current SWGDE recommendations call for documented, reproducible analysis, manual verification or validation through another methodology, and technical review of the completed work.
A Cell Sector Is Not a Location Pin
Historical cell-site analysis is powerful because it can place a device within an approximate geographic area at a relevant time. Its strength disappears when that conclusion is overstated.
A handset does not always connect to the geographically closest tower. Cell selection may be influenced by radio conditions, antenna orientation, terrain, buildings, network load, interference, maintenance, technology, and provider configuration. Sector coverage is not a perfect wedge, and the lines drawn from an azimuth and beamwidth do not represent hard geographic boundaries.
Accordingly, a standard CDR generally supports wording such as:
The records show that the device used a sector oriented toward the area containing the incident location at the relevant time.
It generally does not support:
The records prove that the device was at the incident address.
The distinction becomes even more important when a map displays a sector as a clean triangle. The graphic may be useful for orientation, but it is an illustration of antenna configuration, not a measured coverage footprint.
Specialized historical location data can add an estimated distance or proprietary location calculation. That still requires the examiner to understand the provider's methodology, uncertainty, confidence values, and limitations. A precision geolocation return should be mapped with its reported uncertainty radius, not as a single unquestioned point.
An RF survey can help evaluate coverage at a location or along a route, but it samples conditions at the time of the survey. It may not recreate the exact radio environment that existed months or years earlier.
Why 4G and 5G Make Interpretation More Complex
Modern CDR forensics is not limited to a single voice-switch record. The 3GPP charging framework includes separate specifications for core-network charging, packet-switched services, IP Multimedia Subsystem services, and CDR parameter descriptions across LTE and 5G environments.
That matters in practice:
- VoLTE and VoNR calls may involve IMS-generated records rather than a legacy circuit-switched model.
- Wi-Fi calling can alter which network elements and location fields are available.
- A single user action may generate multiple related records that must be correlated, not counted as separate human actions.
- Data-session records may be numerous, long-lived, or periodically updated, and their timestamps may not identify the instant a person used a particular app.
- Over-the-top services such as encrypted messaging and app-based calls may appear only as data traffic in standard carrier records. The communicating account and content may require handset, cloud, or provider-specific evidence.
- Dual-SIM devices and eSIM profiles make number-only attribution increasingly fragile.
- An MVNO and its host network may each possess a different part of the evidentiary picture.
The transition to 5G does not automatically transform historical CDRs into GPS-quality evidence. It increases the number of possible records, identifiers, services, and network paths the examiner may need to understand.
Communication Analysis Without Narrative Inflation
Link analysis can reveal high-frequency contacts, clusters, bridges between groups, sudden changes in behavior, and communications surrounding a critical event. It can also create a false sense of certainty.
Frequency does not prove importance. A short repeated contact may be automated. A service number may connect unrelated subscribers. A family-plan account may contain several users. A business line may represent a role rather than an individual. A zero-duration record may be an unanswered call, failed attempt, routing artifact, or provider-specific event.
Analyze sequence and context, not just totals. Useful questions include:
- Did contact begin or stop around the event?
- Was the communication answered, completed, forwarded, or unsuccessful?
- Did the same device or SIM remain associated with the number?
- Does the handset contain a matching call or message artifact?
- Is the relationship supported by contacts, cloud accounts, financial activity, travel, or other evidence?
- Are missing periods caused by inactivity, retention limits, another device, Wi-Fi use, or a gap in the production?
The absence of a CDR event is not automatically evidence that no communication occurred. The parties may have used another number, another device, an app, Wi-Fi, an offline method, or a service not represented in the production.
The Most Common Failure Modes
The same errors repeatedly weaken CDR evidence:
- Treating the account subscriber as the device user
- Treating the device user as the speaker or message author
- Mapping a tower coordinate as the handset's location
- Drawing a sector wedge as if it were a measured coverage boundary
- Using a current cell-site list for a historical event without validation
- Ignoring carrier-specific definitions for time, duration, direction, and disposition
- Overwriting source values during normalization
- Allowing spreadsheet software to alter long identifiers or timestamps
- Double-counting multiple network records created by one human action
- Treating data-session timing as proof of a particular app action
- Using a mapping or link-analysis platform without manually validating critical results
- Presenting investigative leads as final forensic conclusions
Most of these failures are not caused by weak software. They are caused by an examiner moving from data to narrative too quickly.
Reporting and Testimony That Survives Scrutiny
A strong report allows another qualified examiner to reproduce the work and understand where observation ends and interpretation begins.
Document:
- The legal and evidentiary materials received
- The original filenames, hashes, and preservation steps
- The carrier, record types, date ranges, and known omissions
- The provider keys, legends, and time conventions used
- The normalization schema and every material transformation
- The tools and versions used
- The validation samples and technical review
- The mapping method, source of site data, scale, legend, and sector assumptions
- Each conclusion, its supporting records, and its limitations
Use disciplined language in testimony:
- Say "the records show" when describing a recorded fact.
- Say "is consistent with" when the evidence supports more than one possible explanation.
- Say "cannot determine" when the records do not support identity, content, exact location, or intent.
- Do not convert an account association into a claim about a person without corroboration.
- Do not claim greater precision than the carrier data and method can support.
One of the most defensible sentences an examiner can use is:
This analysis identifies the network event recorded by the provider and the approximate area consistent with the serving cell information. It does not, by itself, identify the person using the device or establish the device's exact location.
That limitation does not weaken the evidence. It defines the evidence correctly.
The Legal Boundary Is Part of the Forensic Boundary
In the United States, Carpenter v. United States held that the government's acquisition of the historical CSLI at issue was a Fourth Amendment search and that the government generally must obtain a warrant supported by probable cause before compelling a carrier to disclose such records. The Court specifically held that accessing seven days of historical CSLI constituted a search, while leaving unresolved whether a shorter period might be treated differently. The opinion also did not decide the rules for real-time CSLI or tower dumps.
That narrow scope matters. Examiners should not reduce Carpenter to a slogan or assume it answers every modern location-data question. Statutes, state constitutions, local rules, civil discovery standards, consent, exigency, national-security authorities, and later case law may alter the analysis. Legal sufficiency should be determined by qualified counsel in the relevant jurisdiction.
Forensic sufficiency remains the examiner's responsibility. Even lawfully obtained records can be misinterpreted, and a valid warrant does not make an invalid inference scientifically sound.
A Supervisor's Quality-Control Checklist
Before releasing a CDR analysis, a supervisor should be able to answer yes to the following:
- Did we receive the record types needed to answer the investigative question?
- Did we preserve and hash the original production?
- Did we obtain and apply the correct carrier key and historical cell-site list?
- Can every normalized row and visualization be traced to its source?
- Were time-zone and daylight-saving conversions independently checked?
- Were number, SIM, device, subscriber, and user attribution kept separate?
- Were critical tower and sector mappings manually verified?
- Were automated results checked against the underlying data?
- Are all material assumptions and limitations stated?
- Did a qualified second examiner complete a technical review?
- Does the report distinguish investigative leads from final opinions?
- Is the proposed testimony no more precise than the data supports?
If any answer is no, the analysis is not ready for court.
The Standard Examiners Should Defend
CDR forensics is strongest when it is used as one layer in a broader evidentiary reconstruction. Carrier records can show network events, reveal communication patterns, associate subscriptions and devices, and place a handset within an approximate service area. Handset artifacts can add user activity and content. Cloud records can connect accounts and applications. Video, access logs, financial transactions, and vehicle systems can independently anchor time and place.
The goal is not to make the CDR tell the whole story. The goal is to determine exactly which part of the story the network can prove, document how that conclusion was reached, and resist every temptation to claim more.
That is the difference between a map that looks persuasive and an analysis that survives cross-examination.
Take it further
This article gives you the framework. The Waldrep Company's Mobile Device Forensics Fundamentals course expands the workflow through mobile preservation, acquisition, device identifiers, call and messaging artifacts, location evidence, cloud legal process, validation, reporting, and testimony.
The self-paced program includes 14 modules, 21 lessons, 10 CPE hours, examiner reference materials, and a certificate of completion. Tuition is $497 through September 30, 2026, then increases to $697. Government purchase orders and net-30 billing are accepted, and agencies receive 25 percent off purchases of five or more seats.
Sources and further reading
- SWGDE, Recommendations for Historical Cell Site Analysis, Version 3.0, March 3, 2025. www.swgde.org/documents/published-complete-listing/17-f-001-recommendations-for-historical-cell-site-analysis/
- NIST SP 800-101 Rev. 1, Guidelines on Mobile Device Forensics. www.nist.gov/publications/guidelines-mobile-device-forensics
- 3GPP TS 32.240, Charging Architecture and Principles. www.3gpp.org/dynareport/32240.htm
- 3GPP 32 Series Specifications. www.3gpp.org/dynareport/32-series.htm
- Carpenter v. United States, 585 U.S. 296 (2018). www.supremecourt.gov/opinions/17pdf/16-402_h315.pdf
This article is educational and does not provide legal advice. Investigators should consult the applicable law, agency policy, prosecutor, or counsel before seeking or using telecommunications records.