Cell Phone & Mobile Device Forensics | The Waldrep Company
Mobile Device Forensics

Cell Phone & Mobile Device Forensics

Attorneys nationwide retain cell phone forensics expert Eric Waldrep to recover and explain what smartphones hold: deleted text messages, app data, call logs, photos, and location history. 19 years of digital forensics experience. casework in federal and state courts.

Cell Phone Forensics Services for Attorneys Nationwide

The Waldrep Company provides cell phone forensics services to attorneys across the country from its lab in Addison, Alabama. Eric L. Waldrep, a Magnet Certified Forensics Examiner (MCFE), has 19 years of digital forensics experience and 27 years in law enforcement. He has completed casework in federal and state courts.

Mobile device forensics is the disciplined recovery and interpretation of data from smartphones and tablets: what is on the device now, and in many cases what someone tried to remove. A sound examination uses validated tools, documents every step, and produces findings another qualified examiner could reproduce.

Intake works at a distance. Ship a device to the lab under documented chain of custody, arrange a hand-off, or transfer a backup or a prior extraction electronically. When testimony is needed, Eric travels.

Devices Supported

iPhone and iPad (iOS), Android smartphones and tablets, feature phones, wearables, and GPS units, across current and older operating system versions.

  • Logical, file system, and physical extraction
  • Deleted SMS, iMessage, and app message recovery
  • Call logs, voicemail, and contact records
  • Photo and video metadata analysis (EXIF)
  • Location history and GPS artifacts
  • App data: WhatsApp, Signal, Telegram, Snapchat
  • Social media, browser, and search history
  • Locked and encrypted device handling, capability varies by model
  • Hash verification and chain of custody throughout
  • Written reports built for attorneys and juries
  • Deposition and trial testimony nationwide
19
Years in Digital Forensics
Fed + State
Courts Qualified
MCFE
Magnet Certified Examiner

Deleted Text Messages, App Data, and the Rest of What a Phone Holds

A smartphone records far more than its owner sees on screen. These are the artifact families a mobile device forensics examination looks at most often.

Text Messages & iMessage

SMS, MMS, and iMessage threads with timestamps and participants. Many deleted messages are recoverable, though survival depends on the device, elapsed time, and overwrites.

Messaging Apps

WhatsApp, Telegram, Snapchat, and Signal artifacts where they exist. One honest caveat: apps built around disappearing messages can leave little behind, and we say so before you spend money.

Call Logs & Contacts

Incoming, outgoing, and missed calls with duration and timestamps, plus voicemail and contact records that show who was talking to whom, and when.

Photos, Videos & Metadata

EXIF metadata can show when a photo was taken, on what device, and often where. Valuable when the authenticity or timing of an image is disputed.

Location Artifacts

GPS records, cached locations, Wi-Fi association history, and app location data that help reconstruct where a device was and when it was there.

Browser & Search History

Visited pages, search terms, and cached content, including entries the user cleared, where those artifacts survive on the device.

Recovered messages raise their own litigation questions: authentication, completeness, and how to present them. Our guide to deleted text messages in court walks through each one.

iPhone Forensics, Android Forensics, and the Tools Behind Both

iPhone forensics works inside Apple's tightly controlled ecosystem. Depending on the model and iOS version, an examination draws on the device itself, encrypted local backups, and synced data. Apple's protections shape what is reachable, which is why the honest answer to most iPhone questions starts with the model and OS version.

Android forensics covers a much wider mix of manufacturers, chipsets, and OS builds. That variety cuts both ways: some Android devices give up more than any iPhone would, others less. The examination plan is built around the specific handset in front of us, not a generic template.

Already Have the Other Side's Extraction?

You may not need a new acquisition at all. Opposing expert report review is $2,750 flat. See our Cellebrite report review service for how that works.

Tools Used in Casework

Examinations rely on Cellebrite UFED, GrayKey, and Magnet AXIOM, applied and cross-checked by the examiner. These are tools, not conclusions: significant findings get verified against the underlying data rather than taken on a parser's word.

  • Cellebrite UFED for extraction and decoding
  • GrayKey for supported iOS and Android acquisitions
  • Magnet AXIOM for analysis and reporting
  • Manual validation of key artifacts in the raw data

From Intake to Report: How a Mobile Device Forensics Case Runs

The same sequence every time, documented at every step, so the work can be explained and defended later.

  • Free consultation. We talk through the case question, the devices or data available, and whether an examination is the right spend. Start at the contact page or call (251) 216-1164.
  • Authority confirmed. Before any work begins, the legal basis for the examination is confirmed and the scope goes in writing.
  • Device intake. Ship the device, hand it off, or transfer a backup or prior extraction. Chain of custody documentation starts the moment evidence arrives.
  • Forensic acquisition. Extraction using the method the device supports, with hash verification of the evidence files. $1,500 per device.
  • Analysis. Focused review of the artifacts that matter to the case question, billed from $425/hr, with findings verified in the underlying data.
  • Report and testimony. A written report in plain language, exhibits your team can use, and deposition or trial testimony when the case calls for it. Full fee schedule on the rates page.

Cell Phone Forensics Services Across Practice Areas

Family Law

In a custody or divorce matter, messages, photos, and location history often carry the story the parties dispute. We recover what exists, document what does not, and present it without spin.

Criminal Defense

An independent examination of the same phone the state examined, or a review of the extraction the prosecution produced, can confirm, put in context, or contradict the government's reading of the data.

Accident & Personal Injury

Was the phone in use at impact? That question has a dedicated service page: mobile device forensics for accident investigations. Attorneys can also start with the free accident phone evidence checklist.

Employment Disputes

Departing-employee data theft, harassment claims, and policy violations frequently come down to what a company or personal device actually recorded, and when.

Examinations Only With Proper Authority

A forensic examination happens only when there is a proper legal basis for it: the client's own device, written consent from the device's owner, or legal process obtained through counsel, such as a court order or an agreed discovery protocol.

That rule protects the evidence and the client. If you are not sure whether you have authority to examine a device, raise it during the consultation before the device is touched. A phone someone happens to possess is not a phone they necessarily have the right to search.

What It Costs

Forensic acquisition is $1,500 per device. Consulting, analysis, and review time is billed from $425/hr. The full fee schedule, including testimony and retainer options, is published on the rates page. The initial consultation is free.

Where We Work

The Waldrep Company is based in Addison, Alabama and serves attorneys nationwide. Intake is remote, devices ship under documented chain of custody, and Eric travels for testimony. Call (251) 216-1164 or email info@thewaldrepcompany.com.

Cell Phone Forensics FAQ

Straight answers to the questions attorneys ask before retaining a mobile device forensics examiner.

Often, yes. Phones rarely erase data the moment a user deletes it, so deleted messages are frequently recoverable. Whether a specific message survives depends on the device model, the operating system version, how much time has passed, and whether the storage that held it has been overwritten. Recent deletions on a lightly used device recover best. No examiner can promise a particular message is still there, which is why we start with a free consultation about what the case actually needs.
Not always. The physical device gives the deepest access, but an encrypted local backup, a cloud backup, or a prior forensic extraction produced in discovery can often answer the question at hand. We regularly work from extractions produced by law enforcement or by the other side. When the device is available, shipped intake with documented chain of custody works fine, so distance is not a barrier.
Acquisition of a single device typically takes a few days once it arrives, depending on the model and storage size. Analysis and reporting depend on scope: a focused question moves much faster than a full communications review. You get a written time estimate during the consultation, and court deadlines are flagged and planned around up front.
Capability varies by manufacturer, model, operating system version, and the state the device is in, and it changes as forensic tools are updated. Some locked devices can be examined and some cannot, and no honest examiner promises access to a locked device before looking at the specifics. Bring the details to the consultation and you will get a plain answer about what is realistic.
No expert can guarantee how a court will rule, and you should be cautious with one who does. What we can describe is the method: validated tools, documented procedure, hash-verified evidence, and an unbroken chain of custody, all recorded so another examiner could check the work. Eric Waldrep has completed casework in federal and state courts.
Devices and evidence files enter a documented chain of custody at intake and stay in secure storage when not under examination. Working copies are hash-verified against the original acquisition, so any alteration would be detectable. Case data is never shared outside the engagement, and at the close of the matter devices are returned and data is retained or destroyed per counsel's written instruction.

Ready to Discuss Your Case?

We offer a free, confidential consultation for attorneys. Call or email to get started today.

Train Your Team

Build the same capability in-house. Our self-paced Mobile Device Forensics course covers iOS and Android extraction and analysis with Cellebrite, Magnet AXIOM, and GrayKey.

View the Course →

Request a Mobile Device Examination

Tell us what the matter involves and we will respond personally. Initial consultations are free, and nothing you send here is a retention.

Sending this does not create an attorney-client or expert relationship, and please do not send privileged material or case evidence through this form. Prefer the phone? Call (251) 216-1164.