Mobile Device Evidence Intake Checklist
Mobile-device handling decisions can affect lock state, encryption, remote access, network behavior, volatile data, and later acquisition options. Follow current legal authority, agency policy, and validated tool guidance.
PUBLIC OPERATIONAL REFERENCE
Before changing device state
- Photograph the device, screen, connections, accessories, packaging, and visible damage.
- Record date, time, timezone, displayed time, power state, lock state, and battery condition.
- Record make, model, serial number, IMEI or MEID, SIM or eSIM context, and asset identifiers when visible.
- Document network icons, notifications, connected accessories, and any active application or call state.
- Confirm legal authority and scope for the device, accounts, applications, cloud data, and removable media.
Isolation and preservation
- Select an isolation method based on device state, risks, policy, and available validated equipment.
- Do not assume airplane mode, a Faraday enclosure, or power removal is always the correct action.
- Record every touch, menu action, cable connection, power decision, and isolation step.
- Preserve passwords, recovery keys, tokens, paired devices, and account information only when lawfully obtained.
- Maintain power and monitor heat or battery risk when continued power is operationally justified.
Interpretation limit
A generic checklist cannot select the correct seizure strategy. Device state, encryption, remote-wipe risk, tool support, and authority must be evaluated together.
Continue with the complete workflow
Public references are starting points. DFIR Field Toolkit connects operational references with an encrypted local case record, evidence inventory, field forms, amendments, and exports.
Create one complete case free or explore the synthetic product demo.