Geolocation Artifacts: How to Find Them on Mobile Devices (2024)

Industry News

Geolocation Artifacts: How to Find Them on Mobile Devices (1)

Geolocation artifacts are forensically valuable data created by GPS or other location-based technologies on a device that determine an individual’s geographic location. This data can be useful in various investigations related to crimes or other incidents.

In today’s digital age, the use of mobile devices has become pervasive across different domains. With the increase in usage, the role of geolocation in mobile device investigations has become more crucial than ever.

Geolocation Artifacts in Investigations

In mobile device investigations, geolocation data can provide valuable information about the locations of suspects, victims, and witnesses. It can help investigators to track a person’s movements and verify their alibis. For example, if someone claims to have been at a particular location at a certain time, geolocation data collected from his or her mobile device can be used to confirm or refute the claim. Moreover, geolocation data can help investigators reconstruct crime scenes and establish timelines. When analyzing the geolocation data from multiple devices, investigators can correlate the data from various sources to better understand the events that occurred. This information can be used to build a case against the accused and provide evidence in court.

Geolocation Artifacts: How to Find Them on Mobile Devices (2)

Geolocation data can also help investigators locate lost or stolen devices. Using the GPS coordinates provided by the mobile device, investigators can identify the device’s last known location and track it down.

Top Geolocation Artifacts for Android and iOS

Magnet Forensics has curated the following list of top geolocation artifacts and where they can be found on a given device. Magnet AXIOM and AXIOM Cyber will surface these artifacts for you quickly and easily, and Magnet GRAYKEY and VERAKEY provide same-day access to the latest iOS and Android devices; but it’s important you know where to look:

Android Geolocation Artifacts
/data/data/com.google.android.apps.maps/databases/gmm_storage.db
iOS Geolocation Artifacts
/private/var/mobile/Containers/Data/Application/[APPGUID]/Library/Maps/GeoHistory.mapsdata
/private/var/mobile/Containers/Data/Application/[APPGUID]/Library/Maps/GeoBookmarks.plist
/private/var/mobile/Library/Caches/com.apple.routined/Cache.sqlite
/private/var/mobile/Library/Caches/com.apple.routined/Local.sqlite

Leveraging Geolocation Artifacts

While many examiners spend the bulk of their time using the artifact explorer in AXIOM Examine, other features like Timeline and Connections can help surface items of interest. The volume of artifacts from a modern mobile device examination can make it easy for potential geolocation artifacts of interest to blend into the noise, almost hiding in plain sight.

Using the Timeline explorer can help to profile when a particular activity occurred on a device or provide context as to what a user was doing on their device at a certain time. The use of absolute and relative time filters can also help examiners find key details around points of interest in the timeline of a specific investigation.

Geolocation Artifacts: How to Find Them on Mobile Devices (3)

The connections explorer provides a visual representation of how the various artifacts in your case are related. By using the distinct properties of each artifact, called artifact attributes, you can show relationships between an artifact of your choosing – such as a screen name or phone number – to see how they relate to the geolocation artifacts in your case.

Geolocation Artifacts: How to Find Them on Mobile Devices (4)

These days, mobile devices often have greater storage capacity, even rivaling traditional computers. Still, the always-on, always-connected nature of mobile devices means that cloud stored data cannot be overlooked. The Potential Cloud Evidence Leads dashboard is a great resource for identifying other sources of data which may be relevant to your investigation – particularly when mobile devices are involved.

Geolocation Artifacts: How to Find Them on Mobile Devices (5)

Applications on a device may not always store data locally or there may be additional logs, usage, and analytics data available directly from the connected cloud account. The potential cloud evidence leads dashboard helps examiners by surfacing potential sources of cloud-stored data and accounts from the installed applications and accounts recovered on a device. This can help to provide an efficient method for directing further investigative efforts in a case.

If you haven’t tried Magnet AXIOM or AXIOM Cyber, request a free trial today.

Geolocation Artifacts: How to Find Them on Mobile Devices (2024)

FAQs

What are the data artifacts can be found on mobile phones? ›

Pictures, videos, audio files, and sometimes voicemail messages. Internet browsing history, content, cookies, search history, analytics information. To-do lists, notes, calendar entries, ringtones. Documents, spreadsheets, presentation files and other user-created data.

How do mobile devices identify my geographical location? ›

Global Positioning System (GPS)

GPS geolocation is based on communication satellites that orbit the earth, that continuously broadcast their status, exact location, and precise time. A GPS device that receives these signals is able to determine its GPS location.

Why are mobile devices and network artifacts relevant to a computer examiner? ›

Forensic investigators must track activities across multiple devices to get the full picture of events. For example, a hacker may have used a vulnerable device to gain access to the network and spread it across other, more sensitive devices.

What is the value of communication artifacts in digital investigations? ›

These communication artifacts help investigators uncover important connections and unlock the truth. They can reveal what was said, when it was said, and who said it to whom.

What evidence can be found on a cell phone? ›

The Process of Seizing and Searching Mobile Phones in Criminal Cases. If a cellphone is seized in connection with a criminal case, police will seek to search the digital contents of the phone to include its call history, messages, emails, photos, web browsing history, and installed mobile applications.

What information can be found on a cell phone? ›

Cops can potentially see a wide range of information on your phone, including your location history, internet browsing activity, call and text records, social media posts and messages, email communications, photos and videos, and app usage data.

What are trackers on my phone? ›

Spyware is a type of malware used to track people's phones and record their activity. If you think your phone is being tracked, check for suspicious apps that you don't remember installing, check your phone app usage for anything you don't recognize, and look for any strange increases in network activity.

How to trace a mobile location? ›

Be ready to find a lost Android device
  1. Step 1: Check that you're signed in to a Google Account.
  2. Step 2: Check that Location is on.
  3. Step 3: Check that Find My Device is on.
  4. Step 4: Find offline devices and devices without power.
  5. Step 5: Check if your device is listed on Google Play.
  6. Step 6: Check that you can find your device.

How do you know if your phone location is being tracked? ›

If you're concerned with location tracking, here's how to locate spyware on your iPhone and Android to make sure your phone is not being tracked.
  • Update location-sharing for your phone apps. ...
  • Confirm location-sharing is off for maps, chats, and other apps. ...
  • Check your phone for suspicious apps. ...
  • Audit your phone battery usage.

How much does a cell phone forensics cost? ›

In most legal cases, the cell phone investigator can recover and analyze the cell phone's evidence and generate forensic tool reports for the legal team's review for an average cost of $3,500 to $5,000. Each smartphone takes approximately 8 to 12 hours of lab time.

What type of evidence can be extracted from a mobile device? ›

The information obtained via mobile device forensics may include deleted files, application data, GPS data, call logs, text messages, and photographs and videos. Like other domains of forensics, mobile device forensics is commonly used to recover evidence in connection with a criminal investigation.

How to do cell phone forensics? ›

How the Cell Phone Forensics Process Works
  1. Seizure of the phone. Seizing the phone in question is essential because many files are stored within it. ...
  2. Protect the data. After a seizure, the phone must be isolated from any network to prevent it from sending out signals. ...
  3. Extract the data. ...
  4. Analyze the information.

How do you investigate digital evidence? ›

Process Involved in Digital Evidence Collection

The main processes involved in digital evidence collection are given below: Data collection: In this process, data is identified and collected for investigation. Examination: In the second step the collected data is examined carefully.

What are examples of digital artifacts? ›

A scan of a drawing with large areas of whitespace; the diamond Moiré pattern is a scanning artifact. Digital artifact can be of any content types including text, audio, video, image, animation or a combination.

What are examples of communication artifacts? ›

Communication Artifacts are created as expressions of human thought. They include advertisem*nts, art, ceremonial and documentary artifacts, exchange media, and personal symbols. Advertising artifacts are objects that were created to call attention to products, services, or events.

What data is stored on a mobile phone? ›

Phone memory refers to RAM (Random Access Memory). RAM is the part of the phone that is used to store the operating system (OS) and where apps and data currently in use are kept. Whereas, phone storage is used to store data such as apps, photos, videos, and files that are necessary for the phone to run.

What are data artifacts? ›

Files that are related to databases are called artifacts (or objects). Database artifacts perform actions against one or more databases, such as defining calculations.

What sorts of data can be collected with a mobile phone? ›

There are many mobile phone applications (referred to as platforms) that will allow you to build a mobile data collection survey. These platforms will allow you to customise the survey to collect specific data as required, such as photographs, information from a list selection, voice recordings, GPS coordinates, etc.

What are artifacts in Android? ›

Artifacts are temporary or final files or directories that are produced by the Android Gradle plugin during the build. Depending on its configuration, each com. android. build.

References

Top Articles
Latest Posts
Article information

Author: Golda Nolan II

Last Updated:

Views: 6263

Rating: 4.8 / 5 (78 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Golda Nolan II

Birthday: 1998-05-14

Address: Suite 369 9754 Roberts Pines, West Benitaburgh, NM 69180-7958

Phone: +522993866487

Job: Sales Executive

Hobby: Worldbuilding, Shopping, Quilting, Cooking, Homebrewing, Leather crafting, Pet

Introduction: My name is Golda Nolan II, I am a thoughtful, clever, cute, jolly, brave, powerful, splendid person who loves writing and wants to share my knowledge and understanding with you.