A locked smartphone can contain years of a person’s digital life: text messages, photographs, videos, contacts, application data and other information that could become evidence in a criminal investigation.

But a passcode doesn't necessarily mean investigators have reached a dead end.

Law-enforcement agencies around the world use specialized mobile-device forensic technology designed to access and extract information from smartphones, including systems made by companies such as Cellebrite and Magnet Forensics.

Two of the best-known names in the industry are Cellebrite’s UFED technology and Magnet Graykey.

These systems can give trained forensic investigators access to data that may otherwise be inaccessible through ordinary use of a phone, including information stored behind a device passcode or within protected portions of its file system.

Cellebrite describes its current UFED platform as technology for lawfully accessing and collecting digital evidence from smartphones and other devices. Depending on the device and circumstances, the system supports methods including full-file-system and physical extractions.

Magnet Forensics similarly markets Graykey as mobile-device access technology used by forensic investigators. The company says Graykey supports Apple devices as well as a growing range of Android phones, including Samsung Galaxy and Google Pixel models.

Together, technologies like these have transformed the smartphone into one of the most valuable potential sources of evidence in modern investigations.

What Investigators Can Potentially Recover

Getting into the phone is only the beginning.

Once investigators obtain an appropriate forensic extraction, specialized software can process the resulting data and organize potentially relevant information for examination.

Depending on the phone and type of extraction available, that can include messages, photographs, videos, contacts, call information, application databases and other files stored on the device.

A full-file-system extraction can go considerably deeper than simply scrolling through the phone's visible screens.

Cellebrite says UFED supports full-file-system extraction methods designed to obtain protected and containerized information from supported devices. The company's broader forensic platform can then process and analyze the resulting data.

Graykey can similarly work alongside Magnet AXIOM to process mobile-device extractions. Magnet says its technology can handle iOS keychain and Android keystore information, potentially providing access to additional application and account data contained in a forensic image.

In some circumstances, investigators may also recover deleted information.

Deleting a message or file through a phone's normal interface does not necessarily mean every underlying trace of that information immediately disappears. Whether deleted information remains recoverable depends on numerous technical factors, including how the operating system and application stored it, encryption, subsequent device activity and whether the relevant data has been overwritten or otherwise made inaccessible.

That means “deleted” should not automatically be interpreted as “gone forever.”

How a Locked Phone Can Still Become Evidence

Modern iPhones and Android devices employ sophisticated encryption and security protections specifically designed to prevent unauthorized access.

That creates a constant technological contest between smartphone manufacturers strengthening security and forensic companies developing new lawful-access capabilities for investigators.

Cellebrite says its advanced services can determine or disable certain PIN, pattern and password screen locks on supported Apple and Android devices. Its commercial forensic products also advertise capabilities for accessing encrypted and protected data on supported devices.

Graykey has become particularly well known for mobile-device access. Magnet says the system is continually updated as Apple and Android manufacturers introduce new hardware, operating systems and security features.

The exact capabilities aren't static.

A forensic technique that works against one iPhone model and operating-system version might not work against another. A security update can close an avenue investigators previously relied on, while forensic vendors may subsequently develop another method of obtaining access.

The condition in which police obtain a phone can matter as well.

Forensic professionals distinguish between different device states, including whether a phone has recently been unlocked. Cellebrite specifically advertises techniques involving devices in an “After First Unlock,” or AFU, state as part of its current mobile-access capabilities.

That helps explain why investigators sometimes take unusual precautions after seizing a smartphone. Preserving the device in the condition in which it was found can affect what evidence remains accessible.

Cellebrite UFED Has Become a Major Forensic Platform

Cellebrite's Universal Forensic Extraction Device, commonly known as UFED, has become one of the recognizable technologies in digital forensics.

Despite the name, UFED isn't necessarily a single mysterious machine sitting inside a police department.

Cellebrite offers the technology in multiple configurations, including software that runs on forensic computers, ruggedized laptops and dedicated portable hardware intended for evidence collection in laboratories or in the field.

Its purpose is to acquire data while preserving forensic integrity so investigators can analyze the information without simply manipulating the original evidence like an ordinary phone user would.

The extraction can then become part of a larger digital-forensics workflow in which examiners search, categorize and interpret potentially relevant information.

That distinction matters in criminal cases.

Investigators aren't simply trying to “look through” a suspect's phone. Digital-forensics procedures are designed to preserve evidence and document how it was collected so the material can potentially withstand scrutiny later in court.

Graykey Became Known for Accessing Locked Phones

Graykey emerged as another major player in the same field and is now part of Magnet Forensics.

Magnet describes Graykey as technology capable of accessing mobile evidence from iOS and Android devices, with support that evolves as manufacturers release new phones and operating systems.

After Graykey obtains access, investigators can move the resulting extraction into forensic-analysis software.

Magnet's AXIOM platform, for example, can process Graykey extractions and help examiners identify and analyze data contained within them.

The result is a process with two distinct challenges: first gaining lawful technical access to the device, and then making sense of what can be an enormous amount of information once the extraction is complete.

A modern smartphone can contain hundreds of gigabytes of data.

Finding the handful of messages, images or application records relevant to an investigation can therefore become as important as obtaining the phone itself.

These Tools Cannot Automatically Unlock Every Phone

Despite their capabilities, mobile forensic systems should not be described as universal phone-unlocking machines.

There is no guarantee that plugging a seized smartphone into Cellebrite or Graykey will instantly reveal everything inside it.

Success can depend on the manufacturer, model, processor, operating-system version, passcode configuration, security settings, device state and the specific forensic capabilities available at that time.

Magnet itself notes that the fragmented Android ecosystem creates significant challenges because of the enormous variety of manufacturers, chipsets and devices.

New security updates can also change what is technically possible.

That creates an ongoing race between the companies designing smartphone security and the forensic companies attempting to access devices under lawful authority.

A Smartphone Can Become a Digital Timeline

The significance of mobile forensics extends beyond finding an incriminating text message.

Phones have become repositories for enormous portions of everyday life.

Depending on what information is available and legally within the scope of an investigation, digital evidence can help investigators reconstruct communications, relationships and sequences of events.

Photos can contain timestamps and other metadata. Messaging databases can preserve conversations. Application information can provide additional context. Other device records can potentially help establish when certain activity occurred.

Investigators can then compare digital evidence with surveillance footage, witness accounts, financial records and other evidence.

That is why smartphones have become so important in cases ranging from fraud and robbery to organized crime and homicide.

Cellebrite quotes one law-enforcement digital-forensics official as saying mobile forensics now touches virtually every type of crime his agency investigates, from relatively minor offenses to complex homicide cases.

Access Still Requires Legal Authority

The technical ability to extract information from a device is separate from the government's legal authority to search it.

In the United States, law enforcement generally must operate within constitutional and statutory rules governing searches and seizures, and the precise authority to search a particular phone can depend on the warrant, consent, exigent circumstances and other legal issues specific to the case.

Cellebrite itself describes its advanced access services as available to law-enforcement agencies with legal authority to access the devices involved.

A forensic tool therefore doesn't eliminate the legal questions surrounding a phone search.

It changes what may be technologically possible once investigators have authority to conduct one.

That difference has become increasingly important as smartphones have evolved from simple communication devices into enormous repositories of personal information.

Today, seizing a phone can potentially give investigators access to far more than the calls a person made.

With specialized forensic technology, a smartphone can become a searchable digital record of communications, photographs, application activity and other information accumulated over months or years.

And even when that phone is locked—or information appears to have been deleted—the investigation may not necessarily end there.