Legal Cyber Academy
Standard or guidanceFreeCurrent

Guidelines on Mobile Device Forensics

Richard Ayers, Sam Brothers, Wayne Jansen · National Institute of Standards and Technology · Revision 1, May 2014 · 2014

Identifier: NIST SP 800-101 Rev. 1

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

NIST's guidance on seizing, preserving, acquiring and examining mobile phones and their associated media, including the acquisition-level model (manual, logical, physical, chip-off, JTAG) that practitioners still use as shared vocabulary. It supersedes the 2007 first edition of SP 800-101.

Who it is for, and when

Useful for an examiner who needs a federal reference for why a particular acquisition level was chosen, and for a lawyer who needs to understand what 'logical' versus 'physical' extraction actually means in a report. It also covers preservation decisions at seizure: radio isolation, power state, and PIN/passcode handling.

What it does not cover

It is still the current NIST revision but is now over a decade old: it does not address Android file-based encryption, iOS Secure Enclave and Data Protection classes, modern checkm8/bootloader exploits, cloud-side account acquisition or the current commercial extraction tools. Do not cite its device coverage or tool capability claims as present-day fact.

Go to the source

Open at csrc.nist.gov (opens in a new tab)

https://csrc.nist.gov/pubs/sp/800/101/r1/final

Details

Type
Standard or guidance
Written for
Working examinerWorking examiner
Author
Richard Ayers, Sam Brothers, Wayne Jansen
Publisher
National Institute of Standards and Technology
Version verified
Revision 1, May 2014
Year
2014
Identifier
NIST SP 800-101 Rev. 1
Topics
mobile, imaging, evidence-handling, encryption, us-federal
Checked at source
Standards are revised. Confirm the current revision with the publisher before citing this.
  • SWGDE's guidance on acquiring data from computers and computer storage, including write blocking, live versus dead acquisition, verification and the handling of encrypted and self-encrypting media. The version verified here is 17-F-002-2.1 dated 5 August 2025.

  • SWGDE's guidance on the front half of mobile device work: isolating and preserving a seized handset, handling power and network state, and choosing among logical, file system and physical acquisition routes. The version verified here is 18-F-003-2.0 dated 21 August 2025.

  • A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.

  • The acquisition half of the job done properly with Linux command-line tools: write protection, image formats, attaching subject media, image management and transfer, integrity by cryptographic and piecewise hashing, PKI signatures and RFC 3161 timestamping, drive security (ATA passwords, Opal self-encrypting drives, BitLocker, FileVault), and difficult cases such as RAID, VM images and damaged media.

  • An NIJ special report, produced by the Technical Working Group for the Examination of Digital Evidence, covering policy and procedure, evidence assessment, acquisition, examination, documentation and reporting. It is the second guide in NIJ's digital evidence series, after the first responder guide.