The recent developments in cell phone technology helped in development of Cell phone forensics as a great resource for forensic examiners and hi-tech crime investigators.

Forensics has the potential to provide a wealth of information by retrieving information with relevant format which includes deleted text messages, address book entries that you have deleted, Photographs that you have taken and deleted, dialed and received calls etc.

Today Cell phones became more advanced and sophisticated in being used for inappropriate usage. Investigators realized that there was a need to develop specific tools and process to search for evidence without affecting the information and introduced to get the file system and memory data helping the individuals, while Cell phones are becoming more like desktop computers functionally. Cell phones rely on flash memory for persistent storage designed to perform a predefined tasks using embedded software. The National Institute of Standards and Technology (NIST) is the one, which developed the guidelines in cell phone forensics.

Cell phone forensics has two methods in order to collect the data; one is logical method, which acquires files and directories from the file system of the flash memory. Secondly, we can get all data from bit-by-bit copy of entire physical memory using a low level access method. Cell phone forensics can be largely divided by memory forensics and SIM forensics. Mobile phone based on GSM/WCDMA telecommunication technology stores data such as phone book, SMS message and IMSI in SIM/USIM. So SIM forensics is required to extract data from the cell phone with memory forensics. In this process of SIM forensics, a user PIN will be demanded according to access condition of elementary file in which data is stored.

The types of tools available for Cell phone examination include commercial forensic tools, device management tools, open source tool; self developed tools, diagnostic tools and hacker tools. Forensic tools are typically designed to acquire data from internal memory of handsets and removable identity modules such as SIMS found in GSM. These forensic tools support full range of acquisition and reporting functions to acquire device contents.

