Phones and tablets
iPhone and Android records, Cellebrite extractions, application data, messages, media, timestamps, location related records, call activity, and device usage.
Portland, Maine
Rune Forensics provides digital forensic services and independent evidence review for Portland and Maine matters involving mobile devices, computers, Cellebrite extractions, cloud accounts, email records, questioned media, and forensic reports.
Digital forensics for Portland and Southern Maine
Portland, Cumberland County, and Southern Maine matters may involve communications, phones, computers, email systems, cloud storage, photographs, video, browser activity, deleted records, metadata, system logs, or an existing forensic report. The practical question is what those records actually prove.
Rune Forensics evaluates whether the available evidence can answer the question presented, whether additional preservation is needed, and whether a prior extraction or report accurately describes the underlying records. Rune Forensics is based in Massachusetts and supports Portland and statewide Maine matters through appropriate evidence handling arrangements.
Evidence sources
A phone extraction, laptop image, email export, and cloud record may each show something different about the same event.
iPhone and Android records, Cellebrite extractions, application data, messages, media, timestamps, location related records, call activity, and device usage.
File activity, browser records, USB history, account usage, application artifacts, cloud sync, and deleted files where recoverable.
Email, cloud storage, login records, mailbox rules, provider exports, shared drives, and account activity that may need correlation.
Metadata, file structure, encoding characteristics, editing indicators, provenance questions, and surrounding evidence.
Cellebrite Reader reports, UFDR files, Magnet reports, forensic images, exports, examiner reports, timelines, assumptions, and technical limitations.
Device examination
Mobile device forensics may involve iPhone and Android acquisition, Cellebrite analysis, Full File System acquisition where supported, application databases, messages, photographs, videos, location information, browser activity, device usage, and timeline reconstruction.
The acquisition method depends on the device, operating system, security state, authorization, and available forensic support. Deleted artifacts may be reviewed where recoverable, but deleted data recovery is never promised.
Phone review may include messages, chat applications, account records, call activity, media, timestamps, device usage, and location related data.
Cellebrite output may need review beyond the Reader report view, including source databases, timestamps, extraction scope, and missing context.
Computer examinations may include user activity, file activity, browser records, USB history, application artifacts, account activity, and external storage use.
Computer forensic analysis can help assess when files were created, opened, modified, copied, deleted, or synchronized with a cloud service.
Computer forensics
Windows and macOS systems may contain records that help explain file movement, user activity, browser activity, cloud synchronization, metadata, account use, external devices, and deleted files where recoverable.
Learn more about computer forensic analysis when laptops, desktops, external drives, or business systems are part of the evidence.
Independent forensic review
Counsel may already have an extraction, export, forensic image, report, screenshot set, or timeline. Rune Forensics reviews the underlying material to assess what was examined, what may have been omitted, and whether the stated conclusion is supported.
Second opinions and rebuttal analysis
A forensic report might not be the final evidence. It is a work product that should be evaluated against source records, extraction scope, tool output, artifacts, and stated limitations.
A second examination may identify database information, timestamp context, acquisition limits, or interpretation issues that are not apparent from a simple report view.
Review the independent forensic review service when existing forensic work needs to be tested, explained, or challenged.
Questioned media
Portland and Maine matters may involve suspected deepfakes, AI generated imagery, manipulated photographs, edited video, questioned recordings, social media content, recompressed files, transcoded files, or disputed screenshots.
Digital media authentication may consider metadata, file structure, encoding characteristics, frame level anomalies, editing indicators, provenance, transmission history, account records, and surrounding context.
Original source files are generally preferable because social media downloads, screenshots, and recompressed copies may remove important technical evidence.
Technical indicators are reviewed in relation to the file type and available source material.
Where the file came from can matter as much as what appears on screen.
The strongest opinions are built from original files and corroborating records.
Maine attorneys and litigation teams
Digital forensic support can help attorneys identify preservation issues, understand discovery material, evaluate technical reports, and decide whether additional examination is needed.
Related services include civil litigation digital evidence, insurance claim evidence review, and personal injury digital evidence.
Identify phones, computers, accounts, exports, media, email records, and existing reports that should be protected before normal use changes them.
Review focused artifacts, timelines, metadata, account records, and device activity tied to the legal or investigative question.
Evaluate opposing forensic evidence, prior reports, extraction scope, omitted context, and whether opinions remain within the available records.
Prepare written findings, consultation, exhibits, deposition preparation, and testimony support where appropriate.
Criminal defense review
Criminal defense work may involve independent review of seized devices, Cellebrite extractions, police forensic reports, search warrant evidence, communications, application artifacts, timestamps, location evidence, and forensic methodology.
The purpose is to determine whether the digital evidence was preserved, extracted, interpreted, and explained in a way the records support.
Defense review can matter when a report presents selected artifacts without source data, extraction scope, timestamp context, or technical limitations.
Review may examine the stated method, extraction type, parsed results, omitted records, and whether the findings are supported by source artifacts.
Device activity, message records, location artifacts, and account records may need to be correlated before a timeline is treated as reliable.
Missing records, extraction limits, tool limitations, alternate explanations, and unsupported assumptions should be identified when they matter.
Maine matter types
The right scope depends on the matter, evidence source, legal authority, deadline, and available records.
Communications, files, metadata, device activity, timelines, and production disputes.
Independent review of extractions, reports, timelines, and conclusions offered from digital evidence.
Departing employees, account access, file transfers, cloud sync, and internal records.
Device activity, media, metadata, location related records, communications, and authenticity questions.
Questions the evidence may help answer
The ability to answer any question depends on the evidence available, device condition, account records, retention, acquisition method, and other technical limitations.
Was a file opened, created, copied, modified, or deleted?
Can communications be placed into a reliable timeline?
Does underlying device data match screenshots or exported messages?
Was a particular account or application used on the device?
Can activity from multiple evidence sources be correlated?
Does an existing forensic report accurately describe the underlying artifacts?
Does a photograph or video contain indicators consistent with editing or manipulation?
What can the available metadata actually establish?
Why Rune Forensics
Rune Forensics focuses on digital forensic examination, independent review, evidence preservation, timeline analysis, media authentication, documented findings, and litigation focused consulting.
Findings are tied to artifacts, metadata, logs, source records, and surrounding context. Technical limitations are stated when they affect the strength of a conclusion.
Review professional qualifications, learn more about business forensic investigations, or browse practical digital evidence resources.
Forensic process
Start with what needs to be established, challenged, or explained.
Identify devices, accounts, exports, reports, media, and other relevant records.
Use appropriate forensic acquisition and analysis methods for the evidence source.
Compare artifacts, timestamps, records, metadata, and surrounding context.
Explain findings and limitations without overstating conclusions.
Expert reports and litigation support
Depending on the scope, Rune Forensics can provide written forensic findings, attorney consultation, explanation of technical evidence, demonstrative support, deposition support, and expert testimony where appropriate.
For Portland and Southern Maine matters, services may be coordinated through remote consultation, secure evidence transfer, physical evidence shipment where appropriate, scheduled evidence delivery, onsite collection by arrangement, and forensic examination after transfer.
Scope dependent work may include documented acquisition, extraction review, preserved exports, forensic images, or source record review.
Deliverables may include artifact findings, timelines, technical consultation, written reports, exhibits, and independent review findings.
Support may include consultation, deposition preparation, testimony, and explanation of technical evidence.
Serving Portland and Southern Maine
Rune Forensics supports Portland and Maine matters where the evidence and scope are appropriate.
Review related services, read forensic resources, or start a scoped inquiry through contact.
Devices can be transported, shipped, or handled by arrangement. Existing reports, UFDR files, cloud exports, media files, and other electronic records may also be reviewed remotely when the scope allows.
FAQ
Yes. Work may include mobile device review, computer forensics, cloud and email evidence, independent report review, and expert consultation for attorneys, businesses, investigators, insurers, and individuals with legitimate forensic needs.
Yes. Existing Cellebrite extractions may be reviewed for extraction scope, parsed records, source artifacts, timestamps, application databases, omitted context, and limitations.
Yes. A Reader or UFDR report can be reviewed, but a report view may not show every source artifact or database detail. The underlying extraction can provide important context.
Yes, where legally and technically appropriate. The method depends on the device model, operating system, security state, authorization, and available forensic support.
Sometimes. Recovery depends on the device, operating system, application, encryption, elapsed time, storage activity, backups, and acquisition method.
Yes. Review may include seized device reports, Cellebrite extractions, police forensic reports, search warrant returns, communications, location evidence, timestamps, and methodology.
Where retained and appropriate, Rune Forensics can provide written findings, attorney consultation, deposition support, testimony support, and explanation of technical evidence.
Video and image authentication may include metadata, encoding characteristics, file structure, edit indicators, compression, source records, and surrounding context.
Yes. Suspected deepfake or AI generated media can be reviewed for technical indicators, provenance, account records, file history, and contextual evidence.
No. Rune Forensics does not maintain a Portland office. Portland area matters are handled through secure arrangements, shipping, transport, remote review where appropriate, or other agreed evidence handling methods.
Maine forensic review
Helpful starting information includes the nature of the matter, the type of evidence, device make and model if known, whether an extraction or forensic report already exists, and any preservation or litigation deadline.
Contact Rune Forensics