Mobile device forensics is systematically structured into three primary methodological categories: manual extraction, logical extraction, and physical extraction. Manual extraction involves an examiner visually reviewing and photographing on-screen device contents. Logical extraction utilizes software protocols to pull active file systems, directories, and structured databases recognized by the operating system. Physical extraction—the most comprehensive and technically rigorous method—involves executing a bit-by-bit memory dump of the entire flash storage chip, enabling recovery of deleted files, unallocated space artifacts, and hidden system data.