iOS and Android coverage
Mobile-device acquisition and artifact reconstruction across the major mobile platforms.
OpenText • Digital forensics
OpenText Mobile Investigator covers iOS and Android mobile-device forensics for field and lab use, with court-defensible evidence packaging and integration into the rest of the OpenText DFIR line.
A Merito Mobile Investigator engagement assesses the customer's mobile case profile honestly (corporate and civil cases vs. locked-device-heavy criminal cases), stands up field-acquisition and lab-mode workflows accordingly, and pairs with EnCase Forensic for unified court-defensible evidence.
What it is
OpenText Mobile Investigator is the mobile-device forensic product inside the OpenText DFIR line. It covers iOS and Android device acquisition, artifact reconstruction, and evidence packaging for criminal, civil, and corporate investigations. Mobile devices have become the primary repository of personal and operational data for most users, and DFIR programs that ignore mobile forensics miss most of the relevant evidence on modern cases.
Honest market positioning: Cellebrite (UFED) leads mobile forensics market share. Cellebrite has the deepest device-coverage and exploit catalog, particularly on locked-device scenarios where extracting evidence requires specialized techniques. OpenText Mobile Investigator is competitive on day-to-day mobile forensics, integrates natively with the rest of the OpenText DFIR line, and covers the standard iOS and Android case load most corporate and civil investigations face. Programs running specialist criminal-investigation mobile forensics typically pick Cellebrite; programs running corporate and civil mobile forensics inside an OpenText DFIR line consolidate on Mobile Investigator.
Field and lab use is the operational shape. Mobile Investigator runs in field acquisition mode (responder collects evidence from a phone in the field) and lab analysis mode (forensic analyst runs deep analysis on acquired data in the lab). Programs running the EnCase chain-of-custody discipline get integrated court-defensible evidence packaging across mobile and disk forensics.
What breaks Mobile Investigator adoption is misaligning the tool to the case profile. Programs running heavy criminal-investigation mobile forensics with frequent locked-device scenarios sometimes find Mobile Investigator's coverage insufficient and need Cellebrite. Programs running corporate and civil cases with cooperative-user scenarios get the value Mobile Investigator delivers. Merito's engagement scopes the case profile honestly so the tool fits the work.
Ideal use cases
What it is best at
Mobile-device acquisition and artifact reconstruction across the major mobile platforms.
Field acquisition for IR responders and lab analysis for forensic depth in one product.
Mobile evidence integrates with disk-level Forensic analysis for unified court-defensible evidence.
Audit and chain-of-custody discipline through Information Assurance; tiered triage through Endpoint Forensics and Response.
Chain-of-custody evidence packaging that fits OpenText DFIR line discipline.
Core capabilities
Where Mobile Investigator extracts evidence from devices.
iOS acquisition
Logical and file-system iOS acquisition for cooperative-user and supported scenarios.
Android acquisition
Logical and file-system Android acquisition with broad device coverage.
Field-mode acquisition
On-scene acquisition workflow for IR responders.
Cloud backup acquisition
iCloud, Google account, and other cloud backup forensic acquisition where authorized.
Lab-mode artifact reconstruction.
Artifact reconstruction
Messages, call logs, contacts, location data, app data, photos, and other mobile-specific artifacts.
App-data analysis
Common-app artifact reconstruction (messaging, social, productivity, financial apps).
Cross-device timeline
Timeline reconstruction across mobile and disk evidence when paired with EnCase Forensic.
Search and indexing
Full-text and metadata search across acquired mobile evidence.
Court-defensible packaging inside the DFIR line.
Chain-of-custody packaging
Evidence packaging compatible with EnCase forensic chain-of-custody discipline.
EnCase Forensic integration
Mobile evidence integrates with disk-level Forensic analysis for unified court-defensible evidence.
Information Assurance integration
Audit and chain-of-custody discipline across mobile forensic actions.
Compliance reporting
Audit-ready evidence for legal and regulated proceedings.
Where it fits in the stack
Deployment and implementation
Licensing and packaging
Mobile Investigator standalone
Standalone mobile forensic product for field and lab use.
Best for: DFIR teams running mobile forensic case loads.
Mobile Investigator with EnCase Forensic
Bundled with EnCase Forensic for integrated mobile and disk forensics.
Best for: DFIR labs running unified mobile and disk evidence.
Merito services
Merito sells licenses and the delivery work around them. Pick the service that matches where you are in the lifecycle.
Deployment, field-acquisition setup, EnCase Forensic pairing, case-profile assessment.
Explore service02DFIR program scoping for OpenText Mobile Investigator alongside Cellebrite UFED and Magnet AXIOM Cyber.
Explore service03IR-workflow integration with mobile triage.
Explore service04Named engineer, priority SLAs, and release-time coverage for Mobile Investigator.
Explore service05Long-term run support including field-acquisition operations, lab-analysis maintenance, and EnCase Forensic integration upkeep.
Explore service06Role-based training for DFIR analysts and IR responders.
Explore service07Merito-placed DFIR engineers and OpenText specialists embedded on long-running programs.
Explore serviceOpenText Mobile Investigator licensing
Mobile Investigator pricing arrives with deployment, field-acquisition setup, EnCase Forensic pairing, and honest case-profile assessment so the tool fits the investigation requirements (Cellebrite for locked-device-heavy cases, Mobile Investigator for OpenText-DFIR-line corporate and civil work).
Merito point of view
Merito has scoped DFIR programs where Cellebrite UFED is the right answer (criminal-investigation case loads with frequent locked-device scenarios, programs requiring the deepest device-coverage catalog) and others where OpenText Mobile Investigator is the right answer (corporate and civil case loads, programs running OpenText DFIR line consolidation, programs that want EnCase Forensic-integrated mobile evidence). Both decisions are valid; the right one depends on the case profile.
Merito recommends OpenText Mobile Investigator specifically for programs running corporate and civil mobile forensics and for programs already running OpenText DFIR line consolidation. For programs picking specialist mobile forensic depth, Cellebrite UFED is the market leader and Magnet AXIOM Cyber is competitive on cloud-mobile forensics. Merito surfaces those alternatives honestly during scoping.
Case-profile assessment is the load-bearing decision. Programs that adopt Mobile Investigator without honest case-profile assessment sometimes find that locked-device scenarios or specialist exploit requirements exceed the product's capability. Merito treats case-profile assessment as central work in the implementation rather than a checkbox.
What buyers usually underestimate
Related from Merito
Related solutions
Related services
Related products
Frequently Asked Questions
Consultation request
Share your mobile forensic case load, OpenText DFIR footprint, and program priorities. A Merito OpenText specialist follows up within one business day.
iOS and Android
On-scene acquisition and lab-grade analysis for corporate, civil, and law-enforcement cases.
DFIR line integration
Unified court-defensible evidence across mobile and disk forensics.
Next step
A Merito Mobile Investigator engagement scopes the case profile alongside deployment. Programs that mismatch tool capability to investigation requirements struggle on locked-device scenarios.