2. Contents
• Basics of Mobile Technologies
▫ IMEI, IMSI, MSISDN
• Investigation using Mobile
▫ Mobile found on a crime scene
▫ Investigating using mobile number
▫ Using IMEI & IMSI in investigation
• Location Tracing
▫ Interceptors
▫ Cell ID
▫ LAC ID
▫ Triangulation (Theoretical)
3. AIM of the Course
To equip the investigation officers on modern
techniques for approaching from crime scene to
the criminal, by using scientific ways
4. Basics of Mobile Technologies
• IMEI
▫ Stands for International Mobile Equipment
Identity
▫ IMEI can be simply defined as the Chassis number
of a Mobile Set.
▫ It is unique to every Mobile set.
For mobile sets with dual SIM support there are two
IMEI.
▫ To find IMEI number you have to dial *#06# from
the respective mobile set, or just see it from the
label below battery of mobile set.
5. Basics of Mobile Technologies
• IMEI
▫ IMEI is of 15 digits
▫ Last digit is known is check digit or network digit.
▫ We usually ignore last digit in investigation
because it is not fixed. Every network read it
differently.
6. Basics of Mobile Technologies
• IMSI
▫ Stands for International Mobile Subscriber
Identity
▫ IMSI can be simply defined as the Chassis number
of a SIM card.
▫ It is unique to every SIM Card.
▫ It is written on back side of SIM.
▫ Replacing a SIM for same mobile number will
change IMSI.
▫ IMSI of Pakistani SIMs has a prefix of 410
7. Basics of Mobile Technologies
• MSISDN
▫ Stands for Mobile Systems International
Subscriber Identity Number.
▫ MSISDN is the mobile number in full format.
▫ If your mobile number is 03001234567 then
MSISDN of your number would be
+923001234567.
(+92 or 0092 is the International dialing code for
Pakistan)
8. Investigation using Mobile
• In some cases you might find a mobile set on a crime
scene. Being investigation officer you have to
consider mobile phone as a normal evidence as well.
You have to look for fingerprints and blood strains
on mobile sets first. After normal investigation then
you will come to technical investigation.
• Once you are done with fingerprints & blood strains
related investigation on mobile then you will look if
the mobile is in working condition, if its in working
condition switch on mobile phone.
9. Investigation using Mobile
• First thing to check after switching on mobile
phone is to check Missed Call details from
mobile phone. Because you will not find missed
call information in CDR or any other source
once lost from mobile phone call register.
• Missed call information are very helpful in
investigating things because criminals use
missed calls as preset indication of some activity.
• Also note down contact details from phonebook.
10. Investigation using Mobile
• Pictures & Videos can also help in investigation
so go through gallery of the mobile set as well.
• If mobile set found on crime scene is not in
working condition so don’t worry you still can
use it in investigation in many ways. Find IMEI
on the back of the mobile set.
11. CDR
• CDR stands for Call data record
• On second stage call detail record of the suspect
number is obtained .
• Call detail record reveals location of the calls,
timing, IMEI number . Contacts, duration etc.
• All above mentioned details reveals a sketch of
the nature of the suspect like professional or
none professional, new gang or old gang.
• This helps in interrogation process as well.
12. CDR
• CDR can also be obtained by sending IMEI of the mobile
set.
• CDR by Mobile number or IMEI or IMSI can be obtained
from concerned mobile companies of intelligence
agencies. Khyber Pakhtunkhwa Police’s CTD department
is now authorized to request mobile companies for
issuance of CDR to them.
• You have to sent a letter to CTD or CKC for the issuance
of the CDR along with FIR number as case reference.
• CKC would further send an email to Mobile company
and they would sent back printed CDR to you.
13. DIFFERENT FORMAT OF CDR
• There is a log with every Call or SMS.
• Every mobile SIM(IMSI) number is different from
others and recognizable by its network system.
• When a person connects to another SIM through its
network, it makes log in the system, and when we
interpret that logs it gives us CDR.
• CDR of different companies are different in shape but
information it gives are almost the same.
14. TELENOR CDR FORMAT
MSISDN
CALL_DIALED
_NUM IMSI IMEI
CALL_START_
DT_TM
CALL_END_D
T_TM
INBOUND_O
UTBOUND_I
ND SEC: Cell_Lac_Id Cell_Site_Id CALL_TYPE Location
92346504073
0
92315259965
5
41006051454
7323
35742205358
011
2014-05-
2604:29:07 OUTGOING 0 471 4872 SMS
Village Shawa
Muhallah Ahmed
KhelTehsil & District
Swabi SWABI
92346504073
0
92315259965
5
41006051454
7323
35742205358
011
2014-05-
2604:29:43
2014-05-
2604:29:43 INCOMING 0 471 4872 SMS
Village Shawa
Muhallah Ahmed
KhelTehsil & District
Swabi SWABI
92346504073
0
92315259965
5
41006051454
7323
35742205358
011
2014-05-
2604:29:47 OUTGOING 0 471 4872 SMS
Village Shawa
Muhallah Ahmed
KhelTehsil & District
Swabi SWABI
92346504073
0
92315259965
5
41006051454
7323
35742205358
011
2014-05-
2604:30:09
2014-05-
2604:30:09 INCOMING 0 471 4872 SMS
Village Shawa
Muhallah Ahmed
KhelTehsil & District
Swabi SWABI
15. MOBILINK CDR FORMAT
Sr # Call Type A-Party B-Party Date & Time Duration Cell ID IMEI IMSI Site
1 Outgoing 923059748406 789 1-2-2014 15:58:28 113 CB10C082 353393043825590 410018728264770 AliSherKalay_new, Samar bagh distt lower dir
34.95306/71.6758
2 Outgoing 923059748406 789 1-2-2014 16:06:57 113 CB10A4B7 353393043825590 410018728264770 Rahemabad_BC, open plot of land total
measuring 60’ x 60’, situated at village
Raheemabad, P.O samarbagh, Tehsil
Samarbagh, District Dir (L).
34.95091/71.69273
3 Incoming SMS 923059748406 4D4 1-2-2014 16:09:03 0 CB10A4B7 353393043825590 410018728264770 Rahemabad_BC, open plot of land total
measuring 60’ x 60’, situated at village
Raheemabad, P.O samarbagh, Tehsil
Samarbagh, District Dir (L).
34.95091/71.69273
4 InComing 923059748406 3440905442 1-2-2014 18:48:15 220 CB10DF03 357876048705470 410018728264770 Kambut, plot measuring 10 marlas, bearing
khetoni no. 1, file book no. 1 situated at
village Likor Kambat, tehsil and samer bagh
abd District Dir Lower 34.9757/71.66876
16. ZONG CDR FORMAT
CALL_TYPE MSISDN_ID STRT_TM BNUMBER
MIN
S
SEC
S
LAC_I
D
CELL_I
D IMEI SITE_ADDRESS LNG LAT
Incoming Call 3153964393 24-02-14 8:20 3159148678 1 30 057E E5D4 357743046542860 Village Kaoga,Chamlha Tehsil Dagar Distt Bunar 72.51333 34.3904
Outgoing Call 3153964393 24-02-14 8:31 3159148678 0 12 057E E5D4 357743046542860 Village Kaoga,Chamlha Tehsil Dagar Distt Bunar 72.51333 34.3904
Outgoing Call 3153964393 24-02-14 8:33 3159148678 0 8 057E E5D4 357743046542860 Village Kaoga,Chamlha Tehsil Dagar Distt Bunar 72.51333 34.3904
Outgoing Call 3153964393 24-02-14 8:33 3159148678 1 66 057E E5D1 357743046542860 Village Kaoga,Chamlha Tehsil Dagar Distt Bunar 72.51333 34.3904
Incoming Call 3153964393 24-02-14 8:34 3159148678 1 42 057E E5D1 357743046542860 Village Kaoga,Chamlha Tehsil Dagar Distt Bunar 72.51333 34.3904
Outgoing Call 3153964393 24-02-14 8:38 310 0 1 057E E5D1 357743046542860 Village Kaoga,Chamlha Tehsil Dagar Distt Bunar 72.51333 34.3904
Outgoing Call 3153964393 24-02-14 8:41 222 0 1 057E E5D4 357743046542860 Village Kaoga,Chamlha Tehsil Dagar Distt Bunar 72.51333 34.3904
Outgoing Call 3153964393 24-02-14 8:42 3149875239 2 98 057E E5D4 357743046542860 Village Kaoga,Chamlha Tehsil Dagar Distt Bunar 72.51333 34.3904
Outgoing Call 3153964393 24-02-14 8:44 3159148678 3 154 057E E5D4 357743046542860 Village Kaoga,Chamlha Tehsil Dagar Distt Bunar 72.51333 34.3904
Outgoing Call 3153964393 24-02-14 8:47 3159911103 1 45 057E E5D4 357743046542860 Village Kaoga,Chamlha Tehsil Dagar Distt Bunar 72.51333 34.3904
26. Select column B and select Paste Special and select the checkbox of
“Skip Blanks” and ok
Now delete column C, now u r format is ready for analysis.
27.
28. Click on the Insert Tab and click on the
PivotTable
29. On the next screen click on “ok”
without changing any field
60. Select Column D and Right Click,
Select Paste Special, check skip blanks
and click ok
Then delete column E and the CDR is ready for further processing.
61. Picturial view of GSM Interceptor and DF
GSM Interceptor
GSM Interceptor fitted in Vehicle
Handheld DF
62. Corresponds to a single
cellular tower and
normally identifies the
sector of coverage 120
degree of 360 degree
coverage tower.
Sector1
Sector2
Sector3
63. A grouping of Cell IDs to form a broader coverage area
(sometimes is one per city or village)
64. The orientation is
the relationship
between the
directions on the
map and the
corresponding
cell ID direction
in reality.