Earlier quoted context omitted.
You will never be able to justify the collateral intrusion that getting all the connections to a single cell site would represent. If you don't know who you're looking for then it isn't actually that much help in any case. Assuming you know that the suspect phone will have pinged a given cell site, then you still have to work out which phone it was. Assuming that they're not daft enough to use anything other than an…
I'm not sure if you read the links? The UK doesn't have the same requirements as the US. They don't have a collateral intrusion limitation. Once you have the IMEI of interest you can find everywhere it has been and every number dialled, and all DNS requests and IP transfers. You just need a dialled number which has a plan attached and you can look up the phone book entry from that persons phone (though police would n…
Once you have an IMEI number that you can attribute to the suspect, having exhausted all conventional means of finding the data then you go ahead and start requesting billing and cell site data.
Note, however, that this won't tell you what ip addresses have been assigned to that account.