For Counsel · Received Extractions

You Got a Cellebrite Extraction in Discovery. Now What?

Open it today, on your own machine, without an enterprise license. Triage it free, analyze it fully for $599 one-time and keep the evidence in your custody the entire time.

An attorney who receives a Cellebrite UFED or VeraKey full-filesystem extraction in discovery can open it in Sherlock Forensics iPhone Analyzer without any Cellebrite license. The free edition previews every artifact view for triage; the $599 Forensic Edition unlocks full analysis, search, export and a court-ready report. Fully offline, read-only, evidence never leaves counsel's custody.

Windows 10/11 | One-time license | Fully offline | 100 percent read-only

The Situation

The Production Arrived. The Tool That Reads It Did Not.

It is one of the most common asymmetries in modern litigation. The producing party, often the prosecution or a better-resourced opponent, worked the phone evidence on an enterprise forensic platform. What lands on your side is a drive or a download link: a folder tree, some descriptor files with unfamiliar extensions and a report PDF that shows you exactly what the other side chose to show you.

The platforms that traditionally open that production are licensed by annual subscription in the four to five figures, priced for labs that acquire devices weekly, not for counsel who needs to review one production in one matter. The practical alternatives have been ugly: pay a vendor thousands to re-host the extraction, rely on the producing party's own report or let the deadline pressure decide for you.

Sherlock Forensics iPhone Analyzer removes that dependency. It opens the extracted Cellebrite UFED tree directly. The same ingestion is validated on VeraKey (Grayshift, now Magnet Forensics) productions. Your review is no longer limited to the report the other side generated; you work the underlying evidence yourself.

Free First

Triage the Production Before You Spend a Dollar

The free edition is a working triage tool, not a crippled demo. It opens the production and previews every artifact view: the first 25 percent of each view, capped at 100 rows, with file metadata and hashes visible. In one sitting you see the shape of the evidence: which message threads exist and with whom, the call patterns, the location picture, the app inventory and what the automated findings flag.

That changes the sequencing of the whole review. Instead of retaining an examiner to tell you whether the production matters, you learn whether it matters first, then brief the examiner with specifics: these three threads, this date range, this location question. The $599 Forensic Edition unlocks the complete data set, global and keyword-watchlist search, export and the court-ready report when the matter justifies it, a spend a single case budget absorbs.

Every hour of that review happens on your own workstation, offline. The production is never uploaded, never synced and never modified; analysis is 100 percent read-only. That keeps the review consistent with the custody terms most protective orders impose, though the specific order governing your matter always controls.

How To

How to Review a Produced Extraction, Step by Step

  1. Preserve the original. Keep the production media and archive intact as received. Work from a copy, consistent with your protective order and chain-of-custody practice.
  2. Unpack a working copy. Extract the archive copy to a local folder so the full-filesystem tree and its .ufd, .ufdx and DeviceInfo.txt descriptors are browsable.
  3. Triage free. Open the tree in Sherlock. Detection is automatic. Preview every view and decide whether the production matters to the case.
  4. Verify provenance. The extraction-provenance view merges the UFED descriptors into one record: device model, iOS build, acquisition tool and version, capture times and the per-dump SHA-256 and HMAC recorded at acquisition, carried verbatim. Your examiner can compare the recorded hashes against the files as received.
  5. Analyze and report. Unlock the Forensic Edition when justified, work the full data set across 130+ views and produce the court-ready report with an optional SHA-256 evidence-integrity manifest.

Beyond Their Report

See What the Producing Party's Report Left Out

A produced report is a set of choices: which artifacts were run, which filters were applied, which threads were exported. Working the underlying extraction yourself replaces those choices with your own. Sherlock presents the evidence in dedicated, searchable views that feed one merged timeline and one global search, so the questions that matter to your theory of the case get asked directly:

  • Pattern of life: Screen Time usage with daily totals, power-log app usage, app install and uninstall history, the launch-by-launch app sequence and the Focus and Do Not Disturb timeline, the behavioral picture around the moments that matter.
  • Whereabouts: significant locations with dwell times and enter and exit transitions, Apple Maps history, Find My devices and Waze destinations.
  • Messaging beyond iMessage: chat recovered from on-device web caches for Skype, Facebook Messenger, Instagram and TikTok direct messages, Discord, Reddit and others, alongside delivered-notification previews that survive in-app deletion. These are recovered from web caches and notification previews for apps whose message stores are not directly readable; the interface and report label them as such.
  • Deleted and hidden: hidden and deleted photos, records carved from freed SQLite pages and media the device owner did not intend to surface.

Everything exports to CSV or JSON. Flagged items roll into a report your examiner can stand behind. The producing party's platform did the acquisition; Sherlock gives your side a real analysis seat on the result.

See It

Sherlock Forensics iPhone Analyzer dashboard overview of an ingested extraction with device summary, artifact counts and investigative highlights
The production, triaged: every artifact and finding in one dashboard
Sherlock Forensics iPhone Analyzer threaded conversation reconstruction with attachments from a produced extraction
Threaded conversations with attachments
Sherlock Forensics iPhone Analyzer merged activity timeline correlating events across every artifact source
One merged timeline across the whole device
Sherlock Forensics iPhone Analyzer global search running a keyword across every artifact view in the production
One search across every artifact in the production

Chain of Custody

Provenance You Can Put in Front of a Court

Reviewing a production raises the integrity question in both directions: you need to show your review did not alter the evidence and you may want to test whether the production matches what was acquired. Sherlock supports both. Analysis is 100 percent read-only. The extraction-provenance view carries the UFED descriptors verbatim, including the per-dump SHA-256 and HMAC values recorded at capture, so recorded hashes can be compared against the files as received and the result stated on the record.

The court-ready HTML report documents case and evidence numbers, examiner identification, disclosed methodology and an optional SHA-256 evidence-integrity manifest, the documentation elements described in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics. The tool is built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice. None of this is legal advice; admissibility and protective-order compliance are questions for counsel in the specific jurisdiction and matter.

Honest Scope

What This Workflow Is and Is Not

Sherlock analyzes the production you received; it does not create extractions of locked devices and it does not bypass security on any iPhone. Full-filesystem acquisition is the acquisition platform's job: Cellebrite or GrayKey class tooling produced what you were handed. Sherlock's own acquisition of a device in hand uses Apple's supported logical path and requires the passcode and the Trust prompt.

Confirmed ingestion formats are Cellebrite UFED and VeraKey full-filesystem extractions, validated against real device images. Received something else? Contact us before purchasing and we will confirm whether the layout is readable. For the full capability picture, see the Sherlock Forensics iPhone Analyzer product page and the companion guide to reading a Cellebrite UFED extraction.

Questions

Received-Extraction FAQ for Counsel

Opposing counsel produced a Cellebrite extraction. How do I open it?
Unpack the produced archive to a local folder on a Windows workstation and point Sherlock Forensics iPhone Analyzer at the extracted tree. It detects the UFED layout, resolves every artifact at its real on-device path and presents the evidence in dedicated searchable views. No Cellebrite license is required to analyze a production you already hold.
Can I look at the production before spending anything?
Yes. The free edition opens the extraction and previews every artifact view: the first 25 percent of each view, capped at 100 rows, with file metadata and hashes. That is a genuine triage pass across messages, calls, locations and app data before any purchase decision.
Does the produced evidence leave my custody during analysis?
No. Sherlock runs entirely on your own workstation and is fully offline. Nothing is uploaded anywhere. Analysis is 100 percent read-only, so the production itself is never modified. That keeps review inside typical protective-order obligations, though counsel should always confirm against the specific order governing the matter.
Can I verify the production was not altered before it reached me?
The extraction-provenance view carries the UFED .ufd, .ufdx and DeviceInfo.txt descriptors verbatim, including the per-dump SHA-256 and HMAC values the acquisition tool recorded at capture. Your examiner can compare those recorded hashes against the files as received and testify to the result.
What if the production came from VeraKey instead of Cellebrite?
Sherlock reads both. Full-filesystem ingestion is validated on Cellebrite UFED and on VeraKey (Grayshift, now Magnet Forensics) extractions, with device identity read from authoritative on-device sources.
Do I still need a forensic examiner?
For strategy and testimony, usually yes. What changes is the economics and the control: counsel can triage the production immediately instead of waiting for a vendor, decide which threads matter and brief the examiner with specifics. The court-ready report with its SHA-256 evidence-integrity manifest supports the examiner's testimony; it does not replace professional judgment or legal advice.
What does a full analysis cost?
$599 one-time for the Forensic Edition. No subscription and no per-case fees. It unlocks the complete data set, global and keyword-watchlist search, CSV and JSON export and the court-ready HTML report. Compare that with a second enterprise analysis seat at four to five figures per year or per-matter vendor hosting fees.

Start Now

The Production Is Sitting There. Open It.

Download the free edition, point it at the produced tree and know by the end of the day whether the evidence matters. Unlock the full analysis seat when it does: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: Read a Cellebrite UFED extraction · Product page · What Cellebrite actually costs