Before an examiner reads a single message, the list of apps on a phone already tells a story. It shows where communication happened, where files could be stored and which tools a subject chose to install. Sherlock Forensics iPhone Analyzer builds that inventory into one searchable view: the apps on the device with their versions, their bundle identifiers, the permissions they hold and, where the evidence supports it, when they were installed. It is the map you read first to know where the rest of the evidence lives.
Permissions add a second layer to the inventory. An app that holds location, microphone, camera or full-photo access is an app worth understanding, because the permission tells you what the app could reach. Read alongside the usage record, the inventory moves from a static list to a working picture: which apps were on the device, what they were allowed to touch and how active they were. That framing is what turns a pile of app data into a plan for the examination.
