Per-Artifact Deep Dive

App Inventory: What Was Installed and What Was Hidden

The list of apps on a phone is a map of where evidence lives and whether someone tried to bury it. Here is what the inventory shows, what it says about anti-forensic behavior and how it reaches a courtroom.

Sherlock Forensics iPhone Analyzer inventories installed and previously installed iPhone apps with their versions, bundle identifiers, permissions and install timeline, then flags wipe, vault and encrypted-messaging apps by category. The installed list reads from a backup; the full install and uninstall history comes from a full-filesystem extraction. The finding is that an app was present, not its content. $599 one-time; the free edition previews it first.

Windows 10/11 | One-time license | Backup for installed apps, extraction for full history | 100 percent read-only

The Artifact

The Map of a Device

Before an examiner reads a single message, the list of apps on a phone already tells a story. It shows where communication happened, where files could be stored and which tools a subject chose to install. Sherlock Forensics iPhone Analyzer builds that inventory into one searchable view: the apps on the device with their versions, their bundle identifiers, the permissions they hold and, where the evidence supports it, when they were installed. It is the map you read first to know where the rest of the evidence lives.

Permissions add a second layer to the inventory. An app that holds location, microphone, camera or full-photo access is an app worth understanding, because the permission tells you what the app could reach. Read alongside the usage record, the inventory moves from a static list to a working picture: which apps were on the device, what they were allowed to touch and how active they were. That framing is what turns a pile of app data into a plan for the examination.

Anti-Forensic Signals

When the App Itself Is the Evidence

Some apps matter not for what is inside them but for the fact that they are there at all. Secure-delete and wipe utilities, hidden-vault and photo-locker apps that disguise stored content and encrypted-messaging apps all tell an examiner something before their data is ever opened. Sherlock surfaces these by category in the inventory, so an examiner sees at a glance that a device carried the tools of concealment or destruction. The finding here is presence, not content: that the app was installed and when.

Timing is what makes this powerful. An encrypted-messaging app installed the week an event took place, a photo-vault added right before a device changed hands or a wipe utility removed the day after are the kind of context the raw artifacts do not carry on their own. Where a full-filesystem extraction preserves the uninstall record, a deleted app becomes visible too. A vault or wipe app that was installed and then removed shortly before acquisition is often more telling than one still on the phone. Sherlock reports these as what they are, presence and timing, leaving the inference to the examiner and the trier of fact rather than overstating what an app's mere existence proves.

Source Scope

What Each Source Shows

Being precise about source is part of what keeps this artifact defensible. The currently installed apps are visible from an encrypted backup, so a logical acquisition already gives an examiner the installed inventory and app permissions. The full install and uninstall history, the deeper app metadata and the strongest anti-forensic picture, including apps that were removed, come from a Cellebrite UFED or VeraKey full-filesystem extraction.

Sherlock states which detail belongs to which source rather than implying a backup surfaces the whole history. Where the evidence is a backup, an examiner works the installed inventory and permissions honestly. Where a full-filesystem extraction is in hand, the uninstall record and the deeper metadata open up. The anti-forensic reading gets far stronger because removed tools come into view.

See It

Sherlock Forensics iPhone Analyzer app inventory view showing installed apps and their permissions from an iPhone
Installed apps with the permissions they hold, in one searchable inventory

Court-Ready

From the Inventory to the Report

App-presence evidence has to be stated with care because it is easy to overread, so the report is built to keep it precise: the court-ready HTML report carries case and evidence numbers, examiner identification, disclosed methodology, per-artifact SHA-256 hashing and an optional evidence-integrity manifest, with app presence and timing described for exactly what they are, the documentation practice set out in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics. Analysis is 100 percent read-only; the evidence is never modified.

Built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record so testimony rests on it rather than on recollection.

Honest Scope

What This Analysis Is and Is Not

Sherlock inventories the apps the acquired evidence records and flags categories of interest by their presence. It does not unlock a locked device, does not bypass a passcode and does not claim that installing an app proves intent on its own. The presence of a vault or a wipe app is a signal an examiner weighs, not a verdict. A backup shows the installed apps; the full install and uninstall history needs a full-filesystem extraction. Sherlock does not pretend a backup carries the removed-app record. Sherlock reports what the acquired evidence holds and describes presence and timing precisely, which is what an examiner can defend on the stand.

Questions

App Inventory FAQ

What app inventory does Sherlock build from an iPhone?
Sherlock Forensics iPhone Analyzer inventories the apps on an iPhone: installed and previously installed apps with their versions, bundle identifiers, permissions and the install timeline the evidence retained. It gives an examiner one searchable list of what was on the device and, where the source supports it, what used to be.
What is anti-forensic app detection?
It is surfacing apps whose presence is itself relevant: secure-delete and wipe utilities, hidden-vault and photo-locker apps and encrypted-messaging apps. Sherlock flags these by category so an examiner sees them in the inventory. The finding is that the app was present, not the content of any app; the presence and timing are the intelligence.
Can Sherlock show apps that were deleted?
Where the source retains it, yes. A full-filesystem extraction preserves traces of apps that were installed and later removed, so Sherlock can surface previously installed apps and uninstall timing that a plain installed-app list would miss. A cleared app is a data point, especially a wipe or vault app removed shortly before acquisition.
Does app inventory need a full-filesystem extraction?
The currently installed apps are visible from an encrypted backup. The full install and uninstall history, deeper app metadata and the strongest anti-forensic picture come from a Cellebrite UFED or VeraKey full-filesystem extraction. Sherlock states which detail belongs to which source rather than blurring them.
Why does the app inventory matter?
It frames the rest of the examination. Knowing which messaging, storage or anti-forensic apps were present tells an examiner where evidence might live and whether a subject took steps to hide or destroy it. An encrypted-messaging or wipe app installed right before an event or removed right after is context the raw artifacts do not give on their own.
Is app-inventory evidence court-defensible?
Analysis is read-only and the court-ready report documents examiner details, methodology and per-artifact SHA-256 hashing, with app presence and timing described for exactly what they are. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record for testimony.

Start Now

See the App Inventory in Your Evidence

Download the free edition, open a backup or extraction and read the app inventory yourself. Unlock the full history and the court-ready report when the case calls for it: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: iPhone full-filesystem analysis · Read a Cellebrite UFED extraction · The full parser list · Product page