Per-Artifact Deep Dive

Apple Maps and Waze: Where a Device Asked to Go

A navigation history is a record of intent, the places a device searched and the routes it asked for. Here is what a full-filesystem extraction holds, how to read it honestly and how it reaches a courtroom.

Sherlock Forensics iPhone Analyzer reconstructs Apple Maps and Waze history from a full-filesystem extraction: searched places, requested directions, dropped pins, favorites and recent locations. It reads this as navigation intent, that the device asked about a place, not proof the person traveled there or who was driving. This artifact needs a full-filesystem extraction, not a logical backup. $599 one-time; the free edition previews it first.

Windows 10/11 | One-time license | Full-filesystem extraction | 100 percent read-only

The Artifact

The Navigation Record

Where a person points their navigation is a window into what they were planning. Apple Maps and Waze keep a history of that: the places searched, the directions and routes requested, the pins dropped on the map, the favorites saved and the recent locations. Sherlock Forensics iPhone Analyzer reconstructs that record into a searchable view, drawing from both Apple Maps and Waze and attributing each entry to the app that produced it, with the times the navigation history retained.

The value is that navigation captures deliberate interest. A person may never message about a place, yet a route requested to its address is a documented act of looking it up and asking how to get there. Repeated searches for the same location, a saved favorite or a route planned to an address the day before an event are the kind of entries that reframe a timeline. Read across the merged Activity Timeline, navigation lines up against the location record, calls and messages, so intent and movement can be compared side by side.

The Honest Read

Intent, Not Proof of Travel

The discipline that keeps navigation evidence sound is refusing to overread it. A searched place or a requested route shows that the device asked about a location. It does not show that the person went there, nor who was holding the phone. Someone can look up an address they never visit. A route can be planned and abandoned. Sherlock presents Maps and Waze entries as navigation intent tied to the device, not as proof of travel, because that is what the artifact actually establishes.

Read that way, the evidence is strong rather than brittle. Navigation intent corroborated by the device location record, by a message or by a call to the same place becomes a persuasive picture, while navigation intent presented as proof of presence collapses the moment an opposing expert points out that a search is not a journey. Sherlock scopes it honestly so the examiner argues from what the record supports, attributing to the device rather than assuming the person, the same restraint the tool applies to every whereabouts artifact.

Source Scope

Why This One Needs a Full-Filesystem Extraction

The deeper Maps and Waze navigation history sits in app storage and system caches that a logical backup does not carry, so this artifact requires a Cellebrite UFED or VeraKey full-filesystem extraction. Sherlock scopes it to a full-filesystem source rather than implying a backup surfaces it. Where the evidence is only a logical backup an honest analysis says the deep navigation history is out of scope for that source.

Where a case already has a Cellebrite or VeraKey image, the navigation record is right there to work alongside the location history and the other whereabouts artifacts. Both Apple Maps and Waze come through the same extraction, each attributed to its own app, so an examiner reads the built-in and the third-party navigation side by side.

Court-Ready

From the Route to the Report

Navigation evidence has to be labeled as intent so it is never overstated into proof of travel, so the report is precise: the court-ready HTML report carries case and evidence numbers, examiner identification, disclosed methodology, per-artifact SHA-256 hashing and an optional evidence-integrity manifest, with navigation entries described as intent tied to the device, the documentation practice set out in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics. Analysis is 100 percent read-only; the evidence is never modified.

Built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record so testimony rests on it rather than on recollection.

Honest Scope

What This Analysis Is and Is Not

Sherlock reads Apple Maps and Waze history from a full-filesystem extraction produced by acquisition tooling. It does not unlock a locked device, does not bypass a passcode and does not surface the deep navigation history from a logical backup that never carried it. A searched place or requested route is navigation intent tied to the device, not proof that the person traveled there or who was driving. Sherlock reports what the acquired evidence holds and describes navigation as intent to be corroborated, which is what an examiner can defend on the stand.

Questions

Apple Maps and Waze Forensics FAQ

What Apple Maps and Waze history does Sherlock recover?
Sherlock Forensics iPhone Analyzer reconstructs the navigation record: searched places, requested directions and routes, dropped pins, favorites and recent locations from Apple Maps and Waze. It reads this from a full-filesystem extraction and presents it as navigation activity tied to times.
Does a Maps search prove someone went there?
No. A searched place or a requested route shows navigation intent, that the device asked about or was directed to a location, not that the person traveled there or who was holding the phone. It is corroborating whereabouts intent, weighed against location history and the rest of the record, not proof of travel on its own.
Does Maps and Waze history need a full-filesystem extraction?
Yes. The deeper Maps and Waze navigation history sits in app storage and system caches that a logical backup does not carry, so this artifact requires a Cellebrite UFED or VeraKey full-filesystem extraction. Sherlock scopes it to a full-filesystem source rather than implying a backup surfaces it.
Does Sherlock read Waze as well as Apple Maps?
Yes, where the extraction holds it. Waze is a third-party navigation app that keeps its own history of searched destinations and routes. Sherlock surfaces that alongside the Apple Maps record from a full-filesystem extraction, each attributed to its app.
How does navigation history help a case?
It shows where a device asked to go and when. A route requested to an address before an event, a place searched repeatedly or a saved favorite can establish interest in a location and line up against the location record and messages from the same window. Read as intent and corroborated, it builds a picture rather than standing alone.
Is navigation evidence court-defensible?
Analysis is read-only and the court-ready report documents examiner details, methodology and per-artifact SHA-256 hashing, with navigation entries described as intent tied to the device, not proof of travel. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record for testimony.

Start Now

See the Navigation Record in Your Evidence

Download the free edition, open a full-filesystem extraction and read the Apple Maps and Waze history yourself. Unlock the full analysis and the court-ready report when the case calls for it: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: Significant Locations forensics · Read a Cellebrite UFED extraction · iPhone full-filesystem analysis · Product page