Digital forensics for private investigators

Cell Phone and Tablet Forensics for Private Investigators

Get the texts, images, locations, call logs and app data your cases turn on, off phones and tablets you are authorized to examine, in court-ready reports. One-time price, no lab and no $15,000 Cellebrite bill.

Cell phone forensics for a private investigator is the authorized extraction and examination of data from a phone or tablet, such as messages, call logs, photos, location history and app records, documented in a court-ready report. Sherlock Forensics tools do this by logical acquisition on devices you have consent or lawful authority to examine, for a one-time price.

Authorized work only. These tools are for investigators working with the device owner's consent or a lawful authority to examine the device. They are not a way into a phone you are not permitted to access, and they do not bypass a locked or encrypted device. Access requires the device be unlocked and, on Android, that USB debugging can be enabled.

Cell phone data extraction

What a private investigator can extract from a phone

With authorized access to an unlocked device, phone forensics on a modern handset is logical acquisition: the tool collects the records the operating system will hand over, parses them into readable evidence and hashes every item for a court-ready report. On a typical case that covers:

  • Messages. SMS, MMS, RCS and the app messages whose databases are accessible on the device.
  • Call logs and contacts. Incoming, outgoing and missed calls with timestamps, tied to the address book.
  • Images and video. Photos and video in accessible storage, with capture time and, where the file carries it, GPS location.
  • Location history. Location records the device and its accessible apps retain, on a timeline.
  • App data. Records from apps whose data is readable on the device, parsed into conversations, events and files.

Every acquired item is recorded with its source and a SHA-256 hash, and the examination produces a court-ready report an investigator or attorney can hand to opposing counsel. This is real cell phone data extraction and forensic phone examination, done on your own workstation, with no evidence sent to a cloud.

Honest limits

What phone forensics can and cannot recover

Court-defensible work means being precise about what survives on a modern phone. The overclaims you will read elsewhere do not hold up under cross-examination.

  • Deleted records, not deleted files. Carving a deleted photo back off the raw storage is effectively gone on a modern encrypted phone, because the device encrypts each file and wipes freed blocks. What can be recovered is a deleted record that still lingers inside an accessible database, for example a message left in a database's free space or preserved in a later reply that quoted it. Every recovered item is flagged as recovered with its exact source.
  • WhatsApp and other protected apps are conditional. Logical acquisition collects accessible WhatsApp media and a local encrypted backup when one is present, and reading that backup needs the supported format and the correct key. It does not reach WhatsApp's protected live chat database, which sits in app-private storage that requires a full-filesystem or rooted acquisition. The report records the access decision the device made, including the routes it denied.
  • Locked or encrypted devices. These tools do not break a passcode or defeat encryption. The device must be unlocked and accessible.

That transparency is the point. A report that states exactly what was collected, what was recovered and what the device refused is what holds up in front of a judge, and it is what a blanket promise to "recover deleted data" cannot stand behind.

Cellebrite cell phone forensics, without the Cellebrite bill

Why private investigators choose Sherlock Forensics over Cellebrite and Magnet

Cellebrite and Magnet build the platforms the largest labs run, at enterprise prices and with the training and lab overhead to match. For the private investigator doing digital forensics on a consenting client's device, that is far more tool than the case needs. Sherlock Forensics gives you the logical acquisition, the examination workspace and the court-ready report for a one-time price.

CapabilitySherlock ForensicsCellebrite / Magnet
PriceOne-time, from $399Thousands per year, per seat
SetupInstalls on your own Windows, macOS or Linux workstationLab hardware, licensing and training
Logical acquisition with authorized accessYesYes
Court-ready hashed reportYesYes
Reads a Cellebrite or Magnet full-filesystem image you were givenYesYes
Runs entirely offline, no evidence to a cloudYesVaries
Physical extraction and locked-device accessNo, logical acquisition onlyYes, at enterprise cost

Where a case genuinely needs physical extraction or locked-device access, that remains the enterprise platforms' territory. For the authorized, consent-based work that fills a private investigator's caseload, Sherlock Forensics covers it for a fraction of the cost.

The tools

Pick the tool for the device

Sherlock Forensics Android Acquirer

$399 one-time

Logical acquisition of an Android phone or tablet over authorized ADB, with examination of a full-filesystem image you were given. Messages, call logs, media, locations and app records across a large parser catalog, in a court-ready report.

See Android Acquirer

Sherlock Forensics iPhone and iPad Analyzer

$599 one-time

Acquire and analyze logical iPhone and iPad backups, and read Cellebrite or Magnet full-filesystem extractions, with 200+ artifact views, encrypted-backup decryption using the correct key, and court-ready reports.

See iPhone and iPad Analyzer

Sherlock Forensics PST Viewer

Free, Forensic Edition from $67

When a case turns on email, open and search PST and OST archives without Outlook, view attachments and export messages, with a forensic report and SHA-256 verification.

See PST Viewer

Straight answers

Private investigator phone forensics FAQ

Can a private investigator do phone forensics?

Yes, on a device they are authorized to examine, with the owner's consent or a lawful authority. Modern phone forensics on an unlocked, accessible device is logical acquisition: collecting the messages, call logs, media, locations and app records the device will hand over, and documenting them in a court-ready report. It does not extend to a device the investigator is not permitted to access, and it does not bypass a locked or encrypted phone.

What can a private investigator extract from a phone?

With authorized access to an unlocked device: SMS, MMS and accessible app messages, call logs and contacts, photos and video with capture time and any embedded GPS, location history and records from apps whose data is readable on the device. Each item is hashed and sourced for a court-ready report. Protected app databases such as WhatsApp's live chat store require a full-filesystem or rooted acquisition rather than ordinary logical access.

Do I need Cellebrite for cell phone forensics?

Not for authorized, consent-based logical work. Cellebrite and Magnet are enterprise platforms priced for large labs and needed mainly for physical extraction and locked-device access. For extracting and examining the accessible data on a consenting client's phone or tablet, Sherlock Forensics gives you logical acquisition and a court-ready report for a one-time price, and it also reads a Cellebrite or Magnet full-filesystem image you were given in discovery.

Can these tools recover deleted texts or photos?

Within honest limits. Carving a deleted file back off a modern encrypted phone is effectively impossible for any tool, because the device wipes freed blocks. What can be recovered is a deleted record that still survives inside an accessible database, and every recovered item is flagged with its exact source. No tool honestly un-deletes photos that the device has already cleared.

Are the reports court-ready?

Yes. Every acquired and recovered item carries its source and a SHA-256 hash, the report records the access decisions the device made, and the examination runs offline on your own workstation with no evidence sent to a cloud. That provenance is what holds up under examination.