Digital forensics for private investigators
Cell Phone and Tablet Forensics for Private Investigators
Get the texts, images, locations, call logs and app data your cases turn on, off phones and tablets you are authorized to examine, in court-ready reports. One-time price, no lab and no $15,000 Cellebrite bill.
Cell phone forensics for a private investigator is the authorized extraction and examination of data from a phone or tablet, such as messages, call logs, photos, location history and app records, documented in a court-ready report. Sherlock Forensics tools do this by logical acquisition on devices you have consent or lawful authority to examine, for a one-time price.
Cell phone data extraction
What a private investigator can extract from a phone
With authorized access to an unlocked device, phone forensics on a modern handset is logical acquisition: the tool collects the records the operating system will hand over, parses them into readable evidence and hashes every item for a court-ready report. On a typical case that covers:
- Messages. SMS, MMS, RCS and the app messages whose databases are accessible on the device.
- Call logs and contacts. Incoming, outgoing and missed calls with timestamps, tied to the address book.
- Images and video. Photos and video in accessible storage, with capture time and, where the file carries it, GPS location.
- Location history. Location records the device and its accessible apps retain, on a timeline.
- App data. Records from apps whose data is readable on the device, parsed into conversations, events and files.
Every acquired item is recorded with its source and a SHA-256 hash, and the examination produces a court-ready report an investigator or attorney can hand to opposing counsel. This is real cell phone data extraction and forensic phone examination, done on your own workstation, with no evidence sent to a cloud.
Honest limits
What phone forensics can and cannot recover
Court-defensible work means being precise about what survives on a modern phone. The overclaims you will read elsewhere do not hold up under cross-examination.
- Deleted records, not deleted files. Carving a deleted photo back off the raw storage is effectively gone on a modern encrypted phone, because the device encrypts each file and wipes freed blocks. What can be recovered is a deleted record that still lingers inside an accessible database, for example a message left in a database's free space or preserved in a later reply that quoted it. Every recovered item is flagged as recovered with its exact source.
- WhatsApp and other protected apps are conditional. Logical acquisition collects accessible WhatsApp media and a local encrypted backup when one is present, and reading that backup needs the supported format and the correct key. It does not reach WhatsApp's protected live chat database, which sits in app-private storage that requires a full-filesystem or rooted acquisition. The report records the access decision the device made, including the routes it denied.
- Locked or encrypted devices. These tools do not break a passcode or defeat encryption. The device must be unlocked and accessible.
That transparency is the point. A report that states exactly what was collected, what was recovered and what the device refused is what holds up in front of a judge, and it is what a blanket promise to "recover deleted data" cannot stand behind.
Cellebrite cell phone forensics, without the Cellebrite bill
Why private investigators choose Sherlock Forensics over Cellebrite and Magnet
Cellebrite and Magnet build the platforms the largest labs run, at enterprise prices and with the training and lab overhead to match. For the private investigator doing digital forensics on a consenting client's device, that is far more tool than the case needs. Sherlock Forensics gives you the logical acquisition, the examination workspace and the court-ready report for a one-time price.
| Capability | Sherlock Forensics | Cellebrite / Magnet |
|---|---|---|
| Price | One-time, from $399 | Thousands per year, per seat |
| Setup | Installs on your own Windows, macOS or Linux workstation | Lab hardware, licensing and training |
| Logical acquisition with authorized access | Yes | Yes |
| Court-ready hashed report | Yes | Yes |
| Reads a Cellebrite or Magnet full-filesystem image you were given | Yes | Yes |
| Runs entirely offline, no evidence to a cloud | Yes | Varies |
| Physical extraction and locked-device access | No, logical acquisition only | Yes, at enterprise cost |
Where a case genuinely needs physical extraction or locked-device access, that remains the enterprise platforms' territory. For the authorized, consent-based work that fills a private investigator's caseload, Sherlock Forensics covers it for a fraction of the cost.
The tools
Pick the tool for the device
Sherlock Forensics Android Acquirer
$399 one-time
Logical acquisition of an Android phone or tablet over authorized ADB, with examination of a full-filesystem image you were given. Messages, call logs, media, locations and app records across a large parser catalog, in a court-ready report.
See Android AcquirerSherlock Forensics iPhone and iPad Analyzer
$599 one-time
Acquire and analyze logical iPhone and iPad backups, and read Cellebrite or Magnet full-filesystem extractions, with 200+ artifact views, encrypted-backup decryption using the correct key, and court-ready reports.
See iPhone and iPad AnalyzerSherlock Forensics PST Viewer
Free, Forensic Edition from $67
When a case turns on email, open and search PST and OST archives without Outlook, view attachments and export messages, with a forensic report and SHA-256 verification.
See PST ViewerStraight answers
Private investigator phone forensics FAQ
Can a private investigator do phone forensics?
Yes, on a device they are authorized to examine, with the owner's consent or a lawful authority. Modern phone forensics on an unlocked, accessible device is logical acquisition: collecting the messages, call logs, media, locations and app records the device will hand over, and documenting them in a court-ready report. It does not extend to a device the investigator is not permitted to access, and it does not bypass a locked or encrypted phone.
What can a private investigator extract from a phone?
With authorized access to an unlocked device: SMS, MMS and accessible app messages, call logs and contacts, photos and video with capture time and any embedded GPS, location history and records from apps whose data is readable on the device. Each item is hashed and sourced for a court-ready report. Protected app databases such as WhatsApp's live chat store require a full-filesystem or rooted acquisition rather than ordinary logical access.
Do I need Cellebrite for cell phone forensics?
Not for authorized, consent-based logical work. Cellebrite and Magnet are enterprise platforms priced for large labs and needed mainly for physical extraction and locked-device access. For extracting and examining the accessible data on a consenting client's phone or tablet, Sherlock Forensics gives you logical acquisition and a court-ready report for a one-time price, and it also reads a Cellebrite or Magnet full-filesystem image you were given in discovery.
Can these tools recover deleted texts or photos?
Within honest limits. Carving a deleted file back off a modern encrypted phone is effectively impossible for any tool, because the device wipes freed blocks. What can be recovered is a deleted record that still survives inside an accessible database, and every recovered item is flagged with its exact source. No tool honestly un-deletes photos that the device has already cleared.
Are the reports court-ready?
Yes. Every acquired and recovered item carries its source and a SHA-256 hash, the report records the access decisions the device made, and the examination runs offline on your own workstation with no evidence sent to a cloud. That provenance is what holds up under examination.
