Corporate and HR Investigations

iPhone Forensics for Insider-Threat and HR Investigations

A company-owned iPhone, examined under proper authorization, on your own workstation, with a record that holds up if the matter leaves the building.

Corporate and HR teams use Sherlock Forensics iPhone Analyzer to examine company-owned iPhones under proper authorization: app inventory, permissions, anti-forensic app detection, communications and, from a full-filesystem extraction, usage patterns. Analysis is read-only and offline, the record is court-ready and device activity is never presented as person activity without corroboration. $599 one-time.

Windows 10/11 | One-time license | Fully offline | 100 percent read-only

First Principle

Authorization Comes Before the Tool

The most important step in a corporate device examination happens before any software opens. An examination has to rest on a proper footing: a company-owned device, an acceptable-use policy the employee agreed to, documented authorization to examine and observance of the privacy rules that apply in your jurisdiction. Those are questions for legal and HR advisors. They are not questions Sherlock Forensics iPhone Analyzer answers or can answer for you. The tool produces a defensible technical record; it does not determine whether you were entitled to create one.

That order matters because insider-threat and HR matters escalate. A routine policy inquiry can become a termination, a civil claim or a criminal referral. At each step the first question asked of the evidence is whether it was gathered lawfully. Get the authorization documented before acquiring, keep the examination inside its stated scope and the technical record that follows carries its own weight. Skip that footing and the cleanest forensic report in the world is a liability.

What It Surfaces

The Artifacts an Insider-Threat Inquiry Reaches For

Once the examination is authorized, the questions are practical: what was on this device, what was moved off it, what was hidden. Sherlock reads the artifacts those questions turn on, each in its own searchable, exportable view:

  • App inventory and permissions. Installed apps, app inventory, app state and the TCC permission grants that show which apps could reach the camera, microphone, location and contacts.
  • Anti-forensic app detection. Hidden-vault apps, encrypted-messaging apps and anonymity or VPN apps are flagged inline everywhere apps appear and surfaced in the Findings view, the tooling an employee reaches for when they want activity to disappear.
  • Sharing and movement. AirDrop and sharing history, installed cloud and messaging apps and, from a full-filesystem extraction, the cross-app cached-web-request view that surfaces in-app web and API activity across nearly every installed app.
  • Communications. iMessage and SMS threaded, WhatsApp with groups, call history and contacts, with global search running a name, project code or phrase across every artifact at once.
  • Usage patterns. From a full-filesystem extraction, Screen Time and power-log usage, app install and uninstall history and the launch sequence, the pattern-of-life record of how the device was actually used around the dates in question.

App inventory, permissions and anti-forensic detection populate from an ordinary encrypted backup; the usage-pattern and cross-app web depth needs a full-filesystem extraction. The parser list maps which source each view reads from, so the investigation knows what acquisition it needs to reach a given artifact.

The Exfiltration Question

Surfacing Artifacts Is Not Concluding a Case

Data-exfiltration inquiries are where an eager tool does the most damage. Sherlock surfaces the artifacts that bear on the question, an AirDrop transfer, a cloud app installed the week of a resignation, a vault app hiding files, a spike in usage of a file-sharing app, but it does not declare that exfiltration occurred. The distance between a suggestive artifact and a proven act is exactly where a rushed investigation loses an employment tribunal or a civil suit.

Worked properly, the artifacts are leads to corroborate, not conclusions to assert. An AirDrop record corroborated by a badge-out time, a cloud login in the access logs and the file's presence elsewhere is a finding. The same record alone is a question. Sherlock is built to support that discipline: every artifact feeds one merged timeline so an investigator can line device events up against the independent evidence that either confirms or dissolves the theory. The report presents the artifacts with their limits stated rather than dressed as a verdict.

The Limit That Governs

Device Activity Is Not Person Activity

The same rule that governs criminal usage evidence governs corporate matters. It is worth stating in an HR context precisely because the stakes feel more informal: the device records what the device did, not who did it. A shared workstation phone, a device left unlocked on a desk, a family member with the passcode, each breaks the line between the device and a single person. An examiner or investigator who presents device activity as an employee's proven conduct, without corroboration, hands the employee's counsel the opening they need.

The defensible posture is the same one that holds up in court: present what the device shows, state what attribution requires and let the corroborating evidence, account logs under a known login, physical access records, content that only the individual would have, carry the attribution argument. Sherlock presents the record; the organization and its advisors make the case.

In-House Economics

Keep Routine Inquiries In-House, Escalate the Rest

Most corporate device questions are routine: a policy check, an offboarding review, an early-stage inquiry that may or may not become something. Sending each of those to an outside firm is slow and expensive. Building the capability in-house has traditionally meant a five-figure annual platform. Sherlock changes that arithmetic: $599 one-time puts a real forensic capability on an investigator's workstation, with the free edition covering triage at no cost, so the routine work stays inside the organization and moves at the organization's pace.

The escalation path stays clean because the record is standard. When a matter does warrant outside counsel or a retained examiner, the court-ready report, its per-artifact SHA-256 hashing and the read-only provenance transfer without rework: the outside expert receives a documented, hashed record rather than a pile of screenshots. In-house for speed, outside for the hard fight, one evidentiary standard across both.

Defensible Record

Built to Survive the Dispute It Might Become

An HR examination that stays internal still has to be defensible, because the ones that do not stay internal are exactly the ones that matter most. Analysis is 100 percent read-only, so the device evidence is never altered. The court-ready HTML report documents case and evidence numbers, examiner identification, disclosed methodology, per-artifact SHA-256 hashing and an optional evidence-integrity manifest, the documentation elements described in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics. Built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice.

Honest Scope

What This Is and Is Not

Sherlock is a forensic analysis tool, not legal or HR advice and not an authorization to examine anyone's device. It does not unlock locked devices, does not acquire full-filesystem extractions and does not reach iCloud; its own acquisition needs an unlocked device and the passcode through Apple's logical path. It otherwise reads an existing backup or a Cellebrite UFED or VeraKey extraction. Whether an examination is lawful and within policy is a decision for your legal and HR advisors in your jurisdiction. The tool makes the technical record defensible once that decision is properly made.

Questions

Corporate iPhone Investigation FAQ

Can we investigate a company iPhone in-house?
With proper authorization, yes. On a company-owned device examined under your acceptable-use policy and legal guidance, Sherlock Forensics iPhone Analyzer runs a forensic examination on your own workstation: app inventory, usage patterns, communications and anti-forensic app detection. It requires an unlocked device and the passcode for its own acquisition. It otherwise reads an existing backup or extraction. Authorization and privacy scope are questions for counsel and HR, not for the tool.
What authorization do we need first?
That is a question for your legal and HR advisors, not for us. In general, examinations run on company-owned devices under a clear acceptable-use policy and documented authorization, with jurisdiction-specific privacy rules observed. Sherlock does not determine whether you are authorized; it produces a defensible technical record once you are. When in doubt, get sign-off before acquiring.
What does the tool surface in an insider-threat inquiry?
Installed apps and app inventory, app permissions, anti-forensic app detection flagging hidden-vault and anonymity apps, communications across iMessage, WhatsApp and more, AirDrop and sharing history and, from a full-filesystem extraction, the usage patterns and app install and uninstall history that show how the device was actually used. Everything feeds one merged timeline and global search.
Does this prove an employee did something?
No. The tool documents what is on the device and how the device was used; it attributes activity to the device, not to a person. Attribution, intent and policy conclusions are for the investigation and counsel to argue from corroborating evidence. An honest report presents the record and its limits, which is what withstands challenge in an employment dispute or a court.
Can it detect data exfiltration?
It surfaces artifacts relevant to exfiltration questions: AirDrop and sharing history, installed cloud and messaging apps, app inventory changes and, from a full-filesystem extraction, the cross-app cached-web-request view and usage records. Whether those artifacts amount to exfiltration is an analytical judgment for the investigator, corroborated across sources, not a verdict the tool renders.
What does it cost versus an outside firm?
$599 one-time for the license, with the free edition previewing every view first. For routine in-house inquiries that keeps the work inside the organization at a fraction of an outside engagement. Escalate to outside counsel or a retained examiner when the matter warrants; the in-house record transfers cleanly because it is standard, hashed and documented.

Start Now

Build the Capability In-House

Download the free edition and see the examination surface on a test device before you need it in anger. Confirm authorization with your advisors, then unlock the full seat when a matter calls for it: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: Screen Time forensics · The full parser list · Product page