For the Defense

Read the Same iPhone Evidence the Prosecution Relies On

Independent review is the defense's job. It should not require the prosecution's tool budget to do it.

Criminal defense teams use Sherlock Forensics iPhone Analyzer to independently review produced iPhone evidence: a Cellebrite UFED or VeraKey extraction or an iPhone backup opens on a defense workstation, offline, with carved records flagged, provenance hashes comparable against the files as received and a court-ready report. Free triage first; $599 one-time for full analysis.

Windows 10/11 | One-time license | Fully offline | 100 percent read-only

The Asymmetry

The State Has a Lab. The Defense Gets a PDF.

In most phone-evidence cases the prosecution's examiner worked the device on an enterprise platform and produced a report of the findings that matter to the prosecution's theory. The defense receives that report and, if discovery goes well, the underlying extraction or backup beside it. The structural problem is that the report is a set of choices, which artifacts were run, which filters applied, which threads exported. The defense cannot evaluate those choices from the report itself.

Independent review means opening the underlying evidence and reading it with defense questions in mind. That has traditionally required either retaining a lab for every first look or licensing the same enterprise platforms the state uses, both at costs that appointed and private defense budgets absorb badly. Sherlock Forensics iPhone Analyzer removes the tooling barrier: the produced extraction or backup opens on a defense workstation at $599 one-time, with a free edition that makes the first look cost nothing at all.

If the immediate question is simply how to open a production you just received, the step-by-step is on the received-in-discovery page. This page is about what a defense practice does with that access.

Verification

Verify the Load-Bearing Claims, Not Just the Headlines

Provenance first. For extractions, Sherlock's provenance view carries the acquisition tool's descriptors verbatim, including the per-dump SHA-256 and HMAC values recorded at capture. The defense compares recorded hashes against the files as received; a match closes one line of doubt, a mismatch is a discovery issue worth raising before trial rather than during it.

Recovered records second. Deleted-content claims decide cases and deserve direct inspection. Sherlock flags carved records as recovered, distinct from live records, so a defense examiner can locate the exact messages behind a recovery claim, see that they sit in freed SQLite pages and speak precisely to what freed-page carving establishes: that a record existed and was deleted, subject to the survival physics every tool works under. The examiner can equally testify that overwritten records are unrecoverable by any tool, which matters when the absence of evidence is being argued as evidence.

Honest empty states third. When Sherlock Forensics iPhone and iPad Analyzer shows a view as empty, it is because the source cannot contain that artifact or the record is not there, stated as such. That distinction, what the evidence cannot show versus what it does not show, is frequently where a produced report's implications outrun its data, which is exactly the gap cross-examination lives in.

Beyond Their Report

The Views the Production Report May Have Skipped

The defense's questions are rarely the prosecution's questions. The same evidence answers both. From any produced source, Sherlock reads the full communications record, threaded iMessage and SMS with Tapback reactions distinguished from typed messages, WhatsApp with group membership, call history and contacts, with global search running any name or phrase across every artifact at once. From a full-filesystem extraction, the behavioral layer opens: pattern-of-life views from Screen Time and power-log records, significant locations with dwell times, app install and uninstall history and chat recovered from web caches and notification previews, labeled for what it is.

All of it feeds one merged timeline, which is where alternative narratives live or die: what the device was doing in the minutes the case turns on, in sequence, from independent artifacts. The parser list maps the full surface to the source each view reads from, so counsel knows what to request in discovery to reach it.

The working product matters as much as the reading. Any view exports to CSV or JSON for the case file, flagged items roll into the defense's own report and the report prints to PDF from any browser, so the thread, the timeline slice or the provenance mismatch that supports a motion arrives as an exhibit-ready document rather than a screenshot of someone else's software. When the defense theory needs a specific artifact in front of the court, it comes out of the evidence directly, hashed and documented.

Economics

Priced for Defense Budgets, Appointed Ones Included

The retained expert is not replaced by any of this; testimony and methodology disputes stay with the expert. What changes is where the budget goes. First-pass reading of produced evidence, the triage that decides whether the phone matters at all, runs on the free edition. Full analysis, when the matter justifies it, is $599 one-time on a license the practice keeps for the next case. Lab hours get spent where they earn their rate: on the disputed findings, not on opening files.

For appointed matters the arithmetic is even simpler. A one-time $599 seat with free triage fits inside authorization frameworks that a five-figure annual platform subscription never will. The license outlives the case rather than expiring with the fiscal year.

Court-Ready

Documentation Built for the Daubert Fight

Defense findings face the same admissibility scrutiny as the prosecution's, so the documentation is symmetrical: the court-ready HTML report carries case and evidence numbers, examiner identification, disclosed methodology, per-artifact SHA-256 hashing and an optional evidence-integrity manifest, with recovered records flagged throughout, the documentation elements described in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics. Analysis is 100 percent read-only, so the defense can state under oath that the production was never altered in its custody.

Built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice, including documenting acquisition methodology for Daubert challenges. The tool documents the record; admissibility argument remains counsel's craft.

Honest Scope

What This Is and Is Not

Sherlock is an analysis tool, not legal advice and not a substitute for a retained expert where testimony is needed. It does not unlock devices, does not acquire full-filesystem extractions and does not reach iCloud; it reads what was produced or what an unlockable device yields through Apple's logical path. Confirmed extraction formats are Cellebrite UFED and VeraKey, validated against real device images. Discovery scope, protective-order compliance and authority questions belong with counsel; the tool's job is to make the evidence readable and the record defensible once those questions are answered.

Questions

Defense iPhone Analysis FAQ

Can the defense independently analyze the prosecution's iPhone evidence?
Yes, when the underlying evidence is produced. A Cellebrite UFED or VeraKey full-filesystem extraction or a MobileBackup2 backup opens directly in Sherlock Forensics iPhone Analyzer on a defense workstation, fully offline. The defense examiner reviews the same records the prosecution's tool parsed rather than relying on the produced report alone.
How do we verify a deleted-message claim?
Recovered records are flagged as recovered, carved from freed SQLite pages, distinct from live records. A defense examiner can locate the specific records behind a recovery claim, confirm whether they sit in freed pages and testify to what carving methodology does and does not establish, including that overwritten records are unrecoverable by any tool.
Can we check that the production matches what was acquired?
For extractions, yes. The extraction-provenance view carries the acquisition tool's descriptors verbatim, including the per-dump SHA-256 and HMAC values recorded at capture, so the defense can compare recorded hashes against the files as received and raise any mismatch with the producing party.
What does this cost against a retained lab?
The license is $599 one-time. The free edition previews every artifact view first, so triage costs nothing. Retained experts remain essential for testimony and methodology disputes; what changes is that counsel and the examiner stop paying lab hours for the first-pass reading of evidence they were already handed.
Does this work for court-appointed matters?
The economics fit appointed budgets: free triage, $599 one-time if the matter justifies full analysis and no subscription surviving the case. The court-ready report documents methodology, examiner details and integrity hashing in the form courts typically require.
Is this legal advice or a substitute for an expert?
Neither. Sherlock is an analysis tool. Discovery strategy, admissibility argument and testimony remain with counsel and the retained expert. What the tool changes is access: the defense reads the evidence itself, early and affordably, instead of arguing from the other side's report.

Start Now

Read the Evidence, Not Just Their Report

Download the free edition, open the production and see what the evidence actually holds before the next status conference. Unlock the full seat when the case calls for it: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: Analyze an extraction received in discovery · iMessage forensics · The full parser list