For Litigation Teams

iPhone eDiscovery Without an Enterprise Seat

You were handed an iPhone extraction or you need to review a client's device. Here is how to open it, work it and produce a defensible record for a fraction of the enterprise price.

Sherlock Forensics iPhone Analyzer is the review and production layer for iPhone evidence in litigation. It opens a Cellebrite or VeraKey extraction or a backup, reconstructs messages, web activity, locations and app usage into a searchable timeline, then exports a court-ready report with SHA-256. $599 one-time; the free edition previews the evidence first.

Windows 10/11 | One-time license | Opens a backup or an extraction | 100 percent read-only

The Problem

You Have the Evidence and No Way to Open It

A recurring moment in modern litigation: a phone matters to the case and someone hands your team a Cellebrite or VeraKey extraction of it, in discovery, from opposing counsel or from a forensic vendor you retained. The evidence is now in your possession and you still cannot read it, because the extraction is a forensic image, not a folder of documents. The tools that open it, Cellebrite Physical Analyzer and Magnet AXIOM, are priced for full-time forensic labs at roughly four to fifteen thousand dollars a year per seat. A firm that needs to review one iPhone in one matter cannot justify that, so the evidence sits unread and a case turns on a file nobody opened.

Sherlock Forensics iPhone Analyzer exists for exactly that gap. It reads the same extraction and gives real analysis for a one-time $599 license. The free edition opens the image and previews it before any purchase, so counsel can confirm what is inside a received extraction with no commitment. The same tool works when the device is your own client's: acquire a backup, review what is on it and decide what is responsive, all without standing up an enterprise forensic seat for a single matter.

Any Source

Backups and Extractions, the Same Review

The evidence in a matter arrives in whatever form the acquisition produced, so Sherlock accepts the full range. It opens an existing iTunes or Finder backup, acquires a fresh encrypted logical backup over USB from a device you can unlock and Trust, then ingests a full-filesystem extraction produced by Cellebrite UFED or VeraKey acquisition tooling. Opening a third-party extraction is analysis of an image someone else captured, not an acquisition Sherlock performs; the distinction is stated plainly because it is the honest one and because it is what a court will ask.

Whichever source the matter turns on, the review surface is the same. You are not learning one interface for a backup and another for an extraction. A backup carries the everyday communication and web record; a full-filesystem extraction adds behavioral depth the backup does not hold. Both land in the same searchable views and the same merged timeline, so a reviewer works the evidence the same way regardless of how it was collected.

The Review Surface

What Litigation Teams Actually Read

An iPhone in a matter is rarely about one artifact. A dispute over who knew what and when is answered by reading communication against activity, so Sherlock reconstructs the device into dedicated views and one merged Activity Timeline. Messages, call history, Safari and web activity, locations, photos with their metadata and app usage each become a searchable and exportable view. Global search runs across all of them at once. A reviewer can pull every reference to a name, a number or a term across the whole device rather than opening artifacts one at a time.

The merged timeline is what makes this defensible to argue from. A message at a given minute reads in sequence with the location, the web search and the app activity from the same window, so a reviewer builds a factual chronology instead of a stack of disconnected exports. When a matter hinges on sequence, that a search preceded a message, that a location coincided with a call, the timeline is the artifact that shows it. Every view exports to CSV or JSON so responsive material moves cleanly into a review platform or an exhibit.

Deleted content is handled the same disciplined way throughout. When a record is deleted, iOS marks its database page free rather than erasing it, so Sherlock carves what the freelist still holds. What survives depends on time and device use since the deletion, so recent deletions on a lightly used phone are often recoverable while data cleared long ago on a busy device has usually been overwritten and is gone. Every carved record is flagged as recovered and never blended into the live record, which is the labeling a reviewer and a court both require.

See It

Sherlock Forensics iPhone Analyzer merged Activity Timeline showing messages, locations and app usage from an iPhone in one chronological view
Messages, locations and app activity merged into one searchable chronology

Defensible

Built to Survive the Authenticity Challenge

Electronic evidence draws an authenticity challenge, so the production is documented for it. Analysis is 100 percent read-only and the source is never modified. The court-ready HTML report carries case and evidence numbers, examiner identification, disclosed methodology and per-artifact SHA-256 hashing, with an optional evidence-integrity manifest and recovered records flagged throughout. A hash that matches the source lets a party show the record is what it was when acquired, the kind of certification contemplated by Federal Rule of Evidence 902(14) on self-authentication of electronic records. The methodology follows the documentation practice in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics.

Built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice. Admissibility always depends on jurisdiction, authority and evidence handling, which Sherlock does not decide. What it does is produce a documented, hashed, read-only record so an examiner testifies from the report rather than from recollection, so opposing counsel is met with a verifiable chain rather than an unexplained export.

Honest Scope

What This Tool Is and Is Not

Sherlock is the analysis and production layer, not a full collection platform; saying so protects the teams that rely on it. It analyzes a backup or an extraction that you already hold. It does not reach a custodian's iCloud account through a provider, does not collect over the network and does not unlock a locked device or bypass a passcode. Preservation and collection stay with your acquisition process, whether that is a logical backup Sherlock makes from an unlockable device or an extraction a vendor captured. Content a subject deleted long enough ago to be overwritten is gone. The report says so rather than implying a recovery no tool can promise.

Read the other way, that scope is the point. For the common litigation need, opening an iPhone backup or a received extraction, reviewing it and producing a defensible record, Sherlock does the whole job at a one-time $599 that a single matter can carry. It is additive to whatever acquired the evidence, letting a firm work an iPhone without renting an enterprise forensic seat by the year.

Questions

iPhone eDiscovery FAQ

Can I use Sherlock for iPhone eDiscovery?
Yes. Sherlock Forensics iPhone Analyzer is the review and production layer for iPhone evidence. It opens a Cellebrite UFED or VeraKey full-filesystem extraction or a logical backup, reconstructs messages, web activity, locations, call history and app usage into searchable views and a merged timeline, then exports a court-ready report with per-artifact SHA-256. It is a one-time $599 license rather than a per-seat annual subscription.
Do I need Cellebrite or Magnet AXIOM to review an extraction?
No. If opposing counsel or your own vendor hands you a Cellebrite or VeraKey extraction, you do not have to license Cellebrite Physical Analyzer or Magnet AXIOM to open it. Sherlock reads the same extraction and gives real analysis for $599. The free edition previews it first so counsel can triage a received image before any purchase.
What evidence sources does Sherlock accept?
An encrypted logical backup you make over USB from a device you can unlock and Trust, an existing iTunes or Finder backup or a full-filesystem extraction produced by Cellebrite UFED or VeraKey acquisition tooling. Ingesting a third-party extraction is analysis of an image someone else acquired, not acquisition; Sherlock's own acquisition is the logical backup path.
Is the output defensible in court?
Analysis is 100 percent read-only and the court-ready report documents case and evidence numbers, examiner identification, disclosed methodology and per-artifact SHA-256 hashing, with recovered records flagged so live and carved data never blur. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record so testimony rests on it.
Can Sherlock recover deleted messages for a matter?
Sometimes. When a record is deleted, iOS marks its SQLite page as free rather than erasing it, so Sherlock carves records from freed pages where the freelist has not been overwritten. Recent deletions on lightly used devices are often recoverable; data deleted long ago on a busy device has usually been overwritten and is gone. Every carved record is flagged as recovered, never presented as a live entry.
Does Sherlock collect from iCloud or a custodian remotely?
No. Sherlock is an on-device evidence tool, not a remote or cloud-collection platform. It analyzes a backup or extraction that you already hold. It does not reach a custodian's iCloud account through a provider, does not collect over the network and does not unlock a locked device. Preservation and collection stay with your acquisition process; Sherlock is the analysis and production layer.

Start Now

Open the Evidence You Already Hold

Download the free edition, open a backup or a received extraction and see the evidence for yourself. Unlock the full review and the court-ready production when the matter calls for it: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: Analyze an extraction from discovery · Defense attorney iPhone analysis · Read a Cellebrite UFED extraction · Product page