Per-Artifact Deep Dive

Find My Forensics: Devices, AirTags and the People They Share With

Find My is not only a location feature. It is a map of a person's device ecosystem and their closest contacts, recorded by the device itself.

Sherlock Forensics iPhone Analyzer reads Find My from a full-filesystem extraction: the owner's paired devices, the AirTags and accessories on the account and the family or friends the owner shares location with. It is association and account-control evidence as much as whereabouts, read alongside the location artifacts on one merged timeline. A logical backup does not carry this depth. $599 one-time.

Windows 10/11 | One-time license | Full-filesystem depth | 100 percent read-only

The Artifact

Three Records in One View

Find My quietly keeps three distinct records that matter to an investigation. The first is the owner's own paired devices: the iPhones, iPads, Macs and Apple Watches signed into the same account, which shows the full set of hardware a person controls. The second is the AirTags and accessories registered to the account, the tracked-item set. The third is family location sharing: the people the owner deliberately chose to share their location with, a named list of close ties.

Sherlock Forensics iPhone Analyzer reads all three into one Find My view, each entry named from the device's own record. Every entry feeds the merged Activity Timeline and global search, so a shared contact or a paired device can be cross-referenced against the messages, locations and app activity elsewhere in the case.

Association

The Association Evidence Cases Underuse

Most phone analysis chases content: what was said, where the device went. Find My answers a different and often more durable question, who is connected to whom. A family-sharing roster is not an incidental artifact; it is a deliberate act by the owner, naming the people they wanted to see their location. That makes it strong evidence of a close relationship, independent of whether a single message thread survives.

The paired-device list does the parallel job for account control. It shows the other devices under the same Apple account, which corroborates that a person owns and operates the ecosystem an investigation is attributing to them. In matters where identity or account ownership is contested, that independent corroboration can matter more than any single communication. Sherlock surfaces both plainly so an examiner can lay the association record next to the content record and let them reinforce each other.

There is a defensive value to the association record as much as an offensive one. When a subject disputes that a device or an account is theirs, the ecosystem is hard to disown: a paired watch, a family member sharing back, a registered accessory each tie the account to a real person and a real network of relationships. Conversely, an association the record does not show is itself informative. If a purported close contact is absent from a sharing roster the owner curated, that absence is a fact an examiner can put on the record rather than an assumption. The point throughout is the same as with every artifact: report the connections the device actually holds and let the case argue what they mean, corroborated against the rest of the record before any conclusion is drawn.

Tracked Items

AirTags and the Tracking Question

The AirTags and accessories registered to an account are increasingly relevant evidence. Matters that involve tracking, stalking or the movement of a vehicle or an asset turn directly on which trackers an account controls. Knowing that a specific account registered a specific AirTag is a concrete fact an examiner can build on, whether the question is who was tracking a person or where a tagged item traveled.

Sherlock reads the registration record from the extraction: which trackers the account owns, surfaced in the Find My view. As always, the tool reports the record and leaves the significance to the examiner. What a registered tracker means for a case depends on the case. Sherlock does not draw that conclusion for it.

The Source

Why This Needs a Full-Filesystem Extraction

The Find My detail at this depth lives in the behavioral layer of the operating system, which a logical backup does not copy out. It reaches an examiner inside a full-filesystem extraction produced by Cellebrite UFED or VeraKey class tooling. Load a logical MobileBackup2 backup and the deep Find My view shows an honest empty state, because the source cannot contain it. Load the extraction and it populates. The free edition shows which populates for the device, with per-view item counts, before any purchase decision is made. New to working with extractions? The image-loading workflow covers opening one.

The Honest Limit

What Find My Does and Does Not Settle

Find My is powerful for what it is and misleading if pushed past it. It records the device ecosystem, the tracked-item set and the sharing relationships. It also corroborates account ownership. It does not, on its own, place a specific person at a specific location; that is the job of the location artifacts, which themselves attribute to the device rather than the person without corroboration. Read honestly, Find My is association and account-control evidence first and a whereabouts input second through the shared-member locations, always assembled with the rest of the record rather than asserted alone.

Court-Ready

From the Record to the Report

Analysis is 100 percent read-only; the evidence is never modified. The court-ready HTML report carries the Find My record, case and evidence numbers, examiner identification, disclosed methodology, per-artifact SHA-256 hashing and an optional evidence-integrity manifest, the documentation elements described in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics. Built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record so testimony rests on it.

Honest Scope

What This Analysis Is and Is Not

Sherlock analyzes a full-filesystem extraction; it does not create one and does not acquire Find My data from a device beyond the logical backup path, which does not carry this depth. Producing a full-filesystem extraction requires Cellebrite or GrayKey class acquisition tooling. Confirmed ingestion formats are Cellebrite UFED and VeraKey, validated against real device images. It does not reach the live Find My network or a subject's iCloud account through a provider; it reads what the extraction holds. Different source? Contact us before purchasing and we will confirm the layout is readable.

Questions

Find My Forensics FAQ

What does Find My hold that matters forensically?
Three things. The owner's own paired devices (iPhones, iPads, Macs, Apple Watches), the AirTags and accessories registered to the account and the family or friends the owner shares location with. Together they map the person's device ecosystem and their close-contact network from the device's own record.
Can I get Find My data from a normal iPhone backup?
The Find My detail of this depth lives in the full filesystem, so it populates from a Cellebrite UFED or VeraKey full-filesystem extraction. From a logical backup the deep Find My view shows an honest empty state rather than fabricated data. Sherlock says which source carries it.
How is Find My association evidence, not just location?
The family-sharing roster names the people an owner chose to share location with, which is a deliberate close-tie signal; the paired-device list shows the other devices under the same account. Both establish association and account control independent of any single message thread, which is often exactly what a case needs to corroborate identity and relationships.
What can AirTag records show?
The AirTags and accessories registered to the account are part of the owner's tracked-item set. In investigations that involve tracking, stalking or asset movement, knowing which trackers an account controls is directly relevant. Sherlock reads the registration record from the extraction; interpreting its significance is for the examiner and the case.
Does Find My prove where a person was?
It records the device ecosystem and sharing relationships and corroborates account ownership; it does not by itself place a specific person somewhere. As with every device artifact, attribution to a person rests on corroboration across the record. Find My is strongest as association and account-control evidence, read alongside the location artifacts.
Is Find My evidence court-defensible?
Analysis is read-only and the court-ready report documents examiner details, methodology and per-artifact SHA-256 hashing. Find My feeds the merged timeline and global search alongside the other artifacts. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record for testimony.

Start Now

Read the Ecosystem in Your Extraction

Download the free edition, load the extraction and see for yourself whether the Find My view populates for the device in front of you. Unlock the full record when the case calls for it: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: Significant Locations forensics · The forensic image load workflow · iPhone forensics fact checks · Product page