Pillar Guide
iPhone and iPad Forensics Guides
A field-guide library for iPhone and iPad evidence, drawn from 20 years of digital forensics. Each guide covers one artifact type or one investigation task and what an examiner can actually recover from it. All of them run on the same Windows tool, the Sherlock Forensics iPhone and iPad Analyzer.
iPhone forensics is the practice of recovering and analyzing the data an iPhone or iPad stores: messages, calls, contacts, browsing history, photos, location, Health records and the keychain. A logical backup or a full-filesystem extraction is parsed into searchable, exportable views. Deleted records are carved from freed database pages where they survive. This library groups the Sherlock Forensics guides into artifact recovery, acquisition and backups, legal admissibility and investigation use-cases. Every guide maps to the free or the $599 Forensic Edition of the Sherlock Forensics iPhone and iPad Analyzer, a Windows tool that reads iPhone and iPad backups and extractions with no Mac required.
Artifact Recovery Guides
Each iPhone app leaves its own trail. These guides cover what the keychain, the messaging apps, the browser, maps, Apple Health and the photo library store. They also show how an examiner recovers each one.
Saved passwords, tokens and Wi-Fi keys recovered from the keychain. WhatsApp Forensics on iPhone
Recover WhatsApp chats, media and call logs from a backup. iPhone Call History Forensics
Recover deleted call records and rebuild the call timeline. Safari History Forensics
Recover browsing history, searches and open tabs from Safari. iPhone Voicemail Forensics
Recover visual voicemail audio and transcripts as evidence. iPhone Contacts Forensics
Rebuild the address book including deleted contacts. Apple Notes Forensics
Recover notes, attachments and locked-note metadata. Apple Health Forensics
Workouts, heart rate and GPS routes as timeline evidence. Apple Maps and Waze Forensics
Trips, searches and saved places from Apple Maps and Waze. Find My Forensics
Owner devices, AirTags and Family Sharing locations as evidence. Recover Deleted iPhone Photos
What survives deletion in the photo library and how to recover it. iPhone Device Information Forensics
The device profile: identifiers, accounts and configuration. iPhone Bluetooth Device History
Paired and nearby Bluetooth history as proximity evidence. Cross-App Cached Web Forensics
Cached web content left behind by in-app browsers. iPhone App Inventory and Anti-Forensic Detection
Installed apps, hidden vault apps and the anti-forensic wipe signs an examiner looks for.
Acquisition and Backups
Before you can read an iPhone you have to acquire it. These guides explain how to open and extract iTunes and MobileBackup2 backups on a Windows PC and how to move data off an old device.
Open and read a legacy iTunes backup on a Windows PC. View an iPhone Backup on Your PC
View and extract the contents of an iPhone backup on a PC. Get Photos and Messages Off an Old iPhone
Move photos and messages off an old iPhone to a computer. Get Text Messages Off an Old iPhone
Export text messages from an old iPhone onto a PC.
Legal and Admissibility
Evidence only matters if it holds up. These guides cover authentication, chain of custody and the Daubert standard for iPhone reports.
Investigation Use-Cases
The same iPhone analysis serves many investigations. These guides look at litigation, insurance fraud, private-investigator work and access for a deceased family member.
Collecting iPhone data defensibly for litigation and eDiscovery. iPhone Evidence for Insurance Fraud
Using iPhone evidence to investigate suspected fraud. iPhone Forensics for Private Investigators
Affordable iPhone analysis built for private investigators. Access a Deceased Family Member's iPhone
Accessing a deceased family member's iPhone data respectfully.
Tool Comparison
Commercial iPhone forensic suites cost thousands per seat. This guide compares the Sherlock Forensics logical alternative against Elcomsoft iOS Forensic Toolkit.
See the Software Behind These Guides
Sherlock Forensics iPhone and iPad Analyzer runs on Windows and reads iPhone and iPad backups and full-filesystem extractions. The free tier previews every artifact view. The Forensic Edition is $599 one-time for full data and court-ready reports.
Get iPhone and iPad Analyzer Compare Free vs Forensic Edition
Frequently Asked Questions
What can iPhone forensics recover?
A logical iPhone extraction can surface messages, call history, contacts, Safari history, photos, location data, Health records, the keychain and app data. Deleted items sometimes survive in the underlying databases and can be carved back out. Each guide in this library covers one artifact type in detail.
Do I need a Mac to analyze an iPhone?
No. Sherlock Forensics iPhone and iPad Analyzer runs on Windows 10 and 11. It reads iTunes and MobileBackup2 backups and Cellebrite full-filesystem extractions on a standard PC, with no Mac required.
Is iPhone evidence admissible in court?
It can be, when the acquisition is documented and the report is authenticated. A defensible chain of custody, a repeatable method and clear reporting are what make a device report hold up. See the admissibility and chain-of-custody guides in this library.