Per-Artifact Deep Dive

Device Information: The Identity Every Case Starts With

Before any artifact means anything, you have to know which phone produced it. Here is the device profile Sherlock builds and why it anchors the whole examination.

Sherlock Forensics iPhone Analyzer builds the iPhone device profile: model, iOS version, serial number, IMEI, capacity, device name, the signed-in account and the backup dates. It is the identity the examination sits on, matching the evidence to the seized device and anchoring the timeline to the right timezone. It works from an encrypted backup as well as a full-filesystem extraction. $599 one-time; the free edition previews it first.

Windows 10/11 | One-time license | Works from a backup or an extraction | 100 percent read-only

The Artifact

What the Device Profile Holds

Every examination has to start with a plain question: which phone is this. The device profile answers it. Sherlock Forensics iPhone Analyzer surfaces the identity of the device into one overview: the model, the iOS version, the serial number, the IMEI where it is present, the storage capacity, the device name the owner set, the account signed into it and the backup dates the evidence retained. It is the first screen an examiner reads, because everything else in the case is an artifact belonging to this specific device.

These fields are small but they carry weight. The device name and account personalize a piece of evidence that would otherwise be a mass of records. The iOS version tells an examiner what the device was capable of and which artifacts to expect. The capacity and model set expectations for how much data should be present. Read together, the profile turns an anonymous extraction into a named, dated, identified device, which is the foundation the rest of the analysis is built on.

Why It Matters

Identity, Provenance and the Clock

The device profile does three jobs that hold the rest of the examination together. First it establishes identity: the serial, the IMEI and the model can be matched against the identifiers recorded when the phone was seized or received, so an examiner can document that the evidence analyzed is the case device rather than assuming it. That single check heads off a challenge that can otherwise unravel an entire report.

Second it fixes provenance: a named device with a known account and known backup dates ties the evidence to a source and a moment, which is what a defensible chain depends on. Third and easy to overlook, it anchors the clock. The device timezone recorded in the profile is what lets every timestamp elsewhere in the examination read in the correct local time, so a message, a call and a location line up honestly rather than drifting hours out of sequence. Get the device profile right and the timeline is trustworthy; get it wrong and every downstream time is suspect.

Any Source

Reachable From a Backup or an Extraction

The identifying profile does not require deep acquisition. The core device identity, the model, the iOS version, the serial, the capacity, the device name and the account, is carried in an encrypted logical backup, so Sherlock builds the profile from a backup you make over USB from a device you can unlock and Trust, from an existing iTunes or Finder backup or from a Cellebrite UFED or VeraKey full-filesystem extraction. The identity of the device is available whichever way the evidence arrived.

A full-filesystem extraction can add further system-level detail around the device, but the identifying profile itself comes through a backup in full. That means an examiner can confirm which device an evidence file belongs to from the least invasive acquisition, which is exactly the check you want to be able to make early and cheaply.

See It

Sherlock Forensics iPhone Analyzer device overview showing model, iOS version, serial, capacity and account for an iPhone
The device profile: model, iOS version, identifiers, capacity and account in one overview

Court-Ready

From the Profile to the Report

Because the device profile is what ties evidence to a specific phone, it belongs in the record: the court-ready HTML report carries case and evidence numbers, examiner identification, disclosed methodology, per-artifact SHA-256 hashing and an optional evidence-integrity manifest, with the device profile recorded as the identity of the evidence, the documentation practice set out in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics. Analysis is 100 percent read-only; the evidence is never modified.

Built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record so testimony rests on it rather than on recollection.

Honest Scope

What This Analysis Is and Is Not

Sherlock reads the device profile from evidence you can lawfully acquire: a device you can unlock, an existing backup or a full-filesystem extraction produced by acquisition tooling. It does not unlock a locked device and does not bypass a passcode. The profile identifies the device and the account signed into it, not the person who was holding the phone; attribution to an individual is a separate question weighed against the rest of the record. Sherlock reports the identifiers the acquired evidence carries and records them precisely, which is what an examiner can match against a custody record and defend on the stand.

Questions

Device Information Forensics FAQ

What device information does Sherlock show?
Sherlock Forensics iPhone Analyzer builds the device profile: model, iOS version, serial number, IMEI where present, storage capacity, device name, the signed-in account and the backup dates the evidence records. It is the at-a-glance identity of the device the rest of the examination sits on.
Why does the device profile matter?
It answers the first question in any examination: which device is this. Matching the serial, IMEI and model against a seizure or custody record ties the evidence to the case device. The device timezone anchors every timestamp in the examination so the timeline reads in the right local time.
Can the device profile confirm the evidence matches the seized phone?
It supports that check. The serial number, IMEI, model and capacity in the device profile can be compared against the identifiers recorded when the phone was seized or received, so an examiner documents that the analyzed evidence corresponds to the case device rather than assuming it.
Does the device profile need a full-filesystem extraction?
No. The core device identity, model, iOS version, serial, capacity, device name and account, is carried in an encrypted logical backup, so Sherlock builds the profile from a backup as well as from a full-filesystem extraction. An extraction can add further system detail, but the identifying profile does not require one.
Does device information identify a person?
No. The profile identifies the device and the account signed into it, not who was holding the phone. An account ties activity to a credential, which is strong corroboration, but attribution to a person is a separate question the examiner weighs against the rest of the record.
Is device-information evidence court-defensible?
Analysis is read-only and the court-ready report documents examiner details, methodology and per-artifact SHA-256 hashing, with the device profile recorded as the identity of the evidence. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record for testimony.

Start Now

See the Device Profile in Your Evidence

Download the free edition, open a backup or extraction and read the device profile yourself. Unlock the full examination and the court-ready report when the case calls for it: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: The forensic image load workflow · Read a VeraKey extraction · The full parser list · Product page