Full-Filesystem Depth

iPhone Full-Filesystem Analysis: What the Deep Image Actually Holds

The extraction was the hard part. The analysis should not cost a second enterprise seat. Sherlock Forensics iPhone Analyzer works the full depth of a Cellebrite UFED or VeraKey image for $599 one-time.

A full-filesystem iPhone extraction contains the behavioral logs, on-device intelligence caches and third-party app storage that lighter acquisitions never copy out. Sherlock Forensics iPhone Analyzer ingests a Cellebrite UFED or VeraKey extraction, resolves every artifact at its real on-device path and runs 130+ parser views against that depth. $599 one-time; free edition previews every view.

Windows 10/11 | One-time license | Fully offline | 100 percent read-only

The Evidence Layers

Why the Full Filesystem Is a Different Class of Evidence

iPhone evidence comes in layers. The surface layer is what any acquisition method reaches: messages, call history, contacts, photos, browser history. Cases are won on it every week and for most matters it is enough. But underneath sits a behavioral layer the operating system keeps for itself: usage databases, power logs, intelligence caches and application containers. That layer never leaves the device through lighter acquisition paths. It comes out only in a full-filesystem extraction, produced with Cellebrite or GrayKey class tooling.

The behavioral layer changes the questions an examiner can answer. The surface layer shows what was said; the behavioral layer shows what was done: when the device was used, which apps ran and for how long, where the device dwelled and for how many minutes, what was installed and uninstalled and when. In disputes that turn on timeline, intent or presence, that is frequently the decisive evidence.

The economics have been the barrier. The platforms that acquire the full filesystem also sell the analysis seats, subscription-priced for full-time labs. Sherlock Forensics iPhone Analyzer separates the two: acquisition stays with the platform that owns it; analysis of the resulting extraction runs on any Windows workstation at $599 one-time.

Parser Depth

What Sherlock Parses Out of a Full-Filesystem Image

Sherlock runs 130+ dedicated parser views against the extraction, every one searchable, exportable and feeding a single merged timeline and global search. On a full-filesystem image, the groups added in version 1.2.0 reach their full depth:

  • Pattern of life. Screen Time app usage with daily totals, power-log app usage, app install and uninstall history with versions, the launch-by-launch app sequence, app intents, Siri actions and analytics and the Focus and Do Not Disturb timeline. Together they reconstruct how the device was actually used, hour by hour.
  • Whereabouts. Significant locations with dwell times and enter and exit transitions, Apple Maps history, Find My devices, AirTags and family location-sharing members, Waze destinations and named place-visit life events.
  • Messaging recovery. Chat recovered from on-device web caches for Skype, Facebook Messenger, Google Chat, LINE, imo, MeWe, Gettr, MEGA Chat, Instagram direct messages, TikTok direct messages, Discord and Reddit, with delivered-notification previews that survive in-app deletion. Recovered from web caches and notification previews for apps whose message stores are not directly readable, labeled as such in the interface and the report.
  • Media intelligence. Hidden and deleted photos, screenshots, photo albums, per-photo camera make and model, edited photos, Apple Podcasts, the media library and Now Playing history.
  • Health and contacts. Workouts with GPS routes, heart-rate history, Fitbit GPS tracks, contact frequency, significant contacts and the entities learned by the on-device intelligence platform.
  • Apps, accessories and web. Bluetooth and Bluetooth LE device history, Snapchat memories, AirDrop and sharing history, the Stocks watchlist, the Clock app and a cross-app cached-web-request view that surfaces in-app web and API activity from nearly every installed app.

The classic artifact set is all present as well: threaded messages and iMessage, WhatsApp with groups, call history, Safari, photos with capture GPS, keychain-derived Wi-Fi networks, notes, calendars and the automated findings that flag emergency calls, hidden-vault apps and privacy-sensitive permission grants for first-look triage.

Integrity

Provenance at Full-Filesystem Depth

Depth without provenance is a liability on the stand. Sherlock's extraction-provenance view parses and merges the acquisition descriptors, for a UFED image the .ufd, .ufdx and DeviceInfo.txt files, into one record: device model, iOS build, examiner machine, acquisition tool and version, start and end times and the per-dump SHA-256 and HMAC the acquisition tool recorded at capture. The full descriptor is carried verbatim so nothing is hidden. Analysis is 100 percent read-only throughout.

The court-ready HTML report carries case and evidence numbers, examiner identification, disclosed methodology and an optional SHA-256 evidence-integrity manifest, the documentation elements described in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics. Built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice.

See It

Sherlock Forensics iPhone Analyzer dashboard overview with device summary, artifact counts and investigative highlights
Dashboard overview of the full extraction
Sherlock Forensics iPhone Analyzer merged activity timeline correlating behavioral and communication events
The merged timeline: behavior and communication in one sequence
Sherlock Forensics iPhone Analyzer location intelligence plotted on an offline map
Location intelligence on an offline map
Sherlock Forensics iPhone Analyzer app permissions view showing TCC grants for camera, microphone and location
App permissions and privacy-sensitive grants

Honest Scope

What This Analysis Is and Is Not

Sherlock analyzes full-filesystem extractions; it does not create them. Producing an FFS image of a modern iPhone requires Cellebrite or GrayKey class acquisition tooling. On current hardware and iOS versions even those platforms face real limits. Sherlock's own acquisition of a device in hand uses Apple's supported logical path, which requires the passcode and the Trust prompt and reaches the surface layer, not the behavioral layer described above. The deep groups on this page light up when the case source is a full-filesystem extraction.

Confirmed ingestion formats are Cellebrite UFED and VeraKey (Grayshift, now Magnet Forensics), validated against real device images. Different source? Contact us first and we will confirm whether the layout is readable.

Questions

Full-Filesystem Analysis FAQ

What is an iPhone full-filesystem extraction?
A full-filesystem (FFS) extraction is a copy of the iPhone's user data partition taken with elevated access: system databases, application containers, behavioral logs and caches, far beyond what lighter acquisition methods copy out. Producing one requires Cellebrite or GrayKey class acquisition tooling. Sherlock Forensics iPhone Analyzer analyzes the extraction those tools produce.
What does a full-filesystem image contain that lighter acquisitions do not?
The behavioral and system layer: Screen Time and power-log usage records, app install and uninstall history, the launch-by-launch app sequence, significant locations with dwell times, on-device intelligence caches, third-party app containers and web caches that hold recoverable chat from apps with no readable message store. That layer is where pattern-of-life analysis lives.
Can Sherlock analyze my full-filesystem extraction?
Yes, if it came from Cellebrite UFED or VeraKey (Grayshift, now Magnet Forensics). Point Sherlock at the extracted tree; it detects the layout, resolves every artifact at its real on-device path and runs the full parser suite. Ingestion of both formats is validated against real device images.
Does Sherlock create full-filesystem extractions?
No. Full-filesystem acquisition requires Cellebrite or GrayKey class tooling. Sherlock analyzes the extraction such a tool produced. Its own acquisition of a device in hand uses Apple's supported logical path and requires the passcode and the Trust prompt.
How many artifact views does the analysis produce?
130+ dedicated views, each searchable and exportable, spanning communications, media, web, location, personal, apps, system and the deep full-filesystem groups added in version 1.2.0: pattern of life, whereabouts, messaging recovery from web caches and notification previews, expanded media, health and contact intelligence. Every view feeds one merged timeline and one global search.
Is the analysis defensible in court?
Analysis is 100 percent read-only and the extraction-provenance view carries the acquisition tool's own descriptors verbatim, including per-dump SHA-256 and HMAC values. The court-ready report documents examiner details, methodology and an optional SHA-256 evidence-integrity manifest. Admissibility depends on jurisdiction and on proper evidence handling.
What does it cost compared to an enterprise analysis platform?
$599 one-time for the Forensic Edition against annual enterprise analysis subscriptions in the four to five figures. The free edition previews every artifact view first: the first 25 percent of each view, capped at 100 rows.

Start Now

Put a Real Analysis Seat on Your Extraction

Download the free edition and open your Cellebrite UFED or VeraKey image today. Unlock the full depth when the case calls for it: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: Read a Cellebrite UFED extraction · Product page · Forensic tool comparison