iPhone evidence comes in layers. The surface layer is what any acquisition method reaches: messages, call history, contacts, photos, browser history. Cases are won on it every week and for most matters it is enough. But underneath sits a behavioral layer the operating system keeps for itself: usage databases, power logs, intelligence caches and application containers. That layer never leaves the device through lighter acquisition paths. It comes out only in a full-filesystem extraction, produced with Cellebrite or GrayKey class tooling.
The behavioral layer changes the questions an examiner can answer. The surface layer shows what was said; the behavioral layer shows what was done: when the device was used, which apps ran and for how long, where the device dwelled and for how many minutes, what was installed and uninstalled and when. In disputes that turn on timeline, intent or presence, that is frequently the decisive evidence.
The economics have been the barrier. The platforms that acquire the full filesystem also sell the analysis seats, subscription-priced for full-time labs. Sherlock Forensics iPhone Analyzer separates the two: acquisition stays with the platform that owns it; analysis of the resulting extraction runs on any Windows workstation at $599 one-time.



