Per-Artifact Deep Dive

Keychain Forensics: The Keys to the Device

The keychain is where an iPhone keeps its saved credentials. What Sherlock can read from it depends entirely on the source. This page is exact about that line.

Sherlock Forensics iPhone Analyzer surfaces the iPhone keychain in the clear from a Cellebrite full-filesystem extraction, which carries the decrypted keychain in full: saved passwords, credentials, authentication tokens, certificates and Wi-Fi passwords. A Magnet VeraKey extraction ships the keychain SEP-encrypted, so on that source it stays locked. Saved Wi-Fi passwords are the broad exception, coming through an encrypted backup as well. $599 one-time; the free edition previews it first.

Windows 10/11 | One-time license | Cellebrite full-filesystem for the full keychain | 100 percent read-only

The Artifact

What the Keychain Holds

The keychain is the iPhone's secure store for the credentials a device accumulates: saved account passwords, Wi-Fi network passwords, authentication tokens, certificates and other secrets that apps and the system tuck away so a user does not retype them. In an examination it is one of the most concentrated artifacts on the device, because it documents in one place which services the device held access to and which networks it joined. Sherlock Forensics iPhone Analyzer presents it as a searchable keychain view, each item shown with its account and service where the record carries them.

Wi-Fi passwords are often the highest-value entries. Every network the device saved, with its password, is a record of the places the device was configured to connect, which reads as whereabouts corroboration alongside the location artifacts. Saved account credentials document the services a person used from the device. Certificates and tokens round out the picture of the device's trusted relationships. Each is read as a stored keychain item, evidence of what the device retained, not a live login.

Source Scope

The Line That Decides Everything: Where the Keychain Comes From

The keychain is the artifact where the source of the evidence matters most, so this page states the line plainly. The full keychain in the clear comes from a Cellebrite full-filesystem extraction, which ships the keychain already decrypted. From that source Sherlock surfaces the saved passwords, credentials, authentication tokens, certificates and Wi-Fi passwords in full. It is the acquisition that carries the decrypted keychain that makes this readable, not the analysis tool alone.

A Magnet VeraKey extraction is different, in a way that is decisive. VeraKey ships the keychain SEP-encrypted, so on a VeraKey image the keychain content stays locked. Sherlock reports it as locked rather than pretending to read it, because the encryption does not permit otherwise from that source. Any claim to decrypt a full keychain from every extraction would be false. This page does not make it: the full keychain in the clear is the Cellebrite full-filesystem case. A VeraKey image keeps it sealed.

The Broad Exception

Wi-Fi Passwords Come Through a Backup Too

There is one honest exception worth stating clearly, because it widens what is reachable without a full-filesystem extraction. Saved Wi-Fi passwords live in the keychain subset that an encrypted backup carries, so they come through an encrypted MobileBackup2 backup as well as from a Cellebrite full-filesystem extraction. That means Wi-Fi passwords do not require the Cellebrite image; a backup you make from an unlockable device (or an existing encrypted backup) surfaces the saved networks with their passwords.

The exception is specific to what the backup carries, not a blanket keychain read. A VeraKey image still keeps the keychain, Wi-Fi passwords included, SEP-encrypted and locked. The rule underneath is consistent throughout: Sherlock reads exactly what the source makes available, surfaces Wi-Fi from a backup or a Cellebrite extraction, reads the full keychain from a Cellebrite extraction and marks a VeraKey keychain locked. Nothing here is stretched past what the acquisition actually yields.

See It

Sherlock Forensics iPhone Analyzer keychain view showing saved credentials and Wi-Fi passwords in the clear from a Cellebrite full-filesystem extraction
Saved credentials and Wi-Fi passwords in the clear from a Cellebrite full-filesystem extraction

Court-Ready

From the Keychain to the Report

Because keychain evidence carries credentials and turns on the source, the documentation records both: the court-ready HTML report carries case and evidence numbers, examiner identification, disclosed methodology, per-artifact SHA-256 hashing and an optional evidence-integrity manifest, with the source scope stated and any locked keychain marked as locked, the documentation practice set out in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics. Analysis is 100 percent read-only; the evidence is never modified.

Built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record so testimony rests on it rather than on recollection.

Honest Scope

What This Analysis Is and Is Not

Sherlock reads the keychain that the acquired evidence carries. The full keychain in the clear comes from a Cellebrite full-filesystem extraction; a VeraKey extraction ships it SEP-encrypted and it stays locked; saved Wi-Fi passwords also come through an encrypted backup. It does not unlock a locked device, does not bypass a passcode and does not decrypt a VeraKey keychain that the Secure Enclave keeps sealed. A saved keychain item shows a credential the device stored, tied to the device, not proof of who entered it. Sherlock reports what the source makes available, states the scope and marks what is locked, which is what an examiner can defend on the stand.

Questions

Keychain Forensics FAQ

What does Sherlock recover from the iPhone keychain?
From a Cellebrite full-filesystem extraction, which carries the decrypted keychain in full, Sherlock Forensics iPhone Analyzer surfaces saved passwords, credentials, authentication tokens, certificates and Wi-Fi passwords in the clear. Each is presented as a saved keychain item with its account and service where the record holds them.
Does keychain recovery work from any extraction?
No. The full keychain in the clear depends on the source. A Cellebrite full-filesystem extraction ships the keychain already decrypted, so it reads in full. A Magnet VeraKey extraction ships the keychain SEP-encrypted, so on a VeraKey image the keychain stays locked and Sherlock reports it as locked rather than pretending to read it.
Can Wi-Fi passwords come from a backup?
Yes. Saved Wi-Fi passwords are the broad exception. Because the keychain subset that an encrypted backup carries includes them, Wi-Fi passwords come through an encrypted MobileBackup2 backup as well as from a Cellebrite full-filesystem extraction, so they do not require a Cellebrite image. A VeraKey image keeps them SEP-locked with the rest of the keychain.
Does a saved credential prove the owner typed it?
No. A keychain item shows that a credential was saved on the device, not who entered it or whether it is still valid. It is stored-credential evidence tied to the device, weighed with the rest of the record, not proof of a person's action on its own.
Why does the keychain matter in an examination?
The keychain is where the device kept the keys to a person's digital life: account passwords, Wi-Fi networks joined, certificates and tokens. Wi-Fi passwords in particular place the device on named networks. Saved credentials document which services the device held access to, each read as stored evidence tied to the device.
Is keychain evidence court-defensible?
Analysis is read-only and the court-ready report documents examiner details, methodology and per-artifact SHA-256 hashing, with the source scope stated and locked keychains marked as locked. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record for testimony.

Start Now

See the Keychain in Your Evidence

Download the free edition, open a Cellebrite full-filesystem extraction and read the keychain in the clear or open an encrypted backup for the saved Wi-Fi passwords. Unlock the full analysis and the court-ready report when the case calls for it: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: Recover iPhone Wi-Fi passwords · Read a Cellebrite UFED extraction · iPhone forensics fact checks · Product page