Examiner Workflow

How to Load a Forensic iPhone Image, Whatever Produced It

UFED tree, VeraKey capture or a plain backup folder: one workflow from source to court-ready report, on your own Windows workstation.

Sherlock Forensics iPhone Analyzer loads three iPhone evidence sources with automatic detection: an extracted Cellebrite UFED full-filesystem tree, a VeraKey extraction and any MobileBackup2 backup folder. No conversion step, analysis is read-only and provenance from the acquisition descriptors is carried verbatim. Free edition previews every view; $599 one-time unlocks full analysis.

Windows 10/11 | One-time license | Fully offline | 100 percent read-only

Supported Sources

Three Ways iPhone Evidence Arrives, One Way to Work It

iPhone evidence reaches an examiner in a handful of shapes. A full-filesystem extraction arrives from an acquisition platform: an extracted Cellebrite UFED tree with its .ufd, .ufdx and DeviceInfo.txt descriptors or a VeraKey (Grayshift, now Magnet Forensics) capture. A logical backup arrives as a MobileBackup2 folder, whether Sherlock acquired it from an unlocked device or iTunes or Finder made it months before anyone knew there would be a case. Sherlock loads all three through the same open-the-source workflow, with automatic detection deciding the parser path.

SourceHow Sherlock detects itDepth reached
Cellebrite UFED full-filesystem treeUFED .ufd, .ufdx and DeviceInfo.txt descriptorsFull behavioral layer, artifacts at real on-device paths
VeraKey full-filesystem extractionVeraKey extraction layout, device identity from on-device sourcesFull behavioral layer, artifacts at real on-device paths
MobileBackup2 backup folderMobileBackup2 folder layoutSurface layer: messages, media, web, keychain from encrypted backups

There is no proprietary case container to import into and no conversion utility between the evidence and the analysis. That matters beyond convenience: every format conversion is a step someone can be cross-examined about. Loading the source directly, read-only, keeps the distance between what was acquired and what was analyzed as short as it can be.

The Workflow

From Source to Report in Five Steps

  1. Stage the evidence locally. Work from a copy on the analysis workstation and keep the original media intact. If the extraction arrived archived, unpack it to a local folder so the filesystem tree and its descriptors are browsable. Avoid cloud-synced folders; local disk keeps custody clean and analysis fast.
  2. Open the source in Sherlock. Point the tool at the tree or backup folder. Detection is automatic: UFED descriptors, the VeraKey layout or the MobileBackup2 folder layout each route to the right parser path. An encrypted backup prompts for its password and decrypts offline via RFC 3394 keybag unwrap and AES.
  3. Verify identity and provenance. Confirm the device model, iOS build and identifiers Sherlock reads from the source itself. For extractions, review the provenance record carried verbatim from the acquisition descriptors: acquisition tool and version, examiner machine, capture times and the per-dump SHA-256 and HMAC values recorded at capture, ready to compare against the files as received.
  4. Analyze. Work the evidence across 130+ dedicated views. Run global and keyword-watchlist search, read the automated findings, walk the merged timeline and flag items as you go; flagged items roll into the report.
  5. Report and export. Produce the court-ready HTML report with case and evidence numbers, examiner details, disclosed methodology and an optional SHA-256 evidence-integrity manifest. Print to PDF or export any view to CSV or JSON.

Depth Honesty

What Each Source Type Can and Cannot Show

All 130+ views are available against any loaded source, but what populates them depends on what the source contains. Sherlock states that honestly rather than papering over it. A full-filesystem extraction populates the deep behavioral groups: pattern of life from Screen Time and power-log records, significant locations with dwell times and enter and exit transitions, app install and launch history, chat recovered from web caches and delivered-notification previews for apps whose message stores are not directly readable. A logical backup populates the surface layer thoroughly, messages, WhatsApp, call history, Safari, photos with capture GPS and the keychain when the backup is encrypted, while the full-filesystem-only views show honest empty states instead of fabricated data.

That empty state is a feature, not a gap. An examiner who testifies about what the tool showed also testifies about what it did not show. A view that reads empty because the source cannot contain that artifact is a defensible statement. A tool that quietly fills gaps is not.

Field Notes

Common Load Problems and How to Avoid Them

The tree is not fully unpacked. The most common failed load is pointing the tool at an archive or a half-extracted folder. Unpack the whole extraction first and open the top of the resulting tree, the level where the descriptors sit, not a subfolder inside it.

The evidence sits in a cloud-synced folder. OneDrive, Dropbox and their peers touch files while you work, which is exactly the interaction an examiner does not want on evidence and a frequent source of slow or failing reads. Stage the working copy on plain local disk.

You were given the report, not the extraction. A PDF or a viewer export from the producing party is not the evidence; it is a summary of it. If the matter justifies real analysis, request the extraction itself, the tree with its descriptors, then load that.

The backup is encrypted and nobody has the password. An encrypted backup needs its backup password to open; Sherlock decrypts offline once it has it but does not crack passwords. Establish who set the password before the review is scheduled, not after.

The production is partial. If the provenance record's per-dump hashes do not match the files as received or entire directories are missing against the descriptor, document it and raise it with the producing party before drawing conclusions from what remains.

Chain of Custody

Provenance Through the Whole Load

Loading never writes to the evidence: analysis is 100 percent read-only from detection through report. For extractions, the acquisition tool's own record travels with the case, descriptors carried verbatim, per-dump hashes visible, so the integrity chain that started at capture stays unbroken through analysis. The court-ready report then adds the analysis-side documentation: examiner identification, methodology, an optional SHA-256 evidence-integrity manifest and the provenance record, the documentation elements described in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics.

Sherlock is built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible digital forensics practice. The workflow above is the one its own examiners use.

Honest Scope

What This Workflow Assumes

This page is about loading evidence that exists. Sherlock does not create full-filesystem extractions; producing one requires Cellebrite or GrayKey class acquisition tooling. Sherlock's own acquisition of a device in hand uses Apple's supported logical path and requires the passcode and the Trust prompt; it does not bypass locks on any iPhone. Confirmed extraction formats are Cellebrite UFED and VeraKey, each validated against real device images. A different source? Contact us before purchasing and we will confirm whether the layout is readable.

Questions

Loading Forensic iPhone Images: FAQ

What iPhone image formats can Sherlock load?
Three source types: an extracted Cellebrite UFED full-filesystem tree with its .ufd, .ufdx and DeviceInfo.txt descriptors, a VeraKey (Grayshift, now Magnet Forensics) full-filesystem extraction and any MobileBackup2 backup folder made by Sherlock, iTunes or Finder. Detection is automatic for each.
Do I need to convert the image before loading it?
No. Sherlock reads the extracted tree or backup folder directly. The only preparation is unpacking an archived extraction to a local folder so the filesystem is browsable. There is no proprietary case format to import into and no conversion step where evidence could be altered.
How does Sherlock know what kind of image it is looking at?
It detects the source layout: UFED descriptor files mark a Cellebrite extraction, the VeraKey layout marks a VeraKey capture and the MobileBackup2 folder layout marks a backup. Every artifact then resolves at its real on-device path for the extraction types or through the backup layout mapping for backups.
What happens to the chain of custody when I load an image?
Nothing is modified: analysis is 100 percent read-only. For extractions, the provenance view carries the acquisition tool's descriptors verbatim, including per-dump SHA-256 and HMAC values recorded at capture, so the original integrity chain stays visible. The court report documents the analysis methodology on top of that record.
Can I load an encrypted iTunes backup?
Yes, with its backup password. Sherlock decrypts offline using RFC 3394 keybag unwrap and AES. An unencrypted backup opens directly, though it omits the keychain and Health data that only an encrypted backup carries.
Does loading a deeper image unlock more views?
Yes. All 130+ views are available against any source, but the deep behavioral groups, pattern of life, significant locations with dwell times, web-cache messaging recovery and notification previews, populate from full-filesystem depth. From a logical backup those views show honest empty states rather than fabricated data.
What does it cost?
The free edition loads any supported source and previews every artifact view: the first 25 percent of each view, capped at 100 rows. The Forensic Edition at $599 one-time unlocks the full data set, global search, export and the court-ready report. No subscription.

Start Now

Load Your Evidence Today

Download the free edition, open the tree or backup in front of you and see the workflow end to end. Unlock the full seat when the matter calls for it: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: Read a Cellebrite UFED extraction · Read a VeraKey extraction · iPhone full-filesystem analysis