Full-Filesystem Analysis · New in 1.2.0

Read a Cellebrite UFED Extraction Without Cellebrite

You have the extraction. Sherlock Forensics iPhone Analyzer turns it into evidence you can actually work, on your own Windows workstation, for $599 one-time.

Sherlock Forensics iPhone Analyzer opens an extracted Cellebrite UFED full-filesystem tree directly: it detects the extraction, resolves every artifact at its real on-device path and runs 130+ parser views against it. No Cellebrite license needed to analyze an extraction you already have. Free edition previews every view; the $599 Forensic Edition unlocks full analysis and court-ready reporting.

Windows 10/11 | One-time license | SSL.com EV signed | Fully offline

The Situation

You Have the Extraction. Working It Is the Expensive Part.

A Cellebrite UFED full-filesystem extraction arrives in your matter: produced in discovery, delivered by opposing counsel, handed over by a client's outside lab or captured by your own acquisition team on an enterprise seat. The extraction is the easy part to receive and the expensive part to open. The tools that traditionally read it are the same enterprise platforms that produced it, licensed by annual subscription in the four to five figures.

That pricing model makes sense for a lab that acquires devices every week. It makes no sense for the attorney, investigator or examiner who needs to analyze one extraction in one matter. Sherlock Forensics iPhone Analyzer breaks that dependency: point it at the extracted UFED tree and it opens it the same way it opens any evidence source, detects the extraction, resolves every artifact at its real on-device path and runs the full parser suite. One $599 license, owned permanently, fully offline.

The same ingestion is validated on VeraKey (Grayshift, now Magnet Forensics) full-filesystem extractions, so the workflow holds regardless of which of the two major acquisition platforms produced your image.

For Counsel

Attorneys: Triage a Produced Extraction Before You Spend a Dollar

Defense counsel and civil litigators are the people most often handed a UFED extraction with no way to open it. The prosecution or the producing party worked the evidence on their enterprise platform; you receive a folder of files and a descriptor. Retaining a vendor to re-host the extraction costs thousands before you know whether the evidence matters.

The free edition of Sherlock Forensics iPhone Analyzer opens the extraction and previews every artifact view: the first 25 percent of each view, capped at 100 rows, with file metadata and hashes. That is a real triage pass: you see the message threads, the call patterns, the location picture and the app inventory before any purchase. When the matter justifies full analysis, the Forensic Edition unlocks the complete data set, global search, keyword watchlists, export and the court-ready report at $599 one-time, a figure a single case budget absorbs without a motion for costs.

Because analysis runs entirely on your own workstation, offline, the produced evidence never leaves your custody, which keeps the review inside your existing protective-order obligations.

How To

How to Analyze a UFED Full-Filesystem Extraction in Sherlock

  1. Extract the UFED archive. Unpack the full-filesystem archive to a local folder on the analysis workstation so the extraction is a browsable tree alongside its .ufd, .ufdx and DeviceInfo.txt descriptors.
  2. Open the tree in Sherlock. Point the tool at the extracted tree. Detection is automatic; every artifact resolves at its real on-device path. No conversion step and no Cellebrite license required.
  3. Verify provenance. The extraction-provenance view merges the UFED descriptors into one record: device model, iOS build, examiner machine, acquisition tool and version, start and end times and the per-dump SHA-256 and HMAC recorded at acquisition. The full descriptor is carried verbatim so nothing is hidden from you or from the court.
  4. Analyze the artifacts. Work the evidence across 130+ dedicated views, run global and keyword-watchlist search and read the automated findings.
  5. Export the court-ready report. Case and evidence numbers, examiner details, selected sections, an optional SHA-256 evidence-integrity manifest and the provenance record. Print to PDF from any browser.

Analysis Depth

What a Full-Filesystem Extraction Surfaces in Sherlock

A full-filesystem extraction contains the behavioral logs, on-device intelligence caches and third-party app storage that lighter acquisition methods never copy out. Sherlock runs its whole parser suite against that depth. Every artifact lands in a dedicated, searchable, exportable view that feeds a merged timeline and global search:

  • Pattern of life: Screen Time usage with daily totals, power-log app usage, app install and uninstall history with versions, the launch-by-launch app sequence, Siri actions and analytics and the Focus and Do Not Disturb timeline.
  • Whereabouts: significant locations with dwell times and enter and exit transitions, Apple Maps history, Find My devices and AirTags, Waze destinations and named place-visit life events.
  • Messaging recovery: Skype, Facebook Messenger, Instagram and TikTok direct messages, Discord, Reddit and other chat recovered from on-device web caches alongside delivered-notification previews that survive in-app deletion. These come from web caches and notification previews for apps whose message stores are not directly readable, stated as such in the interface and the report.
  • Media and personal: hidden and deleted photos, screenshots, per-photo camera make and model, edited photos, health workouts with GPS routes, heart-rate history and contact-frequency intelligence.
  • Device and apps: Bluetooth and Bluetooth LE device history, AirDrop and sharing history, Snapchat memories and a cross-app cached-web-request view surfacing in-app web and API activity.

Position it honestly: Sherlock is additive to the acquisition platform, not a replacement for it. The extraction tool did the acquisition; Sherlock gives every examiner and every reviewer on the matter an affordable, dedicated analysis seat on the result.

See It

Sherlock Forensics iPhone Analyzer dashboard overview showing device summary, artifact counts and investigative highlights for an ingested extraction
Dashboard overview: every artifact and finding in one surface
Sherlock Forensics iPhone Analyzer activity timeline merging every dated event across communications, media, web and location
Merged activity timeline across every artifact source
Sherlock Forensics iPhone Analyzer location intelligence view plotting geotagged media and location artifacts on an offline map
Location intelligence on an offline map
Sherlock Forensics iPhone Analyzer threaded message reconstruction with attachments
Threaded message reconstruction with attachments
Sherlock Forensics iPhone Analyzer global search running one query across every artifact view
Global search across every artifact at once
Sherlock Forensics iPhone Analyzer deleted content recovery view with carved records and hidden media
Deleted content recovery and hidden media

Court-Defensibility

Provenance Preserved From Acquisition to Report

Analyzing a received extraction raises one question before any other: can you show the evidence was not altered between acquisition and review? Sherlock is built to answer it. The extraction-provenance view carries the UFED descriptors verbatim, including the per-dump SHA-256 and HMAC values the acquisition tool recorded at capture time, so the original integrity chain stays visible and testifiable. Analysis is 100 percent read-only; the extraction is never modified.

The court-ready HTML report documents case and evidence numbers, examiner identification, the disclosed methodology and an optional SHA-256 evidence-integrity manifest, the same documentation elements described in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics. The tool is built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible digital forensics practice. Admissibility always depends on jurisdiction and on the examiner's own evidence handling; the report documents what courts typically require.

Honest Scope

What This Workflow Is and Is Not

Sherlock Forensics iPhone Analyzer analyzes a full-filesystem extraction; it does not create one. Full-filesystem acquisition of a modern iPhone requires Cellebrite or GrayKey class tooling. On current hardware and iOS versions even those platforms face real limits. Sherlock's own acquisition of a device in hand uses Apple's supported logical path and requires the device passcode and the Trust prompt; it does not bypass locks or exploit the device.

Confirmed ingestion formats are Cellebrite UFED and VeraKey full-filesystem extractions, validated against real device images. If your extraction came from another platform, contact us before purchasing and we will confirm whether the layout is readable.

Questions

Reading UFED Extractions: FAQ

Can I open a Cellebrite UFED extraction without Cellebrite?
Yes. Sherlock Forensics iPhone Analyzer opens an extracted Cellebrite UFED full-filesystem tree directly. It detects the extraction, resolves every artifact at its real on-device path and runs its full parser suite against it. You do not need a Cellebrite Physical Analyzer license to analyze an extraction you already have.
What Cellebrite UFED files does Sherlock read?
Sherlock reads the extracted full-filesystem tree and parses the UFED .ufd, .ufdx and DeviceInfo.txt descriptors into a single extraction-provenance record: device model, iOS build, examiner machine, acquisition tool and version, start and end times and the per-dump SHA-256 and HMAC the acquisition tool recorded. The full descriptor is carried verbatim.
I received a UFED extraction in discovery. Can I review it before buying anything?
Yes. The free edition opens the extraction and previews every artifact view: the first 25 percent of each view, capped at 100 rows, with file metadata and hashes. That is enough to triage what the extraction contains and decide whether the matter justifies the $599 Forensic Edition, which unlocks the full data set, global search, export and the court-ready report.
Does Sherlock acquire full-filesystem extractions itself?
No. Sherlock analyzes a full-filesystem extraction that an acquisition tool such as Cellebrite UFED produced. Full-filesystem acquisition of a modern iPhone requires Cellebrite or GrayKey class tooling. Sherlock's own acquisition of a device in hand uses Apple's supported logical path and requires the passcode and the Trust prompt.
Does Sherlock read VeraKey extractions too?
Yes. Full-filesystem ingestion is validated on both Cellebrite UFED and VeraKey (Grayshift, now Magnet Forensics) extractions. Sherlock detects the extraction layout and reads device identity from authoritative on-device sources.
Will analysis of a received extraction hold up in court?
Sherlock preserves the chain from the original acquisition: the extraction-provenance view carries the UFED descriptors verbatim, including the per-dump hashes the acquisition tool recorded. The court-ready HTML report documents examiner details, methodology and an optional SHA-256 evidence-integrity manifest. Admissibility depends on jurisdiction and on proper evidence handling; the report documents what courts typically require.
What does Sherlock surface that my extraction tool's own viewer might not?
Every artifact is a dedicated, searchable, exportable view: pattern-of-life views built from Screen Time and power-log usage, app install and launch history, significant locations with dwell times, messages recovered from web caches and delivered-notification previews for apps with no readable message store, media intelligence and 130+ views in total, each feeding a merged timeline and global search.

Start Now

Open Your Extraction Today

Download the free edition, point it at your extracted UFED or VeraKey tree and see what the evidence holds. Unlock the full analysis seat when the matter calls for it: $599 one-time, no subscription, license key delivered by email.

Get Sherlock Forensics iPhone Analyzer

Related: Sherlock Forensics iPhone Analyzer product page · What Cellebrite actually costs · Forensic tool comparison