Full-Filesystem Analysis · VeraKey

Read a VeraKey Extraction Without a Second Enterprise Seat

VeraKey captured the device. Sherlock Forensics iPhone Analyzer turns that capture into worked evidence on any Windows workstation, $599 one-time.

Sherlock Forensics iPhone Analyzer opens a VeraKey (Grayshift, now Magnet Forensics) full-filesystem extraction directly: it detects the extraction layout, resolves every artifact at its real on-device path and runs 130+ parser views against it, validated on a real iPhone 14 image. Free edition previews every view; the $599 Forensic Edition unlocks full analysis and court-ready reporting.

Windows 10/11 | One-time license | Fully offline | 100 percent read-only

The Situation

The Capture Platform and the Analysis Seat Are Separate Bills

Organizations buy VeraKey for what it does at the acquisition step: consent-based full-filesystem capture of modern iPhones in corporate, HR and internal-investigation settings. What arrives after the capture is a filesystem tree. The traditional next step is an enterprise analysis platform with its own annual subscription, a second bill that often exceeds the first over the life of the tooling.

Sherlock Forensics iPhone Analyzer decouples the two. It ingests the VeraKey extraction directly: detection of the extraction layout is automatic, every artifact resolves at its real on-device path and the full parser suite runs against the capture's depth. Ingestion is validated against a real device image, an iPhone 14 on iOS 16.5.1, alongside the same validation on Cellebrite UFED extractions.

The result is a working model where acquisition stays on the platform built for it and every reviewer who needs to work the evidence gets a $599 one-time seat instead of a subscription, with the free edition available to triage the capture before any purchase at all.

How To

From VeraKey Capture to Court-Ready Report

  1. Unpack the extraction. Extract the VeraKey capture to a local folder on the analysis workstation so the full-filesystem tree is browsable.
  2. Open the tree in Sherlock. Point the tool at the extracted tree. Detection is automatic; no conversion step and no enterprise analysis license required.
  3. Confirm device identity. Sherlock reads model, iOS build and identifiers from authoritative on-device sources inside the extraction itself, so the identity reflects what the filesystem actually records rather than an external label.
  4. Work the evidence. Analyze across 130+ dedicated views, run global and keyword-watchlist search, flag items as you go and read the automated findings.
  5. Report. Produce the court-ready HTML report with case and evidence numbers, examiner details, disclosed methodology and an optional SHA-256 evidence-integrity manifest. Export any view to CSV or JSON.

Analysis Depth

What the Full-Filesystem Depth Surfaces

A full-filesystem capture carries the behavioral layer that lighter acquisitions never copy out. Sherlock's deep view groups are built for exactly that layer:

  • Pattern of life: Screen Time app usage with daily totals, power-log app usage, app install and uninstall history with versions, the launch-by-launch app sequence, Siri actions and analytics and the Focus and Do Not Disturb timeline, the picture of how the device was actually used around the moments an investigation cares about.
  • Whereabouts: significant locations with dwell times and enter and exit transitions, Apple Maps history, Find My devices and accessories, Waze destinations and named place-visit life events.
  • Messaging recovery: chat recovered from on-device web caches for Skype, Facebook Messenger, Google Chat, LINE, imo, MeWe, Gettr, MEGA Chat, Instagram direct messages, TikTok direct messages, Discord and Reddit, with delivered-notification previews that survive in-app deletion. Recovered from web caches and notification previews for apps whose message stores are not directly readable, labeled as such in the interface and the report.
  • Media, health and contacts: hidden and deleted photos, screenshots, per-photo camera make and model, edited photos, health workouts with GPS routes, heart-rate history, contact frequency and significant contacts.
  • Apps, accessories and web: Bluetooth and Bluetooth LE device history, AirDrop and sharing history, Snapchat memories and the cross-app cached-web-request view that surfaces in-app web and API activity.

The classic artifact set runs against the same capture: threaded messages and iMessage, WhatsApp with groups, call history, Safari, photos with capture GPS, notes, calendars and the automated findings that flag hidden-vault apps and privacy-sensitive permission grants. Everything feeds one merged timeline and one global search.

Consent-Based Work

Built for the Investigations VeraKey Serves

VeraKey's natural habitat is the consented examination: a company device in an insider-threat or IP-theft inquiry, an HR matter where the employee handed over the phone, an internal investigation running under policy and counsel's guidance. Those matters need the same evidentiary discipline as a criminal case and rarely have a full-time lab behind them.

Sherlock fits that shape. Analysis runs fully offline on the investigator's workstation, so the capture never leaves the organization's custody. It is 100 percent read-only, so the evidence is never modified. The court-ready report documents examiner identity, methodology and an optional SHA-256 evidence-integrity manifest, the documentation elements described in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics, so a workplace matter that later escalates to litigation arrives with its record already in order. Authority and consent scope are questions for counsel; the tool's job is to make the technical record defensible.

Honest Scope

What This Workflow Is and Is Not

Sherlock analyzes the extraction VeraKey produced; it does not perform full-filesystem acquisition of any iPhone and it does not bypass locks. Sherlock's own acquisition of a device in hand uses Apple's supported logical path, which requires the passcode and the Trust prompt. The deep behavioral groups above light up when the case source is a full-filesystem extraction.

Confirmed ingestion formats are VeraKey and Cellebrite UFED full-filesystem extractions, each validated against real device images. If your capture came from a different platform, contact us before purchasing and we will confirm whether the layout is readable.

Questions

VeraKey Extraction FAQ

Can Sherlock open a VeraKey extraction?
Yes. Sherlock Forensics iPhone Analyzer ingests a VeraKey (Grayshift, now Magnet Forensics) full-filesystem extraction: point it at the extracted tree, it detects the layout, resolves every artifact at its real on-device path and runs the full parser suite. Ingestion is validated against a real device image, an iPhone 14 on iOS 16.5.1.
Do I need a Magnet or Grayshift analysis license to review what VeraKey captured?
No. The extraction itself is a filesystem tree and Sherlock reads it directly. Acquisition stays on the VeraKey platform you already own; the analysis seat is Sherlock at $599 one-time, with a free edition that previews every artifact view first.
What does Sherlock parse out of a VeraKey full-filesystem extraction?
130+ dedicated views spanning communications, media, web, location, personal, apps and system, including the deep full-filesystem groups: pattern of life from Screen Time and power-log records, significant locations with dwell times, app install and launch history, chat recovered from web caches and delivered-notification previews, health workouts with GPS routes and contact intelligence. Every view is searchable and exportable and feeds one merged timeline.
How does Sherlock identify the device in a VeraKey extraction?
Device identity is read from authoritative on-device sources inside the extraction itself, so the model, iOS build and identifiers reflect what the filesystem actually records rather than an external label.
Is VeraKey analysis in Sherlock defensible for workplace and consent-based investigations?
Sherlock keeps analysis 100 percent read-only, runs fully offline on your workstation and produces a court-ready HTML report with examiner details, disclosed methodology and an optional SHA-256 evidence-integrity manifest. Defensibility always also depends on your authority to examine the device and on proper evidence handling; consent scope and policy questions belong with counsel.
Does Sherlock acquire full-filesystem extractions itself?
No. Full-filesystem acquisition is the acquisition platform's job, VeraKey in this workflow. Sherlock analyzes the extraction it produced. Sherlock's own acquisition of a device in hand uses Apple's supported logical path and requires the passcode and the Trust prompt.
What does the free edition show before I buy?
It opens the extraction and previews every artifact view: the first 25 percent of each view, capped at 100 rows, with file metadata and hashes. Global search, export, the court report and the raw SQLite browser unlock in the $599 Forensic Edition.

Start Now

Open Your VeraKey Capture Today

Download the free edition, point it at the extracted tree and see what the capture holds. Unlock the full analysis seat when the matter calls for it: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: Read a Cellebrite UFED extraction · iPhone full-filesystem analysis · Magnet AXIOM alternative