Pattern of Life

Screen Time Forensics: The Device's Own Usage Diary

Messages show what was said. Usage records show what was done: which apps ran, for how long, day by day, in the device's own accounting.

Screen Time forensics reads the iPhone's own usage accounting: per-app usage with daily totals, corroborated by power-log usage, the launch-by-launch app sequence and the Focus timeline. Sherlock Forensics iPhone Analyzer parses these from a Cellebrite UFED or VeraKey full-filesystem extraction into searchable views feeding one merged timeline. $599 one-time; free edition previews coverage first.

Windows 10/11 | One-time license | Full-filesystem depth | 100 percent read-only

The Artifact

What the Usage Diary Contains

iOS keeps meticulous books on its own use. Screen Time, the same system that shows a user their weekly report, records which apps were used and for how long, with daily totals. The power log tracks app activity from the energy side. The system records what was installed and uninstalled, with versions and dates, alongside the sequence in which apps launched. Focus and Do Not Disturb schedules mark when the user silenced the device and when they turned it back on.

Individually each is a data point. Together they are a diary of device behavior written by the operating system itself, timestamped, unglamorous and hard to argue with. In matters that turn on timeline, activity or presence, workplace investigations, custody disputes, insurance claims, alibi corroboration, that diary often speaks more plainly than any message thread.

Sherlock Forensics iPhone Analyzer parses each stream into its own dedicated view: Screen Time usage with daily totals, power-log app usage, app install and uninstall history with versions, the launch-by-launch app sequence and the Focus and Do Not Disturb timeline, alongside the correlation-level Pattern of Life view.

The Source

Why This Takes a Full-Filesystem Extraction

Usage records of this depth live in the behavioral layer of the operating system, the layer a logical backup does not copy out. They reach an examiner only inside a full-filesystem extraction, produced by Cellebrite UFED or VeraKey class acquisition tooling. Sherlock ingests that extraction, resolves the usage artifacts at their real on-device paths and runs the pattern-of-life parser set against them.

The honesty cut both ways: load a logical backup and these views show honest empty states rather than fabricated data, because the source cannot contain them. Load the full-filesystem extraction and they populate. The free edition shows you which, with item counts per view, before any purchase. If you have not worked with extractions before, start with how to load a forensic iPhone image.

Corroboration

Independent Streams That Check Each Other

The forensic strength of usage evidence is that iOS records it several ways for its own reasons, none of them anticipating an investigation. Screen Time accounts for usage in daily totals. The power log sees app activity through energy consumption. The launch sequence records order. The Focus timeline marks silencing behavior. These streams were never designed to agree with each other, so when they do, the narrative they support is difficult to dismiss as a glitch in one database.

Sherlock keeps the streams distinct, one view each, rather than blending them into a single derived score. An examiner can show that the Screen Time total, the power-log activity and the launch sequence independently indicate the same session or flag honestly when they diverge. The merged Activity Timeline then places those sessions in sequence with messages sent, photos taken, locations visited and calls made around the same minutes, which is where a usage record becomes case evidence rather than a curiosity.

The app install and uninstall history deserves its own mention in this composition. An app that was installed two days before the events in question, used heavily through them on the usage streams and uninstalled the day after tells a story all by itself, with versions and dates recorded by the system rather than asserted by anyone.

In Practice

Where the Usage Diary Decides Matters

Workplace and hours disputes. When the question is what an employee's company device was doing during claimed working hours, the daily usage totals and the launch sequence give the inquiry a factual spine: which apps ran, for how long, on which days. The record is the device's own, kept long before anyone anticipated a dispute, which is precisely what makes it persuasive.

Custody and family matters. Claims about phone use around children, at particular hours or in particular volumes, usually arrive as competing recollections. A usage diary replaces recollection with accounting: totals by day and by app, silencing behavior from the Focus timeline and install history showing when an app appeared or vanished.

Timeline corroboration. When a case turns on whether the device was active at a specific time, usage streams either corroborate the claimed timeline or complicate it, in sequence with the messages, photos and locations from the same minutes on the merged timeline. Either answer is evidence; the diary does not take sides.

In every one of these, the scope statement from the section below still governs: the diary shows the device's activity, always presented with the corroboration question in the open.

The Limit That Matters

Device Activity Is Not Person Activity

The most important sentence in any usage-evidence report is the scope statement: these records attribute activity to the device, not to a person. Screen Time cannot testify about whose thumb was on the glass. An examiner who presents usage records as proof of a person's behavior without corroboration invites the cross-examination that undoes the whole report.

Worked honestly, the usage diary is the skeleton and the corroboration is the flesh: message content sent during the session, account activity under a known login, location context from the same minutes, camera captures, witness evidence. Sherlock is built for exactly that composition, usage views and content views feeding one timeline, so the attribution argument is assembled in the open from independent artifacts rather than asserted from a single database. The report presents the record; the case makes the argument.

Court-Ready

From Usage Record to the Report

Every usage view exports to CSV or JSON, flagged items roll into the court-ready HTML report and the report shows usage evidence in sequence with the rest of the record: case and evidence numbers, examiner identification, disclosed methodology, per-artifact SHA-256 hashing and an optional evidence-integrity manifest, the documentation elements described in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics. Analysis is 100 percent read-only throughout; the extraction is never modified.

Built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record so the testimony can stand on it.

Questions

Screen Time Forensics FAQ

What does Screen Time actually record?
iOS keeps its own accounting of app usage: which apps were used and for how long, with daily totals. In Sherlock Forensics iPhone Analyzer that record becomes a dedicated, searchable view with per-app usage and day-by-day totals, read from a full-filesystem extraction.
Can I get Screen Time evidence from a regular iPhone backup?
No. Usage records of this depth live in the behavioral layer that a logical backup does not copy out. They come from a full-filesystem extraction produced by Cellebrite UFED or VeraKey class tooling. From a logical backup, Sherlock shows those views as honest empty states rather than fabricated data.
Does Screen Time prove who was using the phone?
No. An honest examiner never claims it does. Usage records attribute activity to the device, not to a person. What they establish is that the device was actively used, which apps ran and for how long. Attribution to a person comes from corroboration: message content, account activity, location context and witness evidence. Sherlock presents the usage record; the attribution argument belongs to the case.
What corroborates a Screen Time record?
Sherlock reads several independent usage streams from the same extraction: power-log app usage, the launch-by-launch app sequence, app install and uninstall history with versions and the Focus and Do Not Disturb timeline. Independent streams that agree make a usage narrative hard to dismiss as a single-source anomaly.
How does usage evidence appear in the report?
Usage views export to CSV or JSON like every view, flagged items roll into the court-ready HTML report and every dated usage event feeds the merged Activity Timeline so the report can show usage in sequence with messages, calls and locations. Per-artifact SHA-256 hashing and an optional evidence-integrity manifest document the record.
Can I check whether my extraction contains usage data before buying?
Yes. The free edition loads the extraction and shows every view with item counts, previewing the first 25 percent of each view capped at 100 rows, so you see whether the pattern-of-life views are populated for this device before any purchase.

Start Now

Read the Usage Diary in Your Extraction

Download the free edition, load the extraction and see whether the pattern-of-life views populate for your device. Unlock the full record when the case calls for it: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: iPhone full-filesystem analysis · The full parser list · Load a forensic iPhone image