Version 0.6.0 - 2026-07-29 - Full-filesystem analysis tier, deeper messenger and location forensics
- Full-filesystem analysis tier. Loads full-filesystem extractions from Cellebrite and Magnet directly for deep analysis beyond a logical pull. Recovers a modern-Android app inventory from binary XML, account stores present even before the first unlock and the media store on the mainline module path. Builds an app-usage, screen, unlock and boot timeline, a permission-usage timeline, app shortcuts, recents and application exit reasons.
- Messenger content from a full image. Recovers WhatsApp including deleted-for-everyone, Telegram, Google Messages (RCS, SMS and MMS), Google Chat, TikTok and Lemon8 direct messages. Decrypts Session and SimpleX when the key is recovered and reads the WeChat feed without the key.
- Location depth. Adds Google on-device Timeline, Google Maps photo-location trail and last camera position, MIUI Gallery place names, video capture GPS, Health Connect workout routes, saved and airport Wi-Fi travel history and a fused Last Location view.
- Deleted-record recovery extended. Measures deleted MMS, WhatsApp and trashed media, on top of the existing deleted photo and message recovery.
- Document and secret forensics. Decrypts app secrets stored in EncryptedSharedPreferences, scans pulled PDFs for threats and reads OOXML document metadata and OpenVPN configurations.
- Reworked interface. A per-source section rail, iOS-parity views, sortable and filterable tables, a calendar month view, cleaner contacts, a usage bar chart and an FFS Matrix quick reference with a Request Your Device path.
EV code-signed binary (Sherlock Forensics Ltd, SSL.com EV intermediate). SHA-256: 131a69672c2a206ddf51e883368f1f48fb4408089b7f691ef6ec0a95936622fa. TSA countersignature present.
Version 0.5.0 - 2026-07-18 - Full-filesystem image support and deep app-database forensics
- Full-filesystem image viewer. A rooted or beyond-logical acquisition of /data opens in a dedicated full image viewer with sections for overview, timeline, messages, email, calls, contacts, web, media, places, crypto and apps. The same record types and court-ready report are produced whether the source is the logical helper output or the raw databases in a full image.
- Deep app databases parsed from the image. Chrome and Samsung Internet full forensic set (history, per-visit events, saved logins, cookies, form autofill, saved address and payment profiles, bookmarks), Samsung email and Gmail (Gmail protobuf-decoded), Skype messages and calls, contacts and call log and text messages from the Samsung call-log store, device accounts, calendar, app-usage sessions, removed-app history, the Play Store install ledger, the media store and Samsung media hub, location history and the Amazon account store. A logical pull cannot reach this app-private storage.
- Deleted-record recovery. The SQLite reader replays the write-ahead log and walks the freelist inside a full image, so deleted records that still survive in the file come back and are marked as recovered, including deleted photos with paths, times and GPS, together with deleted messages.
- Cryptocurrency evidence. Mycelium Bitcoin wallet addresses and per-transaction outputs are decoded from the wallet database and are traceable on-chain.
- Unified sortable timeline and CSV export. Every dated artifact across all sources merges into one timeline you can filter by kind and date and sort by time, type or detail and export to CSV for report exhibits.
- Older devices handled honestly. The helper-required panel now explains when a device is too old for the helper instead of dead-ending, with a button to send the device details to support directly.
EV code-signed binary (Sherlock Forensics Ltd, SSL.com EV intermediate). SHA-256: ea4944bc58d247fd78db006b29d6cf497228906ab1a86c08f22dfa825bf73284. TSA countersignature present.
Version 0.4.0 - 2026-07-17 - Findings surfaced, photo locations read, a fuller exhibit
- Findings up front. A "worth a look" panel on the overview and a "Findings of note" report section gather what the tool noticed while reading an acquisition, most serious first: a device not in its factory state; a clock not set from the network, so its timestamps may not track real time; an app installed from an APK file that can also read the screen or every notification, which is the shape stalkerware takes; a SIM that has left the phone since it carried a message; messaging accounts whose conversations a logical acquisition cannot reach; files whose contents do not match their name; photos carrying their own GPS coordinates; devices the handset was paired with before. Each is stated as a fact about the material collected, not a conclusion by the tool.
- Photo geolocation. The tool reads GPS coordinates and capture time from each pulled photo's own EXIF. The device media index cannot report this because Android redacts those columns for an app without special permission. The file copied off the phone still carries it. Coordinates show on the files tab and travel into a marked photo's report entry.
- A fuller exhibit. The PDF report identifies the handset from its own build properties (make, model, Android version, security patch, build fingerprint and bootloader state) rather than an operator-typed label alone. It names the apps granted powerful access (accessibility, keyboard, notification-listener role), flags any installed from outside a store and summarises every collected category including user accounts and SIM or telephony.
- More collected and parsed. The on-device helper reads each calendar event's calendar name and attendees, where each app was installed from (a store or a sideloaded APK) and the permissions each app holds. Bluetooth device kind, per-app battery residency and notification-listener holders are read out of the raw dumps.
- Marking and navigation. Conversations, calendar events, saved Wi-Fi networks and paired Bluetooth devices are markable for the report. Apps, contacts and call lists are searchable by name or number. The section tabs moved from a top strip that clipped on an unmaximised window into a scrollable left sidebar shown when a case is open.
- Fixes a customer would hit: the GET DATA button is always clickable and opens the acquire screen when no device is connected; the section tabs no longer run off the right edge on an unmaximised window; the media tab no longer asks you to read a photo's location by hand; and the paired-device list no longer vanishes when there are no saved Wi-Fi networks.
EV code-signed binary (Sherlock Forensics Ltd, SSL.com EV intermediate). SHA-256: 87ecaeb4ae3ee3f5942c5aecbe67a03330b9bf90fb2b4bd617ee300a41c7d96f. TSA countersignature present.
Version 0.3.0 - 2026-07-16 - Built-in results viewer and two-party integrity verification
- RESULTS viewer with fourteen tabs reads an acquisition back inside the tool: overview, device, conversations, calls, contacts, apps, contact map, usage, notifications, battery, files, networks, integrity and marked items. Version 0.2.0 collected to a folder with no way to review it in the application.
- Two-party integrity verification. The on-device helper hashes each file on the phone and the workstation hashes what arrives, so agreement means two independent parties hashed the same bytes. Folder verification re-hashes every file against the manifest to confirm nothing changed since acquisition. The manifest is unsigned, so this evidences that data was not disturbed, not that it is authentic.
- New collections. Call log, app usage history, SIM and telephony, settings provider, paired and nearby Bluetooth, saved Wi-Fi networks, notification access, per-app battery stats and connectivity history.
- Media and data files now pull actual bytes. Prior versions returned MediaStore metadata only, so a run could report success while collecting no photos. Fixed and verified.
- Mark for report. Star items and add notes; they appear as their own PDF section, labelled as the operator's selection rather than a finding by the tool.
- Fixes a customer would hit: manifest now records device artifacts with their folder so the report's own re-hash instruction is followable; the report no longer claims the helper was removed when it was not; SMS and MMS threading and MMS recipients corrected; PDF text wraps instead of running off the page; the extract button no longer hides below the fold on an unmaximized window.
EV code-signed binary (Sherlock Forensics Ltd, SSL.com EV intermediate). SHA-256: ae4c6e451f6c7df928f3d2da03e9daf69740aa3b5f612215c27e271a3b088914. TSA countersignature present.
Version 0.2.0 - 2026-07-16 - Self-contained binary and provenance-hardened helper lifecycle
- Bundled adb, fastboot and signed helper APK unpack on first run. No external Android SDK, Platform Tools or JDK install required. Runs on a clean Windows 10 or 11 workstation with no developer tooling.
- Helper install recorded in the acquisition manifest with UTC timestamp and APK SHA-256. Chain of custody captured at deployment, not reconstructed after the fact.
- Staged copies swept off the device with removal verified. Belt-and-suspenders cleanup so nothing lingers on the phone after acquisition.
- One-click helper removal returns the device to its pre-acquisition state. Auditable and reversible.
- Fixed installation gap where prior versions expected adb beside the exe. Reported by a customer who tried to acquire without an existing Android developer environment. Fresh Windows 10 VM regression test added to release gate.
EV code-signed binary (Sherlock Forensics Ltd, SSL.com EV intermediate). SHA-256: 47b6aad63aa5ac3df450b54b19948ecc7602e9d69608008daec7963ca20982c2. TSA countersignature present.