Sherlock Forensics iPhone and iPad Analyzer · New Release

Sherlock Forensics iPhone and iPad Analyzer
iOS forensic software for Windows

Sherlock Forensics iPhone Analyzer acquires and analyzes iPhone or iPad logical MobileBackup2 backups on Windows and analyzes Cellebrite UFED full-filesystem extractions. Read-only, court-defensible, fully offline. 130+ artifact views across communications, media, web, location, personal, apps and system. HEIC and HEVC decode built in. Encrypted-backup offline decryption via RFC 3394 keybag unwrap and AES. Installer, application executable and bundled ffmpeg are all EV signed (SSL.com), so Windows SmartScreen shows no warning.

Free tier: preview 25 percent of artifacts (capped at 100 rows per view). Forensic Edition ($599 one-time): unlimited data, global search, CSV and JSON export, court-ready HTML report, raw SQLite browser, file extraction and screen capture.
Before you buy - device requirements. Sherlock Forensics iPhone Analyzer uses Apple's official MobileBackup2 logical acquisition path. To use it on a device, you must have: (1) the device passcode or PIN, (2) the ability to physically connect the device to your Windows forensic workstation via USB and (3) the ability to unlock the device and tap "Trust" on the "Trust This Computer" prompt. Sherlock Forensics iPhone Analyzer does NOT bypass lock codes. It does not jailbreak the device or exploit iOS security. Locked devices without a passcode and untrusted devices are not supported by this tool or by any logical acquisition method.

SSL.com EV signed · SHA-256 verifiable · No SmartScreen warning

Sherlock Forensics iPhone Analyzer dashboard overview showing case summary, device attribution, artifact counts and investigative highlights at a glance
Dashboard overview · every dated event, every artifact, every finding in one investigative surface

Overview

What Sherlock Forensics iPhone Analyzer Actually Is

Sherlock Forensics iPhone Analyzer is a Windows forensic workstation that acquires and analyzes iPhone or iPad evidence from a logical MobileBackup2 backup and, as of version 1.2.0, analyzes a Cellebrite UFED full-filesystem extraction. Read-only, court-defensible, fully offline. Sherlock delivers the same user-experience shape as Magnet AXIOM and Cellebrite Physical Analyzer in the logical-acquisition scope. The honest credibility floor is EnCase-grade rigor for iOS logical evidence.

Every artifact view in the tool ships as its own dedicated, searchable, exportable interface. The Forensic Edition unlocks the full data set and court-ready reporting; the Free Edition previews 25 percent of every artifact so an evaluator can see the exact tool depth before purchase.

Acquisition

Logical Backup Over MobileBackup2

Sherlock Forensics iPhone Analyzer uses the MobileBackup2 logical acquisition path. This is the universal method: it works on any iPhone or iPad you can unlock, no jailbreak, no exploit. iOS decrypts the data on-device as it is copied out so the result is already plaintext.

Encrypted-backup mode: Sherlock sets the backup password itself before acquisition then decrypts the backup offline using RFC 3394 keybag unwrap and AES. Operators do not configure a password; the tool handles the encryption flip end-to-end. Encrypted backups actually contain more data than unencrypted backups (keychain, Health, Wi-Fi passwords) which is why the tool automates the flip.

The acquisition channel is read-only. A destination free-space pre-flight prevents partial-capture failures.

New in 1.2.0

Full-Filesystem Extraction Analysis: Bring Your Cellebrite UFED Extraction

Sherlock Forensics iPhone and iPad Analyzer 1.2.0 analyzes a Cellebrite UFED full-filesystem extraction. It detects the extraction, resolves every artifact at its real on-device path and runs the full parser suite against it. Sherlock does not acquire the extraction; it analyzes the one your acquisition tool produced.

Point Sherlock at an extracted Cellebrite UFED full-filesystem tree and it opens it the same way it opens a backup. A full-filesystem extraction is a much deeper evidence source than a logical backup: it contains the behavioral logs, on-device intelligence caches and third-party app storage that a logical backup never copies out. Sherlock resolves every artifact at its real on-device path and runs the whole parser suite against the tree.

An extraction-provenance view parses and merges the UFED .ufd, .ufdx and DeviceInfo.txt descriptors into one record: device model, iOS build, examiner machine, acquisition tool and version, start and end times and the per-dump SHA-256 and HMAC the acquisition tool recorded. The full descriptor is carried verbatim so nothing is hidden from the examiner or the court.

The scope is worth stating plainly. Sherlock Forensics iPhone Analyzer does not itself acquire a full-filesystem extraction; that requires Cellebrite, GrayKey or comparable acquisition tooling. Sherlock's own acquisition remains the logical MobileBackup2 path with the device requirements above. What 1.2.0 changes is the economics of the analysis seat: the extraction your organization already paid enterprise money to capture now analyzes in Sherlock at $599 one-time instead of on a second enterprise analysis license.

New in 1.3.0

Two Validated Devices, Life360 and Keychain in the Clear

Version 1.3.0 validates full-filesystem ingestion against a second device class (iPhone 12 mini, iOS 17.6.1) on top of the iPhone 11 baseline, adds a Life360 family location-sharing view, shows the recovered keychain in the clear on a Cellebrite full-filesystem extraction, then gives every sidebar artifact a true record count. All from the full-filesystem depth a logical backup does not carry.

Validated across two device classes

Full-filesystem ingestion is now proven end to end against a second device and iOS build: an iPhone 12 mini (A14, iOS 17.6.1) acquired with Cellebrite Inseyets UFED, alongside the iPhone 11 (iOS 17.3) reference image validated in 1.2.0. The extraction's integrity was verified against the SHA-256 the acquisition tool recorded before parsing, then the whole artifact suite was confirmed against the device. Sherlock reads Apple's own file system, so support is vendor-agnostic and generational: the same parsers apply across A-series devices and modern iOS builds. Each new validation widens the range Sherlock is demonstrably correct on.

Life360 family location sharing

A new Life360 view recovers an identity, communication and whereabouts source a logical backup never captures. Sherlock reads every circle, the full member roster with each member's real identity (name, email address and phone number) and their role (owner, admin or member, including members later removed). It also reads the complete in-app chat with timestamps, sender, circle and a flag on every message that shared a live location. The signed-in account is identified as the circle owner, which corroborates device ownership from an independent source. This is full-filesystem depth; it does not appear in a logical backup.

Keychain in the clear, on a Cellebrite full-filesystem extraction

On a Cellebrite full-filesystem extraction the Keychain badge now reads its true count (782 items on the validated device) where it previously read zero: saved app and website passwords, Wi-Fi keys, tokens and account identifiers, decrypted with the device-class keys the extraction provides and each verified against its own authentication tag so nothing shown is a guess. This is a forensic tool and the decrypted secrets are the evidence, so they are shown in full by default, with a one-click mask for screen-sharing. The honest boundary: a VeraKey extraction carries the keychain SEP-encrypted, so on a VeraKey image those secrets stay locked. The keychain-in-the-clear capability is specific to a Cellebrite full-filesystem extraction.

A complete evidence inventory

Every artifact in the extracted-data tree now shows its true record count, so an examiner sees how many messages, locations, health records, keychain items or app-store rows a device holds before opening a single view. Artifacts with no records collapse out of the tree automatically (toggleable), so the sidebar shows what the device actually contains rather than a wall of empty categories, while the analysis and correlation views always stay reachable. Reliability work in the same release keeps the installed-app inventory, owner attribution and the Indicators, Findings and Duplicate Files views working correctly on full-filesystem cases.

New in 1.3.1

Open the Extraction .zip, Configure the Lab, Read the Keychain in Full

Version 1.3.1 lets an examiner hand Sherlock the extraction .zip directly: it confirms what the package is, unpacks the Cellebrite or Magnet full-filesystem archive inside with a live progress readout and opens it in Analyze, never modifying the source. It adds a Settings page for the lab's folders and defaults along with a fully attributed keychain readout including saved Wi-Fi passwords.

Open an extraction .zip directly

Trained examiners expect to hand a tool the extraction .zip rather than unpack it by hand, so Sherlock now reads the archive first and shows a confirmation card before anything is written: the vendor, the device when the descriptor names it, the full-filesystem archive inside and its unpacked size, where it will be written and whether the destination has room. A wrong file or a too-small drive is caught before a multi-gigabyte extraction begins. On confirm, Sherlock unpacks the nested full-filesystem archive inside a Cellebrite or Magnet package, verifies its hash sidecar when one is present, resolves the filesystem root and opens it in Analyze with a live readout of percentage, bytes and throughput.

Both major full-filesystem package formats are handled, including very large images: a Magnet iPhone extraction with hundreds of thousands of files and a 20 GB inner archive unpacks and opens correctly, as does a Cellebrite UFED package. Filenames the host cannot represent and paths past the Windows length limit are handled automatically. The source archive is never modified or deleted. Re-opening the same .zip reuses the existing extraction rather than unpacking again. A package that does not yield a usable filesystem is reported rather than silently opened. This is unpacking and analyzing an extraction another tool produced; Sherlock's own acquisition remains the logical MobileBackup2 path and it does not acquire a full filesystem from any device.

A Settings page for the lab

A new Settings page puts the lab's configuration in one place: the working folder for extractions, the case cache and report output folders, examiner name and agency (which flow into the report and the provenance record) along with display defaults for timestamp zone, hiding empty artifacts, revealing keychain secrets and hash verification on ingest.

The keychain as a fully attributed source

Every recovered keychain item now carries its full attribution: creation and last-modified timestamps, the accessibility (data-protection) class, whether the secret is device-bound so it can never leave the device, whether it syncs through iCloud Keychain and the server, port and protocol for internet items. A saved credential is now a dated, classified record rather than just a service and a secret. Items whose class key was not in the extraction, the device-bound keys the Secure Enclave never released, are labeled honestly as locked rather than shown blank, so an examiner knows an item exists even when its secret cannot be recovered from that dump. The full bulk keychain in the clear remains specific to a Cellebrite full-filesystem extraction, since a Magnet extraction carries the bulk keychain SEP-encrypted.

Saved Wi-Fi passwords are the broad exception. They are cross-linked into the Wi-Fi Networks view with the date each network was saved. They come through from an encrypted logical backup as well as a Cellebrite full-filesystem extraction, so they turn up in almost every image an examiner works. A VeraKey or Magnet extraction carries the keychain SEP-encrypted, so on those images the Wi-Fi passwords stay locked.

New in 1.4.1

Ask: a Grounded Local AI Assistant and Media-Aware Search

Version 1.4.1 adds Ask, a local AI assistant that surfaces leads from the open case grounded in specific reproducible records, never drawing conclusions and always showing the tools and counts behind each answer. It runs entirely on the examiner workstation with no cloud and no account. A local media pass lets you find a photo by its contents or a voicemail by what was said, as search aids where the image and audio stay the authority, along with accent-insensitive full-text search and cached heavy views.

Ask, grounded and auditable, surfaces leads for the examiner

Ask answers questions about the open case, but it is built as a forensic assistant, not an oracle. It never reads the case directly; it queries the same deterministic parsers the rest of Sherlock uses, so every statement it makes is backed by a specific record the examiner can open and reproduce. It is not a black box: each answer shows the tools it called, the arguments it passed and how many records came back, so the work is repeatable and reviewable. It also holds the evidence-not-verdict line the rest of the tool keeps. Ask surfaces leads for the examiner to confirm and tells you plainly what it could not find, rather than concluding, proving or identifying anyone. The examiner and the record carry the case; Ask accelerates finding, it does not decide.

Local and confidential, nothing leaves the workstation

Ask runs entirely on the examiner workstation. Inference happens locally on the machine, using the GPU when one is present and the CPU otherwise, so it runs on a plain forensic laptop. Nothing about the case leaves the workstation: there is no cloud service, no account to sign into and no path by which evidence could be exfiltrated or exposed to discovery through a third party. For a forensic tool that handles sensitive evidence, keeping every inference local is the honest and important default. Ask needs a local model, roughly 4.7 GB, downloaded once with the examiner's permission on first use and fully offline after that. The AI engine itself ships inside the installer, so there is nothing to install; the one-time model download is stated plainly rather than hidden.

Find a photo by its contents, a voicemail by what was said

An optional local pass enriches search with the content of media. A vision model produces a description of an image and an on-device speech-to-text pass transcribes voicemails and voice notes, both folded into search so you can find a photo by what it shows or a voicemail by what was said, across message-attachment images and voice notes. As with Ask, the vision-description and speech-to-text passes use local models the examiner consents to download on first use, running offline afterward; these model downloads are stated plainly, not bundled silently. These outputs are probabilistic AI search aids for locating evidence, not ground truth. The image itself and the audio itself remain the authority. A lead is confirmed by opening the media. This on-device transcription is a search-enrichment layer and does not replace the iOS-stored transcript, which remains what the voicemail view shows as the record. GPS coordinates read from attachment photos are deterministic metadata and are stated as fact. The pass runs locally, resumably, with a live feed and was validated against the Josh Hickman public reference image.

Full-text search across the whole case

Full-text search now spans the case with real forensic ergonomics. It is accent-insensitive, so a search for jose matches Jose with an accent, it ranks results by relevance and interleaves them across the underlying databases and it skips internal bookkeeping tokens so every hit is genuine content rather than a structural artifact.

Faster heavy views and reliability fixes

Heavy views such as the Media Library, Home Screen, Contacts, Communications Map and Health now cache per case, so they return instantly instead of re-parsing on every open. Reliability fixes round out the release: previously-uncounted sidebar nodes (the file-system manifest, the device ark and two data-list nodes) are now counted, HEIC images at very long paths transcode correctly, the bundled ffmpeg is updated with media-decoder security fixes and the Microsoft C++ runtime is bundled so the tool starts on a clean Windows install with no prerequisite.

Analysis

130+ Artifact Views From Logical Backups and Full-Filesystem Extractions

Every item below is a dedicated, searchable, exportable view. The Free Edition previews the first 25 percent of each view (capped at 100 rows). The Forensic Edition unlocks the complete data set.

Communications

Messages (SMS and iMessage), Conversations (threaded), Chats and Groups, WhatsApp messages, WhatsApp Groups (members, admin, JIDs), Message Attachments, Call History, Voicemail, Contacts.

Media

Photos and videos with capture GPS. HEIC decodes and HEVC video plays in-app. Favorites, Hidden, Recently-Deleted, Geotagged, Photos and Videos filters. Media Library, Voice Memos.

Web and Location

Safari history, Web Searches, Web Domains, Shared Links, Safari Tabs, open local tabs, Safari Bookmarks, Cookies, Safari Downloads, Wi-Fi networks (with saved passwords from keychain), Bluetooth devices (paired vs merely seen, with public and random address trackability), Locations (geotagged media and shared pins on an offline map), Location Access (locationd clients), Weather saved locations including the device owner HOME address.

Personal

Notes (with password-protected flagging), Reminders, Calendar, Health and Activity, Focus and Do Not Disturb modes, Alarms, Keyboard Lexicon.

Apps and System

Installed Apps, App Inventory, App State (recently-used and badged), App Permissions (TCC covering camera, microphone and location access), Network Usage, SIM and Cellular identity (phone number, ICCID, IMEI or MEID, carrier), Home Screen layout (dock, pages, folders, widgets - reveals apps hidden in folders), Device Settings (locale, languages, keyboards), Accounts, Keychain (passwords, tokens, Wi-Fi keys), Provisioning Profiles (enterprise, developer, MDM sideload provenance).

Acquisition and Integrity

Overview dashboard, Device Summary, Backup Info, Provenance, Acquisition Integrity, File Manifest (every backup file with size, hashes, metadata, on-demand content preview and SQLite table browser in Forensic Edition). Version 1.2.0 adds an Extraction Provenance view for ingested full-filesystem extractions that merges the UFED .ufd, .ufdx and DeviceInfo.txt descriptors into one record.

New in 1.2.0: Full-Filesystem Depth

The groups below ship in version 1.2.0 and draw on the depth of a full-filesystem extraction: the behavioral logs, on-device intelligence caches and third-party app storage that a logical backup never copies out. Open a Cellebrite UFED full-filesystem extraction in Sherlock to reach them.

Messaging Recovery: Web Caches and Notification Previews

Skype, Facebook Messenger, Google Chat, LINE, imo, MeWe, Gettr, MEGA Chat, Instagram direct messages, TikTok direct messages, Discord and Reddit chat recovered from on-device web caches. A delivered-notifications view recovers per-app banner content (title, subtitle, body, time) that survives in-app deletion. These messages are recovered from web caches and notification previews for apps whose message stores are not directly readable; this is not a full extraction of those apps' message databases.

Whereabouts and Location

Apple Maps history, Find My (the owner's devices, AirTags and accessories and family location-sharing members), significant locations with dwell times, location enter and exit transitions, location permission requests, Waze destinations and named place-visit life events.

Pattern of Life and Device Behavior

Screen Time app usage and daily totals, powerlog app usage, app install and uninstall history with versions, the launch-by-launch app sequence, app intents and Siri actions, Siri analytics, the Focus and Do Not Disturb timeline, Handoff and user-activity events, App Store activity and text-input, audio-route and read-receipt signals from the on-device intelligence streams.

Expanded Media

Hidden and deleted photos, screenshots, photo albums, per-photo camera make and model, edited photos, Apple Podcasts, the music and media library and Now Playing history.

Health and Fitness

Health workouts with GPS routes, heart-rate history and Fitbit GPS tracks and heart rate.

Contacts and Intelligence

Contact frequency, significant contacts, ID-status contact lookups and the entities and message activity learned by the on-device intelligence platform.

Apps, Accessories and Web

Bluetooth and Bluetooth LE device history, Snapchat memories, the Stocks watchlist, AirDrop and sharing history, the Clock app (world clock, timers, stopwatch and alarms) and a cross-app cached-web-request view that surfaces in-app web and API activity from nearly every installed app.

See It At Work

Screenshots from Sherlock Forensics iPhone and iPad Analyzer showing the acquisition workflow, investigation dashboard, communications reconstruction, web and location intelligence and system-artifact extraction. The visual coverage spans all six manifest artifact groups. Click any image for full-size view.

Acquisition Workflow

Sherlock Forensics iPhone Analyzer acquisition workflow step 1 - device selection screen showing detected iPhone and iPad devices connected for logical MobileBackup2 acquisition
Step 1: Device Selection
Sherlock Forensics iPhone Analyzer acquisition workflow step 2 - backup configuration screen for encrypted-backup password automation and output destination
Step 2: Backup Configuration
Sherlock Forensics iPhone Analyzer acquisition workflow step 3 - live acquisition progress with byte counter and estimated completion
Step 3: Acquire Data

Investigation Dashboard

Sherlock Forensics iPhone Analyzer dashboard overview showing device summary and artifact counts and acquisition integrity indicators
Dashboard Overview
Sherlock Forensics iPhone Analyzer activity timeline showing chronological event correlation across communications, media and web activity
Activity Timeline (chronological event correlation)
Sherlock Forensics iPhone Analyzer global search interface showing keyword query across every artifact view
Global Search Across All Artifacts
Sherlock Forensics iPhone Analyzer deleted content recovery view surfacing carved SQLite messages and hidden media and deleted contacts
Deleted Content Recovery + Hidden Media

Communications

Sherlock Forensics iPhone Analyzer iMessage and SMS messages view with threaded conversation reconstruction and attachment previews
iMessage + SMS View
Sherlock Forensics iPhone Analyzer WhatsApp messages and groups view with member, admin and JID reconstruction
WhatsApp Messages + Groups
Sherlock Forensics iPhone Analyzer call history view showing incoming, outgoing and missed calls with contact attribution and duration
Call History with Attribution

Web + Location Intelligence

Sherlock Forensics iPhone Analyzer Safari history, bookmarks and cookies view for iOS web activity reconstruction
Safari History + Bookmarks + Cookies
Sherlock Forensics iPhone Analyzer location intelligence view showing geotagged media pins and Weather saved HOME address on offline map
Location Intelligence (Weather HOME + Geotagged Media)
Sherlock Forensics iPhone Analyzer Bluetooth devices view distinguishing paired versus merely seen devices with trackability metadata
Bluetooth Devices (Paired vs Seen + Trackability)

System Artifacts

Sherlock Forensics iPhone Analyzer Home Screen layout view revealing dock, pages, folder structure and apps hidden in folders
Home Screen Layout (Reveals Apps Hidden in Folders)
Sherlock Forensics iPhone Analyzer keychain extraction view surfacing Wi-Fi passwords, tokens and credentials from decrypted encrypted backup
Keychain Extraction (Wi-Fi Passwords + Tokens + Credentials)
Sherlock Forensics iPhone Analyzer app permissions view showing TCC grants for camera, microphone, location and contacts access
App Permissions (TCC - Camera / Microphone / Location)

Correlation

Correlation and Findings - Automated First-Look Triage

Activity Timeline: every dated event merged chronologically, filterable across every artifact source.

Findings (Investigative Highlights): automated first-look triage surfaces emergency calls, deleted content recovered, privacy-sensitive permission grants, hidden-vault apps, blocked callers, home location, online accounts (subpoena targets) and device attribution (phone number, Apple IDs).

Pattern of Life, Communication Map, Communication Insights (top contacts, callers and domains), Contact Activity, Unknown Contacts (handles messaged that are not saved).

Deleted and recovered: Deleted and Hidden media and Messages, Calls and Contacts carved from freed SQLite database pages. Content the subject deleted on-device but the SQLite freelist has not overwritten is recoverable through standard freed-page carving methodology applied across the iOS artifact set.

Global search and keyword-watchlist search across every artifact at once. Per-view filter, sort, date-range and item flagging (flagged items roll into the report).

Anti-forensic app detection: hidden-vault, encrypted-messaging and anonymity or VPN apps are flagged inline everywhere apps appear (Installed Apps, App Inventory, App State, Home Screen, App Permissions) and surfaced in Findings.

Reporting

Reporting and Export - Forensic Edition

Court-ready HTML report (print to PDF from any browser): case and evidence numbers, agency, examiner, selectable sections grouped by topic, Investigative Highlights, optional evidence-integrity SHA-256 manifest and communication summary, UTC or local time.

CSV or JSON export of any individual artifact view. Export all data as JSON in one action.

Court-Defensibility

Forensic Guarantees

  • 100 percent read-only. The evidence file is never modified.
  • Per-file SHA-256 and a provenance and acquisition manifest (chain of custody).
  • Timezone is explicitly disclosed (all times shown in the examiner workstation zone; iOS does not record the device zone in a logical backup). Tool version is stamped in the manifest.
  • Tolerant parsing that surfaces warnings and never silently hides data. Every view has an error boundary so a data surprise does not blank-screen the tool.

Honest Scope

What Sherlock Forensics iPhone Analyzer Does Not Do

Honest scope disclosure matters more than marketing polish. Sherlock Forensics iPhone Analyzer does not do full-filesystem (FFS) acquisition of any device; the Secure Enclave blocks that path on A12 and newer hardware and FFS acquisition remains the territory of Cellebrite and GrayKey class tooling. What version 1.2.0 adds is analysis: Sherlock reads a full-filesystem extraction that such a tool produced. From a logical backup alone, FFS-only artifacts (knowledgeC pattern-of-life, Significant Locations, deep app-container internals) are not available and show honest empty states rather than fabricating data.

Sherlock Forensics iPhone Analyzer is not a raw disk imager. That is a separate Sherlock tool (Sherlock Disk Imager).

Version 1.4.1 is Windows x64 only. macOS and Linux builds are not currently available.

Compare

Free vs Forensic Edition

FeatureFreeForensic Edition ($599)
Data access per artifact25 percent preview (100-row cap)Unlimited
Screen capture (export screens)-Yes
Open MobileBackup2 backupYesYes
Encrypted-backup decryptionYesYes
All 130+ artifact viewsPreview onlyFull
Deleted-content carvingPreview onlyFull
Anti-forensic app detectionYesYes
Global and keyword-watchlist search-Yes
CSV and JSON export-Yes
Court-ready HTML report-Yes
Raw SQLite table and SQL browser-Yes
File extraction from backup-Yes
Chain of custody manifestYesYes

Requirements

System Requirements

  • Windows 10 version 2004 or later and Windows 11, 64-bit.
  • Microsoft Edge WebView2 runtime (installer auto-installs if missing).
  • All dependencies bundled: HEIC and HEVC decode and ffmpeg. Photos, HEIC and video all work out of the box with no extra installation.

Download

Download and Integrity Verification

File: Sherlock-iOS-Analyzer-1.4.1-AI-x64-setup.exe (NSIS installer, Windows x64, 68.87 MB).

SHA-256: d6ffd2af48f9918b887aa787edeae7da1580f6635d6c5e0c714cbb7b81bfc171 (also in the accompanying .sha256 sidecar - verify before installing).

Signed with the SSL.com EV Code Signing certificate (Sherlock Forensics Ltd, Burnaby BC), RFC3161-timestamped. Installer, application executable and bundled ffmpeg are all signed so Windows SmartScreen shows no warning on download or first launch.

d6ffd2af48f9918b887aa787edeae7da1580f6635d6c5e0c714cbb7b81bfc171

How to verify:
1. Open PowerShell (right-click Start menu, click Terminal)
2. Run: Get-FileHash .\sherlock-ios-analyzer.exe
3. Compare the output with the hash above. If they match, the file has not been tampered with.

Cellebrite Alternative

iPhone Forensics Without Cellebrite or GrayKey: The $599 Logical Alternative

The enterprise iOS forensic platforms price a solo examiner or a mid-market firm out of the room. Cellebrite, GrayKey, Magnet AXIOM, Elcomsoft iOS Forensic Toolkit and MSAB all bundle physical and full-filesystem acquisition behind annual subscriptions that run from four to five figures a year. For the majority of civil litigation, family law, workplace and defense matters, the evidence that decides the case lives in the logical backup: iMessage and SMS threads, WhatsApp, call history, Safari, photos with capture GPS, locations and the keychain. Sherlock Forensics iPhone and iPad Analyzer reads all of it from an encrypted MobileBackup2 backup at $599 one-time, no subscription.

Sherlock is honest about the trade. It does not bypass a locked device and it does not do full-filesystem imaging of a Secure Enclave device. It needs the passcode and a Trust prompt, the same as Apple's own backup path. What it gives back is enterprise-grade analysis depth on the logical evidence, on a Windows workstation, at a price a single case can justify. Version 1.2.0 adds the other half of the full-filesystem economics: when a case did justify a Cellebrite UFED full-filesystem extraction, that extraction now analyzes in Sherlock at $599 one-time instead of on a second enterprise analysis seat.

CapabilitySherlock Forensics iPhone and iPad AnalyzerCellebriteGrayKeyMagnet AXIOMElcomsoft
Price$599 one-time$10,000+ per year$15,000+ per year$4,000+ per year$1,500+ per year
License modelOne-time, ownedAnnual subscriptionAnnual subscriptionAnnual subscriptionAnnual subscription
Runs on WindowsYesYesApplianceYesYes
iOS logical acquisitionYesYesYesYesYes
Encrypted backup decryptionYes, automatedYesYesYesYes
Deleted content carvingYesYesYesYesPartial
Keychain extractionYesYesYesYesYes
Full-filesystem or physical acquisitionNoYesYesYesYes
Passcode or lock bypassNoYesYesNoSome models
Court-ready report with SHA-256YesYesYesYesYes

The read is simple. If your case needs a passcode broken or the raw filesystem carved off a locked handset, you need Cellebrite or GrayKey and their annual contract. If you have a device you can unlock and the logical backup holds the evidence, which is the common case, Sherlock delivers the analysis at a fraction of the lifetime cost.

How To

How to Acquire and Analyze an iPhone or iPad Backup

The whole workflow runs on one Windows workstation, offline, read-only, from connect to court report.

  1. Connect and trust the device. Plug the unlocked iPhone or iPad into the workstation over USB. Unlock it and tap Trust on the Trust This Computer prompt, then enter the passcode. The tool cannot pair with a locked or untrusted device. It does not attempt to bypass either.
  2. Acquire the logical backup. Sherlock drives Apple's MobileBackup2 path. It sets the backup password itself, captures an encrypted backup and streams it to your chosen destination on a read-only channel with a free-space pre-flight that prevents partial-capture failures.
  3. Decrypt offline. The tool unwraps the backup keybag with RFC 3394 and AES on the workstation. No password to configure, no cloud round-trip. The encrypted backup is where the keychain, Health data and Wi-Fi passwords live, which is why the tool always captures one.
  4. Analyze the artifacts. Review the acquisition across 130+ dedicated views: messages, calls, WhatsApp, Safari, photos with GPS, locations, keychain, app permissions and the rest. Carve deleted messages, calls and contacts from freed SQLite pages. Run global and keyword-watchlist search and read the automated Findings.
  5. Export the court-ready report. Produce an HTML report with case and evidence numbers, examiner details, selected sections, an optional SHA-256 evidence-integrity manifest and a chain-of-custody provenance record. Print to PDF from any browser. Export any view to CSV or JSON.

Who Uses It

Who Uses Sherlock Forensics iPhone and iPad Analyzer

Civil litigation

Counsel and litigation-support teams pull iMessage threads, call logs, Safari history and geotagged photos from a party's own device under a preservation order or consent, at a cost that fits a case budget rather than an annual platform contract.

Family law

Custody, marital-misconduct and harassment matters turn on messages, locations and contacts. Sherlock reconstructs threaded conversations and maps geotagged media, with a court-ready report and per-artifact SHA-256 for the file.

Workplace and insider investigations

HR and corporate investigators acquire a company-owned or consented iPhone during a policy, harassment or data-exfiltration inquiry. App inventory, permissions, WhatsApp and anti-forensic app detection surface the shape of the activity without a five-figure tool spend.

Criminal defense

Defense examiners review the same logical evidence the prosecution relies on, verify deleted-content recovery against the SQLite freelist and document the acquisition methodology for a Daubert challenge, all from a one-time-licensed tool.

Law enforcement

Investigators with a warrant and a device they can unlock get a defensible logical acquisition and a full analysis surface on a standard Windows workstation, with the honest-scope disclosure that full-filesystem artifacts blocked by the Secure Enclave show empty rather than fabricated.

Court-Ready

Chain of Custody and Court-Ready iPhone Evidence

Sherlock Forensics iPhone and iPad Analyzer is built by CISSP, ISSAP and ISSMP certified forensic examiners with 20 years of court-defensible digital forensics. Every acquisition is read-only and the evidence file is never modified. Each backup file carries a per-file SHA-256 in a provenance and acquisition manifest that documents chain of custody from the device forward.

The report format states its own scope. Times are shown in the examiner workstation timezone and that fact is disclosed on the face of the report, because iOS does not record the device timezone in a logical backup. The tool version is stamped in the manifest. Parsing is tolerant and surfaces warnings rather than silently dropping data, so an examiner can testify to exactly what the tool did and did not read. Admissibility depends on jurisdiction and on the examiner following proper evidence-handling procedure. The report documents what courts typically require for mobile evidence.

Acquisition Types

Logical vs Physical iPhone Acquisition: What Each One Reaches

Buyers researching iPhone forensics run into three acquisition types. The difference decides which tool a case needs. Understanding them is the difference between buying the right tool and overpaying for capability a matter never uses.

Logical acquisition copies the data Apple exposes through the MobileBackup2 backup path: messages, call history, contacts, Safari, photos, app data from an encrypted backup and the keychain. It needs a device you can unlock and a Trust prompt. It does not modify the device and it produces court-defensible evidence for the overwhelming majority of civil, family, workplace and defense matters. This is what Sherlock Forensics iPhone and iPad Analyzer does. It is what most cases actually turn on.

Full-filesystem acquisition reaches deeper into the operating system: knowledgeC pattern-of-life, Significant Locations, app-container internals and system databases that never enter a backup. On A12 and newer iPhones the Secure Enclave blocks this path unless the passcode is known and a supported exploit chain is available. Cellebrite, GrayKey, Magnet AXIOM and Elcomsoft compete here. Sherlock does not compete in FFS acquisition. What version 1.2.0 adds is the analysis half: Sherlock opens a full-filesystem extraction one of those tools produced and runs its full parser suite against it. From a logical backup alone, those FFS-only artifacts show as honest empty states rather than fabricated data.

Physical acquisition images the raw storage and is largely historical on modern encrypted iPhones because the flash is encrypted at rest. It survives mostly on legacy hardware.

The practical takeaway is that logical acquisition answers most questions a case asks of an iPhone, at a fraction of the cost of the platforms built for the harder physical and full-filesystem paths. A firm that handles the occasional locked-device case can send that one out to a lab and keep the routine logical work in-house on a one-time-licensed tool. Sherlock is built for exactly that in-house logical workload, with the honesty to tell you when a case has crossed into territory it does not cover.

Evidence Scope

What an Encrypted iPhone Backup Actually Contains

The single most important fact for iPhone evidence is that an encrypted iOS backup contains substantially more than an unencrypted one. This is Apple's design, not a tool trick. When a backup is encrypted, iOS includes the keychain, Health and Activity data, Wi-Fi passwords, saved website credentials and call history that it deliberately omits from an unencrypted backup. Sherlock always captures an encrypted backup for this reason, sets the password itself and decrypts it offline, so an examiner gets the fuller evidence set without configuring anything.

Inside that encrypted backup, the evidence that decides cases is genuinely present. iMessage and SMS reconstruct as threaded conversations with attachments. WhatsApp messages and group metadata are there, which is a real difference from a non-rooted Android device where the WhatsApp database sits locked in app-private storage. Safari history, cookies, bookmarks and open tabs reconstruct the subject's web activity. Photos carry their capture GPS and EXIF. The keychain surfaces Wi-Fi passwords and stored tokens. Locations map from geotagged media, shared pins and the Weather app's saved home address.

The honest boundary is worth stating as plainly as the capability. Everything above depends on a successful backup of a device you can unlock and have authority to acquire. Data the subject never backed up is not in the backup. Content deleted long enough ago that iOS has purged it or that the SQLite freelist has overwritten is gone rather than recoverable. iCloud-only data that never synced to the device is out of scope and requires credentials or legal process through a different method. Sherlock reads what the acquired backup carries accurately. Its report states the scope of what it read so an examiner can testify to it without overreaching.

Deleted Data

Deleted iPhone Data: What Survives and What Does Not

The most common question in an iPhone case is whether deleted data can be recovered. The honest answer is that some can and some cannot. A credible tool tells you which rather than promising everything. Sherlock Forensics iPhone and iPad Analyzer applies standard freed-page carving to the SQLite databases inside a logical backup. When a subject deletes a message, a call or a contact, iOS marks that record's database page as free rather than immediately erasing it. Until the database writes new data over that freed page, the deleted record is still physically present and Sherlock carves it back out for review.

What survives therefore depends on how heavily the device was used after the deletion. A message deleted an hour before acquisition on a lightly used phone is very likely recoverable. The same message deleted months ago on a busy phone has probably been overwritten and is gone. This is physics, not a tool limitation. It applies equally to Cellebrite, Magnet AXIOM and every other forensic tool that carves the same freed pages. What separates a defensible tool is that it recovers what is actually there and reports honestly on the rest, rather than fabricating records to look thorough.

Sherlock carves deleted messages, calls and contacts across the iOS artifact set, surfaces Recently Deleted and Hidden media that remains in the backup and recovers deleted Safari history from freed pages where it survives. Recovered items are flagged as recovered in the interface and in the court report, so an examiner can distinguish live records from carved ones on the stand. That distinction matters more to a case outcome than a bigger recovery number would.

Questions

iPhone and iPad Analyzer FAQ

Does Sherlock Forensics iPhone and iPad Analyzer require a jailbreak?
No. The tool uses the MobileBackup2 logical acquisition path, which works on any iPhone or iPad you can unlock. No jailbreak, no exploit, no elevated device access. iOS decrypts the data on-device as it is copied out, so the result is already plaintext.
Can Sherlock Forensics iPhone and iPad Analyzer decrypt an encrypted backup?
Yes. The tool sets the backup password itself before acquisition, then decrypts offline using RFC 3394 keybag unwrap and AES. Operators do not configure a password. Encrypted backups contain more data than unencrypted ones, including the keychain, Health data and Wi-Fi passwords, which is why the tool automates the encryption flip.
What does the free tier include?
The free tier opens a case and previews every artifact: the first 25 percent, capped at 100 rows per view, with file metadata and hashes. It does not include export, global search, the court report, the raw SQLite browser or file extraction. Those unlock in the Forensic Edition.
How do I extract iMessages from an iPhone forensically?
Acquire an encrypted MobileBackup2 backup from a device you can unlock, then open it in Sherlock. The Messages view reconstructs iMessage and SMS as threaded conversations with attachments. Deleted messages are carved from freed SQLite pages where the freelist has not overwritten them. Message content depends on a successful backup of the device you have consent or authority to acquire.
How do I decrypt an encrypted iPhone backup?
Sherlock handles it end to end. It sets the backup password during acquisition, then unwraps the backup keybag with RFC 3394 and AES on the workstation, fully offline. You do not supply or configure a password. If a device already has a backup password you do not know, the tool sets its own on a fresh acquisition rather than attempting to crack the existing one.
Can I recover deleted iPhone messages, calls or contacts?
Sometimes. Sherlock carves deleted messages, calls and contacts from freed SQLite database pages. Records the subject deleted on-device that the SQLite freelist has not yet overwritten are recoverable. Records already overwritten are gone. This is standard freed-page carving applied across the iOS artifact set, not a guarantee of universal deleted-data recovery.
How do I extract WhatsApp from an iPhone?
WhatsApp message data is included in an encrypted iOS backup, so Sherlock reconstructs WhatsApp messages and groups, including members, admins and JIDs, from the acquired backup. This is a genuine difference from non-rooted Android, where the WhatsApp database sits in app-private storage. On iOS the encrypted backup carries it, provided WhatsApp was included in the backup.
Can Sherlock extract the iPhone keychain?
Yes, from an encrypted backup. The keychain, including Wi-Fi passwords, tokens and stored credentials, is only present when the backup is encrypted, which is why the tool always captures an encrypted backup. Sherlock decrypts the keychain offline and presents it as a searchable, exportable view.
Can Sherlock extract iCloud data from an iPhone?
No. Sherlock reads a local MobileBackup2 backup captured over USB from a device you can unlock. It does not reach into iCloud. iCloud acquisition requires the account credentials or legal process and a different acquisition method. Sherlock does not imply otherwise. What it analyzes is the local backup on your workstation.
Is Sherlock a Cellebrite alternative for iPhone forensics?
For logical iOS evidence, yes. Sherlock delivers comparable analysis depth on an encrypted MobileBackup2 backup at $599 one-time versus Cellebrite's multi-thousand-dollar annual subscription. The honest limit is that Cellebrite also does full-filesystem and passcode-bypass acquisition that Sherlock does not. If your case needs the logical backup analyzed, Sherlock covers it at a fraction of the lifetime cost. New in 1.2.0: Sherlock also analyzes the full-filesystem extraction Cellebrite UFED produces, so the deep analysis runs in Sherlock at $599 one-time instead of on a second enterprise analysis seat.
Is Sherlock a GrayKey alternative?
Partly. GrayKey's value is brute-forcing a locked passcode and pulling a full filesystem, which Sherlock does not do. Sherlock needs a device you can unlock. Once you have that, Sherlock analyzes the logical backup at $599 one-time rather than GrayKey's five-figure annual contract. They solve different halves of the problem: GrayKey gets into a locked phone, Sherlock analyzes an unlockable one.
Can Sherlock open a Cellebrite UFED full-filesystem extraction?
Yes, new in 1.2.0. Point Sherlock at an extracted Cellebrite UFED full-filesystem tree and it opens it the same way it opens a backup: it detects the extraction, resolves every artifact at its real on-device path and runs the full parser suite. An extraction-provenance view merges the UFED .ufd, .ufdx and DeviceInfo.txt descriptors into one record with the full descriptor carried verbatim. Sherlock does not itself acquire a full-filesystem extraction; it analyzes the one your acquisition tool produced.
Can Sherlock show the iPhone keychain in the clear?
On a Cellebrite full-filesystem extraction, yes. Version 1.3.0 reads the recovered keychain at its true count (782 items on the validated device): saved app and website passwords, Wi-Fi keys, tokens and account identifiers, decrypted with the device-class keys the extraction provides and each verified against its authentication tag. They are shown in full by default and maskable with one click. A VeraKey extraction carries the keychain SEP-encrypted, so those secrets stay locked on a VeraKey image. From an encrypted logical backup, Sherlock still surfaces the keychain items the backup itself carries.
What is the Life360 view?
New in 1.3.0, from a full-filesystem extraction Sherlock recovers Life360 family location-sharing data: every circle, the member roster with each member's identity (name, email, phone) and role including removed members. It also reads the in-app chat with a flag on every message that shared a live location. The signed-in account is identified as the circle owner, which corroborates device ownership independently. It comes from full-filesystem depth and a logical backup does not carry it.
Can Sherlock extract iPhone location history?
Yes, within the logical backup's scope. Sherlock maps geotagged media, shared pins, the Weather app's saved locations including the device owner home address and locationd client access on an offline map. Full Significant Locations lives in the full filesystem behind the Secure Enclave, so a logical backup shows an honest empty state rather than fabricated data. Open a Cellebrite UFED full-filesystem extraction in Sherlock 1.2.0 and significant locations parse with dwell times, alongside Apple Maps history, Find My and Waze destinations.
What iOS versions are supported?
The MobileBackup2 logical path is universal across modern iPhone and iPad hardware and iOS versions. Full-filesystem acquisition is blocked by the Secure Enclave on A12 and newer devices, so FFS-only artifacts show honest empty states from a logical backup. Sherlock 1.2.0 analyzes a full-filesystem extraction produced by Cellebrite UFED class tooling, which populates those views. Logical acquisition and the full analysis surface work regardless of the iOS version, as long as you can unlock the device and tap Trust.
What is the difference between an encrypted and an unencrypted backup?
An encrypted backup contains more evidence: the keychain, Health data, Wi-Fi passwords and saved credentials that Apple omits from an unencrypted backup. Sherlock always captures an encrypted backup for this reason, setting the password itself and decrypting offline, so you get the fuller data set without configuring anything.
Does Sherlock support iPad?
Yes. Sherlock Forensics iPhone and iPad Analyzer treats iPad the same as iPhone. Any iPad you can unlock and trust supports the MobileBackup2 logical acquisition and the full analysis surface, including messages, Safari, photos with capture GPS, app inventory and the keychain from an encrypted backup.
Can Sherlock recover deleted photos from an iPhone?
It surfaces Recently Deleted media that is still present in the backup and flags Hidden media. Photos the subject deleted that iOS has already purged from the backup are not recoverable by a logical acquisition. Media that remains, including geotagged photos with capture GPS and EXIF, is fully reviewable and exportable.
Can Sherlock extract Safari history and cookies?
Yes. Sherlock reconstructs Safari history, web searches, visited domains, shared links, open tabs, bookmarks, cookies and downloads from the logical backup. Deleted Safari history that survives in freed SQLite pages is carved where the freelist has not overwritten it.
Can it recover deleted messages, calls or contacts?
Yes, subject to survival. Sherlock carves deleted messages, calls and contacts from freed SQLite database pages. Content the subject deleted on-device that the freelist has not overwritten is surfaced for review through standard freed-page carving methodology applied across the iOS artifact set.
Does it work on A12, A13 or newer devices?
Yes for logical acquisition, which is universal across iPhone and iPad hardware. Full-filesystem acquisition is blocked by the Secure Enclave on A12 and newer, so FFS-only artifacts such as knowledgeC pattern-of-life and Significant Locations and deep app-container internals show honest empty states from a logical backup rather than fabricated data. Sherlock does not acquire a full filesystem from any device; as of 1.2.0 it analyzes a full-filesystem extraction that Cellebrite UFED class tooling produced.
Is the installer signed?
Yes. The installer, the application executable and the bundled ffmpeg are all signed with the SSL.com EV Code Signing certificate (Sherlock Forensics Ltd, Burnaby BC), RFC3161-timestamped. Windows SmartScreen shows no warning on download or first launch because all three components carry the EV chain.
Can it detect hidden vault apps?
Yes. Anti-forensic app detection flags hidden-vault apps, encrypted-messaging apps and anonymity or VPN apps inline everywhere apps appear, across Installed Apps, App Inventory, App State, Home Screen and App Permissions. It surfaces them in the Findings view.
Is the $599 price a subscription?
No. The $599 USD Forensic Edition license is a one-time payment. No subscriptions and no recurring charges. You own the license permanently with free updates included. One-time pricing is a genuine differentiator versus Cellebrite, GrayKey and Magnet AXIOM, which charge annual subscriptions in the four to five figure range.
What operating systems does Sherlock Forensics iPhone and iPad Analyzer support?
Windows 10 version 2004 or later and Windows 11, 64-bit. The Microsoft Edge WebView2 runtime is required and the installer auto-installs it if missing. HEIC decoders and ffmpeg are bundled so photos, HEIC images and video work out of the box. macOS and Linux are not currently supported.
Is iPhone evidence from Sherlock court-admissible?
Sherlock produces court-ready HTML reports with per-artifact SHA-256, chain-of-custody provenance, examiner identification and disclosed acquisition methodology, built by CISSP, ISSAP and ISSMP certified examiners with 20 years of courtroom experience. Admissibility depends on jurisdiction and on the examiner following proper evidence handling. The report documents what courts typically require for mobile evidence.
Can I analyze an existing iTunes or Finder backup without the device?
Yes. Sherlock opens any MobileBackup2 backup folder, so an existing local backup made by iTunes or Finder analyzes without the device present. If that backup is encrypted you need its backup password. An unencrypted backup opens directly, though it omits the keychain and Health data that only an encrypted backup carries.

New in 1.1.0

New in Version 1.1.0

Photo Moments as Whereabouts Evidence

The Photos app builds its own titled clusters of place and time. Sherlock now surfaces them as a whereabouts summary on an offline map, searchable and sortable, exportable to CSV, KML and GeoJSON so a moment plots in Google Earth or GIS. Each cluster feeds the activity timeline, global search, the Overview dashboard and the court report, so a photo cluster reads as a dated whereabouts event everywhere it appears.

Known-File Search

Match an external hash set against the evidence to find which files are present and where. Sherlock accepts a SHA-256 or SHA-1 list, including NSRL, Project VIC or a plain sha256sum file. It reports malformed entries rather than silently dropping them, so a hash-matching pass is auditable end to end.

Duplicate Files

Detect byte-identical files across the backup, grouped by content, with reclaimable-space totals. This surfaces cross-app data flow, planted copies and review-reduction opportunities in one view.

Preservation and Subpoena Targets

A deduplicated, priority-ranked list of the off-device data holders an examiner should serve preservation letters on, iCloud, online accounts and AI providers among them, one recipient per provider. It turns the artifacts into an action list for the next step of the case.

Antivirus Helper for Evidence Integrity

Windows Defender scans every file the analyzer opens before the read returns. That serializes file access and slows indexing. It can also lock, quarantine or alter an evidence file mid-view, even though Sherlock only ever reads evidence and never executes it. The Overview now offers a one-click helper that excludes the case folder from Defender real-time scanning, with your approval. It is Windows-only, runs elevated, is fully reversible the same way and carries the case path inside an encoded command rather than on a command line. The result is faster review and an evidence file that Defender cannot touch mid-examination.

Sharper Message Accuracy

Tapback reactions are now distinguished from typed messages in the timeline, the thread views and the message counts, so a reaction is never read as an original communication. Group-membership events such as participant and group-name changes are labeled rather than rendered blank. Roughly ninety sidebar nodes carry an item-count badge for at-a-glance triage. A blank badge means the node is not a counted list and a zero means counted and empty, so a count is never a fabricated zero.

Changelog

Release History

v1.4.1 (2026-07-24) - Ask local AI assistant, media enrichment, full-text search, faster views, About and license dialog with in-app update check and install

  • Ask, a local AI assistant. Answers questions about the open case by querying the same deterministic parsers, so every statement is backed by a specific reproducible record. It shows the tools it called, the arguments and the record counts behind each answer, surfaces leads for the examiner to confirm and reports what it could not find, rather than drawing conclusions or identifying anyone. Runs entirely on the workstation, GPU when present and CPU otherwise, with no cloud and no account. Needs a local model (roughly 4.7 GB) downloaded once with permission on first use, offline after; the AI engine ships in the installer.
  • Media enrichment for search. An optional local pass describes images with a vision model and transcribes voicemails and voice notes with on-device speech-to-text, folded into search so a photo is findable by its contents and a voicemail by what was said, across attachment images and voice notes. These are AI search aids for locating evidence; the image and audio remain the authority and a lead is confirmed by opening the media. The on-device transcription is a search layer and does not replace the iOS-stored transcript the voicemail view shows. GPS from attachment photos is read deterministically. The vision and transcription models are consented local downloads, offline after. Validated on the Josh Hickman reference image; local, resumable, with a live feed.
  • Full-text search. Accent-insensitive (a search for a plain name matches its accented spelling), relevance-ranked and interleaved across databases, skipping internal bookkeeping tokens so every hit is real content.
  • Faster views. Media Library, Home Screen, Contacts, Communications Map, Health and other heavy views cache per case for instant return instead of re-parsing.
  • Fixes. Previously-uncounted sidebar nodes (file-system manifest, device ark, two data-list nodes) now counted; HEIC transcodes for very long paths; bundled ffmpeg updated with media-decoder security fixes; Microsoft C++ runtime bundled so it starts on a clean Windows install with no prerequisite.

EV code-signed binary (Sherlock Forensics Ltd, SSL.com EV Code Signing, RFC3161-timestamped). SHA-256: d6ffd2af48f9918b887aa787edeae7da1580f6635d6c5e0c714cbb7b81bfc171.

v1.3.1 (2026-07-22) - Open an extraction .zip, Settings page, fully attributed keychain

  • Open an extraction .zip directly. Hand Sherlock the Cellebrite or Magnet full-filesystem package .zip; it confirms the vendor, device, inner archive and free space before unpacking, then extracts the nested full-filesystem archive with a live percentage, bytes and throughput readout and opens it in Analyze. Validated on a Magnet iPhone extraction with hundreds of thousands of files and a 20 GB inner archive, as well as a Cellebrite UFED package. The source archive is never modified or deleted. Re-opening the same .zip reuses the existing extraction. Sherlock still does not acquire a full filesystem; it unpacks and analyzes one an acquisition tool produced.
  • Settings page. One place for the working folder, case cache and report output folders, examiner name and agency (into the report and provenance) and display defaults for timestamp zone, empty-artifact hiding, keychain-secret reveal and hash verification on ingest.
  • Keychain full attribution. Every recovered item now carries creation and last-modified dates, data-protection class, device-bound and iCloud-sync flags and server, port and protocol. Items whose class key was not in the extraction are labeled locked rather than blank. The bulk keychain in the clear remains Cellebrite-full-filesystem-scoped; a Magnet extraction carries it SEP-encrypted.
  • Saved Wi-Fi passwords. Cross-linked into the Wi-Fi Networks view with the date saved, recovered from an encrypted logical backup as well as a Cellebrite full-filesystem extraction, so they appear in almost every image (a VeraKey or Magnet extraction keeps the keychain SEP-encrypted, so they stay locked there).

EV code-signed binary (Sherlock Forensics Ltd, SSL.com EV Code Signing, RFC3161-timestamped). SHA-256: 479d4f39db89d70ffaf809b2fed87fdf9357d983e6bc3286646a97a1b224e4ed.

v1.3.0 (2026-07-21) - Second validated device, Life360, keychain on full-filesystem

  • Second validated device class. Full-filesystem ingestion validated end to end against an iPhone 12 mini (A14, iOS 17.6.1) acquired with Cellebrite Inseyets UFED, on top of the iPhone 11 (iOS 17.3) reference image from 1.2.0. Extraction integrity was verified against the acquisition tool's recorded SHA-256 before parsing. Sherlock reads Apple's own file system, so the parsers are vendor-agnostic and generational across A-series devices and modern iOS builds.
  • Life360 family location sharing. A new view recovers every circle, the full member roster with each member's identity (name, email, phone) and role including removed members. It reads the complete in-app chat with a flag on every message that shared a live location. The signed-in account is identified as the circle owner, corroborating device ownership independently. Full-filesystem depth; a logical backup never captures it.
  • Keychain in the clear on a Cellebrite full-filesystem extraction. The Keychain badge now reads its true count (782 items on the validated device) instead of zero: saved passwords, Wi-Fi keys, tokens and account identifiers, decrypted with the device-class keys the extraction provides and each authentication-tag verified. Shown in full by default, maskable with one click. A VeraKey extraction carries the keychain SEP-encrypted, so those secrets stay locked on a VeraKey image.
  • Complete evidence inventory. Every sidebar artifact now shows its true record count, while artifacts with no records auto-collapse (toggleable) so the sidebar shows what the device actually holds.
  • Reliability on full-filesystem cases. The installed-app inventory, Notable Apps and owner-attribution views now read the full-filesystem's own sources instead of failing on an absent logical-only metadata file; the Indicators, Findings and Duplicate Files views no longer disappear after opening; and concurrency hardening lets databases open reliably during first-load indexing.

EV code-signed binary (Sherlock Forensics Ltd, SSL.com EV Code Signing, RFC3161-timestamped). SHA-256: 17a0fd77be1df6821a280565071f3cd796a6332e6e335eb46b0e7e8352c5de48.

v1.2.0 (2026-07-21) - Full-filesystem extraction analysis and 50+ new artifact views

  • Cellebrite UFED full-filesystem extraction analysis. Point Sherlock at an extracted UFED full-filesystem tree and it opens it the same way it opens a backup: it detects the extraction, resolves every artifact at its real on-device path and runs the full parser suite. Sherlock analyzes the extraction; acquiring it remains the acquisition tool's job.
  • Extraction provenance. The UFED .ufd, .ufdx and DeviceInfo.txt descriptors merge into one record: device model, iOS build, examiner machine, acquisition tool and version, start and end times and the per-dump SHA-256 and HMAC the acquisition tool recorded, with the full descriptor carried verbatim.
  • More than fifty new artifact views. Messaging recovered from web caches and delivered-notification previews (Skype, Facebook Messenger, Instagram and TikTok direct messages, Discord and others), whereabouts views including significant locations with dwell times and Find My and Apple Maps history, pattern-of-life views from Screen Time and powerlog and app install and launch history, hidden and deleted photos, health workouts with GPS routes, contact frequency intelligence, Bluetooth device history, Snapchat memories, AirDrop history and a cross-app cached-web-request view.
  • Validation. Parser output validated against the Josh Hickman iOS 17.3 public reference image, the standard DFIR test image.

EV code-signed binary (Sherlock Forensics Ltd, SSL.com EV Code Signing, RFC3161-timestamped). SHA-256: b82a3741b0aa370e5dd99b61b5a4053059b16d59e213639a6d9d43b659178705.

v1.1.2 (2026-07-20) - Acquisition safety and usability

  • Show and confirm the backup password. The Acquire screen now shows the backup password Sherlock will set on the device and requires the operator to confirm they have recorded it before the capture can start. That password is the only key to the encrypted evidence and any later backup, so recording it up front means a lost key store can never strand a device.
  • Synced-destination guard. A pre-flight check detects a destination inside a cloud-sync folder such as OneDrive, Dropbox, Google Drive or iCloud Drive and blocks Start until a local folder is chosen, with an override for a false positive. Cloud sync grabs each backup file as it is written and fails the capture, so this heads it off before it starts.
  • Accurate media-folder sizing. A loose media folder reports the size of its media files, consistent with the media count, rather than the whole tree, so there are no more larger-than-the-device numbers, with leftover non-media data surfaced as a warning.

EV code-signed binary (Sherlock Forensics Ltd, SSL.com EV Code Signing, RFC3161-timestamped). SHA-256: 6881c2b3ce4eea61a7985ed5b51170032de8ea19e04f99d7e6fcd532d5ecef49.

v1.1.1 (2026-07-20) - Acquisition-safety hardening

  • Encrypted-acquisition password safety. The auto-generated backup password is now saved to Sherlock's key store and confirmed on disk before it is ever set on the device. If it cannot be saved the acquisition aborts and the device is left untouched, so a run can never leave a device behind a password the tool did not record.
  • Clearer Error 104 guidance. The message now leads with the most common cause, a destination that is rejecting writes such as OneDrive or another cloud sync, real-time antivirus or a flaky destination or USB drive. It detects a re-write storm and recommends a local non-synced folder, with device lock kept as a secondary possibility.
  • Accurate partial sizing. A failed backup's preserved partial is now sized from what actually landed on disk, so the reported size never exceeds what the device holds.

EV code-signed binary (Sherlock Forensics Ltd, SSL.com EV Code Signing, RFC3161-timestamped). SHA-256: 30e39926302d4f3ee148673bac9b1d7ee36006b4f4f39b0a2206013fcd930ace.

v1.1.0 (2026-07-18) - New parsers, cross-surface correlation, evidence-integrity audit

  • Photo Moments. The Photos app titled place-and-time clusters surface as a whereabouts summary on an offline map, with search, sort and CSV, KML and GeoJSON export, feeding the timeline, global search, Overview and court report.
  • Known-File Search. Match a SHA-256 or SHA-1 hash set (NSRL, Project VIC or a sha256sum list) against the evidence to find which files are present and where, with malformed entries reported rather than silently dropped.
  • Duplicate Files. Byte-identical files grouped by content with reclaimable-space totals.
  • Preservation and Subpoena Targets. A deduplicated, priority-ranked list of off-device data holders (iCloud, online accounts, AI providers) to serve preservation letters on.
  • Roughly 130 artifact views across communications, media, web and location, personal, apps and system, acquisition and integrity.
  • Message accuracy. Tapback reactions are distinguished from typed messages everywhere and excluded from counts, group-membership events are labeled and roughly ninety sidebar nodes carry item-count badges where a blank badge is not-a-list and zero is counted-and-empty.
  • Exports and reporting. KML and GeoJSON for Photo Moments, iCal for calendar and vCard for contacts, per-view CSV for every tabular view and the Preservation Targets, Duplicate Files and Photo Moments sections added to the court report.
  • Antivirus helper. A one-click, reversible, approval-gated Windows Defender exclusion for the case folder that stops on-access scans from serializing reads or locking, quarantining or altering evidence the tool only ever reads.
  • Evidence-integrity audit. Every core parser was cross-validated against real device data and locked with regression tests, the provenance manifest uses a stable externally reproducible SHA-256 line and the URL-scheme allowlist, CSV formula-injection guard and JSON-injection escaping are locked with tests.

EV code-signed binary (Sherlock Forensics Ltd, SSL.com EV Code Signing, RFC3161-timestamped). SHA-256: 0d4739d3051b241f6caf29663870efbadb5e9b875e78cd574f95c485de609c5b.

v1.0.0 (2026-07-14) - Initial Release

  • Windows forensic workstation for iPhone and iPad evidence.
  • MobileBackup2 logical acquisition with encrypted-backup offline decryption.
  • 130+ artifact views across six manifest groups: Communications; Media; Web and Location; Personal; Apps and System; Acquisition and Integrity.
  • Findings automated first-look triage and Activity Timeline and Pattern of Life and Communication Map and anti-forensic app detection.
  • Deleted-content carving from freed SQLite database pages (Messages and Calls and Contacts).
  • Court-ready HTML report and CSV and JSON export and raw SQLite browser (Forensic Edition).
  • Read-only acquisition and per-file SHA-256 and provenance manifest.
  • SSL.com EV Code Signing on installer and application executable and bundled ffmpeg. No SmartScreen warning.

Checkout - iPhone Analyzer Forensic Edition ($599)

$599.00 USD. One-time payment. License key delivered to your email.

Secure via Stripe One-time purchase No subscription

Download

Your email is optional. If you provide it, we send 3 product introduction emails over the next 2 weeks. No long-term marketing. No data sharing. Skip the field and download directly.