Per-Artifact Deep Dive

Significant Locations: The iPhone's Own Whereabouts Record

Where the device went, when it arrived, how long it stayed, kept by iOS itself. Here is how it becomes evidence and what it can and cannot prove.

Significant Locations is iOS's own log of places an iPhone visited, with arrival and departure times and dwell durations. Sherlock Forensics iPhone Analyzer parses it from a Cellebrite UFED or VeraKey full-filesystem extraction into a mapped, searchable view with enter and exit transitions, alongside Apple Maps, Find My and Waze. A logical backup does not carry it. $599 one-time.

Windows 10/11 | One-time license | Full-filesystem depth | 100 percent read-only

The Artifact

What Significant Locations Records

iOS quietly keeps its own record of the places a device returns to. Significant Locations logs the locations an iPhone visited regularly, when it arrived and left each one and how long it stayed. Apple built it to power features like traffic predictions and location-based suggestions, not for an investigation, which is precisely what makes it valuable evidence: it is the device's own contemporaneous account of its whereabouts, written long before anyone had a reason to question it.

Sherlock Forensics iPhone Analyzer parses that record into a dedicated view: each visited place with its dwell time and the enter and exit transitions that bound it, plotted on an offline map. In matters that turn on presence, where a device was at a given time, whether it visited a particular place, how its movements line up against a claimed account, this is frequently the single most consequential artifact on the phone.

What gives the record its evidentiary weight is that iOS was not keeping it for a courtroom. The device logged these visits as a byproduct of ordinary use, continuously, without anyone deciding which places mattered, which is exactly why a defense or a prosecution finds it hard to argue the record was curated after the fact. The dwell times add a dimension a single GPS ping cannot: not just that a device passed through a location but that it stayed there for two hours, ten minutes or overnight, which is often the difference between presence and mere transit. An examiner who reads the transitions in order can reconstruct a day's movement as the device itself recorded it, then test that reconstruction against every other artifact on the phone.

The Source

Why This Needs a Full-Filesystem Extraction

Significant Locations lives in the full filesystem, behind the Secure Enclave, in the behavioral layer a logical backup never copies out. It reaches an examiner only inside a full-filesystem extraction produced by Cellebrite UFED or VeraKey class tooling. Load a logical MobileBackup2 backup and Sherlock shows the Significant Locations view as an honest empty state, because the source genuinely cannot contain it, rather than fabricating a record. Load the full-filesystem extraction and it populates.

That honest empty state matters on the stand as much as the data does. An examiner can state precisely why a view is empty, the source does not carry that artifact, without leaving room for an inference that the device had no location history. If you have not worked with extractions before, the image-loading workflow covers getting the extraction open; the full-filesystem analysis overview covers the rest of the behavioral layer.

Cross-Check

One Record Among Several

Significant Locations is strongest when it is not alone. A full-filesystem extraction carries several independent location records. Sherlock reads them into views that check each other:

  • Apple Maps history: searched and navigated destinations, which show intent toward a place rather than only presence at it.
  • Find My: the owner's own devices, AirTags and accessories and family location-sharing members.
  • Waze destinations: a second navigation record independent of Apple Maps.
  • Geotagged media: photos and videos with capture GPS, which place the device at a spot at a precise moment, readable from any source.
  • Named place-visit life events and location permission requests: supporting context around when and how location was captured.

When Significant Locations, a geotagged photo and a Maps search all point at the same place and time, the whereabouts finding is hard to dismiss as a single-source artifact. When they diverge, that is worth surfacing honestly rather than papering over. Every one feeds the merged Activity Timeline, so location reads in sequence with messages, calls and app usage from the same minutes.

The Limit That Governs

Device Whereabouts Is Not a Person's Whereabouts

The load-bearing sentence in any location report is the scope statement: Significant Locations records where the device was, not who was carrying it. A phone left at home, lent to a family member or forgotten in a car breaks the line between the device and its owner. An examiner who presents device location as a person's proven whereabouts without corroboration invites the cross-examination that unravels the report.

Worked honestly, the location record is a spine that corroboration gives flesh to: a geotagged selfie at the location, a message sent from it, an account login from its network, a witness. Sherlock is built for exactly that composition, location views and content views feeding one timeline, so the attribution argument is assembled in the open from independent artifacts rather than asserted from one database. The tool maps where the device was; the case argues who put it there.

See It

Sherlock Forensics iPhone Analyzer location intelligence view plotting visited places and geotagged media on an offline map
Location intelligence plotted on an offline map, no internet connection touched

Court-Ready

From the Map to the Report

The dwell times and transitions Sherlock shows are the values iOS itself recorded, carried through without smoothing or inference, so an examiner testifies to the device's own record rather than a derived estimate. Analysis is 100 percent read-only; the extraction is never modified. The court-ready HTML report carries the mapped locations, case and evidence numbers, examiner identification, disclosed methodology, per-artifact SHA-256 hashing and an optional evidence-integrity manifest, the documentation elements described in NIST Special Publication 800-101 Revision 1, Guidelines on Mobile Device Forensics.

Built by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record so testimony rests on it.

Honest Scope

What This Analysis Is and Is Not

Sherlock analyzes a full-filesystem extraction; it does not create one and does not acquire location data from a device itself beyond the logical backup path, which does not carry Significant Locations. Producing a full-filesystem extraction requires Cellebrite or GrayKey class acquisition tooling. Confirmed ingestion formats are Cellebrite UFED and VeraKey, validated against real device images. From a logical backup, the Significant Locations, Apple Maps, Find My and Waze views show honest empty states while geotagged media and shared pins still map. Different source? Contact us before purchasing and we will confirm the layout is readable.

Questions

Significant Locations FAQ

What are Significant Locations on an iPhone?
Significant Locations is iOS's own record of places the device visited regularly, with the times it arrived and left and how long it stayed. It is one of the strongest whereabouts artifacts on an iPhone. Sherlock parses it from a full-filesystem extraction into a dedicated view with dwell times and enter and exit transitions.
Can I get Significant Locations from a normal iPhone backup?
No. Significant Locations lives in the full filesystem behind the Secure Enclave and a logical MobileBackup2 backup does not contain it, so from a backup Sherlock shows the view as an honest empty state rather than fabricated data. It populates from a Cellebrite UFED or VeraKey full-filesystem extraction.
Does Significant Locations prove where a person was?
It proves where the device was, not who was carrying it. Significant Locations attributes visits to the iPhone. Placing a specific person at a location needs corroboration: message content, photos with capture GPS, account activity, witness evidence. Sherlock presents the location record and its dwell times; the attribution argument belongs to the case.
What other location artifacts does Sherlock read?
From a full-filesystem extraction: Apple Maps history, Find My devices and AirTags and family location-sharing members, Waze destinations, location permission requests and named place-visit life events. From any source it also maps geotagged media and shared pins on an offline map. Together they cross-check a whereabouts narrative from independent records.
How accurate are the dwell times?
The dwell times and transitions are the values iOS itself recorded, carried through without adjustment, so they are as accurate as the device's own location system was at the time. Sherlock reports what the artifact holds rather than smoothing or inferring, so an examiner can testify to the source rather than to a derived estimate.
Is location evidence from Sherlock court-defensible?
Analysis is read-only and the court-ready report documents examiner details, methodology and per-artifact SHA-256 hashing. Significant Locations plots on an offline map and feeds the merged timeline so it reads in sequence with the rest of the evidence. Admissibility depends on jurisdiction, authority and evidence handling; the report documents the record for testimony.

Start Now

Map the Whereabouts in Your Extraction

Download the free edition, load the extraction and see whether the Significant Locations view populates for the device. Unlock the full record when the case calls for it: $599 one-time, no subscription.

Get Sherlock Forensics iPhone Analyzer

Related: Screen Time forensics · iPhone full-filesystem analysis · The full parser list