New Wifi database from Apple intelligence
Apple Intelligence, while officially released only in 2024 (a few months ago) for macOS 15.1 (Sequoia) has been around for over a year in beta on most macOS and iOS systems. Its only available for...
View Articlemac_apt update to BTM processing
This post highlights improvements to the AUTOSTART plugin in mac_apt.Since macOS 13 (Ventura), Login items and Background tasks are managed and tracked via .BTM files. This is located at the...
View ArticleNSKeyedArchive Deserializer update
A long time ago I wrote some code to make NSKeyedArchives (NSKA) human readable, basically de-serializing the data. It was then converted to a library for use in other projects like iLeapp and mac_apt....
View ArticleReading OneDrive Logs Part 2
In the last OneDrive blog post, I outlined how the ODL file format is structured. A working version of an ODL parser was also created to read these files. One key detail was how personal file/folder,...
View ArticleReading OneDrive Logs
Due to the popularity of OneDrive, it has become an important source of evidence in forensics. Last week, Brian Maloney posted about his research on reconstructing the folder tree from the usercid.dat...
View ArticleGboard has some interesting data..
Gboard - the Google Keyboard, is the default keyboard on Pixel devices, and overall has been installed over a billion times according to the Play Store.Although not the default on most non-Google...
View ArticleiOS Application Groups & Shared data
BackgroundTracking down an iOS application's Data folder, aka, SandboxPath in iOS is fairly easy. One simply needs to look at the applicationState.db sqlite database located under...
View ArticleIntroducing ios_apt - iOS Artifact Parsing Tool
ios_apt is the new shiny companion to mac_aptios_apt is not a separate project, it's just a part of the mac_apt framework, and serves as a launch script that processes iOS/iPadOS artifacts. Why yet...
View ArticleKTX to PNG in Python for iOS snapshots
App snapshots on iOS are stored as KTX files, this is fairly well known at this point, thanks to the research by Geraldine Blay (@i_am_the_gia) and Alex Brignoni (@AlexisBrignoni) here and here. They...
View ArticleScreentime Notifications in Catalina (10.15)
If you routinely perform mac forensics, you've probably done a few macOS Catalina (10.15) examinations already. And if you are the kind that verifies your data, you may have noticed that for ScreenTime...
View ArticleParsing unknown protobufs with python
Protocol Buffers are quite popular, more and more apps and system files are storing data in this format in both iOS and Android operating systems. If you aren't familiar with Protocol Buffers, read...
View ArticleGoogle Search & Personal Assistant data on android
The Google app, previously known as Google Now, is installed by default on most phones. From the app's description -The Google app keeps you in the know about things that matter to you. Find quick...
View ArticleUsagestats on Android 10 (Q)
UsageStatsIf you are unfamiliar with this artifact, Alex Brignoni explains the UserStats artifact in the blog post here. Located at /data/system/usagestats/ this information can be useful in cases. Up...
View ArticlemacOS 10.15 Volumes & Firmlink magic
With macOS 10.15 - Catalina, Apple has introduced a change in the way system and user data is stored on disk. In prior versions, the root '/' volume was stored in a single volume usually named...
View ArticlePart 3 - ADB keyvalue backups - Wifi and System settings
This is Part 3 of the continuing blog series on ADB keyvalue backups. Today we focus on Wifi settings and other system configuration available...
View ArticlePart 2 - ADB keyvalue backups - Call Logs
This is Part 2 of the continuing blog series on ADB keyvalue backups. Today we focus on Call Log Backups. Call logs are backed up under...
View ArticleADB keyvalue backups and the .data format
The ADB backup has been a very useful tool for getting data from Android phones, particularly those phones/devices that are otherwise not accessible due to lack of support by forensic software vendors...
View ArticleMaking NSKeyedArchives human readable
If you've been doing macOS analysis, you are definitely familiar with the (now not so new) serialized plist format also known as an NSKeyedArchive. There are parsers available to extract data from this...
View Article$Recycle bin and Undo operations
This week Phil Moore made an excellent finding (link here), one that most of us have seen for years but not investigated. Those $I files that seem orphaned/abandoned without explanation now have one....
View ArticleThe ._ (dot-underscore) file format
If you've ever looked at removable media and found several hidden files which start with ._ and there exists one for almost every file (or folder) on the disk, this is the result of having that media...
View Article