Quantcast
Channel: Yogesh Khatri's forensic blog
Browsing index pages (61 articles)
↧

Image may be NSFW.
Clik here to view.

New Wifi database from Apple intelligence

Apple Intelligence, while officially released only in 2024 (a few months ago) for macOS 15.1 (Sequoia) has been around for over a year in beta on most macOS and iOS systems. Its only available for...

View Article


Image may be NSFW.
Clik here to view.

mac_apt update to BTM processing

This post highlights improvements to the AUTOSTART plugin in mac_apt.Since macOS 13 (Ventura), Login items and Background tasks are managed and tracked via .BTM files. This is located at the...

View Article


Image may be NSFW.
Clik here to view.

NSKeyedArchive Deserializer update

A long time ago I wrote some code to make NSKeyedArchives (NSKA) human readable, basically de-serializing the data. It was then converted to a library for use in other projects like iLeapp and mac_apt....

View Article

Image may be NSFW.
Clik here to view.

Reading OneDrive Logs Part 2

In the last OneDrive blog post, I outlined how the ODL file format is structured. A working version of an ODL parser was also created to read these files. One key detail was how personal file/folder,...

View Article

Image may be NSFW.
Clik here to view.

Reading OneDrive Logs

Due to the popularity of OneDrive, it has become an important source of evidence in forensics. Last week, Brian Maloney posted about his research on reconstructing the folder tree from the usercid.dat...

View Article


Image may be NSFW.
Clik here to view.

Gboard has some interesting data..

Gboard - the Google Keyboard, is the default keyboard on Pixel devices, and overall has been installed over a billion times according to the Play Store.Although not the default on most non-Google...

View Article

Image may be NSFW.
Clik here to view.

iOS Application Groups & Shared data

BackgroundTracking down an iOS application's Data folder, aka, SandboxPath in iOS is fairly easy. One simply needs to look at the applicationState.db sqlite database located under...

View Article

Image may be NSFW.
Clik here to view.

Introducing ios_apt - iOS Artifact Parsing Tool

ios_apt is the new shiny companion to mac_aptios_apt is not a separate project, it's just a part of the mac_apt framework, and serves as a launch script that processes iOS/iPadOS artifacts. Why yet...

View Article


Image may be NSFW.
Clik here to view.

KTX to PNG in Python for iOS snapshots

App snapshots on iOS are stored as KTX files, this is fairly well known at this point, thanks to the research by Geraldine Blay (@i_am_the_gia) and Alex Brignoni (@AlexisBrignoni) here and here. They...

View Article


Image may be NSFW.
Clik here to view.

Screentime Notifications in Catalina (10.15)

If you routinely perform mac forensics, you've probably done a few macOS Catalina (10.15) examinations already. And if you are the kind that verifies your data, you may have noticed that for ScreenTime...

View Article

Image may be NSFW.
Clik here to view.

Parsing unknown protobufs with python

Protocol Buffers are quite popular, more and more apps and system files are storing data in this format in both iOS and Android operating systems. If you aren't familiar with Protocol Buffers, read...

View Article

Image may be NSFW.
Clik here to view.

Google Search & Personal Assistant data on android

The Google app, previously known as Google Now, is installed by default on most phones. From the app's description -The Google app keeps you in the know about things that matter to you. Find quick...

View Article

Image may be NSFW.
Clik here to view.

Usagestats on Android 10 (Q)

UsageStatsIf you are unfamiliar with this artifact, Alex Brignoni explains the UserStats artifact in the blog post here. Located at /data/system/usagestats/ this information can be useful in cases. Up...

View Article


Image may be NSFW.
Clik here to view.

macOS 10.15 Volumes & Firmlink magic

With macOS 10.15 - Catalina, Apple has introduced a change in the way system and user data is stored on disk. In prior versions, the root '/' volume was stored in a single volume usually named...

View Article

Image may be NSFW.
Clik here to view.

Part 3 - ADB keyvalue backups - Wifi and System settings

This is Part 3 of the continuing blog series on ADB keyvalue backups. Today we focus on Wifi settings and other system configuration available...

View Article


Image may be NSFW.
Clik here to view.

Part 2 - ADB keyvalue backups - Call Logs

This is Part 2 of the continuing blog series on ADB keyvalue backups. Today we focus on Call Log Backups. Call logs are backed up under...

View Article

Image may be NSFW.
Clik here to view.

ADB keyvalue backups and the .data format

The ADB backup has been a very useful tool for getting data from Android phones, particularly those phones/devices that are otherwise not accessible due to lack of support by forensic software vendors...

View Article


Image may be NSFW.
Clik here to view.

Making NSKeyedArchives human readable

If you've been doing macOS analysis, you are definitely familiar with the (now not so new) serialized plist format also known as an NSKeyedArchive. There are parsers available to extract data from this...

View Article

Image may be NSFW.
Clik here to view.

$Recycle bin and Undo operations

This week Phil Moore made an excellent finding (link here), one that most of us have seen for years but not investigated. Those $I files that seem orphaned/abandoned without explanation now have one....

View Article

Image may be NSFW.
Clik here to view.

The ._ (dot-underscore) file format

If you've ever looked at removable media and found several hidden files which start with ._ and there exists one for almost every file (or folder) on the disk, this is the result of having that media...

View Article
Browsing index pages (61 articles)


Latest Images