abrignoni / iOS-KnowledgeC-StructuredMetadata-Bplists
Scripts to extract compound bplists in the iOS -> KnowledgeC.db -> structuredmetadata table.
☆23Updated 5 years ago
Alternatives and similar repositories for iOS-KnowledgeC-StructuredMetadata-Bplists:
Users that are interested in iOS-KnowledgeC-StructuredMetadata-Bplists are comparing it to the libraries listed below
- Python script that generates a HTML triage report of iOS notifications content.☆15Updated 5 years ago
- Collection of SQL query templates for digital forensics use by platform and application.☆101Updated 3 years ago
- ☆65Updated last month
- A script to mine SQLite databases for hidden gems that might be overlooked☆54Updated 4 years ago
- ☆30Updated 4 years ago
- ☆19Updated 5 years ago
- iOS forensics utility☆12Updated 6 years ago
- Script that checks for available updates for the most commonly used Digital Forensics tools☆59Updated 4 years ago
- macOS triage is a python script to collect various macOS logs, artifacts, and other data.☆26Updated 3 years ago
- Different DFIR and CTI utilities☆36Updated 4 years ago
- AFF4 Standard Documents☆28Updated 3 years ago
- Dump the iOS Frequent Location binary plist files☆83Updated 6 years ago
- Android Usagestats XML + Protobuf Parser☆22Updated 4 years ago
- Resources for HFS+ Forensics☆36Updated 9 years ago
- http://moaistory.blogspot.com/2016/08/ie10analyzer.html☆16Updated 8 months ago
- Module(s) related to reading SEGB (fka "Biome") data from iOS, mascOS, etc.☆18Updated 10 months ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆15Updated last year
- A DFVFS Backed Forensic Viewer☆40Updated 4 years ago
- WLEAPP is an open source project that aims to parse Windows OS artifacts for the purpose of triage analysis.☆30Updated last year
- "Fuzzy matching" for SQLite databases☆29Updated 4 years ago
- macOS/iOS database location scraper to extract location data☆80Updated 2 years ago
- iOS Backup Examiner - A forensics tool for parsing an iOS backup's Info.plist file☆21Updated 8 years ago
- This is a GUI (for Windows 64 bit) for a procedure to virtualize your EWF(E01), DD (raw), AFF disk image file without converting it, dire…☆54Updated 5 years ago
- ☆10Updated 5 years ago
- A fork of The Sleuthkit with Pooled Storage and APFS support. See https://www.youtube.com/watch?v=k1XPillJ7aw for more info and usage.☆26Updated 5 years ago
- CIRCL system forensic tools or a jumble of tools to support forensic☆42Updated 2 years ago
- Quick iOS Backup UnFunkerizor☆21Updated 3 years ago
- Binaries for the log2timeline projects and dependencies☆39Updated 6 months ago
- Personal settings for X-Ways Forensics☆30Updated 2 years ago
- CLBX file format☆20Updated 3 years ago