Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Most defiantly. iOS is a different kettle of fish.

Same challenges are present with performing forensics on an iPhone! The top commercial forensic toolkits will try to jailbreak the handset if possible to pull off artifacts. Good luck on newer hardware with the latest iOS versions. [1]

On the topic of iOS forensics, you can still get quite many useful artifacts from iOS backups with Mobile Verification Toolkit [2] being quite exceptional. I have had less success with iOS backups and the popular iLEAPP forensics software [3].

[1] https://blog.elcomsoft.com/2022/09/ios-forensic-toolkit-8-0-...

[2] https://docs.mvt.re/en/latest/

[3] https://github.com/abrignoni/iLEAPP



Thanks for those great tools recs. Had never seen mvt before and I'm running a check of my local iTunes backup with it now! (Funnily, this seems one of the easier ways to backup my text message history into an easily searchable form)


If you haven't used it before, Timesketch [1] is excellent indexing and searching timeline data for forensics analysis.

MVT takes a (MACB) timeline of your phone backup file changes and other events - including your text message history.

Here is a simple script that I wrote converts it into a format compatible with Timesketch [2] so it's trivial to explore events from the phone, indexed and searchable by time, kind of what you would see in Kibana.

[1] https://timesketch.org/

[2] https://github.com/x1sec/mvt2timesketch


Thank you for your every post, very informative!


defiantly -> definitely, right?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: