π New blog post on Apple Unified Logs (iOS) and how to query them effectively.
πͺ΅ Learn how to generate a .logarchive using a macOS device, third-party tools, or straight from files in a full file system extraction.
πͺ΅ Use a macOS device to convert the .logarchive into a JSON file for use outside of a macOS environment.
πͺ΅ Process the JSON file with iLEAPP in order to query the data using SQLite.
If you are not looking at unified logs you are missing incredibly valuable evidence in your cases.
Thanks to the following researchers for their invaluable contributions:
π Lionel Notari
π Tim Korver
π Johann POLEWCZYK
π Heather Charpentier
Read the blog post here:
https://abrignoni.blogspot.com/2025/05/extraction-processing-querying-apple.html
#DigitalForensics #DFIR #MobileForensics #UnifiedLogs #AppleForensics #iOSForensics #iLEAPP
#DigitalForensics

