๐ New blog post on Apple Unified Logs (iOS) and how to query them effectively.
๐ชต Learn how to generate a .logarchive using a macOS device, third-party tools, or straight from files in a full file system extraction.
๐ชต Use a macOS device to convert the .logarchive into a JSON file for use outside of a macOS environment.
๐ชต Process the JSON file with iLEAPP in order to query the data using SQLite.
If you are not looking at unified logs you are missing incredibly valuable evidence in your cases.
Thanks to the following researchers for their invaluable contributions:
๐ Lionel Notari
๐ Tim Korver
๐ Johann POLEWCZYK
๐ Heather Charpentier
Read the blog post here:
https://abrignoni.blogspot.com/2025/05/extraction-processing-querying-apple.html
#DigitalForensics #DFIR #MobileForensics #UnifiedLogs #AppleForensics #iOSForensics #iLEAPP
#DigitalForensics




