Notifications
Clear all

IOS app data

11 Posts
6 Users
0 Likes
1,098 Views
(@kev21903)
Posts: 12
Active Member
Topic starter
 

Is it possible to determine when applications are downloaded and deleted in iOS?

 
Posted : 02/07/2019 9:56 am
(@dandaman_24)
Posts: 172
Estimable Member
 

Yes it is.

 
Posted : 02/07/2019 11:08 am
passcodeunlock
(@passcodeunlock)
Posts: 792
Prominent Member
 

Jailbrake the device and check /var/log/* )

Many apps don't clean up well after removal, the dates of the remnant data could be also a lead.

 
Posted : 02/07/2019 6:13 pm
(@matrix4n6)
Posts: 6
Active Member
 

I was not testing it yet but maybe it's worth a look The tool by Sarah Edwards https://github.com/mac4n6/apollo

 
Posted : 03/07/2019 4:34 am
(@dandaman_24)
Posts: 172
Estimable Member
 

In order to use Apollo, you need a FS which you can only get from a jailbroken device or from a GK / ufed premium dump

 
Posted : 03/07/2019 6:50 am
(@deefir)
Posts: 49
Eminent Member
 

In order to use Apollo, you need a FS which you can only get from a jailbroken device or from a GK / ufed premium dump

Not quite. APOLLO requires artefacts included in an encrypted iOS backup - ie Health database etc. It definitely doesn't have to be jailbroken to extract the required databases.

 
Posted : 15/07/2019 5:45 am
(@kev21903)
Posts: 12
Active Member
Topic starter
 

Once the device is jail broken what the best way to look at the root?

 
Posted : 23/07/2019 11:08 am
marky.mark
(@marky-mark)
Posts: 22
Eminent Member
 

Hi,

If you want you can connect yourself to the phone with a gui client like putty or just bare SSH to connect to the terminal.

If you want to take the forensic path, you make an aquisition of the device and work with that.

M.

 
Posted : 23/07/2019 2:03 pm
(@kev21903)
Posts: 12
Active Member
Topic starter
 

So the phone is jailbroken iOS 12.2

What is the next step to get a physical image?

 
Posted : 24/07/2019 6:56 am
(@deefir)
Posts: 49
Eminent Member
 

You at least have to try and do some of the work yourself. You've literally been provided with all of the answers.

 
Posted : 24/07/2019 8:26 am
Page 1 / 2
Share: