Notifications
Clear all

IOS app data

11 Posts
6 Users
0 Reactions
1,697 Views
(@kev21903)
Active Member
Joined: 6 years ago
Posts: 12
Topic starter  

Is it possible to determine when applications are downloaded and deleted in iOS?


   
Quote
(@dandaman_24)
Estimable Member
Joined: 11 years ago
Posts: 172
 

Yes it is.


   
ReplyQuote
passcodeunlock
(@passcodeunlock)
Prominent Member
Joined: 9 years ago
Posts: 792
 

Jailbrake the device and check /var/log/* )

Many apps don't clean up well after removal, the dates of the remnant data could be also a lead.


   
ReplyQuote
(@matrix4n6)
Active Member
Joined: 6 years ago
Posts: 6
 

I was not testing it yet but maybe it's worth a look The tool by Sarah Edwards https://github.com/mac4n6/apollo


   
ReplyQuote
(@dandaman_24)
Estimable Member
Joined: 11 years ago
Posts: 172
 

In order to use Apollo, you need a FS which you can only get from a jailbroken device or from a GK / ufed premium dump


   
ReplyQuote
(@deefir)
Eminent Member
Joined: 6 years ago
Posts: 49
 

In order to use Apollo, you need a FS which you can only get from a jailbroken device or from a GK / ufed premium dump

Not quite. APOLLO requires artefacts included in an encrypted iOS backup - ie Health database etc. It definitely doesn't have to be jailbroken to extract the required databases.


   
ReplyQuote
(@kev21903)
Active Member
Joined: 6 years ago
Posts: 12
Topic starter  

Once the device is jail broken what the best way to look at the root?


   
ReplyQuote
marky.mark
(@marky-mark)
Eminent Member
Joined: 7 years ago
Posts: 22
 

Hi,

If you want you can connect yourself to the phone with a gui client like putty or just bare SSH to connect to the terminal.

If you want to take the forensic path, you make an aquisition of the device and work with that.

M.


   
ReplyQuote
(@kev21903)
Active Member
Joined: 6 years ago
Posts: 12
Topic starter  

So the phone is jailbroken iOS 12.2

What is the next step to get a physical image?


   
ReplyQuote
(@deefir)
Eminent Member
Joined: 6 years ago
Posts: 49
 

You at least have to try and do some of the work yourself. You've literally been provided with all of the answers.


   
ReplyQuote
Page 1 / 2
Share: