Skip to content

Commit 4573541

Browse files
committed
Update documentation files
1 parent 811abf1 commit 4573541

File tree

2 files changed

+8
-7
lines changed

2 files changed

+8
-7
lines changed

admin/docs/module_info.md

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -9,11 +9,11 @@ The data below is generated by the [@module_info.py](https://github.com/abrignon
99

1010
Total number of modules: 271
1111
Number of v1 artifacts: 88
12-
Number of v2 artifacts: 295
13-
Number of modules with 'lava output': 258
14-
Number of modules using 'artifact_icon': 169
15-
Number of modules using 'version': 238
16-
Number of modules using 'last_update_date': 70
12+
Number of v2 artifacts: 296
13+
Number of modules with 'lava output': 259
14+
Number of modules using 'artifact_icon': 171
15+
Number of modules using 'version': 237
16+
Number of modules using 'last_update_date': 72
1717
Number of modules with errors or no recognized artifacts: 3
1818

1919
## V2 Artifacts Table
@@ -129,6 +129,7 @@ Number of modules with errors or no recognized artifacts: 3
129129
| [airdropId.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/airdropId.py) | airdropId | Airdrop ID | none | settings | | 2025-01-28 | Extract Airdrop ID | ``*/mobile/Library/Preferences/com.apple.sharingd.plist`` |
130130
| [allTrails.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/allTrails.py) | allTrailsTrailDetails | AllTrails - Trail Details | html, tsv, lava | map | | 2024-12-17 | Extract trail details from AllTrails App | ``*/Documents/AllTrails.sqlite*`` |
131131
| [allTrails.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/allTrails.py) | allTrailsUserInfo | AllTrails - User Info | all | user | | 2024-12-17 | Extract user info from AllTrails App | ``*/Documents/AllTrails.sqlite*`` |
132+
| [appConduit.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/appConduit.py) | appConduit | App Conduit | standard | activity | | 2025-04-05 | The AppConduit log file stores information about interactions between iPhone and other iOS devices, i.e. Apple Watch | ``*/mobile/Library/Logs/AppConduit/AppConduit.log.*`` |
132133
| [appGrouplisting.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/appGrouplisting.py) | appGrouplisting | Bundle ID by AppGroup & PluginKit IDs | html, tsv, lava | package | | 2024-12-20 | List can included once installed but not present apps. Each file is named .com.apple.mobile_container_manager.metadata.plist | ``*/Containers/Shared/AppGroup/*/.com.apple.mobile_container_manager.metadata.plist``, ``*/Containers/Data/PluginKitPlugin/*/.com.apple.mobile_container_manager.metadata.plist`` |
133134
| [appItunesmeta.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/appItunesmeta.py) | get_appItunesmeta | Apps - Itunes Metadata | standard | | 0.2 | | iTunes & Bundle ID Metadata contents for apps | ``*/iTunesMetadata.plist``, ``**/BundleMetadata.plist`` |
134135
| [appleAlarms.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/appleAlarms.py) | alarms | Alarms | standard | clock | | 2024-12-22 | Extraction of alarms set | ``*/mobile/Library/Preferences/com.apple.mobiletimerd.plist`` |
@@ -287,7 +288,7 @@ Number of modules with errors or no recognized artifacts: 3
287288
| [subscriberInfo.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/subscriberInfo.py) | subscriberInfo | Subscriber Info | standard | settings | 0.1 | | Information about inserted SIM Cards | ``*/wireless/Library/Databases/CellularUsage.db*`` |
288289
| [sysShutdown.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/sysShutdown.py) | get_sysShutdown | Sysdiagnose - Shutdown Log | none | | 0.1 | | Parses the shutdown.log file from Sysdiagnose logs, based off work by Kaspersky Lab https://github.com/KasperskyLab/iShutdown | ``*/shutdown.log`` |
289290
| [systemVersionPlist.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/systemVersionPlist.py) | systemVersionPlist | System Version plist | standard, tsv, none | | 5.0 | | Parses basic data from */System/Library/CoreServices/SystemVersion.plist which is a plist in GK Logical Plus extractions that will contain the iOS ver | ``*/System/Library/CoreServices/SystemVersion.plist`` |
290-
| [tcc.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/tcc.py) | tcc | Application Permissions | standard | | 0.7.2 | | Extract application permissions from TCC.db database | ``*/mobile/Library/TCC/TCC.db*`` |
291+
| [tcc.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/tcc.py) | tcc | Application Permissions | standard | key | | 2025-04-07 | Extract application permissions from TCC.db database | ``*/mobile/Library/TCC/TCC.db*`` |
291292
| [teams.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/teams.py) | teamsMessages | Teams Messages | standard | | 1.0 | | Microsoft Teams messages and shared media | ``*/mobile/Containers/Shared/AppGroup/*/SkypeSpacesDogfood/*/Skype*.sqlite*``, ``*/mobile/Containers/Shared/AppGroup/*/SkypeSpacesDogfood/Downloads/*/Images/*`` |
292293
| [teams.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/teams.py) | teamsContacts | Teams Contacts | standard | | 1.0 | | Microsoft Teams contact list | ``*/mobile/Containers/Shared/AppGroup/*/SkypeSpacesDogfood/*/Skype*.sqlite*`` |
293294
| [teams.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/teams.py) | teamsUser | Teams User Information | standard | | 1.0 | | Microsoft Teams user profile and sync data | ``*/mobile/Containers/Shared/AppGroup/*/SkypeSpacesDogfood/*/Skype*.sqlite*`` |

admin/docs/modules_parsing_sqlite_db.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,7 @@ This document outlines iLEAPP modules parsing SQLite databases using the new `ge
5656
| sms |
5757
| splitwise |
5858
| subscriberInfo |
59+
| tcc |
5960
| tileAppDisc |
6061
| tileAppNetDb |
6162
| twint |
@@ -143,7 +144,6 @@ This document outlines iLEAPP modules parsing SQLite databases using the new `ge
143144
| serialNumber |
144145
| slack |
145146
| syncDev |
146-
| tcc |
147147
| teams |
148148
| telegramMesssages |
149149
| teleguard |

0 commit comments

Comments
 (0)