Jailbroken

Jailbroken is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: DB Browser for SQLite, Autopsy, iLEAPP, mac_apt, Credential Access.

Learning Objectives

Analyze a jailbroken iOS device's system files, SQLite databases, and application data using forensic tools to reconstruct user activity and identify installed applications.

Categories: Endpoint Forensics.

MITRE ATT&CK Tactics: Credential Access.

Tools: iLEAPP, Autopsy, mac_apt, DB Browser for SQLite.

Difficulty: medium.