Forensic extraction for WhatsApp, Signal, and Telegram — 8-layer SQLite recovery, anti-forensics detection, court-ready reports.
-
Updated
Jul 16, 2026 - Rust
Forensic extraction for WhatsApp, Signal, and Telegram — 8-layer SQLite recovery, anti-forensics detection, court-ready reports.
Open-source desktop workbench for digital forensic analysis. Inspect ZIP/TAR/7z archives and iTunes/Android backups. Parse and view ABX, SQLite, SEGB, (B)PLIST, REALM, Protobuf, Logs,hex, JSON, XML, and more — all in one GUI.
Useful tools for (not only) digital forensics
Three mobile forensics examinations: iOS full filesystem analysis (Cellebrite), legacy mobile device artifact recovery (Autopsy/FTK), and Android APK static & dynamic analysis (JADX/PCAPdroid).
An open-source forensic parser for Apple Intelligence Report JSON files.
A modern toolchain for booting custom kernels on pre-A7 iOS devices (iPhone 3GS, iPod touch 3, iPad 1). Modern-clang cross-compile pipeline for iOS 5 armv7 binaries, an offline kernelcache patcher, and a forgotten-PIN data recovery walkthrough.
Lightweight forensic support tool for processing extracted iOS WhatsApp ChatStorage.sqlite databases into CSV and HTML timeline outputs.
Digital forensic investigation case study involving cross-device analysis (iOS & Windows), email artifact examination, metadata timeline reconstruction and incident threat assessment. All identifying data anonymized.
Restructure the iOS backup directory from GUID directories to human-readable
Add a description, image, and links to the ios-forensics topic page so that developers can more easily learn about it.
To associate your repository with the ios-forensics topic, visit your repo's landing page and select "manage topics."