Skip to content

Commit

Permalink
Update documentation files
Browse files Browse the repository at this point in the history
  • Loading branch information
actions-user committed Nov 7, 2024
1 parent 88f30ee commit 6829c12
Showing 1 changed file with 6 additions and 6 deletions.
12 changes: 6 additions & 6 deletions admin/docs/module_info.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ The data below is generated by the [@module_info.py](https://github.com/abrignon
Total number of modules: 268
Number of v1 artifacts: 113
Number of v2 artifacts: 189
Number of modules with 'lava output': 76
Number of modules with 'lava output': 77
Number of modules with errors or no recognized artifacts: 3

## V2 Artifacts Table
Expand Down Expand Up @@ -101,9 +101,9 @@ Number of modules with errors or no recognized artifacts: 3
| [accountConfig.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/accountConfig.py) | accountConfig | Account Configuration | html, tsv, lava | Extracts account configuration information | ``*/com.apple.accounts.exists.plist`` |
| [accountData.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/accountData.py) | accountData | Account Data | standard | Extract information about configured user accounts | ``*/mobile/Library/Accounts/Accounts3.sqlite*`` |
| [addressBook.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/addressBook.py) | addressbook | Address Book | | Extract information from the native contacts application | ``*/mobile/Library/AddressBook/AddressBook*.sqlitedb*`` |
| [advertisingID.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/advertisingID.py) | get_adId | Advertising Identifier | lava | Extract Apple advertising identifier | ``*/containers/Shared/SystemGroup/*/Library/Caches/com.apple.lsdidentifiers.plist`` |
| [airdropId.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/airdropId.py) | get_airdropId | Airdrop ID | lava | Extract Airdrop ID | ``*/mobile/Library/Preferences/com.apple.sharingd.plist`` |
| [alarms.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/alarms.py) | get_alarms | Alarms | standard | Extraction of alarms set | ``*/mobile/Library/Preferences/com.apple.mobiletimerd.plist`` |
| [advertisingID.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/advertisingID.py) | advertisingID | Advertising Identifier | none | Extract Apple advertising identifier | ``*/containers/Shared/SystemGroup/*/Library/Caches/com.apple.lsdidentifiers.plist`` |
| [airdropId.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/airdropId.py) | airdropId | Airdrop ID | none | Extract Airdrop ID | ``*/mobile/Library/Preferences/com.apple.sharingd.plist`` |
| [alarms.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/alarms.py) | alarms | Alarms | standard | Extraction of alarms set | ``*/mobile/Library/Preferences/com.apple.mobiletimerd.plist`` |
| [appGrouplisting.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/appGrouplisting.py) | get_appGrouplisting | Bundle ID by AppGroup & PluginKit IDs | html, tsv, lava | List can included once installed but not present apps. Each file is named .com.apple.mobile_container_manager.metadata.plist | ``*/Containers/Shared/AppGroup/*/.com.apple.mobile_container_manager.metadata.plist``, ``**/PluginKitPlugin/*.metadata.plist`` |
| [appItunesmeta.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/appItunesmeta.py) | get_appItunesmeta | Apps - Itunes Metadata | standard | iTunes & Bundle ID Metadata contents for apps | ``*/iTunesMetadata.plist``, ``**/BundleMetadata.plist`` |
| [appleLocationd.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/appleLocationd.py) | get_applelocationd | Location Services | html, tsv, lava | Extracts location services settings | ``*/mobile/Library/Preferences/com.apple.locationd.plist`` |
Expand All @@ -117,7 +117,7 @@ Number of modules with errors or no recognized artifacts: 3
| [applicationstate.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/applicationstate.py) | applicationstate | Application State | html, tsv, lava | Extract information about bundle container path and data path for Applications | ``*/mobile/Library/FrontBoard/applicationState.db*`` |
| [ashHistory.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/ashHistory.py) | AshHistory | Alpine Linux Bash History | all | Extracts command history from Alpine Linux bash | ``*/.ash_history`` |
| [atxDatastore.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/atxDatastore.py) | atxDatastore | iOS ATXDatastore | all | Parses ATXDataStore and matches actions with Frequent locations, when available. | ``*DuetExpertCenter/_ATXDataStore.db*``, ``*routined/Local.sqlite*`` |
| [backupSettings.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/backupSettings.py) | get_backupSettings | Backup Settings | html, tsv, lava | Extracts Backup settings | ``*/mobile/Library/Preferences/com.apple.mobile.ldbackup.plist`` |
| [backupSettings.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/backupSettings.py) | backupSettings | Backup Settings | html, tsv, lava | Extracts Backup settings | ``*/mobile/Library/Preferences/com.apple.mobile.ldbackup.plist`` |
| [biomeAirpMode.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/biomeAirpMode.py) | get_biomeAirpMode | Biome DKEvent Airplane Mode | standard | Parses airplane mode entries from biomes | ``*/Biome/streams/restricted/_DKEvent.System.AirplaneMode/local/*`` |
| [biomeAppinstall.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/biomeAppinstall.py) | get_biomeAppinstall | Biome App Install | standard | Parses airplane mode entries from biomes | ``*/Biome/streams/restricted/_DKEvent.App.Install/local/*``, ``*/Biome/streams/restricted/App.Install/local/*`` |
| [biomeBacklight.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/biomeBacklight.py) | get_biomeBacklight | Biome Backlight | standard | Parses backlight entries from biomes | ``*/Biome/streams/public/Backlight/local/*`` |
Expand Down Expand Up @@ -173,7 +173,7 @@ Number of modules with errors or no recognized artifacts: 3
| [keyboard.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/keyboard.py) | keyboardAppUsage | Keyboard Application Usage | html, tsv, lava, timeline | Extracts keyboard application usage data | ``*/mobile/Library/Keyboard/app_usage_database.plist`` |
| [keyboard.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/keyboard.py) | keyboardUsageStats | Keyboard Usage Stats | html, tsv, lava, timeline | Extracts keyboard usage statistics | ``*/mobile/Library/Keyboard/user_model_database.sqlite*`` |
| [knowledgeC.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/knowledgeC.py) | knowledgeC | knowledgeC | | Extract Pattern of Life from knowledgeC database | ``*/mobile/Library/CoreDuet/Knowledge/knowledgeC.db*`` |
| [lastBuild.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/lastBuild.py) | lastbuild | iOS Information | | Extract iOS information from the LastBuildInfo.plist file | ``*LastBuildInfo.plist`` |
| [lastBuild.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/lastBuild.py) | lastBuild | iOS Information | html, tsv, lava | Extract iOS information from the LastBuildInfo.plist file | ``*LastBuildInfo.plist`` |
| [life360.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/life360.py) | Life360 | Life360 | | Parses Life360 app logs, chat messages, and more | ``*/com.life360.safetymap *.log``, ``*/Library/Application Support/Messaging.sqlite*`` |
| [line.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/line.py) | line | Line Artifacts | | Get Line | ``**/Line.sqlite*`` |
| [mailprotect.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/mailprotect.py) | get_mailprotect | Apple Email | none | Apple Email. | ``*/mobile/Library/Mail/* Index*`` |
Expand Down

0 comments on commit 6829c12

Please sign in to comment.