iLEAPP CLI abrignoni
winget install --id=abrignoni.iLEAPP-cli -e iLEAPP CLI is a command-line tool designed to parse iOS logs, events, and plist files, providing detailed forensic analysis of device data. It supports iOS/iPadOS versions 11 through 17 and can process compressed .tar/.zip files, decompressed directories, or iTunes/Finder backups.
Key Features:
- Parses Mobile Installation Logs, iOS 12+ notifications, build info (iOS version, etc.), wireless cellular service details, screen icons by grid order, application state data for app bundle ID correlation, and user/device connection history.
- Supports parsing directly from compressed files or decompressed directories, including iTunes/Finder backups.
- Available in both CLI and GUI versions for flexible workflow preferences.
- Extensible with artifact plugins that can be added to enhance functionality.
Audience & Benefit: Ideal for forensic investigators, incident responders, and researchers who need to extract detailed information from iOS devices. iLEAPP CLI provides a powerful toolset for analyzing device data without requiring jailbreaking, enabling efficient extraction of critical forensic evidence in both criminal and civil investigations.
