Huge #ALEAPP update for Garmin.
π Interactive maps on the HTML report!
π Eye catching graphs!
π
To and from date selectors!
π Full Android Notifications kept in Garmin
π€ Already thinking how to leverage it on all the LEAPPs!
π Thanks to https://github.com/fabian-nunes,
https://github.com/fabian-nunes for these incredible artifacts and functions. Amazing doesn't begint to describe it.
π Get ALEAPP here:
https://buff.ly/3Px6B1L
π Thanks to @stark4n6 for doing important entomological coding work in #ALEAPP.
π For squashing bugs and keeping #DFIR artifacts current.
π Get ALEAPP for parsing #Android extractions here:
https://github.com/abrignoni/ALEAPP
#DFIR thoughts π
Data without context serves little to no purpose.
Had a case recently where images of interest were found in the #Android Chrome cache. These images were carved, by the paid #DigitalForensics tool, out of the cache files and that was it. When I looked at the source file I could see a URL as well as other data points. The URL was key since it established receipt of the files which fulfilled certain statutory requirements.
As examiners and tool makers we need provide the necessary context that brings the past to the present. Just parsing things out in categories is not enough. Information only has value when it is aggregated into knowledge.
Android Chrome cache parsing has been added to #ALEAPP.
Thanks to @joshua_hickman1 for his public data sets and testing in Windows.
Get ALEAPP here:
π https://github.com/abrignoni/ALEAPP
#dfir #android #digitalforensics #ALEAPP
RT @Get_ArcPoint@twitter.com
Great news for forensic professionals on the go! We're excited to announce that #ATRIO now has #mobilesupport and integrated #ALEAPP, allowing you to access and use our powerful digital forensics tools anywhere. Upgrade your #digitalforensic toolkit today!
π¦π: https://twitter.com/Get_ArcPoint/status/1617976912235692032
#atrio #mobilesupport #ALEAPP #digitalforensic
Super excited that our #OpenSource tool for parsing artifacts from #Android devices is now part of Atrio.
Tools from the #MobileForensics #DFIR community to all.
Check out #ALEAPP for all your Android #DigitalForensics needs here:
π https://github.com/abrignoni/ALEAPP
#opensource #android #mobileforensics #dfir #ALEAPP #digitalforensics #floss #foss #eDiscovery #blueteam
#ALEAPP has been updated to support the Garmin Connect app:
π Cache DB activities
βοΈ Device details
π GCM cache activities
π Notifications
π΄ Sleep details
βοΈ Weather info
π Download here: https://github.com/abrignoni/ALEAPP/
#Stark4N6: Gabbing about Garmin Connect for Android https://www.stark4n6.com/2023/01/gabbing-about-garmin-connect-for-android.html #DFIR #ALEAPP #FOSS
The Garmin app for Android collects all sorts of nuggets, parsers coming soon #ALEAPP
New #ALEAPP and #RLEAPP binaries out now #DFIR #FOSS #MobileForensics
π ALEAPP >>> https://github.com/abrignoni/ALEAPP/releases/tag/v3.1.5
π RLEAPP >>> https://github.com/abrignoni/RLEAPP/releases/tag/v1.0.31
#ALEAPP #rleapp #dfir #foss #mobileforensics
#FOSS tools aren't perfect and neither are we, there's always room for improvements and tweaks. Just pushed 17 file changes to #ALEAPP to fix some minor timelining and parser πβs
πβ Download the latest version here: https://github.com/abrignoni/ALEAPP
#foss #ALEAPP #dfir #mobileforensics
New #ALEAPP artifact parsers for #Android: Native Downloads and Calendar
β¬οΈDownloaded file details, names, sizes
ποΈAttached calendar details
π
List of calendar events
Get ALEAPP here:
π http://github.com/abrignoni/ALEAPP
#ALEAPP #android #digitalforensics #mobileforensics #floss #foss #dfir
New #DFIR parser for #Android in #ALEAPP for the Gmail app:
π§β Email content
πβ Attachments
π¬β Email data
Get it here:
https://github.com/abrignoni/aleapp
#DigitalForensics #FLOSS #FOSS #Python #Coding #MobileForensics
#dfir #android #ALEAPP #digitalforensics #floss #foss #python #coding #mobileforensics
New #ALEAPP artifact parser for #Android: Google Maps Search History
π Coordinates to and from the location
π Google maps URL search link
πΊ Location address
Get ALEAPP here:
π github.com/abrignoni/ALEAPP
#ALEAPP #android #digitalforensics #mobileforensics #floss #foss #dfir
A parser for this is now in the latest #ALEAPP update, go grab it! https://github.com/abrignoni/ALEAPP
Shout out to @joshua_hickman1 for the research and testing! https://infosec.exchange/@joshua_hickman1/109491784619937398
Super happy to chat with Amy at the 2022 Florida ICAC Conference in Orlando, FL.
They are adding #iLEAAP & #ALEAPP support to their Atrio #DFIR product super soon! I'm stoked to see our community project being embraced by tool vendors and makers. Thank you. π
π https://www.arcpointforensics.com/news/getting-started-with-aleapp
#Stark4N6: Thawing the Ice Age Pt. 2 - Tusky on Android #ALEAPP #DFIR #mobileforensics https://www.stark4n6.com/2022/12/thawing-ice-age-pt-2-tusky-on-android.html
#Stark4N6 #ALEAPP #dfir #mobileforensics
New parser in #ALEAPP: Mastodon app for Android
πThanks to @stark4n6 for the awesome work.
πGet notifications, searches, user info, instance details, & more.
πCheck the blogpost here:
https://www.stark4n6.com/2022/12/thawing-ice-age-mastodon-on-android.html
πGet ALEAPP here:
https://github.com/abrignoni/ALEAPP
π #DFIR #DigitalForensics #FOSS #Python
#ALEAPP #dfir #digitalforensics #foss #python
#Stark4N6: Thawing the Ice Age - Mastodon on Android #DFIR #mobileforensics #ALEAPP https://www.stark4n6.com/2022/12/thawing-ice-age-mastodon-on-android.html
#Stark4N6 #dfir #mobileforensics #ALEAPP
Look what's here, @abrignoni made me do it #StreamDeck #ALEAPP #iLEAPP #RLEAPP #FOSS #DigitalForeniscs
#streamdeck #ALEAPP #iLEAPP #rleapp #foss #digitalforeniscs