-
Notifications
You must be signed in to change notification settings - Fork 152
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #876 from JamesHabben/lava-output
Lava output
- Loading branch information
Showing
14 changed files
with
498 additions
and
115 deletions.
There are no files selected for viewing
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,80 @@ | ||
{ | ||
"images": [ | ||
{ | ||
"image_name": "josh_ios15_ffs", | ||
"description": "iPhone 8 extraction with sample data for testing", | ||
"local_image_paths": [ | ||
"~/Documents/phone-images/Josh/iOS_15_Public_Image.tar.gz", | ||
"/home/user/images/iphone_001.zip" | ||
], | ||
"file_path_list": "admin/data/filepath-lists/josh-hickman-ios15.csv.zip", | ||
"download_url": "https://example.com/downloads/iphone_11_pro_001.zip", | ||
"author": { | ||
"name": "Josh Hickman" | ||
}, | ||
"image_info": { | ||
"creation_date": "2023-05-20", | ||
"os_version": "iOS 15.3.1", | ||
"device_model": "iPhone 8", | ||
"extraction_method": "Full Filesystem", | ||
"extraction_tool": "Cellebrite" | ||
}, | ||
"file_info": { | ||
"file_count": 474300, | ||
"md5_hash": "b1ec40d5cd835621326b821d6fa12ff5" | ||
}, | ||
"notes": "" | ||
}, | ||
{ | ||
"image_name": "mvs_ios_2023", | ||
"description": "Magnet Virtual Summit 2023 iOS image for forensic testing and training", | ||
"local_image_paths": [ | ||
"~/Documents/phone-images/magnet/00008101-0010541A1130001E_files_full-001.zip", | ||
"/home/user/images/magnet_mvs_2023_ios.zip" | ||
], | ||
"file_path_list": "admin/data/filepath-lists/magnet-mvs-2023-ios.csv.zip", | ||
"download_url": "https://cfreds.nist.gov/all/MagnetForensics/MagnetVirtualSummit2023", | ||
"author": { | ||
"name": "Magnet Forensics", | ||
"organization": "Magnet Forensics" | ||
}, | ||
"image_info": { | ||
"creation_date": "2023-01-01T00:00:00Z", | ||
"os_version": "iOS 14.7.1", | ||
"device_model": "Unknown", | ||
"extraction_method": "Full Filesystem", | ||
"extraction_tool": "Magnet" | ||
}, | ||
"file_info": { | ||
"file_count": 338104, | ||
"md5_hash": "067606649297d7adcf6082e5ed0acbb9" | ||
}, | ||
"notes": "Image from Magnet Virtual Summit 2023. Contains full file system data." | ||
}, | ||
{ | ||
"image_name": "belkasoft_ctf6_ios_device1", | ||
"description": "BelkaSoft CTF 6 iOS Device 1 image for forensic analysis and competition", | ||
"local_image_paths": [ | ||
"~/Documents/phone-images/belkasoft/BelkaCTF_6_CASE240405_D201AP.tar" | ||
], | ||
"file_path_list": "admin/data/filepath-lists/belkasoft-ctf6-ios-device1.csv.zip", | ||
"download_url": "https://cfreds.nist.gov/all/Belkasoft/BelkaCTF6BogusBill", | ||
"author": { | ||
"name": "BelkaSoft", | ||
"organization": "BelkaSoft" | ||
}, | ||
"image_info": { | ||
"creation_date": "2023-01-01T00:00:00Z", | ||
"os_version": "iOS", | ||
"device_model": "Unknown", | ||
"extraction_method": "Unknown", | ||
"extraction_tool": "Unknown" | ||
}, | ||
"file_info": { | ||
"file_count": 65000, | ||
"md5_hash": "0da3a6df28802cd19d41ef1fde884e7c" | ||
}, | ||
"notes": "Image extracted from zip for BelkaSoft CTF 6, iOS Device 1. " | ||
} | ||
] | ||
} |
Binary file added
BIN
+6.25 MB
admin/test/cases/data/testdata.gmail.gmailLabelDetails.josh_ios15_ffs.zip
Binary file not shown.
Binary file added
BIN
+4.78 MB
admin/test/cases/data/testdata.gmail.gmailLabelDetails.mvs_ios_2023.zip
Binary file not shown.
Binary file added
BIN
+856 KB
admin/test/cases/data/testdata.gmail.gmailOfflineSearch.josh_ios15_ffs.zip
Binary file not shown.
Binary file added
BIN
+124 KB
admin/test/cases/data/testdata.gmail.gmailOfflineSearch.mvs_ios_2023.zip
Binary file not shown.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,114 @@ | ||
{ | ||
"josh_ios15_ffs": { | ||
"description": "", | ||
"maker": "", | ||
"make_data": { | ||
"input_data_path": "/Users/jameshabben/Documents/phone-images/Josh/iOS_15_Public_Image.tar.gz", | ||
"os": "macOS-15.0-x86_64-i386-64bit", | ||
"timestamp": "2024-10-15T16:07:56.063452", | ||
"last_commit": { | ||
"hash": "5edc9a916fd57fae3f9be628768aee79236863e4", | ||
"author_name": "James Habben", | ||
"author_email": "james@wmif.net", | ||
"date": "2024-10-15T16:07:28-07:00", | ||
"message": "Update gmail.py" | ||
} | ||
}, | ||
"artifacts": { | ||
"gmailOfflineSearch": { | ||
"search_patterns": [ | ||
"*/mobile/Containers/Data/Application/*/Library/Application Support/data/*/searchsqlitedb*" | ||
], | ||
"file_count": 1, | ||
"expected_output": { | ||
"headers": [], | ||
"data": [] | ||
} | ||
}, | ||
"gmailLabelDetails": { | ||
"search_patterns": [ | ||
"*/mobile/Containers/Data/Application/*/Library/Application Support/data/*/sqlitedb*" | ||
], | ||
"file_count": 3, | ||
"expected_output": { | ||
"headers": [], | ||
"data": [] | ||
} | ||
} | ||
}, | ||
"image_name": "josh_ios15_ffs" | ||
}, | ||
"mvs_ios_2023": { | ||
"description": "", | ||
"maker": "", | ||
"make_data": { | ||
"input_data_path": "/Users/jameshabben/Documents/phone-images/magnet/00008101-0010541A1130001E_files_full-001.zip", | ||
"os": "macOS-15.0-x86_64-i386-64bit", | ||
"timestamp": "2024-10-15T16:10:47.231161", | ||
"last_commit": { | ||
"hash": "5edc9a916fd57fae3f9be628768aee79236863e4", | ||
"author_name": "James Habben", | ||
"author_email": "james@wmif.net", | ||
"date": "2024-10-15T16:07:28-07:00", | ||
"message": "Update gmail.py" | ||
} | ||
}, | ||
"artifacts": { | ||
"gmailOfflineSearch": { | ||
"search_patterns": [ | ||
"*/mobile/Containers/Data/Application/*/Library/Application Support/data/*/searchsqlitedb*" | ||
], | ||
"file_count": 1, | ||
"expected_output": { | ||
"headers": [], | ||
"data": [] | ||
} | ||
}, | ||
"gmailLabelDetails": { | ||
"search_patterns": [ | ||
"*/mobile/Containers/Data/Application/*/Library/Application Support/data/*/sqlitedb*" | ||
], | ||
"file_count": 6, | ||
"expected_output": { | ||
"headers": [], | ||
"data": [] | ||
} | ||
} | ||
}, | ||
"image_name": "mvs_ios_2023" | ||
}, | ||
"belkasoft_ctf6_ios_device1": { | ||
"description": "", | ||
"maker": "", | ||
"make_data": { | ||
"input_data_path": "/Users/jameshabben/Documents/phone-images/belkasoft/BelkaCTF_6_CASE240405_D201AP.tar", | ||
"os": "macOS-15.0-x86_64-i386-64bit", | ||
"timestamp": "2024-10-15T16:10:59.816421", | ||
"last_commit": { | ||
"hash": "5edc9a916fd57fae3f9be628768aee79236863e4", | ||
"author_name": "James Habben", | ||
"author_email": "james@wmif.net", | ||
"date": "2024-10-15T16:07:28-07:00", | ||
"message": "Update gmail.py" | ||
} | ||
}, | ||
"artifacts": { | ||
"gmailOfflineSearch": { | ||
"search_patterns": [ | ||
"*/mobile/Containers/Data/Application/*/Library/Application Support/data/*/searchsqlitedb*" | ||
], | ||
"file_count": 0, | ||
"note": "No responsive files found for this artifact" | ||
}, | ||
"gmailLabelDetails": { | ||
"search_patterns": [ | ||
"*/mobile/Containers/Data/Application/*/Library/Application Support/data/*/sqlitedb*" | ||
], | ||
"file_count": 0, | ||
"note": "No responsive files found for this artifact" | ||
} | ||
}, | ||
"image_name": "belkasoft_ctf6_ios_device1", | ||
"note": "No responsive files found for any artifacts" | ||
} | ||
} |
Oops, something went wrong.