Skip to content

Commit 6820a13

Browse files
authored
Add files via upload
1 parent a98eaa9 commit 6820a13

File tree

1 file changed

+82
-0
lines changed

1 file changed

+82
-0
lines changed

iOS-Forensics/README.md

Lines changed: 82 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,82 @@
1+
# iOS Forensics
2+
3+
- Let's get it rolling!
4+
5+
no answer needed
6+
7+
- What would look more suspicious? an empty hard drive or a full hard drive?
8+
9+
- `an empty hard drive`
10+
11+
- What is the definition for an abstract view of a hard drive?
12+
13+
- `image`
14+
15+
- Read me!
16+
17+
no answer needed
18+
19+
- Read the above!
20+
21+
no answer needed
22+
23+
- Read the above!
24+
25+
no answer needed
26+
27+
- What is the name of a forensics tool that couldn't be used in a court of law, because data could be written to the device being analysed?
28+
29+
- `iFunBox`
30+
31+
- You've found an iPhone with no passcode lock, what acquisition method would you use?
32+
33+
- `direct acquisition`
34+
35+
- What is the name of the certificate that gets stored on a computer when it becomes trusted?
36+
37+
- `trust certificate`
38+
39+
- Read me!
40+
41+
no answer needed
42+
43+
- Start browsing!
44+
45+
no answer needed
46+
47+
- Who was the recepient of the SMS message sent on 23rd of August 2020?
48+
49+
- `Lewis Randall`
50+
51+
- What did the SMS message say?
52+
53+
- `Did you get the goods?`
54+
55+
- Looking at the address book, what is the first name of the other person in the contacts?
56+
57+
- `Jenny`
58+
59+
- Following on from Question #3, what is their listed "Organization"
60+
61+
- `Transportation`
62+
63+
- Investigate their browsing history, what is the address of the website that they have bookmarked?
64+
65+
- `http://blog.cmnatic.co.uk`
66+
67+
- The suspected received an email, what is the `remote_id` of the sender?
68+
69+
- `51.32.56.12`
70+
71+
- What is the name of the company on one of the images stored on the suspects phone?
72+
73+
- `TryHackMe`
74+
75+
- What is the value of the cookie that was left behind?
76+
77+
- `THM{COOKIES!!!}`
78+
79+
- Data acquired!
80+
81+
no answer needed
82+

0 commit comments

Comments
 (0)