File tree 1 file changed +82
-0
lines changed 1 file changed +82
-0
lines changed Original file line number Diff line number Diff line change
1
+ # iOS Forensics
2
+
3
+ - Let's get it rolling!
4
+
5
+ no answer needed
6
+
7
+ - What would look more suspicious? an empty hard drive or a full hard drive?
8
+
9
+ - `an empty hard drive`
10
+
11
+ - What is the definition for an abstract view of a hard drive?
12
+
13
+ - `image`
14
+
15
+ - Read me!
16
+
17
+ no answer needed
18
+
19
+ - Read the above!
20
+
21
+ no answer needed
22
+
23
+ - Read the above!
24
+
25
+ no answer needed
26
+
27
+ - What is the name of a forensics tool that couldn't be used in a court of law, because data could be written to the device being analysed?
28
+
29
+ - `iFunBox`
30
+
31
+ - You've found an iPhone with no passcode lock, what acquisition method would you use?
32
+
33
+ - `direct acquisition`
34
+
35
+ - What is the name of the certificate that gets stored on a computer when it becomes trusted?
36
+
37
+ - `trust certificate`
38
+
39
+ - Read me!
40
+
41
+ no answer needed
42
+
43
+ - Start browsing!
44
+
45
+ no answer needed
46
+
47
+ - Who was the recepient of the SMS message sent on 23rd of August 2020?
48
+
49
+ - `Lewis Randall`
50
+
51
+ - What did the SMS message say?
52
+
53
+ - `Did you get the goods?`
54
+
55
+ - Looking at the address book, what is the first name of the other person in the contacts?
56
+
57
+ - `Jenny`
58
+
59
+ - Following on from Question #3 , what is their listed "Organization"
60
+
61
+ - `Transportation`
62
+
63
+ - Investigate their browsing history, what is the address of the website that they have bookmarked?
64
+
65
+ - `http://blog.cmnatic.co.uk`
66
+
67
+ - The suspected received an email, what is the ` remote_id ` of the sender?
68
+
69
+ - `51.32.56.12`
70
+
71
+ - What is the name of the company on one of the images stored on the suspects phone?
72
+
73
+ - `TryHackMe`
74
+
75
+ - What is the value of the cookie that was left behind?
76
+
77
+ - `THM{COOKIES!!!}`
78
+
79
+ - Data acquired!
80
+
81
+ no answer needed
82
+
You can’t perform that action at this time.
0 commit comments