diff --git a/docs/ios/records.md b/docs/ios/records.md index 1e6f113..a5a95ce 100644 --- a/docs/ios/records.md +++ b/docs/ios/records.md @@ -4,6 +4,16 @@ In this page you can find a (reasonably) up-to-date breakdown of the files creat ## Records extracted by `check-fs` or `check-backup` +### `backup_info.json` + +!!! info "Availabiliy" + Backup: :material-check: + Full filesystem dump: :material-close: + +This JSON file is created by mvt-ios' `BackupInfo` module. The module extracts some details about the backup and the device, such as name, phone number, IMEI, product type and version. + +--- + ### `cache_files.json` !!! info "Availability" @@ -50,6 +60,16 @@ If indicators a provided through the command-line, they are checked against the --- +### `configuration_profiles.json` + +!!! info "Availability" + Backup: :material-check: + Full filesystem dump: :material-close: + +This JSON file is created by mvt-ios' `ConfigurationProfiles` module. The module extracts details about iOS configuration profiles that have been installed on the device. These should include both default iOS as well as third-party profiles. + +--- + ### `contacts.json` !!! info "Availability" @@ -150,6 +170,16 @@ If indicators are provided through the command-line, they are checked against th --- +### `profile_events.json` + +!!! info "Availability" + Backup: :material-check: + Full filesystem dump: :material-close: + +This JSON file is created by mvt-ios' `ProfileEvents` module. The module extracts a timeline of configuration profile operations. For example, it should indicate when a new profile was installed from the Settings app, or when one was removed. + +--- + ### `safari_browser_state.json` !!! info "Availability" @@ -242,6 +272,18 @@ If indicators are provided through the command-line, they are checked against th --- +### `webkit_resource_load_statistics.json` + +!!! info "Availability" + Backup: :material-check: + Full filesystem dump: :material-check: + +This JSON file is created by mvt-ios `WebkitResourceLoadStatistics` module. The module extracts records from available WebKit ResourceLoadStatistics *observations.db* SQLite3 databases. These records should indicate domain names contacted by apps, including a timestamp. + +If indicators are provided through the command-line, they are checked against the extracted domain names. Any matches are stored in *webkit_resource_load_statistics_detected.json*. + +--- + ### `webkit_safari_view_service.json` !!! info "Availability"