Thesis Friday #9: AUL connecting a USB cable

This week I focused on a subtle but forensically valuable artefact: detecting when a device was physically connected to power. Or physically connected to a USB cable without charging. USB connections are often overlooked during triage, but can be critical…

Thesis Friday #8: AUL – Physical Buttons Volume

As part of my ongoing research into Apple Unified Logs (AUL), this week’s focus is on physical interactions specifically, the use of the volume buttons on an iOS device. While seemingly simple, these artifacts can provide clear and timestamped evidence of user…

Thesis Friday #7: Apple Unified Log or Sysdiagnose?

AUL or Sysdiagnose

Sysdiagnose or CLI Logarchive? When conducting forensic investigations on Apple devices, Unified Logs provide a treasure trove of information about user interactions, system events, and application behavior. However, the way these logs are extracted greatly influences the amount and quality…

Thesis Friday #3: AUL – Phone Application

It’s Friday again. I’m working through the final to-do’s for my thesis. The end is near, which means long days, plenty of words on paper, and just as many being scrapped again. So, let’s dive into today’s topic: the standard…