What problem does it solve?
This Skill solves the problem of time-consuming, ad-hoc review of unknown iOS backups or full-filesystem extractions, giving incident responders a standardized, structured process to quickly understand device contents and assess compromise risk without deep forensic expertise.
Core Features & Use Cases
- Standardized Triage Workflow: Step-by-step guidance to extract device metadata, installed apps, configuration profiles, TCC grants, data usage, and STIX IoC matches from any iOS acquisition.
- High-Risk Indicator Prioritization: Flags top compromise vectors including rogue configuration profiles, suspicious permission grants, and anomalous shutdown log entries common in iOS spyware attacks.
- Use Case: An incident responder handed an iOS device from a suspected targeted attack can use this Skill to complete initial scoping in minutes, identify obvious persistence mechanisms, and decide if a full deep-dive forensic analysis is required.
Quick Start
Use the ios-image-triage skill to run a complete first-pass triage on the provided iOS backup or full-filesystem extraction to identify device details, installed applications, and potential compromise indicators.