ios-image-triage

Triage iOS acquisitions by extracting device metadata, apps, and IoC matches.

11|1|Updated May 4, 2026
One-click install
npx skills add https://github.com/dreadnode/capabilities --skill ios-image-triage
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ios-image-triage
Source: https://github.com/dreadnode/capabilities/tree/main/capabilities/ios-forensics/skills/ios-image-triage
Command: npx skills add https://github.com/dreadnode/capabilities --skill ios-image-triage

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill solves the problem of time-consuming, ad-hoc review of unknown iOS backups or full-filesystem extractions, giving incident responders a standardized, structured process to quickly understand device contents and assess compromise risk without deep forensic expertise.

Core Features & Use Cases

  • Standardized Triage Workflow: Step-by-step guidance to extract device metadata, installed apps, configuration profiles, TCC grants, data usage, and STIX IoC matches from any iOS acquisition.
  • High-Risk Indicator Prioritization: Flags top compromise vectors including rogue configuration profiles, suspicious permission grants, and anomalous shutdown log entries common in iOS spyware attacks.
  • Use Case: An incident responder handed an iOS device from a suspected targeted attack can use this Skill to complete initial scoping in minutes, identify obvious persistence mechanisms, and decide if a full deep-dive forensic analysis is required.

Quick Start

Use the ios-image-triage skill to run a complete first-pass triage on the provided iOS backup or full-filesystem extraction to identify device details, installed applications, and potential compromise indicators.

Frequently Asked Questions about ios-image-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform initial triage on an iOS backup to check for compromise?

iOS acquisition triage involves running a structured first-pass analysis on backups or full-filesystem extractions to extract device metadata, installed apps, configuration profiles, TCC grants, data usage, and STIX IoC matches to quickly identify potential compromise indicators.

What are the key indicators of compromise to look for in iOS forensics?

Key iOS compromise indicators include rogue configuration profiles, suspicious TCC permission grants, anomalous shutdown log entries, and STIX IoC matches. This Skill prioritizes these high-risk vectors common in iOS spyware attacks during the initial scoping process.

Can I use MVT to analyze configuration profiles and TCC grants from an iOS extraction?

Yes, this Skill integrates with Mobile Verification Toolkit (MVT) commands to extract and analyze configuration profiles, TCC grants, data usage records, and shutdown log entries from iOS backups and full-filesystem extractions for comprehensive initial assessment.

Does this iOS triage process work with both iTunes backups and full-filesystem extractions?

Yes, the iOS triage process applies to both iTunes/Finder backups and full-filesystem extractions. It establishes baseline device context and assesses post-compromise posture across different acquisition types for incident response workflows.

What is the best way to quickly scope an unfamiliar iOS device during incident response?

The best way to scope an unfamiliar iOS device is to use a standardized triage workflow that extracts device details, installed applications, and potential compromise indicators in minutes, allowing you to decide if a full deep-dive forensic analysis is required.

Do I need deep forensic expertise to assess iOS device compromise risk?

No deep forensic expertise is needed. This Skill provides a structured process to quickly understand device contents and assess compromise risk from iOS backups or full-filesystem extractions without requiring specialized forensic knowledge.