#segb — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #segb, aggregated by home.social.
-
🚨 The SEGB file format is a key data recovery source on devices that run iOS and macOS. SEGB version 2 comes in the most recent operating system implementations.
🔬 Understand the file format: https://cellebrite.com/en/understanding-and-decoding-the-newest-ios-segb-format/
📄 Parse the file format using Python: https://github.com/cclgroupltd/ccl-segb
#DigitalForensics #MobileForensics #iOSForensics #SEGB #DFIR
-
🚨 The SEGB file format is a key data recovery source on devices that run iOS and macOS. SEGB version 2 comes in the most recent operating system implementations.
🔬 Understand the file format: https://cellebrite.com/en/understanding-and-decoding-the-newest-ios-segb-format/
📄 Parse the file format using Python: https://github.com/cclgroupltd/ccl-segb
#DigitalForensics #MobileForensics #iOSForensics #SEGB #DFIR
-
🐍 New Python parsers for Apple SEGB versions 1 & 2 file formats by Alex Caithness and CCL Solutions Group. Will be updating #iLEAPP soon to support both formats.
📚 These data structures are found in iOS and macOS operating systems. SEGB v2 are found on the latest versions of these operating systems.
🔎 Important note: If you expect Protobuf as the data payload (it usually is) make sure to skip the first 8 bytes before decoding a SEGB v2 file. See line 17 in the attached image.
ℹ Notice how the script provides the offset, metadata offset, and timestamp along with the data.
📎 Get the code here: https://github.com/cclgroupltd/ccl-segb
📖 Thanks to Cellebrite for the file format research found here: https://cellebrite.com/en/understanding-and-decoding-the-newest-ios-segb-format/
#DigitalForensics #MobileForensics #iOSForensics #SEGB #DFIR
-
🐍 New Python parsers for Apple SEGB versions 1 & 2 file formats by Alex Caithness and CCL Solutions Group. Will be updating #iLEAPP soon to support both formats.
📚 These data structures are found in iOS and macOS operating systems. SEGB v2 are found on the latest versions of these operating systems.
🔎 Important note: If you expect Protobuf as the data payload (it usually is) make sure to skip the first 8 bytes before decoding a SEGB v2 file. See line 17 in the attached image.
ℹ Notice how the script provides the offset, metadata offset, and timestamp along with the data.
📎 Get the code here: https://github.com/cclgroupltd/ccl-segb
📖 Thanks to Cellebrite for the file format research found here: https://cellebrite.com/en/understanding-and-decoding-the-newest-ios-segb-format/
#DigitalForensics #MobileForensics #iOSForensics #SEGB #DFIR
-
New design alert, thanks to Ricky Johnson on the assist #SEGB #DFIR https://www.teepublic.com/t-shirt/44654002-segb-this-just-means-more-data
-
New design alert, thanks to Ricky Johnson on the assist #SEGB #DFIR https://www.teepublic.com/t-shirt/44654002-segb-this-just-means-more-data