diff --git a/admin/docs/module_info.md b/admin/docs/module_info.md index 372dff73..4b785fee 100644 --- a/admin/docs/module_info.md +++ b/admin/docs/module_info.md @@ -7,11 +7,11 @@ The data below is generated by the [@module_info.py](https://github.com/abrignon ## Summary -Total number of modules: 263 +Total number of modules: 264 Number of v1 artifacts: 96 -Number of v2 artifacts: 224 -Number of modules with 'lava output': 122 -Number of modules using 'artifact_icon': 17 +Number of v2 artifacts: 232 +Number of modules with 'lava output': 130 +Number of modules using 'artifact_icon': 25 Number of modules with errors or no recognized artifacts: 3 ## V2 Artifacts Table @@ -172,6 +172,14 @@ Number of modules with errors or no recognized artifacts: 3 | [findMyItems.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/findMyItems.py) | findMyItemsLocations | FindMy Items Locations | all | | Extract items locations from Find My | ``*/Caches/com.apple.findmy.fmipcore/Items.data`` | | [findMyItems.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/findMyItems.py) | findMyItemsSafeLocations | FindMy Items Safe Locations | all | | Extract items safe locations from Find My | ``*/Caches/com.apple.findmy.fmipcore/Items.data`` | | [findMyItems.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/findMyItems.py) | findMyItemsCrowdsourcedLocations | FindMy Items Crowdsourced Locations | all | | Extract items crowdsourced locations from Find My | ``*/Caches/com.apple.findmy.fmipcore/Items.data`` | +| [foursquareSwarm.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/foursquareSwarm.py) | foursquare_swarm_account | Foursquare Swarm Account | lava, tsv, timeline | user | Parses and extract Foursquare Swarm Account | ``*/mobile/Containers/Data/Application/*/Library/Caches/foursquare.sqlite*`` | +| [foursquareSwarm.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/foursquareSwarm.py) | foursquare_swarm_contacts | Foursquare Swarm Contacts | lava, tsv | users | Parses and extract Foursquare Swarm Contacts | ``*/mobile/Containers/Data/Application/*/Library/Caches/foursquare.sqlite*`` | +| [foursquareSwarm.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/foursquareSwarm.py) | foursquare_swarm_checkins | Foursquare Swarm Check-ins | lava, tsv, timeline | user-check | Parses and extract Foursquare Swarm Check-ins | ``*/mobile/Containers/Data/Application/*/Library/Caches/foursquare.sqlite*`` | +| [foursquareSwarm.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/foursquareSwarm.py) | foursquare_swarm_tips | Foursquare Swarm Tips | lava, tsv, timeline | info | Parses and extract Foursquare Swarm Tips | ``*/mobile/Containers/Data/Application/*/Library/Caches/foursquare.sqlite*`` | +| [foursquareSwarm.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/foursquareSwarm.py) | foursquare_swarm_stickers | Foursquare Swarm Stickers | lava, tsv | award | Parses and extract Foursquare Swarm Stickers | ``*/mobile/Containers/Data/Application/*/Library/Caches/foursquare.sqlite*`` | +| [foursquareSwarm.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/foursquareSwarm.py) | foursquare_swarm_venues_history | Foursquare Swarm Venues History | lava, tsv, timeline, kml | map-pin | Parses and extract Foursquare Swarm Venues History | ``*/mobile/Containers/Data/Application/*/Library/Caches/foursquare.sqlite*`` | +| [foursquareSwarm.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/foursquareSwarm.py) | foursquare_swarm_venues_photos | Foursquare Swarm Venues Photos | lava, tsv, timeline | camera | Parses and extract Foursquare Swarm Venues Photos | ``*/mobile/Containers/Data/Application/*/Library/Caches/foursquare.sqlite*`` | +| [foursquareSwarm.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/foursquareSwarm.py) | foursquare_swarm_checkins_comments | Foursquare Swarm Check-ins Comments | lava, html, tsv, timeline | message-square | Parses and extract Foursquare Swarm Check-ins Comments | ``*/mobile/Containers/Data/Application/*/Library/Caches/foursquare.sqlite*`` | | [geodMapTiles.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/geodMapTiles.py) | geodMapTiles | GeoD Maptiles | lava, tsv, timeline | | Parses Map Tile Records from Apple geod Cache | ``**/MapTiles.sqlitedb*`` | | [gmail.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/gmail.py) | gmailOfflineSearch | Gmail - Offline Search | html, tsv, lava, timeline | | Parses Gmail offline search content | ``*/mobile/Containers/Data/Application/*/Library/Application Support/data/*/searchsqlitedb*`` | | [gmail.py](https://github.com/abrignoni/iLEAPP/blob/main/scripts/artifacts/gmail.py) | gmailLabelDetails | Gmail - Label Details | html, tsv, lava | | Parses Gmail label details | ``*/mobile/Containers/Data/Application/*/Library/Application Support/data/*/sqlitedb*`` | diff --git a/admin/docs/modules_parsing_sqlite_db.md b/admin/docs/modules_parsing_sqlite_db.md index 4d58c44f..61ea317d 100644 --- a/admin/docs/modules_parsing_sqlite_db.md +++ b/admin/docs/modules_parsing_sqlite_db.md @@ -11,6 +11,7 @@ This document outlines iLEAPP modules parsing SQLite databases using the new `ge | accountData | | allTrails | | callHistory | +| foursquareSwarm | | payByPhone | | subscriberInfo | | twint |