Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
iLEAPP — Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes backup support. | Kitploit
工具/GitHubGitHub/abrignoni/ileapp
iOS SecurityForensicsMobile ForensicsDigital ForensicsIncident ResponseLog AnalysisMobile Forensics 分类第 4 名
GitHubabrignoni/ileapp

iLEAPP

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes backup support.

1.3k3185210小时22分前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
内容在请求的语言中不可用。显示英文版本。

iLEAPP

iOS Logs, Events, And Plists Parser

iLEAPP parses iOS and iPadOS forensic extractions and produces HTML, TSV, timeline, KML, and LAVA output. It supports iOS/iPadOS 11 through current versions.

Browse the full searchable artifact list at leapps.org/artifacts (filter by LEAPP tool).

Quick Start (Recommended)

Download a pre-built release — no Python installation required.

  • LEAPPs Releases — browse all LEAPP family tools
  • iLEAPP GitHub Releases — direct downloads
PlatformDownload
Windows (Intel/AMD)iLEAPP-*-windows-x64-setup.exe (installer) or iLEAPP-*-windows-x64-portable.zip
Windows (ARM)iLEAPP-*-windows-arm64-setup.exe or iLEAPP-*-windows-arm64-portable.zip
macOS (Apple Silicon)iLEAPP-*-macos-arm64.dmg
macOS (Intel)iLEAPP-*-macos-x64.dmg
Linux (Intel/AMD)iLEAPP-*-linux-x64.AppImage
Linux (ARM)iLEAPP-*-linux-arm64.AppImage

Each download holds one program, ileapp. SHA256SUMS.txt in each release lets you check a download.

GUI — open iLEAPP the usual way: from the Start menu after installing on Windows, by double-clicking ileapp.exe in the portable folder, iLEAPP in Applications on macOS, or the AppImage on Linux. Started without arguments, it opens the window; select your input type, source path, output folder, and modules to process.

CLI — give ileapp arguments in a terminal and it runs as a command line instead. The output folder must already exist. On Windows, keep ileapp.exe in its folder with the files beside it.

ileapp.exe -t zip -i C:\path\to\extraction.zip -o C:\path\to\output\

On Linux, run the AppImage with the same arguments. On macOS it is inside the app; to type just ileapp in a terminal, link it onto your PATH once:

sudo ln -s /Applications/iLEAPP.app/Contents/MacOS/ileapp /usr/local/bin/ileapp

Input Types

TypeDescription
fsFolder of extracted files with normal paths and names
zipZIP archive containing files with normal names
tarTAR archive, plain or xz-compressed (.tar.xz)
gzGZIP-compressed archive
itunesiTunes/Finder backup folder with hashed paths and names
fileSingle file input

Encrypted iTunes/Finder backups (-t itunes) are supported. The GUI will prompt for a password before processing when encryption is detected. On the CLI, pass the password with --itunes_password (see Optional parsing options below).

CLI Arguments

These options apply only to the CLI (ileapp / ileapp.exe given arguments, or python ileapp.py). The GUI (ileapp started without arguments, or python ileappGUI.py) exposes the same settings through its interface instead of command-line flags.

Run ileapp --help (or python ileapp.py --help from source) for the built-in reference.

Parsing a case

These three arguments are required for a normal parse run:

ArgumentLong formDescription
-tInput type: fs, tar, zip, gz, itunes, or file
-i--input_pathPath to the input file or folder
-o--output_pathPath to the output folder (must already exist)

Example:

ileapp -t zip -i /path/to/extraction.zip -o /path/to/output/

Optional parsing options

ArgumentLong formDescription
-w--wrap_textPass this flag to disable text wrapping in output files
-m--load_profilePath to an iLEAPP profile file (.ilprofile) to limit which modules run
-d--load_case_dataPath to a LEAPP case data file (.lcasedata)
--custom_output_folderCustom name for the report output subfolder
--custom_artifacts_pathExtra folder to load artifact modules from (e.g. scripts/alternate_artifacts)
--html_row_limitRows above which an artifact's table is left off its HTML page, which then points at the LAVA database and the TSV export instead. Default 50000; 0 writes every table. The GUI uses the default
--itunes_password

Standalone utility modes

These modes do not parse a case. Use them alone — without -t, -i, or -o:

ArgumentLong formDescription
-p--artifact_pathsWrite all artifact search paths to path_list.txt in the current directory
-c--create_profile_casedataInteractive wizard to create a .ilprofile or .lcasedata file in the given folder

Examples:

ileapp -p
ileapp -c /path/to/output/folder/

Contributing

Artifact modules live in scripts/artifacts/ and are loaded dynamically at runtime.

New modules: start with the step-by-step guide at How to Write an iLEAPP Module.

Additional references:

  • Artifact Info Block Structure
  • Updating Modules for Automatic Output Generation
  • Updating Complex Modules to Include LAVA Output
  • Testing Modules

Test data and sample_data for your PR

A PR that adds or changes an artifact is easiest to review and merge when it arrives with two things: a small test fixture cut from a real extraction, and sample_data values that record what the module produced. Scripts generate both. Here is the whole flow.

One rule before anything else: whatever you commit here becomes public. Only use data you are allowed to share, like a test device you populated yourself, a public research image, or a file you sanitized by hand. Never casework.

1. Cut a fixture from your extraction

python admin/test/scripts/make_test_data.py <module> --case 1 --input <extraction.zip>

This pulls the files your module's paths patterns match out of the extraction and writes the case file admin/test/cases/testdata.<module>.json plus one small zip per artifact under admin/test/cases/data/<module>/.

Size rules: under 10 MB per zip, commit it with the PR. Between 10 and 25 MB, commit the case file and attach the zip to a PR comment. Bigger than that, say so in the PR and a maintainer will arrange a handoff.

2. Record the expected output

TZ=UTC python admin/test/scripts/test_module.py <module> -a all -c all

This runs the module against the fixture and writes a snapshot of the output under admin/test/results/<module>/. Commit the snapshot too. It becomes the baseline that guards the module after merge. Keep the TZ=UTC part: the committed snapshots are UTC and CI runs UTC.

3. Run the same comparison CI will run

python admin/test/scripts/run_test_cases.py --module <module>

4. Generate the sample_data values

python admin/scripts/validate_sample_data.py --emit <extraction.zip> --key <image_name>

This runs iLEAPP end to end on your extraction and prints ready-to-paste sample_data blocks for the modules changed on your branch. Paste them into your module's __artifacts_v2__ and add the app name and version you saw on the image. If a count is zero, check the source file really is empty before recording it.

5. Commit it all and open the PR

下载工具