Advertisement · 728 × 90

Posts by James McGee

Post image

KMLer turns CSV and XLSX files into KML files while adding the investigative context examiners and analysts need. 🕵️ Horizontal accuracy visualized, extended data, processing report, and more!
Read more here: tinyurl.com/y8d3je3m 
Get it here: tinyurl.com/3fw8vnn8

4 weeks ago 0 1 0 0
Preview
GitHub - MetadataForensics/HEART_by_Metadata_Forensics: This free tool parses Apple Health and Fitness Application data from Apple iPhone extractions in a forensic manner. This free tool parses Apple Health and Fitness Application data from Apple iPhone extractions in a forensic manner. - MetadataForensics/HEART_by_Metadata_Forensics

🚀 New Release: HEART by Metadata Forensics Version 1.3! 🚀
We’ve added Local Device Time conversions! most Apple Health and Fitness application artifacts are linked to the device recorded the event, the associated time zone is preserved as well. Conversions by activity! github.com/MetadataFore...

1 month ago 0 0 0 0

My own corner of Apple Health forensics lives on the Metadata Forensics company blog, The Metadata Perspective:
lnkd.in/e6HZCBFq

1 month ago 1 0 0 0

If you’re in digital investigations and haven’t joined the Summit yet, you still have time (Feb 23–26). It’s free, eye-opening, and full of practical takeaways:
lnkd.in/ew3taAjV

Looking forward to the rest of the week and continuing the conversation with all of you.
#MVS2026 #DFIRCommunity

1 month ago 0 0 1 0
Post image

Couldn’t start the week better-thank you Christopher Vance for the shout-out in your session, Harping on health data, during the Magnet Virtual Summit 2026! Your Mobile Unpacked series has helped so many of us, and it’s genuinely humbling to have my Apple Health contributions mentioned alongside it.

1 month ago 0 0 1 0
Preview
GitHub - MetadataForensics/iQueryContacts: Advanced parser for Apple Contacts (AddressBook.sqlitedb) with phones, emails, addresses, social accounts, birthdays (including Chinese lunar), and group mem... Advanced parser for Apple Contacts (AddressBook.sqlitedb) with phones, emails, addresses, social accounts, birthdays (including Chinese lunar), and group memberships. - MetadataForensics/iQueryCont...

Ever wondered what secrets are in your Apple Contacts? 📱 iQueryContacts 🕵️ is our new advanced SQL query work for the AddressBook.sqlitedb. All the classic data plus some new info including the Chinese lunar birthday! Find out more at github.com/MetadataFore...

4 months ago 1 0 0 0
Post image
4 months ago 0 0 0 0
Preview
GitHub - MetadataForensics/RowIDetective: An update to our prior work within Lagging for the Win, now reporting all sms.db missing ROWID values up to the message sequence number. An update to our prior work within Lagging for the Win, now reporting all sms.db missing ROWID values up to the message sequence number. - MetadataForensics/RowIDetective

🧩 RowIDetective 🕵️‍♂️ formerly detailed Lagging for the Win: Querying for Negative Evidence in the sms.db. Now detecting missing messages at the end of Apple sms.db. Because every gap tells a story.
🔗 github.com/MetadataFore...

4 months ago 0 0 0 0
Preview
GitHub - MetadataForensics/HEART_by_Metadata_Forensics: This free tool parses Apple Health and Fitness Application data from Apple iPhone extractions in a forensic manner. This free tool parses Apple Health and Fitness Application data from Apple iPhone extractions in a forensic manner. - MetadataForensics/HEART_by_Metadata_Forensics

🚀 New release! HEART by Metadata Forensics (Health Events & Activity Reporting Tool) Version 1.1.0.0!

Now supporting TAR, DAR (some), Advanced Logical (Encrypted) Extractions, iTunes Encrypted Backups.

⬇️ Download: tinyurl.com/v8zesb7h
📖 Article: tinyurl.com/94rx6vk4

5 months ago 0 0 0 0
Preview
GitHub - MetadataForensics/HEART_by_Metadata_Forensics: This free tool parses Apple Health and Fitness Application data from Apple iPhone extractions in a forensic manner. This free tool parses Apple Health and Fitness Application data from Apple iPhone extractions in a forensic manner. - MetadataForensics/HEART_by_Metadata_Forensics

HEART by Metadata Forensics (Health Events & Activity Reporting Tool)

Free tool to parse Apple Health & Fitness data from FFS Extractions.

🔍 31+ artifacts supported
📊 HTML report + CSV/PDF export

⬇️ Download: tinyurl.com/v8zesb7h
📖 Article: tinyurl.com/94rx6vk4

6 months ago 0 0 0 0
Advertisement
Post image

Thanks to our great DFIR Community and discussion on the matter, I’m happy to announce our Google Location History Takeout Parser, Version 1.4.1. We’ve added Horizontal Accuracy KMLs for Records.JSON data and Parking Events. Get it at tinyurl.com/4aua56u4 Google Earth example:

7 months ago 0 0 0 0
Preview
GitHub - MetadataForensics/Google-Location-History-Takeout-Parser: This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic m... This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic manner. - MetadataForensics/Google-Location-History-Takeout-Parser

🚀 Google Location History Timeline Parser v 1.4 is now available! This release features multithreaded processing, time elapsed tracking, input file size calculation, and location-related files including HTML, CSV, and TXT. Available here:
tinyurl.com/4dr3tuv5

10 months ago 0 0 0 0
Preview
GitHub - MetadataForensics/Google-Location-History-Takeout-Parser: This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic m... This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic manner. - MetadataForensics/Google-Location-History-Takeout-Parser

🚀 Google Location History Takeout Parser Version 1.3.0.0 is here! 🎉
With enhanced KML support (TimeSpans, Descriptions & LineStrings), taking your data to the next level. Continue leveraging Google Location History Takeout & Warrant Return data.
👉 tinyurl.com/2s8yzksx

1 year ago 0 0 0 0

Excited for this release, best is yet to come with the LEAPPs! Fantastic project, resource, and tool

1 year ago 0 0 0 0
Preview
Examining the United States v. Ladonies P. STRONG Case The case US v. Strong addresses the legality of warrantless searches of mobile devices, highlighting Fourth Amendment privacy rights. When Strong’s device was searched without a warrant, it r…

We’re thrilled to unveil "Legal Bytes in a Digital World," our new article series examining the intersection of law, technology, and digital forensics. In our debut piece, we explore US v. Strong - available here: tinyurl.com/ymn2ju28 Stay tuned for in-depth analysis and expert perspectives in DFIR.

1 year ago 0 0 0 0

Many thanks to Magnet Forensics, Hexordia, and the CTF authors for this great experience! Glad the timing worked out that I was able to participate - really enjoyable, creative, and challenging. Still may go back and look at some more of these questions..

1 year ago 2 3 1 0
Preview
Hello! Who is on the Line? Have you ever wondered how many individuals were on a phone call or Facetime call when reviewing data extracted from an iOS device? This question came up in a case recently when information was dev…

🔍 New article from Metadata Forensics! 📱 “Hello! Who is on the Line?” – we’re diving into parsing iPhone group calls, something not previously supported by commercial or open-source mobile forensic tools. Check it out 👉 tinyurl.com/3n6c3374

1 year ago 0 0 0 0
Post image
1 year ago 0 0 0 0
Advertisement

🥳 Now also available within iLEAPP! 🎉 Such an incredible tool and community resource 🙌

1 year ago 0 0 0 0
Preview
Beyond the Logs: Using the Health App to Uncover Device Model and OS History This article explores both the healthdb_secure.sqlite and healthdb.sqlite databases for data indicating devices possessed by the user, reviews device information hand-in-hand with OS version and ti…

🕵️‍♂️💾 Uncover your device’s secret history! "Beyond the Logs: Using the Health App to Uncover Device Model and OS History" explores Health Application databases to reveal Apple model & OS info. Find out more at tinyurl.com/2dfwn5xs #metadataforensics #DFIR

1 year ago 0 0 1 0
Post image

This Thanksgiving, I’m grateful for the opportunity to make a difference and help bring justice to light. It’s the small details that matter, and I’m thankful to be part of a journey that strives for truth and fairness for all. Wishing everyone a meaningful Thanksgiving!

1 year ago 0 0 0 0
Post image

Let’s discuss: unpopular opinion? iOS 18: AFU is <72 hrs from reboot and BFU state. Lot of extraction ASAP talk, regardless of search auth. You can articulate, but with auth prior you don’t have to. What am I missing? Are auths after device seizure really going beyond 24 hrs?

1 year ago 0 0 0 0
Post image
1 year ago 0 0 0 0
Preview
Hexordia’s Mobile Data Structures: Honing Your Digital Forensic Edge Hexordia's Mobile Data Structures course offers comprehensive training in SQLite, PList, LevelDB, and Protobuf analysis. With interactive Zoom sessions and hands-on tasks, it provides valuable insight...

Our latest course review is now available! 📱🧠 Explore Hexordia’s Mobile Data Structures: Honing Your Digital Forensic Edge for our thoughts on this course. 📈📊 Find it here: tinyurl.com/msb27jyz 🔗

1 year ago 0 0 0 0
Preview
MetadataForensics - Overview Alongside seeking the digital truth and client satisfaction in all our cases, we also strive to further the DFIR Community with our research and work products. - MetadataForensics

🚀 New Release Alert! 🎉 Check out the latest versions of our Google Location History Timeline Parser and Brute Force Dictionary List Generator! Now with a new graphical interface and enhanced functionality. Download today at github.com/MetadataFore...! 🚀

1 year ago 0 0 0 0
Preview
Rookie Reflections: A Green Examiner’s Forensic Journey Into Cellebrite I came to Metadata Forensics from a local Police department in Georgia, and while I thoroughly enjoyed the “figure it out” education I accrued there. I was excited to start adding the letters to the e...

New Blog Alert: Rookie Reflections: A Green Examiner's Forensic Journey Into Cellebrite, available here: tinyurl.com/3xbmcrje. Discover insights, challenges, and tips from one of our newest team members in her review of Cellebrite’s CCO course!

1 year ago 1 0 0 0
Advertisement
Preview
Sleepless in Cupertino: A Forensic Dive into Apple Watch Sleep Tracking How's your sleep been lately? Currently, there are numerous sleep tracking and monitoring devices available to track, monitor, and quantify sleep patterns for users actively seeking to improve their s...

Wake up to our new article, Sleepless in Cupertino: A Forensic Dive into Apple Watch Sleep Tracking! 🌙 Review how Sleep data is stored and explore parsing with SQL query solutions. 🔍 Learn how this could lend insight into the future Vitals app! 📈 tinyurl.com/yc43kpme

1 year ago 0 0 0 0
Preview
GitHub - MetadataForensics/Google-Location-History-Data-Parser: This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic mann... This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic manner. - MetadataForensics/Google-Location-History-Data-Parser

Google Location History Data Parser Version 1.1.0.0 Released! Now with enhanced compatibility for older Google Location History Takeout data (~2020, 2021) and timestamp clarification, whether in Local Time or UTC+0. Available here: tinyurl.com/btu2u8za

1 year ago 0 0 0 0
Preview
Apple Watch – Worn Data Analysis The article explores a lesser-known data point in Apple Health that shows when an Apple Watch is worn. This data indicates one-hour time periods when the Watch was worn and time segments when the Watc...

🔍 Explore Apple Watch wear data parsed from the healthdb_secure.sqlite! This data can assist in pattern of life analysis and provide valuable context for expected data recording, such as heart rate data.. 📈👀 Available here: tinyurl.com/2a3up53t

1 year ago 0 0 0 0
Preview
GitHub - MetadataForensics/Google-Location-History-Data-Parser: This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic mann... This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic manner. - MetadataForensics/Google-Location-History-Data-Parser

📢 New Release Alert! We’re thrilled to announce the release of Version 1.0.1.7 of our Google Location History Data Parser! 🎉Thanks to our incredible users, your feedback drives our growth and strengthens the DFIR community. 🙌 Check it out: tinyurl.com/4bptenjw #DFIR

1 year ago 0 0 0 0