Commit Graph

  • 9d81b5bfa8 Add a module to parse uninstalled apps from dumpsys data, for both bugreport and AndroidQF output, and match them against package name IoCs. tes 2024-12-11 16:47:19 -03:00
  • 22fce280af Add new iOS versions and build numbers (#572) github-actions[bot] 2024-11-20 11:02:09 +01:00
  • 4739d8853e Merge pull request #570 from mvt-project/fix/files-detection-bug Donncha Ó Cearbhaill 2024-10-31 20:04:33 +01:00
  • ace01ff7fb Merge branch 'main' into fix/files-detection-bug Donncha Ó Cearbhaill 2024-10-31 19:59:53 +01:00
  • 7e4f0aec4d Fix error to due extra equal character in Files detection Donncha Ó Cearbhaill 2024-10-31 19:59:29 +01:00
  • 57647583cc Add new iOS versions and build numbers (#569) github-actions[bot] 2024-10-29 04:17:03 +01:00
  • be9a09ac5c Merge branch 'feature/android-sub-module-loading' into local-timeline-fixes tmp/timeline-improvements Donncha Ó Cearbhaill 2024-10-28 14:12:47 +01:00
  • 08f515e88b Merge branch 'feature/fs-timestamps' into local-timeline-fixes Donncha Ó Cearbhaill 2024-10-28 14:12:29 +01:00
  • 8e895d3d07 Remove protobuf compiler dependency, only needed for dev Donncha Ó Cearbhaill 2024-10-28 13:10:37 +01:00
  • 4a14c97be3 Handle case were we cannot load device timezone Donncha Ó Cearbhaill 2024-10-28 11:55:41 +01:00
  • 39f78851ae Add file timestamp modules to add logs into timeline Donncha Ó Cearbhaill 2024-10-28 11:49:30 +01:00
  • 84d7716ef1 Use local timestamp for Files module timeline. Donncha Ó Cearbhaill 2024-10-28 11:46:05 +01:00
  • 2bb613fe09 Return after loading bugreport module Donncha Ó Cearbhaill 2024-10-28 11:19:45 +01:00
  • 355850bd5c WIP: Run bugreport modules against bugreport.zip in AndroidQF extraction Donncha Ó Cearbhaill 2024-10-28 11:12:20 +01:00
  • bc09e2a394 Initial tests for tombstone parsing Donncha Ó Cearbhaill 2024-10-28 10:51:58 +01:00
  • 2d0de088dd Add generated protobuf parser Donncha Ó Cearbhaill 2024-10-28 10:38:19 +01:00
  • 8694e7a047 Add protobuf parser generation Donncha Ó Cearbhaill 2024-10-28 10:37:30 +01:00
  • 9b41ba99aa WIP: initial tombstone modules Donncha Ó Cearbhaill 2024-10-28 10:34:53 +01:00
  • cd99b293ed Merge pull request #563 from mvt-project/feature/add-package-detections Donncha Ó Cearbhaill 2024-10-24 17:37:30 +02:00
  • 5fe8238ef0 Update tests to work with the new side-loading detections feature/add-package-detections Donncha Ó Cearbhaill 2024-10-24 17:35:34 +02:00
  • 1d44ae3987 Add detections for side-loaded apps, and deduplicate results Donncha Ó Cearbhaill 2024-10-24 17:19:58 +02:00
  • bb68e41c07 Add detection for disabled system packages Donncha Ó Cearbhaill 2024-10-24 16:48:03 +02:00
  • 787b0c1f48 Merge pull request #562 from mvt-project/fix-docker-and-docs Donncha Ó Cearbhaill 2024-10-23 15:25:52 +02:00
  • 83c1bbf714 Revert "Make multiplatform images" Donncha Ó Cearbhaill 2024-10-23 15:22:11 +02:00
  • 17b625f311 Make multiplatform images Donncha Ó Cearbhaill 2024-10-23 15:16:28 +02:00
  • 7772d2de72 Add build dependencies for pyahocorasick Donncha Ó Cearbhaill 2024-10-23 15:10:11 +02:00
  • 37705d11fa Add checksum for ABE jar Donncha Ó Cearbhaill 2024-10-23 14:56:59 +02:00
  • 319bc7e9cd Switch docker build to use local context rather than pulling Donncha Ó Cearbhaill 2024-10-23 14:56:35 +02:00
  • 62cdfa1b59 Add info to docs on using docker image Donncha Ó Cearbhaill 2024-10-23 13:19:34 +02:00
  • cbb78b7ade Update pip version in image to try fix package build issue Donncha Ó Cearbhaill 2024-10-23 13:19:10 +02:00
  • 4598293c82 Generate ADB key on first run to avoid static key in image Donncha Ó Cearbhaill 2024-10-23 13:18:43 +02:00
  • 6e0cd23bbc Add license to Docker image metadata Donncha Ó Cearbhaill 2024-10-23 13:17:47 +02:00
  • d6f3561995 Fix docs build dependencies Donncha Ó Cearbhaill 2024-10-23 12:34:47 +02:00
  • 19b3b97571 Build Docker image on release rather than on branch (#561) Donncha Ó Cearbhaill 2024-10-23 12:04:53 +02:00
  • 2c72d80e7c Fix action which updates iOS verisons and build numbers (#560) Donncha Ó Cearbhaill 2024-10-23 11:55:16 +02:00
  • 720aeff6e9 Add workflow for building Docker image (#559) Donncha Ó Cearbhaill 2024-10-23 11:53:55 +02:00
  • 863de4f543 Fix crash Handling empty adb key list (#558) Donncha Ó Cearbhaill 2024-10-23 11:50:08 +02:00
  • 3afe218c7c Add support for check APK certificate hash IOCs (#557) Donncha Ó Cearbhaill 2024-10-18 16:35:50 +02:00
  • 665806db98 Add initial parser for ADB state in Dumpsys (#547) Donncha Ó Cearbhaill 2024-10-18 15:31:25 +02:00
  • a03f4e55ff Adds androidqf files module (#541) Tek 2024-10-17 18:32:23 +02:00
  • 81b647beac Add basic support for IP indicators in MVT (#556) Donncha Ó Cearbhaill 2024-10-17 18:20:17 +02:00
  • 5ef19a327c Fix error reporting for update check failures (#555) Donncha Ó Cearbhaill 2024-10-17 13:26:53 +02:00
  • f4bf3f362b Refactor CLI help messages to make the CLI code more readable and maintainable. (#554) Donncha Ó Cearbhaill 2024-10-17 12:28:42 +02:00
  • 7575315966 Adds timeout to update checks (#542) Tek 2024-10-17 11:56:05 +02:00
  • 9678eb17e5 Fixes a minor bug in IOC import (#553) Tek 2024-10-17 11:36:33 +02:00
  • 7303bc06e5 Adds recovery of sqlite db when db is opened (#516) Tek 2024-10-17 11:28:13 +02:00
  • 477f9a7f6b Fix CI badge (#552) Donncha Ó Cearbhaill 2024-10-16 17:11:59 +02:00
  • aced1aa74d Fixes a bug in Android SMS parsing #526 (#530) Tek 2024-10-16 16:56:06 +02:00
  • 052c4e207b Improves STIX2 support and testing (#523) Tek 2024-10-16 16:47:10 +02:00
  • 821943a859 Merge branch 'besendorf/main' Donncha Ó Cearbhaill 2024-10-16 16:36:07 +02:00
  • f4437b30b1 Fix black formatting Donncha Ó Cearbhaill 2024-10-16 16:35:28 +02:00
  • d4946b04bf Update deprecated functions and other small changes (#533) besendorf 2024-10-16 16:29:02 +02:00
  • a15d9f721d Merge pull request #544 from mvt-project/feature/use-pyproject-toml Donncha Ó Cearbhaill 2024-10-16 16:06:23 +02:00
  • 10e7599c6e Merge branch 'main' into feature/use-pyproject-toml Donncha Ó Cearbhaill 2024-10-16 15:40:36 +02:00
  • a44688c501 change recursive search for indicator files from os.walk to glob.glob Janik Besendorf 2024-10-08 15:49:03 +02:00
  • c66a38e5c0 Add new iOS versions and build numbers (#549) github-actions[bot] 2024-10-04 10:53:41 +02:00
  • 7d873f14dd Update WIP for dumpstate parser wip/android-dumpstate-parser Donncha Ó Cearbhaill 2024-09-30 19:22:52 +02:00
  • 524bfcf649 WIP: Better dumpstate parser Donncha Ó Cearbhaill 2024-09-30 18:39:11 +02:00
  • ee2fab8d87 Merge main and add dependency change Donncha Ó Cearbhaill 2024-09-30 16:53:50 +02:00
  • f8e2b0921a Merge pull request #509 from scribblemaniac/multistage-docker Donncha Ó Cearbhaill 2024-09-30 12:50:51 +01:00
  • 5225600396 Remove duplicate CI file Donncha Ó Cearbhaill 2024-09-30 13:34:56 +02:00
  • 2c4c92f510 Try using package name as path Donncha Ó Cearbhaill 2024-09-30 13:21:02 +02:00
  • 656feb1da7 Try make sure pytest uses the local editable install Donncha Ó Cearbhaill 2024-09-30 13:11:21 +02:00
  • 79dd5b8bad Temporarily disable automatic type checks in CI Donncha Ó Cearbhaill 2024-09-30 12:53:17 +02:00
  • f79938b082 Run ruff on PRs Donncha Ó Cearbhaill 2024-09-30 12:44:21 +02:00
  • 822536a1cb Add formating change made by ruff linter Donncha Ó Cearbhaill 2024-09-30 12:40:15 +02:00
  • 69fb8c236f Simplify the CI tests using the Makefile Donncha Ó Cearbhaill 2024-09-30 12:39:21 +02:00
  • 5dfa0153ee Restructure MVT to use pyproject.toml Donncha Ó Cearbhaill 2024-09-30 12:26:29 +02:00
  • d79f6cbd7d Run black linter on pull requests (#543) Donncha Ó Cearbhaill 2024-09-30 10:49:00 +01:00
  • 617c5d9e1c Fixes import order tek 2024-09-28 13:15:43 +02:00
  • ae9f874e1b Merge branch 'mvt-project:main' into main besendorf 2024-09-17 20:17:10 +02:00
  • b58351bfbd Add new iOS versions and build numbers (#532) github-actions[bot] 2024-09-17 10:46:42 +02:00
  • 287a11a2ee also search for STIX2 files in directories in MVT_STIX2 Janik Besendorf 2024-09-03 20:20:46 +02:00
  • efe46d7b49 Add new iOS versions and build numbers (#521) github-actions[bot] 2024-08-23 15:10:39 +02:00
  • 102dd31bd6 Add new iOS versions and build numbers (#514) github-actions[bot] 2024-08-07 23:57:46 +02:00
  • e00895aa9d Explicitly install usb version of adb_shell scribblemaniac 2024-07-03 13:06:31 -06:00
  • 79dbf999a9 Use OCI standard labels for docker image scribblemaniac 2024-06-28 14:41:15 -06:00
  • 89d31f3212 Refactor Dockerfile into tool-specific multi-stage builds scribblemaniac 2024-06-28 01:28:03 -06:00
  • caeeec2816 Add packages module for androidqf (#506) Rory Flynn 2024-06-24 19:00:07 +02:00
  • 9e19abb5d3 Fixes for failing CI (#507) Rory Flynn 2024-06-24 18:50:42 +02:00
  • cf5cf3b85d Mark 2.5.4 release (#504) v2.5.4 Rory Flynn 2024-06-21 14:51:16 +02:00
  • f0dbe0bfa6 Prevent command.log from being appended to when run in a loop (#501) Rory Flynn 2024-05-27 19:15:32 +02:00
  • 555e49fda7 Add new iOS versions and build numbers (#499) github-actions[bot] 2024-05-20 23:12:04 +02:00
  • a6d32e1c88 Fix dumpsys accessibility detections for v14+ (#483) Rory Flynn 2024-05-19 22:27:28 +02:00
  • f155146f1e Add new iOS versions and build numbers (#498) github-actions[bot] 2024-05-14 10:58:00 +02:00
  • 9d47acc228 Returns empty string when no date in date converter (#493) Tek 2024-04-30 16:51:58 +02:00
  • cbd41b2aff Mark 2.5.3 release (#490) v2.5.3 Rory Flynn 2024-04-19 17:23:55 +02:00
  • 0509eaa162 Use backwards-compatible datetime.timezone.utc (#488) Rory Flynn 2024-04-19 17:22:10 +02:00
  • 59e6dff1e1 Fail builds on test failure (#489) Rory Flynn 2024-04-19 17:18:27 +02:00
  • f1821d1a02 Mark release 2.5.2 (#486) v2.5.2 Rory Flynn 2024-04-18 16:53:41 +02:00
  • 6c7ad0ac95 Convert timezone-aware datetimes automatically to UTC (#485) Rory Flynn 2024-04-18 16:49:30 +02:00
  • 3a997d30d2 Updates SMS module to highlight new text of Apple notifications tek 2024-04-15 23:28:36 +02:00
  • 6f56939dd7 Requires latest cryptography version tek 2024-04-15 22:41:01 +02:00
  • 7a4946e2c6 Mark release 2.5.1 (#481) v2.5.1 Donncha Ó Cearbhaill 2024-04-11 11:14:42 +02:00
  • e1c4f4eb7a Add more short urls (#479) r-tx 2024-04-11 10:08:15 +01:00
  • f9d7b550dc Add docs explaining how to seek expert help for forensic analysis (#476) Donncha Ó Cearbhaill 2024-04-08 18:47:59 +02:00
  • b738603911 Usbmuxd debug option changed from -d to -v (#464) renini 2024-04-08 18:34:34 +02:00
  • 5826e6b11c Migrate dumpsys_packages parsing into an artifact tek 2024-04-01 01:49:08 +02:00
  • 54c5d549af Fixes bug in dumpsys package parsing tek 2024-04-01 00:56:37 +02:00
  • dded863e58 Add new iOS versions and build numbers (#473) github-actions[bot] 2024-03-27 21:18:09 +01:00