iOS Forensics MCP Server

by RLabs-Inc

354 downloads Not rated yet MIT license

About

iOS Forensics MCP Server for analyzing iPhone/iPad file systems

Details

License
MIT license

Explore

- File System Tools

- Directory navigation with metadata analysis
- File content viewing with type recognition
- File searching with content and pattern matching

- SQLite Analysis

- Database discovery and schema analysis
- Secure query execution with WAL handling
- Deleted record recovery from freelist pages
- Database carving for deep forensic analysis

- Plist Analysis

- Binary and XML plist parsing
- Value extraction with query paths
- Timestamp analysis

- Specialized iOS Parsers

- Messages analyzer (SMS/iMessage)
- Call log analyzer
- Contacts analyzer
- Location data analyzer
- Browser history analyzer
- Photo geolocation extractor
- App data analyzer

- Advanced Analysis
- Timeline generation across multiple data sources
- Pattern recognition for user behavior analysis
- Deleted data recovery
- Comprehensive reporting

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name iOS Forensics MCP Server
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

uv install ios-forensics-mcp


uv sync

Add the MCP server to your Claude Desktop configuration file (typically located at ~/.claude/config.json or similar path based on your OS):

{
  "mcpServers": {
    "ios-forensics": {
      "command": "uv",
      "args": [
        "run",
        "ios-forensics-mcp",
        "--root-path",
        "/path/to/ios_extraction"
      ]
    }
  }
}

After adding this configuration, restart Claude Desktop, and the iOS Forensics MCP server will appear in your available servers list.

npm install -g @anthropic-ai/claude-code


Then add the iOS Forensics MCP server to Claude Code:

bash

Create a configuration file (config.json) to set up your iOS forensics environment:

{
  "ios_filesystem": {
    "root_path": "/path/to/ios_extraction",
    "read_only": true
  },
  "server": {
    "port": 8080,
    "host": "127.0.0.1"
  }
}

ios-forensics-mcp

ios-forensics-mcp --config /path/to/config.json

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "ios forensics mcp server": {
            "ios-forensics-mcp": {
                "command": "uv",
                "args": [
                    "sync"
                ]
            }
        }
    }
}

McpServers

{
    "ios-forensics-mcp": {
        "command": "uv",
        "args": [
            "sync"
        ]
    }
}

A forensic analysis server for iOS file systems using the Model Context Protocol (MCP). This project enables AI assistants like Claude to access and analyze extracted iOS file systems for digital forensics purposes.

🔍 Overview

The iOS Forensics MCP Server provides tools for analyzing iOS device extractions, focusing on:

- File system analysis
- SQLite database parsing with WAL forensics
- Property List (plist) parsing
- iOS artifact analysis (messages, call logs, contacts, locations, etc.)
- Timeline generation
- Forensic reporting

This is designed as an educational/learning tool, allowing users to interact with an AI assistant to explore and analyze iOS data.

🚀 Features

- File System Tools

- Directory navigation with metadata analysis
- File content viewing with type recognition
- File searching with content and pattern matching

- SQLite Analysis

- Database discovery and schema analysis
- Secure query execution with WAL handling
- Deleted record recovery from freelist pages
- Database carving for deep forensic analysis

- Plist Analysis

- Binary and XML plist parsing
- Value extraction with query paths
- Timestamp analysis

- Specialized iOS Parsers

- Messages analyzer (SMS/iMessage)
- Call log analyzer
- Contacts analyzer
- Location data analyzer
- Browser history analyzer
- Photo geolocation extractor
- App data analyzer

- Advanced Analysis
- Timeline generation across multiple data sources
- Pattern recognition for user behavior analysis
- Deleted data recovery
- Comprehensive reporting

📋 Requirements

- Python 3.9+
- MCP compatible client (Claude Desktop, Claude Code, VS Code with MCP plugin, etc.)
- Extracted iOS file system (accessible directory)

📦 Installation

Using uv

```bash

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.