iOS Forensics MCP Server
About
iOS Forensics MCP Server for analyzing iPhone/iPad file systems
Details
- License
- MIT license
Explore
- File System Tools
- Directory navigation with metadata analysis
- File content viewing with type recognition
- File searching with content and pattern matching
- SQLite Analysis
- Database discovery and schema analysis
- Secure query execution with WAL handling
- Deleted record recovery from freelist pages
- Database carving for deep forensic analysis
- Plist Analysis
- Binary and XML plist parsing
- Value extraction with query paths
- Timestamp analysis
- Specialized iOS Parsers
- Messages analyzer (SMS/iMessage)
- Call log analyzer
- Contacts analyzer
- Location data analyzer
- Browser history analyzer
- Photo geolocation extractor
- App data analyzer
- Advanced Analysis
- Timeline generation across multiple data sources
- Pattern recognition for user behavior analysis
- Deleted data recovery
- Comprehensive reporting
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
iOS Forensics MCP ServerCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
uv install ios-forensics-mcp
uv sync
Add the MCP server to your Claude Desktop configuration file (typically located at ~/.claude/config.json or similar path based on your OS):
{
"mcpServers": {
"ios-forensics": {
"command": "uv",
"args": [
"run",
"ios-forensics-mcp",
"--root-path",
"/path/to/ios_extraction"
]
}
}
}
After adding this configuration, restart Claude Desktop, and the iOS Forensics MCP server will appear in your available servers list.
npm install -g @anthropic-ai/claude-code
Then add the iOS Forensics MCP server to Claude Code:
bash
Create a configuration file (config.json) to set up your iOS forensics environment:
{
"ios_filesystem": {
"root_path": "/path/to/ios_extraction",
"read_only": true
},
"server": {
"port": 8080,
"host": "127.0.0.1"
}
}
ios-forensics-mcp
ios-forensics-mcp --config /path/to/config.json
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"ios forensics mcp server": {
"ios-forensics-mcp": {
"command": "uv",
"args": [
"sync"
]
}
}
}
}
McpServers
{
"ios-forensics-mcp": {
"command": "uv",
"args": [
"sync"
]
}
}
A forensic analysis server for iOS file systems using the Model Context Protocol (MCP). This project enables AI assistants like Claude to access and analyze extracted iOS file systems for digital forensics purposes.
🔍 Overview
The iOS Forensics MCP Server provides tools for analyzing iOS device extractions, focusing on:
- File system analysis
- SQLite database parsing with WAL forensics
- Property List (plist) parsing
- iOS artifact analysis (messages, call logs, contacts, locations, etc.)
- Timeline generation
- Forensic reporting
This is designed as an educational/learning tool, allowing users to interact with an AI assistant to explore and analyze iOS data.
🚀 Features
- File System Tools
- Directory navigation with metadata analysis
- File content viewing with type recognition
- File searching with content and pattern matching
- SQLite Analysis
- Database discovery and schema analysis
- Secure query execution with WAL handling
- Deleted record recovery from freelist pages
- Database carving for deep forensic analysis
- Plist Analysis
- Binary and XML plist parsing
- Value extraction with query paths
- Timestamp analysis
- Specialized iOS Parsers
- Messages analyzer (SMS/iMessage)
- Call log analyzer
- Contacts analyzer
- Location data analyzer
- Browser history analyzer
- Photo geolocation extractor
- App data analyzer
- Advanced Analysis
- Timeline generation across multiple data sources
- Pattern recognition for user behavior analysis
- Deleted data recovery
- Comprehensive reporting
📋 Requirements
- Python 3.9+
- MCP compatible client (Claude Desktop, Claude Code, VS Code with MCP plugin, etc.)
- Extracted iOS file system (accessible directory)
📦 Installation
Using uv
```bash
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



