# abrignoni/iLEAPP

iOS Logs, Events, And Plist Parser

Repository: https://github.com/abrignoni/iLEAPP
Canonical: https://ross.abutalabs.com/products/ileapp
Language: Python
License: MIT
License Family: permissive
Last push: 2026-09-02T13:55:23+00:00

## Health v2 (maintenance only)
Score: 100/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 100, release rhythm 99, longevity 100
- inputs: {"age_days": 2445, "days_push": 0, "days_rel": 6, "gap_med": 18, "n_releases_24m": 20}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1185, forks 295 (observed 2026-09-03T02:15:08.760244+00:00)

## What it is
iLEAPP is an open-source iOS and iPadOS forensic artifact parser that extracts logs, events, and plists from device extractions and iTunes backups. It produces HTML reports, TSV files, timelines, KML, and LAVA output for forensic analysis.

## Use cases
- parse iOS forensic extractions into readable reports
- analyze iTunes/Finder backups including encrypted ones
- generate timelines from iOS device artifacts
- extract plists and logs from iPadOS devices
- produce KML location data from iOS extractions
- process zip, tar, or folder-based mobile extractions

## When to choose
- you need to parse iOS/iPadOS 11+ forensic extractions
- you want a free, scriptable alternative to commercial mobile forensics tools
- you need HTML, TSV, timeline, or KML output from iOS artifacts
- you work with encrypted iTunes backups and need password-protected parsing

## When to avoid
- you need to parse Android artifacts (use ALEAPP instead)
- you require commercial support or court-tested validation guarantees
- you need a point-and-click tool with no technical setup and cannot use the provided GUI builds

## Facets
- artifact type: cli-tool
- maturity: active
- function: parser, cli, gui, data-science
- domain: security, developer-tools
- platform: windows, python, cli, cross-platform
- tags: digital-forensics, ios, mobile-forensics, plist, artifact-parsing, incident-response, command-line, macos, linux

## Member repositories
- abrignoni/iLEAPP (main) score 100

## Provenance
- Observed fields: from GitHub, fetched 2026-09-03T02:15:08.760244+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:28:30.393867+00:00, confidence not recorded.
  - readme: https://github.com/abrignoni/iLEAPP (fetched 2026-09-03T02:15:08.760244+00:00, sha 2235bf42bf90)
- Data as of 2026-08-30T08:39:29.467469+00:00.
