iOS analysis using the Sysdiagnose analysis framework workshop - beginners session
Are you, or your organisation, concerned about potential compromise on your iPhone, iPad, or Apple Watch? This workshop equips you with the knowledge and tools to identify red flags on your iOS device. We delve into the world of sysdiagnose and explore methods to verify potential breaches.
This is the starter workshop, we invite you to also join the second deeper dive session with deeper analysis.
This is (more or less) the same workshop that was given at hack.lu 2025.
Are you, or your organisation, concerned about potential compromise on your iPhone, iPad, or Apple Watch? This workshop introduces you to some knowledge and tools to identify red flags on your iOS device. We delve into the world of sysdiagnose and explore methods to verify potential breaches.
During this workshop we will be:
- discussing some ways to know if an iOS device may be compromised
- explore which opensource tools exist to perform analysis
- generating a sysdiagnose file on an iPhone, iPad iWatch, ... (bring your own device)
- use multiple methods to collect the sysdiagnose (sharing, custom app, PyMobileDevice3, ...)
- use the open source sysdiagnose analysis framework to convert the diagnostics data to something usable
- explore what data it contains and (optionally) load it in splunk
- do some data analysis using Splunk and find traces of evil
In addition to providing his services as an independent cybersecurity expert, Christophe actively serves as a Belgian Cyber Reservist and contributes to open-source projects. He is the founder of the MISP Threat Sharing Platform and his contributions to the community also include the creation of MISP-maltego and pystemon, the active development of the sysdiagnose framework, as well as his previous involvement in organizing the FOSDEM conference.
When not immersed in the world of cybersecurity, Christophe enjoys outdoor pursuits such as hiking, climbing, mountaineering, and sailing, finding solace in the beauty of nature.
Incident responder for more than a decade, I'm now working for the European Commission since 2015. I'm currently in charge of the "Situational Awareness, Threat Intelligence and Malware Analysis" in the European Commission Internal CERT (EC Cybersecurity Operation Centre).