Revisiting the APFS Series
Back in 2022 I started the APFS Advent Challenge: a daily run of posts dissecting the on-disk internals of Apple’s file system. Nearly four years...
Read more : Revisiting the APFS SeriesDigital Forensic Researcher and Educator
Back in 2022 I started the APFS Advent Challenge: a daily run of posts dissecting the on-disk internals of Apple’s file system. Nearly four years...
Read more : Revisiting the APFS SeriesA 27-part deep dive into the Apple File System covering on-disk structures, B-Trees, encryption, and more.
View the series : APFS InternalsWhen I started building ida-mcp, the goal was simple: give an LLM headless access to IDA Pro through MCP (Model...
ida-mcp 2.2.0 is out. This release removes the friction between what the LLM wants to do and what MCP lets...
ida-mcp 2.1.0 is out. This release focuses on making the LLM a more efficient analyst: fewer wasted tool calls, less...
The Model Context Protocol (MCP) lets LLMs call external tools, and for reverse engineers the obvious application is connecting an...
PSpice is a SPICE circuit simulator from Cadence Design Systems that encrypts proprietary semiconductor model files to protect vendor IP...
As 2022 ends, so does my APFS Advent Challenge. Deciding at the last minute to write this series of blogs...
As we discussed in an earlier post, Apple’s Fusion Drives combine the storage capacity of a hard disk drive (HDD)...
Earlier in this series, we covered how Object Maps facilitate the implementation of point-in-time Snapshots of APFS file systems by...
Now that we know how to parse the File System Tree, analyze keybags, and unwrap decryption keys, it’s time to...