Showing posts with label unified log. Show all posts
Showing posts with label unified log. Show all posts

Thursday, August 27, 2026

Introducing Peach: A Companion for crush forensics, Built for Logs

Logs are one of the more painful parts of most cases — not because they're rare, but because they come from different sources, in different formats, and sometimes only as raw binary to begin with.

That's the gap Peach is built for — a new tool, and the newest addition to the crush ecosystem, for working with log data. It started because of one specific, painful version of that problem: Apple Unified Logs. Processing AUL at all is already a hurdle — it doesn't run on every system out of the box, something crush has since improved on — and once it does run, it's heavy: the underlying tooling can take a while to churn through a full extraction. What I wanted was something that processes the whole batch quickly, lets you pick a session back up later instead of starting over, and lets you set tags and notes as you go — for reuse later, not just for the one pass you're on.

But somewhere along the way, Peach stopped being an AUL tool. It's grown into something broader: a session-based analysis workbench for log data in general — AUL, EVTX, journald, and text-based logs, all handled the same way, all in the same place.

Sessions as the common thread

Peach has session handling.

A case rarely comes with just one log type. In Peach, a single session can hold AUL, EVTX, journald, and text-based logs together — the iPhone's Unified Log, the Windows event log from the same incident, the Linux server's journal, all in one place, cross-referenced with your own notes and tags.

You can close it, come back the next day, and everything — tags, notes, loaded sources — is still there.

What about crush's own log viewer?

crush has had a multi-log viewer for a while, and it's genuinely good for what it's for: opening a file and quickly seeing what's in it. It can technically handle AUL too — I just wouldn't recommend it for that, it's noticeably more time-intensive than going through Peach. Think of it as the quick look, with Peach as the place you go when the analysis needs to actually go somewhere and stay somewhere.

The formats

AUL is where it started, and still gets the most dedicated rule set — more on that below.

EVTX and journald come with their own rule sets, more IR-focused than the AUL rules — built around what tends to matter when you're looking at an incident rather than reconstructing a timeline of normal use.

Text-based logs work differently: there's no fixed rule set, because the formats vary too much. Instead, you set patterns live against the file to extract fields as you go. For some formats — syslog and pacman.log, for instance — this is already built out and ready to use. Tagging for text-based logs isn't there yet; that's still on the list.


Rules that keep growing

The tagging rules — and, for text-based logs, the format patterns — aren't a fixed set from day one. They're maintained and extended on an ongoing basis, as new artifacts get documented or new patterns turn out to be worth tagging. They all live in the open in the Peach repo, TOML files, if you want to see what's covered right now or track what gets added over time. A simple one looks like this:

[rule]
name = "aul_motion_state"
description = "Motion/activity state transitions (walking, stationary, etc.)"

[rule.match]
sourcetype = "aul"
message_contains = "Motion State Transition:"

[rule.tag]
value = "motion_state"

From crush to Peach: an AUL example

Since AUL is where Peach began, it's also the clearest example of the workflow end to end. The starting point is usually inside crush, with an iOS full filesystem extraction open.

Right-click the AUL folder (/private/var/db/diagnostics), and there's a "Send to Peach" option in the context menu.


Peach loads the data and shows the result with tags already applied from the rule set.



From there it's a normal analysis surface: I can add my own notes to specific entries,


and set my own tags on the fly — without needing to write a formal rule first. Sometimes I just want to mark something as interesting before I know yet whether it deserves to become a reusable rule. Also I can filter on time near one event.


One more thing Peach is useful for: building new rules. Spotting a pattern in the raw log and turning it into a reusable rule is a lot faster when you can search and filter the source material directly and see all events in one view.



A quick word on iLEAPP

With iLEAPP v2.2.0, AUL support landed with awesome results and awesome processing speed. I already worked on the AUL support in Peach the moment iLEAPP added support. I pulled a handful of rules from their AUL module into Peach myself; full credit is documented in each rule in the repo, no secrets there. A good chunk of the underlying artifact research behind those rules — and behind my own — comes from Tim Korver's Thesis Friday series, which has been steadily working through AUL artifacts one at a time - a really nice blog series in AUL.

Why "Peach"?

As a few people already know, I'm a big fan of Finding Nemo. Peach is named after the starfish stuck to the fish tank glass — the one who somehow always has the full overview of everything going on around her. That's pretty much the job description here too.

And yes, Rainbow Mode is back

Rainbow Mode is back — still courtesy of @dugeonlady, who suggested it in the first place because digital forensics tools don't have to be grey. Or dark. She was right then, and she's right now.


Getting it

Peach 0.2.1 is available as a standalone executable for all platforms — no installer, no dependencies to sort out first. Peach releases

crush 0.16.0, with the Peach integration built in, comes in several flavors depending on your platform — check the README for the full list, or grab the latest release directly. crush releases

🐢⭐


Update (31 Aug 2026): Peach 0.4.0 changes how rules get distributed — they'll stay in the peach-forensics repo, but a new peach-rules repo now ships them as versioned zip packages, so Peach can pull the latest rules on demand instead of requiring a full rebuild every time. The zip can also be downloaded and loaded into Peach manually, for air-gapped systems.

Saturday, April 25, 2026

Introducing crush: A DFIR Workbench for Surfing Through Data Formats

Moin! 👋

Today I want to share something a little different from the usual artifact analysis posts — I am releasing crush-forensics v0.5.0, a digital forensic analysis workbench I have been building for a while.

You can find it on GitHub: github.com/kalink0/crush-forensics

The Problem

When I work with acquisitions — especially mobile ones — I often find myself wanting to quickly look at a specific file without firing up a full forensic platform. Maybe I want to check a PLIST, peek into a SQLite database, or just confirm what a binary blob actually contains. Opening the whole acquisition in a heavy tool just to answer a quick question felt like overkill.

At the same time, reaching for a hex editor or writing a one-off script every time also gets old fast. I wanted something in the middle: a lightweight, dedicated workbench that knows about the file formats we actually work with in DFIR — and that lets me navigate directly inside ZIP and TAR archives without extracting anything to disk first.

That is what crush is.

Why "crush"?

I am a big Finding Nemo fan. Crush is the laid-back sea turtle who surfs the East Australian Current — and that is exactly the vibe I wanted for this tool: just riding through data formats, going with the flow. 🐢

The idea of surfing through file formats felt like the right metaphor — you open an archive, navigate the structure, and glide from a PLIST to a SQLite DB to a hex view without fighting the current. Dude.

What Can It Do?

crush is a Python-based GUI application (built with PySide6). It supports:

  • Opening and navigating inside ZIP and TAR archives directly — no extraction to disk needed
  • Opening single files and folders
  • Export files/folders and open them directly in external software
  • Hex Viewer
  • SQLite Viewer
  • Text Viewer with syntax highlighting and encoding detection
  • JSON Viewer (collapsible tree)
  • XML Viewer (collapsible tree)
  • PLIST and BPLIST Viewer
  • SEGB v1 and v2 Viewer
  • ABX Viewer (Android Binary XML)
  • LevelDB Viewer (Chrome LevelDB / Android app databases)
  • Image Viewer
  • Media Viewer (audio and video)
  • Multi-Log Studio — multi-source log analysis with format auto-detection, including Apple Unified Log / .tracev3 / .logarchive, syslog, and more (note: Unified Log support is currently alpha — decoding can be slow, this is actively being worked on)
  • Protobuf Viewer — schema-less, with optional schema decoding
  • PDF text extraction
  • Realm Database Viewer — header, schema/class extraction, top-ref comparison, table/column data decoding

Android ABX viewer in crush (Linux)



iOS SQLite viewer in crush (Windows)


Built-in Data Format Database

One feature I am particularly happy with is the built-in data format database. Crush identifies forensically relevant formats by magic bytes and extension, and surfaces the information directly in the UI for every selected file — including formats that do not have a dedicated viewer yet.

For each format it shows:

  • Full name and abbreviation
  • Category (database, configuration, log, ...)
  • Forensic relevance — what an investigator is likely to find here
  • Relevant platforms (iOS, Android, macOS, Windows, ...)
  • Magic bytes with offset and description
  • Links to format specs and relevant forensic research

Format Reference — the built-in data format database in crush


So for example, when you open an ABX file, crush identifies it via its magic bytes, opens it in the ABX viewer, and right there in the UI you can see that this is an Android Binary XML file used for system and app settings — plus links to the AOSP source and relevant research from CCL Solutions. No more alt-tabbing to a browser to remember what a format is.


Integrity Mode

Crush also has an optional integrity mode for auditability. When enabled:

  • Records SHA-256 hashes when files are opened or exported
  • Hashes ZIP/TAR/file sources on open (folders are not hashed)
  • Writes hashes to the log
  • Creates a crush-export-hashes.txt file next to exported data

You can toggle it via the status badge in the bottom right of the UI. It can also be turned off for faster opening of large ZIP/TAR sources. A small but useful addition for anyone who needs to demonstrate that what they examined is what they got.


Integrity Mode dialog in crush

Installation

v0.5.0 ships with pre-built binaries for Windows, Linux, and macOS — available directly from the GitHub releases page. No Python environment needed, no dependency wrangling — just download and run.

One honest caveat: the macOS binary is currently untested as I do not have a macOS system available. If you are on macOS and give it a try, please let me know how it goes via GitHub issues or direct message — that feedback would be really valuable.

If you prefer to run from source (e.g. for development), the README has full instructions, including the platform-specific system dependencies and how to download the Unified Log parser binaries.

Credits

Crush builds on some excellent work from the DFIR community. Bundled third-party modules include:

  • ccl_bplist by CCL Solutions Group — binary plist parsing
  • ccl_segb by CCL Solutions Group — SEGB parsing
  • ccl_leveldb by CCL Solutions Group — LevelDB / Chrome LevelDB parsing
  • macos-UnifiedLogs by Mandiant — Apple Unified Log parsing

Thank you to everyone in the community whose research and open source work made this possible.

Nightly Builds

If you want to live on the edge — every night a fresh build is automatically created from the latest main branch, including the most recent features and fixes. Changes are tracked in the changelog.md in the repo. Not recommended for production casework, but great if you want to try out what is coming next or help with testing.

What's Next?

There is still a lot I want to add — more decoders, better search, maybe some lightweight timeline capabilities. I will keep building as I run into things I wish it could do during actual casework.

If you try it out, I would love to hear what features would be most useful to you. Open an issue on GitHub, or reach out to me on Mastodon, Bluesky, or LinkedIn.

Until next time — happy forensicating! 🔍

GitHub: github.com/kalink0/crush-forensics