Professional iOS Forensic Scanning & Triage
Fast, deterministic artifact extraction and baseline comparison for incident responders. Operates entirely locally over USB. No jailbreak required.
The gap in mobile triage.
Traditional mobile forensic suites are heavy, slow, and expensive. They require full disk images and hours of processing time before you can begin analysis.
CALIBRE Mobile Labs provides immediate, targeted extraction of critical artifacts. Plug in a device and get actionable intelligence in minutes, not hours. It bridges the gap between basic MDM checks and full-scale lab acquisitions.
Not a hacking tool.
CALIBRE does not bypass device passcodes or break encryption. It uses authorized Apple File Conduit (AFC) and pairing records to interrogate the device exactly as iTunes or Xcode would.
Real-time analysis, live on screen
Watch artifacts surface as the scan runs. Every event is timestamped, classified, and ready to export.
Live File System Analysis
Target: /private/var/mobile/Containers/Data
Built for Incident Response
Jailbreak Detection
Identifies traces of modern checkm8/pondi based jailbreaks, anomalous file paths, and altered partition states.
Targeted Extraction
Pulls specific high-value artifacts (sysdiagnose, plists, databases) without waiting for a full backup.
Baseline Comparison
Compares current device state against known-good baselines to highlight unauthorized profiles or apps.
Profile Analysis
Extracts and parses installed configuration profiles, VPN settings, and root certificates.
Command Line UI
Rich CLI and clean GUI outputs. Designed to fit into existing SOC workflows and analyst habits.
Lightning Fast
Written in Python/C++ utilizing libimobiledevice bindings. Scans typically complete in under 5 minutes.
