Methodology: iOS Data Storage
Storage Surfaces
| Location | Encrypted by default? | Notes |
|---|---|---|
| Keychain | Yes (varies by accessibility flag) | See workflows/keychain_extraction.md |
NSUserDefaults → Library/Preferences/*.plist |
File-level (Data Protection class) | Commonly abused for tokens |
Documents/ |
Data Protection class | Backed up to iCloud by default |
Library/Caches/ |
Data Protection class | Not backed up, but survives reboot |
tmp/ |
Data Protection class | Cleared opportunistically |
| SQLite / Realm / Core Data | File-level only | Data inside is plaintext |
| iOS Pasteboard | No | Cross-app clipboard |
Snapshot cache Library/Caches/Snapshots/ |
No | App switcher screenshots |
Data Protection Classes
# On device (jailbroken):
find /var/mobile/Containers/Data/Application/<UUID> -type f -exec ls -l@ {} \; | grep -i protectionExpected for sensitive files: NSFileProtectionComplete. Vulnerable: NSFileProtectionNone, NSFileProtectionCompleteUntilFirstUserAuthentication (survives lock).
Objection Dumps
> ios nsuserdefaults get
> ios cookies get
> ios nsurlcredentialstorage dump
> ios plist cat <path>
> sqlite connect <path> # then .tables / SELECT
> file download <remote> <local>Snapshot Leak
Background the app with sensitive data on screen. Then:
ssh root@device "ls /var/mobile/Containers/Data/Application/<UUID>/Library/Caches/Snapshots/"If the snapshot shows sensitive data → missing applicationWillResignActive: blur.
Pasteboard Leak
> ios pasteboard monitorOr hook -[UIPasteboard setString:] / -[UIPasteboard setItems:] with a small Frida script (template in references/frida_ios_snippets.md). Flag if passwords/tokens land on the general pasteboard.
Logs
idevicesyslog | grep <bundle_id>Flag tokens, PII, stack traces in NSLog output on release builds.