Workflow: Keychain Extraction & Analysis
Extract
objection -g <bundle_id> explore
> ios keychain dump # human-readable table
> ios keychain dump --json > keychain.jsonTriage Accessibility Attributes
| Attribute | Risk |
|---|---|
kSecAttrAccessibleAlways |
CRITICAL — readable when device locked |
kSecAttrAccessibleAlwaysThisDeviceOnly |
HIGH |
kSecAttrAccessibleAfterFirstUnlock |
MEDIUM — persists after reboot |
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly |
MEDIUM |
kSecAttrAccessibleWhenUnlocked |
LOW |
kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly |
BEST |
Flag any sensitive item (JWT, refresh token, OAuth secret, encryption key, PII) at MEDIUM+ accessibility.
Confirm Biometric Gating
Look for kSecAttrAccessControl presence and flags: .biometryCurrentSet, .userPresence, .devicePasscode. Items lacking SecAccessControl with sensitive contents = finding.
Live Monitoring
objection -g <bundle_id> explore
> ios hooking watch class KeychainItemWrapper
> ios hooking watch class KeychainWrapper
> ios hooking watch method "+[KeychainService getItem:]" --dump-args --dump-returnOr Frida: frida -U <bundle_id> -l scripts/keychain_hooks.js.
Lock-screen Test
# Lock device, then from jailbroken SSH:
ssh root@<device> "ls /var/Keychains/" # keychain DB presence
# Trigger the app (remote push / background fetch) and confirm whether it can still read items.Evidence Fields
Populate evidence.keychain_dump (redact real secret values to last 4 chars) and affected.bundle_id, affected.ios_version. Map to MASTG-TEST-0011 / MASVS-STORAGE-1.