James McGee's Avatar

James McGee

@sqlmcgee

Husband || Father || Digital Forensic Examiner || Cyber Crime Investigator || SQL Query Fanatic || Sometimes I make NFTs of my Dog

42
Followers
21
Following
32
Posts
17.12.2023
Joined
Posts Following

Latest posts by James McGee @sqlmcgee

Preview
GitHub - MetadataForensics/HEART_by_Metadata_Forensics: This free tool parses Apple Health and Fitness Application data from Apple iPhone extractions in a forensic manner. This free tool parses Apple Health and Fitness Application data from Apple iPhone extractions in a forensic manner. - MetadataForensics/HEART_by_Metadata_Forensics

πŸš€ New Release: HEART by Metadata Forensics Version 1.3! πŸš€
We’ve added Local Device Time conversions! most Apple Health and Fitness application artifacts are linked to the device recorded the event, the associated time zone is preserved as well. Conversions by activity! github.com/MetadataFore...

26.02.2026 17:48 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

My own corner of Apple Health forensics lives on the Metadata Forensics company blog, The Metadata Perspective:
lnkd.in/e6HZCBFq

23.02.2026 19:38 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If you’re in digital investigations and haven’t joined the Summit yet, you still have time (Feb 23–26). It’s free, eye-opening, and full of practical takeaways:
lnkd.in/ew3taAjV

Looking forward to the rest of the week and continuing the conversation with all of you.
#MVS2026 #DFIRCommunity

23.02.2026 19:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Couldn’t start the week better-thank you Christopher Vance for the shout-out in your session, Harping on health data, during the Magnet Virtual Summit 2026! Your Mobile Unpacked series has helped so many of us, and it’s genuinely humbling to have my Apple Health contributions mentioned alongside it.

23.02.2026 19:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
GitHub - MetadataForensics/iQueryContacts: Advanced parser for Apple Contacts (AddressBook.sqlitedb) with phones, emails, addresses, social accounts, birthdays (including Chinese lunar), and group mem... Advanced parser for Apple Contacts (AddressBook.sqlitedb) with phones, emails, addresses, social accounts, birthdays (including Chinese lunar), and group memberships. - MetadataForensics/iQueryCont...

Ever wondered what secrets are in your Apple Contacts? πŸ“± iQueryContacts πŸ•΅οΈ is our new advanced SQL query work for the AddressBook.sqlitedb. All the classic data plus some new info including the Chinese lunar birthday! Find out more atΒ github.com/MetadataFore...

02.12.2025 20:42 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image
20.11.2025 00:55 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - MetadataForensics/RowIDetective: An update to our prior work within Lagging for the Win, now reporting all sms.db missing ROWID values up to the message sequence number. An update to our prior work within Lagging for the Win, now reporting all sms.db missing ROWID values up to the message sequence number. - MetadataForensics/RowIDetective

🧩 RowIDetectiveΒ πŸ•΅οΈβ€β™‚οΈ formerly detailed Lagging for the Win: Querying for Negative Evidence in the sms.db. Now detecting missing messages at the end of Apple sms.db. Because every gap tells a story.
πŸ”— github.com/MetadataFore...

13.11.2025 19:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - MetadataForensics/HEART_by_Metadata_Forensics: This free tool parses Apple Health and Fitness Application data from Apple iPhone extractions in a forensic manner. This free tool parses Apple Health and Fitness Application data from Apple iPhone extractions in a forensic manner. - MetadataForensics/HEART_by_Metadata_Forensics

πŸš€ New release! HEART by Metadata Forensics (Health Events & Activity Reporting Tool) Version 1.1.0.0!

Now supporting TAR, DAR (some), Advanced Logical (Encrypted) Extractions, iTunes Encrypted Backups.

⬇️ Download: tinyurl.com/v8zesb7h
πŸ“– Article: tinyurl.com/94rx6vk4

22.10.2025 17:12 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - MetadataForensics/HEART_by_Metadata_Forensics: This free tool parses Apple Health and Fitness Application data from Apple iPhone extractions in a forensic manner. This free tool parses Apple Health and Fitness Application data from Apple iPhone extractions in a forensic manner. - MetadataForensics/HEART_by_Metadata_Forensics

HEART by Metadata Forensics (Health Events & Activity Reporting Tool)

Free tool to parse Apple Health & Fitness data from FFS Extractions.

πŸ” 31+ artifacts supported
πŸ“Š HTML report + CSV/PDF export

⬇️ Download: tinyurl.com/v8zesb7h
πŸ“– Article: tinyurl.com/94rx6vk4

22.09.2025 15:52 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Thanks to our great DFIR Community and discussion on the matter, I’m happy to announce our Google Location History Takeout Parser, Version 1.4.1. We’ve added Horizontal Accuracy KMLs for Records.JSON data and Parking Events. Get it at tinyurl.com/4aua56u4 Google Earth example:

28.08.2025 18:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - MetadataForensics/Google-Location-History-Takeout-Parser: This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic m... This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic manner. - MetadataForensics/Google-Location-History-Takeout-Parser

πŸš€ Google Location History Timeline Parser v 1.4 is now available! This release features multithreaded processing, time elapsed tracking, input file size calculation, and location-related files including HTML, CSV, and TXT. Available here:
tinyurl.com/4dr3tuv5

15.05.2025 20:07 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - MetadataForensics/Google-Location-History-Takeout-Parser: This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic m... This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic manner. - MetadataForensics/Google-Location-History-Takeout-Parser

πŸš€ Google Location History Takeout ParserΒ Version 1.3.0.0 is here! πŸŽ‰
With enhanced KML support (TimeSpans, Descriptions & LineStrings), taking your data to the next level. Continue leveraging Google Location History Takeout & Warrant Return data.
πŸ‘‰ tinyurl.com/2s8yzksx

21.03.2025 18:36 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Excited for this release, best is yet to come with the LEAPPs! Fantastic project, resource, and tool

17.02.2025 15:10 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Examining the United States v. Ladonies P. STRONG Case The case US v. Strong addresses the legality of warrantless searches of mobile devices, highlighting Fourth Amendment privacy rights. When Strong’s device was searched without a warrant, it r…

We’re thrilled to unveil "Legal Bytes in a Digital World," our new article series examining the intersection of law, technology, and digital forensics. In our debut piece, we explore US v. Strong - available here: tinyurl.com/ymn2ju28 Stay tuned for in-depth analysis and expert perspectives in DFIR.

14.02.2025 14:20 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Many thanks to Magnet Forensics, Hexordia, and the CTF authors for this great experience! Glad the timing worked out that I was able to participate - really enjoyable, creative, and challenging. Still may go back and look at some more of these questions..

13.02.2025 23:19 πŸ‘ 2 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Preview
Hello! Who is on the Line? Have you ever wondered how many individuals were on a phone call or Facetime call when reviewing data extracted from an iOS device? This question came up in a case recently when information was dev…

πŸ” New article from Metadata Forensics! πŸ“± β€œHello! Who is on the Line?” – we’re diving into parsing iPhone group calls, something not previously supported by commercial or open-source mobile forensic tools. Check it out πŸ‘‰ tinyurl.com/3n6c3374

05.02.2025 21:23 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image
01.02.2025 04:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

πŸ₯³ Now also available within iLEAPP! πŸŽ‰ Such an incredible tool and community resource πŸ™Œ

01.02.2025 04:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Beyond the Logs: Using the Health App to Uncover Device Model and OS History This article explores both the healthdb_secure.sqlite and healthdb.sqlite databases for data indicating devices possessed by the user, reviews device information hand-in-hand with OS version and ti…

πŸ•΅οΈβ€β™‚οΈπŸ’Ύ Uncover your device’s secret history! "Beyond the Logs: Using the Health App to Uncover Device Model and OS History" explores Health Application databases to reveal Apple model & OS info. Find out more at tinyurl.com/2dfwn5xs #metadataforensics #DFIR

30.01.2025 15:48 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

This Thanksgiving, I’m grateful for the opportunity to make a difference and help bring justice to light. It’s the small details that matter, and I’m thankful to be part of a journey that strives for truth and fairness for all. Wishing everyone a meaningful Thanksgiving!

28.11.2024 15:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Let’s discuss: unpopular opinion? iOS 18: AFU is <72 hrs from reboot and BFU state. Lot of extraction ASAP talk, regardless of search auth. You can articulate, but with auth prior you don’t have to. What am I missing? Are auths after device seizure really going beyond 24 hrs?

14.11.2024 04:01 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image
11.11.2024 13:23 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Hexordia’s Mobile Data Structures: Honing Your Digital Forensic Edge Hexordia's Mobile Data Structures course offers comprehensive training in SQLite, PList, LevelDB, and Protobuf analysis. With interactive Zoom sessions and hands-on tasks, it provides valuable insight...

Our latest course review is now available! πŸ“±πŸ§  Explore Hexordia’s Mobile Data Structures: Honing Your Digital Forensic Edge for our thoughts on this course. πŸ“ˆπŸ“Š Find it here: tinyurl.com/msb27jyz πŸ”—

06.09.2024 14:11 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
MetadataForensics - Overview Alongside seeking the digital truth and client satisfaction in all our cases, we also strive to further the DFIR Community with our research and work products. - MetadataForensics

πŸš€ New Release Alert! πŸŽ‰ Check out the latest versions of our Google Location History Timeline Parser and Brute Force Dictionary List Generator! Now with a new graphical interface and enhanced functionality. Download today at github.com/MetadataFore...! πŸš€

26.08.2024 20:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Rookie Reflections: A Green Examiner’s Forensic Journey Into Cellebrite I came to Metadata Forensics from a local Police department in Georgia, and while I thoroughly enjoyed the β€œfigure it out” education I accrued there. I was excited to start adding the letters to the e...

New Blog Alert:Β Rookie Reflections: A Green Examiner's Forensic Journey Into Cellebrite, available here: tinyurl.com/3xbmcrje. Discover insights, challenges, and tips from one of our newest team members in her review of Cellebrite’s CCO course!

14.08.2024 15:58 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Sleepless in Cupertino: A Forensic Dive into Apple Watch Sleep Tracking How's your sleep been lately? Currently, there are numerous sleep tracking and monitoring devices available to track, monitor, and quantify sleep patterns for users actively seeking to improve their s...

Wake up to our new article, Sleepless in Cupertino: A Forensic Dive into Apple Watch Sleep Tracking! πŸŒ™ Review how Sleep data is stored and explore parsing with SQL query solutions. πŸ” Learn how this could lend insight into the future Vitals app! πŸ“ˆ tinyurl.com/yc43kpme

01.08.2024 20:59 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - MetadataForensics/Google-Location-History-Data-Parser: This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic mann... This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic manner. - MetadataForensics/Google-Location-History-Data-Parser

Google Location History Data Parser Version 1.1.0.0 Released! Now with enhanced compatibility for older Google Location History Takeout data (~2020, 2021) and timestamp clarification, whether in Local Time or UTC+0. Available here: tinyurl.com/btu2u8za

16.07.2024 15:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Apple Watch – Worn Data Analysis The article explores a lesser-known data point in Apple Health that shows when an Apple Watch is worn. This data indicates one-hour time periods when the Watch was worn and time segments when the Watc...

πŸ” Explore Apple Watch wear data parsed from the healthdb_secure.sqlite! This data can assist in pattern of life analysis and provide valuable context for expected data recording, such as heart rate data.. πŸ“ˆπŸ‘€ Available here: tinyurl.com/2a3up53t

21.05.2024 00:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - MetadataForensics/Google-Location-History-Data-Parser: This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic mann... This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic manner. - MetadataForensics/Google-Location-History-Data-Parser

πŸ“’Β New Release Alert! We’re thrilled to announce the release of Version 1.0.1.7 of our Google Location History Data Parser! πŸŽ‰Thanks to our incredible users, your feedback drives our growth and strengthens the DFIR community. πŸ™Œ Check it out: tinyurl.com/4bptenjwΒ #DFIR

29.04.2024 20:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - MetadataForensics/Google-Location-History-Data-Parser: This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic mann... This free tool parses Google Takeout Location History Exports or Google Semantic Location History Warrant Return Data in a forensic manner. - MetadataForensics/Google-Location-History-Data-Parser

Now available! Metadata Forensics, LLC’s Google Location History Data Parser! 🌎 Get it on GitHub: tinyurl.com/4bptenjw πŸ—ΊοΈ Read about it here: tinyurl.com/4ckwta45

18.02.2024 00:52 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0