Difference between revisions of "Type KnowledgeC"
Jump to navigation
Jump to search
(Created page with "{| style="float:right;border:1px solid black" |+ Details | Defined Constant | <code>Type_KnowledgeC</code> |- | File Type Value | 1095 |- | Parent Type | Type_SQLite_Databas...") |
|||
| Line 42: | Line 42: | ||
* [[Type_File_Details]] | * [[Type_File_Details]] | ||
* [[Type_SQLite_Sample]] | * [[Type_SQLite_Sample]] | ||
| + | |||
| + | =Filenames seen= | ||
| + | * <code>knowledgeC.db</code> | ||
Revision as of 07:54, 13 February 2024
| Defined Constant | Type_KnowledgeC
|
| File Type Value | 1095 |
| Parent Type | SQLite |
| Carve | Yes |
| Format Details | Yes |
| MIME Type | application/x-sqlite3
|
| Filename Extension | db
|
| Typical Filename | knowledgeC.db
|
KnowledgeC database
Description
iOS KnowledgeC Database
Truxton Exploiters
This file type is handled by the following ETLs:
Items Produced
Truxton will extract the following from this file type:
- ENTITY_TYPE_DEVICE_NAME
- ENTITY_TYPE_MAC_ADDRESS
- EVENT_TYPE_BLUETOOTH_CONNECTED
- EVENT_TYPE_BLUETOOTH_DISCONNECTED
- Type_File_Details
- Type_SQLite_Sample
Filenames seen
knowledgeC.db