v2.6 Available Now

Professional iOS Forensic Scanning & Triage

Fast, deterministic artifact extraction and baseline comparison for incident responders. Operates entirely locally over USB. No jailbreak required.

CALIBRE MOBILE LABS
FORENSIC DEEP SCAN // X-RAY MODE
SoCNANDLi-ION CELL
DEVICEiPhone 16 Pro
iOS26.5
LINK● USB SECURE
INITIALIZING DEVICE LINK..._
EXTRACTION0%
APPS 193
PERMS 1.2K
PHOTOS 8.4K
MSGS 22K
CONTACTS 612
PROFILES 9
DO NOT DISCONNECT DEVICE DURING SCAN

The gap in mobile triage.

Traditional mobile forensic suites are heavy, slow, and expensive. They require full disk images and hours of processing time before you can begin analysis.

CALIBRE Mobile Labs provides immediate, targeted extraction of critical artifacts. Plug in a device and get actionable intelligence in minutes, not hours. It bridges the gap between basic MDM checks and full-scale lab acquisitions.

Strictly Professional

Not a hacking tool.

CALIBRE does not bypass device passcodes or break encryption. It uses authorized Apple File Conduit (AFC) and pairing records to interrogate the device exactly as iTunes or Xcode would.

Requires unlocked device and valid pairing record. Authorized access only.
The Console

Real-time analysis, live on screen

Watch artifacts surface as the scan runs. Every event is timestamped, classified, and ready to export.

CALIBRE_MobileLabs.exe
Devices
iPhone 14 Pro
Modules
Jailbreak Detect
Artifact Scan
App Extraction

Live File System Analysis

Target: /private/var/mobile/Containers/Data

Status: SCANNING
TIMESTAMP
LEVEL
MODULE
MESSAGE
14:02:11.05
INFO
DeviceConnect
Established secure pairing session
14:02:12.88
SUCCESS
AuthWorker
Escalated privileges via AFC
14:02:15.20
WARN
JailbreakDetect
Found anomalous file permissions in /usr/bin
14:02:18.45
INFO
ArtifactScan
Parsing com.apple.Preferences.plist...
14:02:22.10
ALERT
NetworkScan
Discovered undocumented VPN profile configuration
Human Verification

Every scan is reviewed by a human analyst, not just software

Most scanning tools compare your device against a threat library that may be days or weeks out of date, then show you an instant automated verdict. We don't believe that's good enough for forensic work.

That's why every CALIBRE scan report is securely submitted to our lab, where a technical forensic analyst personally examines the results against threat intelligence that is updated hourly. New spyware variants, zero-day indicators and emerging attack signatures are factored into your assessment the moment they're known, not whenever a software update happens to ship.

01

Scan

The CALIBRE desktop app captures a full encrypted snapshot of your device's state.

02

Submit

The encrypted report is sent to our lab. Nothing is analysed on outdated, locally stored definitions.

03

Analyst review

A forensic analyst manually verifies the findings against the latest hourly threat intelligence.

04

Verified verdict

You receive a report you can trust, checked by an expert and current to the hour.

An instant result is only as good as the library behind it. A reviewed result is as good as the analyst and the intelligence behind it, and ours are never more than an hour old.

Core Capabilities

Built for Incident Response

Jailbreak Detection

Identifies traces of modern checkm8/pondi based jailbreaks, anomalous file paths, and altered partition states.

Targeted Extraction

Pulls specific high-value artifacts (sysdiagnose, plists, databases) without waiting for a full backup.

Baseline Comparison

Compares current device state against known-good baselines to highlight unauthorized profiles or apps.

Profile Analysis

Extracts and parses installed configuration profiles, VPN settings, and root certificates.

Command Line UI

Rich CLI and clean GUI outputs. Designed to fit into existing SOC workflows and analyst habits.

Lightning Fast

Written in Python/C++ utilizing libimobiledevice bindings. Scans typically complete in under 5 minutes.

+
Artifacts Checked
<0m
Average Scan Time
%
Local Processing
/7
Support